UK DUAA right to complain enforces in -- days · 19 June 2026 EU AI Act high-risk enforces in -- days · 2 August 2026

Deployment

Deploy where governance must live.

OBEXGATE supports on-prem, sovereign cloud, partner cloud, federated, and SDK deployment patterns from solo developer environments to enterprise-scale operations.

Deployment topology.

On-prem

Deploy inside the customer network

No external dependency. The evaluation engine, enforcement layer, audit store, and model interface all run inside the customer network. No data leaves the perimeter.

What you control: Infrastructure, network policy, key management, model selection, audit retention, and update cadence.

What OBEXGATE manages: Evaluation logic, enforcement rules, governance dimensions, and audit lineage, all operating on infrastructure you own.

Typical use case: Regulated industries where data cannot leave the network. Defence, critical national infrastructure, financial services with strict data residency requirements, and any environment where cloud dependency is a governance risk in itself.

Deployment note: Supports air-gap operation. No external API calls required once deployed.

Sovereign cloud

Deploy in the customer cloud account

Runs in the customer's own cloud account within a specified jurisdiction. Cross-region replication can be disabled. Encryption keys remain under customer control. Cloud economics without surrendering data residency.

What you control: Cloud account, region selection, key management, network policy, and audit access.

What OBEXGATE manages: Evaluation logic, enforcement rules, governance dimensions, and audit lineage, deployed into infrastructure the customer already operates.

Typical use case: Organisations with existing cloud infrastructure who need data to remain within a specific jurisdiction. EU AI Act compliance, UK data residency requirements, and multi-national organisations managing cross-border governance obligations.

Deployment note: Compatible with AWS, Azure, and GCP. Region selection is determined by the customer.

Partner cloud

Managed in the chosen jurisdiction

OBEXGATE-hosted in a partner cloud environment, single-tenant, within the jurisdiction the customer requires. No self-hosting overhead. Data stays in region.

What you control: Jurisdiction selection, tenant configuration, governance rules, and audit access.

What OBEXGATE manages: Infrastructure, hosting, updates, and operational continuity, within the jurisdiction the customer specifies.

Typical use case: Organisations that need jurisdictional data residency without the operational overhead of running their own cloud infrastructure. Mid-market organisations, professional services firms, and organisations without a dedicated infrastructure team.

Federated

Multi-instance topology

Distributed OBEXGATE instances operating across business units, regions, or jurisdictions, with a central policy authority and local enforcement. Each instance enforces governance independently. Cross-instance verification prevents any single node from self-certifying its own compliance.

What you control: Local data residency per instance, network policy, instance configuration, and which units are federated under central policy.

What OBEXGATE manages: Cross-instance Witness coordination, central policy propagation, drift detection across the federated population, and federated audit lineage.

Typical use case: Multi-national organisations with distinct regional compliance obligations. Holding companies managing subsidiaries under different regulatory regimes. Organisations where business units operate independently but must demonstrate group-level governance to a board or regulator.

Deployment note: The self-cannot-self-ground property applies across the federated topology. No instance can verify its own compliance record without cross-instance corroboration.

Admission Policy Template

Non-technical onboarding

Captures decision types, reviewers, override limits, SLAs, and escalation rules.

SDK

Govern existing workflows

The OBEXGATE SDK embeds the enforcement layer directly inside an existing product or platform. Runtime gates sit inside the application stack. No external service call is required at the point of enforcement.

What you control: Integration points, enforcement scope, rule configuration, and audit routing.

What OBEXGATE manages: Evaluation logic, enforcement verdicts, governance dimensions, and audit lineage, operating inside the application you already run.

Typical use case: Software vendors who need to ship governance as part of their product. Organisations with existing platforms where adding an external dependency at the enforcement boundary is not acceptable. Development teams who need governance embedded at the point of construction rather than bolted on after deployment.

Deployment note: Model-agnostic and cloud-agnostic. The SDK governs the action boundary, not a specific model or cloud provider.

Model-agnostic and cloud-agnostic.

OBEXGATE governs the action boundary rather than a single model family. The same governance pattern can operate across vendors, clouds, and local infrastructure.