Data Sovereignty Qualification Matrix
Not every deployment mode fits every industry. Use this matrix to qualify deals and select region, payload, and witness settings — without giving up tamper-evident evidence.
Named tenant profiles
Sigigo ships configuration presets so sales and engineering start from a known posture instead of negotiating each control from scratch. Profiles map to AWS or Microsoft Azure regions.
| Profile | Typical buyer | Public anchor | Payload residency |
|---|---|---|---|
| P0 — Developer | Startup, dev/test | Disabled | Sigigo-managed |
| P1 — Standard SaaS | Tech company, low regulation | Opt-in | Sigigo-managed |
| P2 — Regulated US | Fintech, SOX | Disabled or RFC 3161 TSA | Sigigo-managed, US region |
| P3 — Healthcare US | HIPAA covered entity | Disabled | Sigigo-managed, US + BAA |
| P4 — EU Enterprise | GDPR, DORA, EU AI Act | Disabled or private witness | Sigigo-managed, EU only |
| P5 — US Federal | FedRAMP, CJIS | Disabled or private witness | GovCloud / approved region |
| P6 — Maximum sovereignty | Bank, gov, hypersensitive AI | Disabled + customer mirror | Customer-managed |
Scenario qualification matrix
Pick the closest scenario, then apply the recommended profile. Most regulated buyers run with blockchainMode: disabled — cryptographic evidence without public ledger publication.
| Scenario | Profile | Region | Anchor | Key controls |
|---|---|---|---|---|
| EU SaaS with personal data | P4 | EU only (AWS or Azure) | Disabled | DPA, erasure policy, reference-only payloads where possible |
| US healthcare / PHI | P3 | US | Disabled | BAA, no public chain, Private Commitment Mode for sensitive fields |
| US fintech / SOX | P2 | US | Disabled or TSA | WORM retention, export bundles for controls testing |
| US federal / CJIS | P5 | GovCloud | Disabled | No public chain, customer mirror optional |
| AI governance (mixed PII) | P4 or P6 | Customer choice | Disabled | Prompt references not raw prompts; customer-managed payload option |
| PCI CDE-adjacent | P2 | Segmented US/EU | Disabled | No PAN in schema; network segmentation |
Configuration dimensions
- dataRegion — Pin processing and storage (e.g. EU West, US East, GovCloud).
- payloadResidency — Sigigo-managed vs customer-managed storage for canonical payloads.
- piiPolicy — Reference-only, hash-allowed, or prohibited in canonical form.
- anchorPolicy — Disabled, RFC 3161 TSA, private witness, or opt-in public chain.
- keyManagement — Sigigo KMS or customer BYOK per region.
- Private Commitment Mode — Salted commitments; sensitive data stays in your vault.
What stays true in every profile
Sovereignty-safe settings change the witness tier (public chain), not the evidence tier. Hashing, signing, Merkle batching, and offline-verifiable export bundles remain the core product — a major step up from mutable application logs and vendor-only audit UIs.
Need help qualifying a deal? Contact us for a sovereignty workshop, explore integrations, or review Privacy Policy and Sub-processors for processor scope.
This guide supports qualification and architecture planning — it is not legal advice. Work with your legal and compliance teams on classification, DPAs, and deployment approvals. See also our Regulatory & Compliance page.