EU data residency. It’s one setting on your key.

Pin an API key to the EU — or US / Asia — and requests route only to nodes in that region. Enforced server-side, fail-closed, on a European-owned control plane. No infra, no migration.

One setting, not a migration

Pin a key to the EU — or US / Asia — when you create it. No servers to run, no data to move, nothing app-side to change.

Enforced server-side, fail-closed

The region lives on the key and is applied at routing time — a request can’t override it. If no compliant node is available you get a clean 503, never a silent fallback to a region you didn’t allow.

European-owned, end to end

The control plane that routes, schedules, and bills is European-owned, on European infrastructure. Sovereignty here comes from enforced region routing plus European ownership — not from you running machines.

On the roadmap: hardware-enforced privacy on shared infrastructure (confidential compute with remote attestation). Not available today — today’s guarantee is European ownership plus enforced region-pinning and fail-closed routing.

Pin a key. Ship in your region.