UK data residency
Your documents, evidence and account data are stored in the United Kingdom, and stay there.
Your data stays in the UK, and so does the inference that analyses it. Snubnose runs on UK infrastructure by default, and scales up to fully private and self-hosted deployments for the most sensitive programmes.
Many compliance platforms run on overseas cloud and run their inference overseas too. Snubnose keeps both in the UK, so you never have to choose between modern tooling and where your data lives.
Your documents, evidence and account data are stored in the United Kingdom, and stay there.
The inference that analyses your evidence runs in the UK by default, in the London region. Your content is processed onshore.
Data is encrypted in transit and at rest. Sensitive credentials are encrypted with per-environment keys that never leave their environment.
On our private tiers, if secure processing is unavailable your content is never sent elsewhere. The request stops rather than falling back to a third party.
The same platform the whole way up. The only thing that changes is how tightly the walls are drawn around your data.
Snubnose runs on UK cloud infrastructure in the London region. Your data is stored in the UK and analysed by inference that runs in the UK. The fastest way to get started, with no infrastructure for you to manage.
A dedicated, isolated environment with a private, self-hosted inference model. Your content is processed entirely within Snubnose's own infrastructure and never reaches a third-party inference service. If private processing is ever unavailable, the request fails rather than routing your data elsewhere.
Deploy Snubnose inside your own cloud tenancy or on your premises, including fully air-gapped networks. The application and a private inference model run entirely within your boundary, so your content never leaves your environment. For the most sensitive programmes.
| Tier | OnShoreDefault | Private OnShoreAvailable | Self-HostedOn request |
|---|---|---|---|
| Where it runs | UK cloud, London region | Dedicated Snubnose infrastructure | Your cloud or premises |
| Tenancy | Shared, multi-tenant | Dedicated, single-tenant | Fully isolated in your estate |
| Inference | UK, London region | Private, self-hosted model | Private, self-hosted in your boundary |
| Your content stays within | The UK | Snubnose's own infrastructure | Your own environment |
| Air-gapped option | No | No | Yes |
| Best suited to | Everyday defence supplier work | More sensitive data | The most sensitive programmes |
The same controls protect every tier. Stepping up a tier tightens the boundary, it never relaxes the fundamentals.
Every connection is secured with TLS, and your data is encrypted at rest. The tokens that connect your cloud systems are encrypted with strong, per-environment keys that never leave their environment.
Development, preview and production are fully separated, each with its own keys and its own data. Private OnShore and Self-Hosted run on dedicated infrastructure isolated from every other customer.
Every action in the workspace is recorded, and every inference call is logged with who triggered it, what it processed and when. Nothing happens to your data that you cannot account for later.
Role-based access controls mean people see only what their role needs. You decide who in your organisation can view evidence, manage controls and invite others.
What defence security teams ask before they trust a platform with their evidence.
No. On the OnShore tier your documents, evidence and account data are stored in the UK and analysed by inference that runs in the UK, in the London region. On the Private OnShore and Self-Hosted tiers your content stays within Snubnose's own infrastructure or your own environment, and is never sent to any third-party service.
On OnShore, inference runs in the UK (London region) on enterprise cloud infrastructure. On Private OnShore, it runs on a private, self-hosted model inside Snubnose's own infrastructure. On Self-Hosted, it runs on a private model inside your own environment. Inference never runs on your content outside the tier you choose.
Yes, through the Self-Hosted tier. The application and a private inference model run entirely within your boundary, with no external connectivity required, including fully air-gapped networks. Self-Hosted is available on request.
OnShore is managed UK cloud, the fastest way to start, with your data and inference kept in the UK. Private OnShore adds a dedicated, isolated environment and a private self-hosted model, so your content never reaches a third-party inference service. Self-Hosted deploys the whole platform inside your own cloud tenancy or premises, so your content never leaves your environment.
On the Private OnShore and Self-Hosted tiers, the request stops. Your content is never silently rerouted to an external service to keep a feature working. Failing closed, rather than falling back, is the default behaviour built into the platform.
Yes. Data is encrypted in transit and at rest. Sensitive credentials, such as the tokens used to connect your cloud systems, are encrypted with strong, per-environment keys that never leave their environment.
Tell us about your environment and the sensitivity of your data, and we will recommend the tier that fits. Private and self-hosted deployments are scoped with you directly.