Technical validation
Technical Sovereignty Audit
Sovereignty is not a label on a region. It is the operational proof that inference, logs, metadata, privileged access, and dependencies stay within the controls your organisation can govern.
SCX examines the routes and control planes behind your AI stack so executives and technical leaders can see where risk is real, where assumptions are untested, and what needs to change first.
Make invisible flows visible
Trace where prompts, embeddings, logs, telemetry, and admin actions travel after they leave your application boundary.
Separate claims from controls
Validate whether "Australian hosted" means local termination, local operations, local support, and enforceable governance.
Create an action plan
Turn technical findings into priorities leadership can fund: remediate, redesign, isolate, or validate continuously.
What the audit looks for
These checks focus on the places where sovereign claims most often break down: routing, logging, model operations, privileged access, and third-party dependencies.
| Category | Checks | Purpose |
|---|---|---|
| Data Flow | Confirm AU traffic termination; identify offshore APIs or fallback routes. | Identify whether traffic leaves Australia or relies on offshore routing. |
| Logging & Telemetry | Verify where logs are stored; confirm retention and access controls. | Determine whether shadow data is stored offshore or accessible by third parties. |
| Models & Inference | Confirm inference location; check embeddings and fine-tuning paths. | Ensure prompts, embeddings, and model operations remain onshore where required. |
| Admin Control | Who has root/orchestration access? Where are privileged admins located? | Determine whether foreign support, parent entities, or offshore administrators can access systems. |
| Dependencies | Third-party libraries calling home? Hidden vendor lock-in points? | Find hidden egress, analytics, telemetry, or lock-in exposures. |
Technical risk assessment matrix
Expand each stack component to see the leak pattern, why it matters, how it can be verified, and the sovereign control SCX expects to see in place.
Sovereignty maturity model
Use this model to align governance, architecture, and executive language around a shared definition of progress.
| Level | Definition |
|---|---|
| Level 1 - Cosmetic Sovereignty | Local branding, offshore reality. |
| Level 2 - Partial Sovereignty | Some workloads local, major gaps remain. |
| Level 3 - Controlled Sovereignty | Core workloads local, governance improving. |
| Level 4 - Operational Sovereignty | Infrastructure, control and costs managed locally. |
| Level 5 - Strategic Sovereignty | AI treated as national-grade strategic infrastructure. |