Two Kinds of Data Sovereignty
A sovereign knowledge platform and a fleet data box both sell sovereignty. I think they mean two different things by it, and only one of them fits a machine fleet.
An ad for a "sovereign AI" platform followed me around Instagram last week, and for once I stopped scrolling. A German company: your data stays in Germany, GDPR the whole way down, ask your company's knowledge anything in plain language. I went and read the whole site.
It's good. I mean that. A real product for a real problem, and the engineering underneath looks honest. But it uses the same word I've built my business on, sovereign, to mean something different from what I mean by it. That difference is the whole post.
Residency is not isolation
When a knowledge platform says sovereign, it almost always means residency: your data is stored on servers in your country, under your laws. German data centers, GDPR, no US hyperscaler in the path. That's a real guarantee, and for documents like your wiki, your SharePoint, your contracts, it's usually all you need. You upload them once, a model reads them, people ask questions. The data sits still, in a compliant place.
The kind of sovereignty I sell is isolation, and it's a different claim. Not "where is my data stored" but "does my data ever leave my control at all." Those sound like the same sentence until you're the one signing off on it. Then they aren't.
What isolation actually looks like
Concretely, for IoT Data Flow, it means:
- One binary per customer. Not a tenant in a shared platform. A separate build, running on its own.
- It runs on your infrastructure, not mine. I never get a copy of your data in my cloud. The software goes to where your data already is.
- Read-only credentials into your own databases. It queries your Postgres, your warehouse. It can't write, and it can't wander off to anything you didn't point it at.
- Every query it answers is logged. When you hand over read-only access, the honest question is "who can touch our data, and can I check afterwards?" The answer is a person (me) and an audit trail, not a policy page.
Nothing in that list copies your data into a pool next to anyone else's. That's the line residency doesn't cross: a compliant shared cloud is still a shared cloud.
Why a fleet is the second kind
A machine fleet doesn't get to pick the easy version. Its data isn't a document you upload once. It's a live stream out of your production systems: telemetry, faults, transactions, money. The box I run in production answers across 3,900+ machines and 2,900+ stores for 40+ tenants on four continents, moving 550,000 rows an hour. It goes live in seven days.
For data like that, "it's in a compliant cloud" still means it left the building. The software comes to your data isn't a line I put on the homepage to sound nice. It's the reason the architecture is shaped the way it is. Even the most compliant cloud quietly inverts it: your data goes to them.
What the cheap version gets right
Two things, and I won't pretend otherwise.
The plain-language part is exactly right. Leadership should be able to ask a question in a sentence and get an answer, without filing a BI ticket first. My box works the same way. Leadership asks in Claude, finance refreshes the numbers in Excel, engineers query SQL. So I'm not going to sniff at someone else clearing that bar.
And honestly, these platforms are doing me a favor. Every one of them teaches the market that where your data lives is a question worth asking. By the time a fleet operator emails me, they already believe sovereignty matters. I used to have to make that argument from scratch. Now I mostly just have to explain which kind.
So which one do you need?
Here's the honest split, and I'll give away the easy half for free. If your problem is "nobody can find what's in our documents," buy the sovereign knowledge tool. It's a good product and you don't need me for that.
If your problem is a fleet whose data can't leave the building (too large, too distributed, too sensitive to hand to anyone's cloud, however compliant), then residency isn't enough. You want isolation, and isolation is a different kind of thing to build. That's the one I build.
Running a fleet whose data can't leave? Tell me what leadership keeps asking that nobody can answer.