Every sovereign buyer eventually puts the same question to a vendor: "if we cut the path through your cloud, what's left of the product?" For cloud ZTNA and SASE, the honest answer is not much — their value is being on your traffic, inspecting it.
Ankayma's control plane only coordinates connections; it was never on your data path, and there's a Prove-it button so you don't take our word for it. The Enterprise line is that same architecture, scaled from one service to your whole stack — on infrastructure you can point to, under a key you hold.
We lead with access, not location: when the path to your data doesn't cross — and can't be read by — a vendor, residency follows by definition. Here is exactly what is structural today versus on the roadmap, so you never over-cite us.
Your data and payloads never traverse our infrastructure. There is nothing to "leave the region" because it was never on our path in the first place — sovereignty by architecture, not a setting you toggle.
From the dedicated tier, your tenant runs on its own isolated infrastructure — your own message bus and datastore, your own tenant CA — not a shared pool. Isolation you can prove per-tenant, not just assert in a policy.
Control plane pinned per-region, on-premises, or air-gapped; bring-your-own-key; a witness-signed ledger your auditor can verify independently; the highest tier lets a very large institution or government operate the control plane itself (data plane still separated). This is where we build to your regulator's specific demands — on the roadmap, with design partners, not shipping today.
Why say the roadmap part out loud? Because a sovereignty claim you can't verify is worth nothing to a regulated buyer. Layer 1 and 2 are structural and live; Layer 3 is honest roadmap. The full list of what we don't do yet is on honest limits.
The three layers above answer where your data is. This table answers who touches the path — including the parts we operate.
| Component | Role | Who controls it |
|---|---|---|
| Direct path (P2P) | The default path between two nodes | No third party on it, including us |
| Relay | Fallback when P2P can't be established | Open source. You can run it on your own infrastructure |
| Control plane | Coordinates connection setup, identity and policy. Never on the data path | We operate it in the standard configuration. Region-pinned or on-premises is an Enterprise option |
If all vendor demo and UAT access runs through one platform, that platform is a dependency your risk team has to assess. Four questions they will ask, answered:
1 · If the control plane is unavailable?
Sessions already running continue. See fail-static for the two boundaries — certificate lifetime, and revocation latency.
2 · If the company stops operating?
The client agent and the relay server are both open source. You can keep running the transport layer yourself. For the control plane, we're open to source escrow terms in a design partner agreement.
3 · What does exit look like?
Removing us means your vendors return to their existing preview workflow. No business data of yours is held in the platform — it holds access metadata, not build contents. We'd suggest writing the removal procedure and its timeline into the pilot record, so it exists before anyone needs it.
4 · Independent verification?
Not yet. See Evidence.
Worth noting for IT risk classification: because an outage here doesn't interrupt operations already running, this dependency sits differently from components on the data path. That's a fact for your assessment to weigh — not a conclusion we're proposing.
Every claim here is a button, not a brochure line: see the real path a connection took, read the signed ledger. You verify sovereignty; you don't trust it.