Sovereign deployment · EUPL open core

The bytes never have to leave your building.

Ministries, municipalities, broadcasters and newsrooms have the same problem in different words: they must show provenance without handing their material to a third party. Provena runs where you put it, with keys you hold.

Request the deployment packRead the source first
DEPLOYMENT MODEL
PROVENA Cloud

We operate it on EU infrastructure. Fastest to start, suitable for most newsrooms and municipalities.

  • Primary regionDE · Nuremberg
  • Backup regionFI · Helsinki
  • Key custodyProvena KMS
  • Time to first signature3 minutes
01FOUR KINDS OF ORGANISATION

Ministries & agencies

Public communication that is generated or assisted must be labelled, and the label must survive a citizen forwarding it. Procurement needs the source, the DPA and a named data location before anything is signed.

  • Qualified seal through your own QTSP
  • Deployment inside government cloud
  • Source escrow and EUPL licence

Broadcasters & newsrooms

Two jobs at once: sign your own output so it can be trusted downstream, and verify incoming material fast enough that the desk does not route around you.

  • Batch verify with signer shown per file
  • Shareable verdict links, no file upload
  • Signing identity per programme or desk

Municipalities

Small communication teams, many channels, no platform engineers. The watch folder and the panel cover the whole workflow without an integration project.

  • No code path required
  • Shared framework agreements
  • Monthly report ready for the council

Regulated infrastructure

Utilities, health and defence-adjacent bodies where the network cannot reach a public endpoint at all. Trust lists arrive as signed bundles on your terms.

  • Air-gapped trust list import
  • No outbound calls from the signer
  • Offline verification bundle for auditors
02 · WHAT PROCUREMENT WILL ASK

The answers, in advance.

Each of these is a document, not a paragraph. The deployment pack contains all of them, plus a reference architecture for the three models above.

Trust & Security detail
  • Where is our data processed?EU only in Cloud; entirely inside your network in the other two models.ANSWERED
  • Can we read the source?verifier-core is public under EUPL. Signing service source under NDA, escrow on request.ANSWERED
  • Who holds the private keys?You do, in your own KMS, on Compliance and Sovereign plans.ANSWERED
  • Is there a DPA and a sub-processor list?Yes, three sub-processors, all EU/EEA, listed with their role and region.ANSWERED
  • What is the SLA?99.9% for Cloud with credits; for self-hosted the SLA covers support response only.ANSWERED
  • ISO 27001?Controls implemented and documented; certification audit scheduled for Q1 2027.IN PROGRESS
  • What happens if you stop operating?Source escrow release, offline verification kit and a documented ledger export format.ANSWERED

Send us your architecture constraints, not your budget.

We will tell you within a week whether Provena fits, and say so plainly if it does not.

Request the deployment pack