Private and sustainable by default
EU privacy requirements and 100% sustainable model infrastructure are the default routing baseline.
Deployment & Sovereignty
Katara was built in the EU for teams whose regulators, customers, and legal counsel require privacy and control over where data lives, which laws reach it, and which models touch it. Choose the boundary. The privacy and governance layer is the same everywhere.
For most software, hosting is an ops detail. For AI over regulated data, it's a legal surface: GDPR transfer rules, sector data-residency requirements, and non-EU legal reach over foreign-owned cloud providers all turn “where does this run?” into a question your DPO has to answer in writing. Most AI infrastructure vendors are US companies on US hyperscalers, and their answer is a standard contractual clause. Ours is a deployment tier.
| US | EU Data Residency | EU Sovereign | |
|---|---|---|---|
| Multi-tenant, Katara-managed | ✓ Available | ✓ Available | → Q3 |
| Single-tenant, Katara-managed | ✓ Available | ✓ Available | → Q3 |
| Single-tenant, client-managed (on-prem) | → Q4 | → Q4 | → Q4 |
Data residency solves half the problem. By default, Katara routes inference through model providers that meet EU privacy requirements and operate on 100% sustainable infrastructure. The Katara AI Gateway remains provider-neutral by design: when policy, capability, or commercial requirements call for a different model, approved workloads can route to other providers, including bring-your-own-key (BYOK) accounts and self-hosted endpoints. Policy decides per workload; the audit trail records the provider and routing decision either way.
EU privacy requirements and 100% sustainable model infrastructure are the default routing baseline.
Route selected workloads to other commercial or open-weight providers when policy allows.
Use your own provider keys, fine-tunes, or self-hosted endpoints with the same governance and audit treatment.
The platform records the routing decision so you can explain why each class of workload goes where.
Chunk-level retrieval permissions · policy-checked model traffic · governed tool registry · tamper-evident audit log · exportable evidence for regulatory examination — identical across all three tiers. The only variable is who owns the metal.
No, and we won’t call it that. EU-region hosting on a US-owned provider gives you data residency; it does not remove non-EU legal reach over the provider. That distinction is exactly why the Sovereign EU tier exists. If a vendor uses “sovereign” to describe a hyperscaler region, ask them this question.
We’re finalizing the reference architecture with our early-access partners and will publish the provider and sub-processor list before general availability.
Yes — any OpenAI-compatible endpoint, including self-hosted open-weight models, can sit behind the Gateway with the same policy and audit treatment.
Katara AI is built and operated from Barcelona, Spain.
Share your residency, sovereignty, or deployment constraints and the workflow you need to govern. We'll come back with the tier, the architecture, and the evidence trail it produces.