Sovereignty is architectural, not contractual.
Most platforms promise not to look at your data. GateHouse is built so the raw data is never sent — and proves what crosses the boundary. Here is how the guarantees hold.
Four architectural facts.
Metadata-only control plane
GateHouse central servers receive metadata only. Raw data never reaches them — the sovereignty claim is a property of the architecture, not a clause in a contract.
Policy-gated boundary
Every disclosure — even metadata destined for GateHouse — must pass the owner’s policy gate first. One gate primitive, applied recursively at every boundary.
Provable governance
ABAC policy authored in Cedar runs in enforcement or attestation mode, so guarantees are formally checkable, not merely tested.
Zero rows exported
Analysis runs where the data lives. The inviolable counter on every surface reads zero rows exported, and it stays there.
The operational safeguards.
In transit and at rest for all metadata GateHouse holds.
Enterprise identity, provisioning and role-based access on the console.
Delegated support access is customer-granted, expiring, and fully logged.
Policy, egress, agent and admin events logged and exportable.
Data residency is a default posture, with SCCs where transfer is required.
Buyer workloads are admitted with provenance, signature and resource limits.
Where we stand.
We state posture as fact, and mark what is in progress honestly. Architecture does much of the work that certifications attest to.