Compliance & Trust
European Data Residency and AI Sovereignty
Where your data lives, where AI inference runs, who can touch what, and the evidence you get for each answer. One page, written for your CISO and your DPO at the same time.
EU region
cloud deployment for European customers, anchored on Azure EU infrastructure
SOC 2
SOC 2 Type II certified
5
deployment models: EU cloud, on-premises, hybrid, sovereign-region, air-gapped
1
audit trail that produces evidence for NIS2, DORA, the EU AI Act, and KRITIS reviews
AI sovereignty is the ability to answer, with evidence, four questions about an AI system operating on your security data: where the data lives, where the AI processes it, who can access it, and who is accountable for what it does. European buyers ask these questions before they ask about features, because NIS2, DORA, the EU AI Act, and national frameworks like KRITIS make the answers a legal matter.
Morpheus AI is the accountable agentic SOC platform from D3 Security. It was designed so those four answers hold up in an audit: a governed autonomy model with per-action approval gates, one decision record for every verdict and action, and deployment options that keep data and AI inference inside the boundary you choose. It connects to your stack through 800+ bidirectional integrations wherever it runs.
This page consolidates D3’s European posture in one place and links to the evidence page for each framework. Bring it to your DPO. The residency matrix below is the same one we walk through in procurement reviews.
The Residency Matrix
Every row is a question your DPO will ask. Every answer depends on the deployment model you choose, so the matrix shows both the standard EU cloud posture and the sovereign options.
| Dimension | Standard EU cloud deployment | Sovereign options |
|---|---|---|
| Data at rest | Stored in the EU region selected at onboarding, on Azure EU infrastructure | On-premises, sovereign-region, or air-gapped storage under your control |
| Data processing | Processed in-region under standard Morpheus EU deployment | Processing stays inside your environment in on-premises and air-gapped models |
| Logs and telemetry | Retained in-region on configurable retention schedules | Retention and location fully customer-controlled |
| Backups | In-region backup within the same EU boundary | Customer-managed backup in sovereign models |
| Support access | Access-controlled and logged | Access granted by your team per session in sovereign models |
| Subprocessors | Listed in the DPA with SCCs where transfers apply | Reduced or eliminated in on-premises and air-gapped models |
Data handling
Retention schedules are configurable per tenant, and Data Processing Agreements with Standard Contractual Clauses are available for every deployment model. Your specific agreement will confirm the terms that apply to you.
Governed Autonomy Is the Sovereignty Feature
Residency answers where. Governance answers who decided. European frameworks ask both.
Human oversight, by design
Four autonomy tiers with per-action approval gates support the human-oversight expectations in EU AI Act Article 14. High-risk actions wait for a human at every tier. When Morpheus is uncertain, it defers to a human.
Evidence per framework
The decision record maps to NIS2 Articles 21 and 23, DORA Articles 5, 6, and 19, and KRITIS-Dachgesetz obligations, and produces evidence for each from the same audit trail.
Deterministic where it counts
Bounded reasoning inside deterministic governance. 70 to 80 percent of the platform runs as predictable code, so the auditable surface stays auditable even as the AI reasons.
Related
The full compliance library: NIS2, DORA, the EU AI Act, KRITIS-Dachgesetz, and the DORA compliance glossary entry. For vulnerability workflows, see the Mythos EU compliance FAQ.
faqs
Frequently Asked Questions
What European security and privacy teams ask about running an agentic SOC.
Can Morpheus keep all data inside the EU?
Yes. The standard EU deployment stores and processes data in an EU region, and on-premises, sovereign-region, and air-gapped models keep everything inside a boundary you control. The residency matrix above shows each dimension by deployment model.
What is a sovereign AI SOC?
A sovereign AI SOC is a security operations capability where the data, the AI processing, and the accountability for automated decisions all stay under the organization’s jurisdictional control. In practice it means in-region residency, in-boundary AI inference, human approval gates on actions, and an audit trail a national regulator can review.
Does the EU AI Act apply to an agentic SOC?
Security tooling obligations depend on how the system is classified and used, and your legal team makes that call. What Morpheus provides is the machinery the Act’s oversight expectations assume: human-oversight controls that support Article 14, decision records for every automated action, and configurable autonomy tiers.
What evidence does an auditor actually see?
Per incident: the triage verdict and its reasoning, every query the platform ran, every action with its command-risk tier, who approved what, and the timeline from first alert to closure. The same record produces evidence for NIS2, DORA, and KRITIS reviews.