Sovereign AI & public sector

Sovereign AI

National inference, citizen-data training, and cross-ministry analytics: encrypted prompts, outputs, and holdings throughout.

The decryption gap is the moment data must be decrypted to be used. Institutional and government buyers.

Is this you?

Government data centre for sovereign encrypted AI

What this looks like in practice

Situation, how Umbra runs it, and what changes for the team that owns the risk.

01

National inference with encrypted prompts and outputs

Citizen-facing or civil-service AI must answer without sending plaintext prompts to a foreign or commercial host. Data-protection authorities ask where inference runs; the honest answer today is often 'abroad, decrypted.'

How it runs

APIs accept encrypted inputs at ministry gateways. Model execution on Umbra N8 nodes stays on ciphertext; decryption occurs only inside ministry key domains under statute. Prompts, context, and draft outputs never traverse foreign infrastructure in the clear.

What changes

Domestic AI services that can demonstrate data never resolved during processing. Sovereignty claims rest on cryptography, not on vendor contractual promises alone.

02

Citizen-data model training

A national model needs population-scale features without a shared plaintext training lake. Privacy impact assessments reject centralised copies; federated plaintext approaches still expose shards at the GPU.

How it runs

Feature engineering and gradient aggregation run on encrypted shards distributed across ministry data centres. Training scales on N8 nodes; identifiable records are never staged in the clear for the training cluster.

What changes

Model quality without collapsing privacy and sovereignty requirements. Programmes advance national AI capability while PIA reviewers see ciphertext-only processing at the compute tier.

03

Cross-ministry analytics

Health, treasury, and interior need joint policy models: fraud, economic planning, benefits integrity: without building a super-database of raw citizen files. Legal mandates restrict purpose and retention; plaintext merges violate both.

How it runs

Ministries contribute encrypted holdings under purpose-limited key governance. Policy models correlate in encrypted space on shared Umbra nodes; outputs are encrypted statistics released only to authorised analytical units.

What changes

Whole-of-government insight that survives privacy impact assessment. Ministries collaborate on models without surrendering raw holdings to a central plaintext warehouse.

04

Secure vendor and research collaboration

Governments engage academic and commercial partners on sensitive datasets under strict data-sharing agreements. Plaintext export to partner GPUs is prohibited; synthetic data alone insufficient for model quality.

How it runs

Partners run agreed models against encrypted citizen or operational datasets inside government-accredited Umbra nodes. Partners receive encrypted model outputs and metrics: never plaintext records: under contractually defined key release.

What changes

Research and vendor partnerships proceed without data export. Programmes retain custody while partners contribute model architecture and training expertise inside cryptographic boundaries.

Constraint

Why plaintext fails here

National AI programmes need population-scale data while citizens require that data never be exposed to vendors, foreign clouds, or ministries without mandate. Hyperscale platforms that decrypt at the accelerator boundary fail the sovereignty test. Tax, health, census, and benefits holdings are statutorily restricted; foreign model APIs export prompts by architecture. Privacy impact assessments block plaintext training lakes; lattice FHE cannot train at national scale within programme timelines.

Approach

Ciphertext through the stack

Conventional AI pipelines copy subsets into GPU farms where access control: not cryptography: is the only barrier. That fails privacy impact assessment and national security review alike. Lattice FHE at roughly 1000× below requirement remains a policy aspiration, not infrastructure. Umbra allows training and inference on encrypted citizen records under national key control at 40M ops/s per card, scaling to N8 nodes for national inference targets. Umbra runtime runs deterministically on ciphertext; RainDB, encrypted inference, and the SDK provide one surface ministries can standardise on. Nodes ship configured and acceptance-tested: the commercial unit sovereign programmes procure.

Why Umbra

Production FHE at rack scale

Sovereign AI programmes cannot credibly deploy on foreign APIs or plaintext domestic GPU farms and still claim data never resolved during processing. Umbra hardware and runtime give ministries a production path to full FHE that software lattices do not offer at rack scale: national inference, citizen-data training, and cross-ministry correlation at throughputs mapped to published specs. TEE and plaintext paths decrypt at the boundary; Umbra does not. For institutional buyers, Umbra is uniquely available as integrated hardware and runtime at this deployable form factor: not as a monopoly claim, but as a diligence-ready alternative to stacks that fail either on speed or on cryptography.

How you buy cards

Sized from one card to multi-card packs

Evaluate on one card → grow RainDB / ZChat packs under national keys → N4/N8 when procurement wants a finished system.

Start

1 × U100 in an accredited ministry host: RainDB on encrypted citizen extracts, or ZChat for private national-model smoke tests.

Scale pack

Scale packs for national inference: multi-card RainDB for cross-ministry query load; ZChat reference (6 × U100 + 2 × NVIDIA GPUs) for encrypted prompts and outputs at programme volume.

Institution path

N4 / N8 in sovereign data centres when procurement wants configured, acceptance-tested systems.

Workflow

Ministry encrypts at the gateway → RainDB / ZChat / SDK run on Umbra under national keys → decryption only inside statute-defined key domains.

Deployment

How it lands

Sovereign programmes anchor in accredited government data centres with air-gapped or sovereign-cloud paths. Evaluation starts on U100 hosts; production scales to N4 or N8 nodes sized to national inference targets: N8 at roughly 1.4 kW wall power, standard airflow, no rack redesign. Engineer-led survey, integration, burn-in, and acceptance follow public-sector procurement rhythms.

Regulatory

What buyers ask next

Data-protection law, national security classification, AI governance, and public-sector cryptography standards all apply. Umbra documentation supports privacy impact assessment via ciphertext-only processing. No FHE evaluation regime currently exists that can assess the scheme; formal certification is available customer-funded. Ministries define retention, purpose limitation, and key escrow.

Request a briefing

Bring the sector constraint. We respond within two business days.

Request a briefing Read the methodology

Integrate · Security

Also