Deploy the same operating model across very different boundaries.

Legation separates the product architecture from the deployment profile, allowing vendors to serve commercial, regulated, European, government, and sovereign customers without inventing a new system every time.

01 / Common topology

One hub model. One customer Embassy model.

Across all profiles, the operator side runs the Legation coordination services while each customer runs an Embassy inside its own environment. The Embassy dials outward, hosts the local enforcement boundary, and connects approved customer-side workloads. Operator hosting is available in three regions—AWS Commercial, AWS GovCloud, and AWS Europe—including EU-resident regions for data-residency requirements.

Vendor ApplicationRegional Legation HubCustomer EmbassyLocal WorkloadsProjection
Every profile inherits a hardened, monitored baselinePrivate networking and PrivateLink, a web application firewall, network ACLs, VPC flow logs, mutually authenticated TLS, KMS and Secrets Manager custody, and an immutable audit and observability path—so the deployment itself is defended and watched, not just the link.
02 / Commercial AWS

Fastest path for startups and enterprise SaaS.

Commercial AWS provides the baseline multi-region hub, customer Embassy, workload identity, outbound connectivity, logging, secrets, and operational controls.

  • Commercial AWS regions
  • Multi-AZ container runtime
  • Latency and health-based routing
  • KMS and Secrets Manager
  • Customer Kubernetes Embassy

Best fit

Software vendors selling into enterprises that require customer-VPC execution, data locality, or stronger isolation than a normal SaaS integration.

03 / US GovCloud

A government-oriented deployment path.

The GovCloud profile adjusts regions, endpoints, identity integrations, service assumptions, and operator boundaries for US public-sector and defense-adjacent environments.

  • AWS GovCloud regions
  • US infrastructure boundary
  • FIPS-oriented endpoint configuration
  • PIV/CAC federation path
  • Partition-specific service validation
Deployment caveatGovCloud feature availability, service identifiers, logging behavior, Redis topology, and authorization boundaries must be validated in the target account and region.
04 / GDPR / EU

European regional operation without forcing a separate product.

The EU profile places hub infrastructure in European commercial AWS regions and keeps customer workloads and enforcement within the customer-selected European boundary.

  • EU-only regional topology
  • Regional data and log storage
  • Customer-local processing
  • EU service endpoints and keys
  • GDPR and EU AI Act-aligned controls
  • Same Embassy and workload model
05 / Sovereign / HSM

For customers whose threat model includes the host and operator.

The Sovereign profile adds stronger key custody, hardware-backed cryptographic operations, tighter administrative separation, and a path to host-resistant workload protection.

  • CloudHSM or PKCS#11 custody
  • Private keys that do not leave hardware
  • TEE-capable workload path
  • Stronger operator separation
  • Higher-assurance evidence and attestation
Commercial disciplineThis profile should be sold as a validated design-partner deployment until the exact HSM, TEE, image, and operational procedures have been tested together.
06 / Profile selection

Choose by threat model—not by feature shopping.

Customer needRecommended starting profile
Enterprise VPC execution, no inbound accessCommercial AWS
EU regional operation and residencyGDPR / EU
US government cloud boundaryUS GovCloud
Hardware-held keys and hostile-host resistanceSovereign / HSM
Unknown or evolving requirementsCommercial baseline with tier-ready controls