Deploy the same operating model across very different boundaries.
Legation separates the product architecture from the deployment profile, allowing vendors to serve commercial, regulated, European, government, and sovereign customers without inventing a new system every time.
One hub model. One customer Embassy model.
Across all profiles, the operator side runs the Legation coordination services while each customer runs an Embassy inside its own environment. The Embassy dials outward, hosts the local enforcement boundary, and connects approved customer-side workloads. Operator hosting is available in three regions—AWS Commercial, AWS GovCloud, and AWS Europe—including EU-resident regions for data-residency requirements.
Fastest path for startups and enterprise SaaS.
Commercial AWS provides the baseline multi-region hub, customer Embassy, workload identity, outbound connectivity, logging, secrets, and operational controls.
- Commercial AWS regions
- Multi-AZ container runtime
- Latency and health-based routing
- KMS and Secrets Manager
- Customer Kubernetes Embassy
Best fit
Software vendors selling into enterprises that require customer-VPC execution, data locality, or stronger isolation than a normal SaaS integration.
A government-oriented deployment path.
The GovCloud profile adjusts regions, endpoints, identity integrations, service assumptions, and operator boundaries for US public-sector and defense-adjacent environments.
- AWS GovCloud regions
- US infrastructure boundary
- FIPS-oriented endpoint configuration
- PIV/CAC federation path
- Partition-specific service validation
European regional operation without forcing a separate product.
The EU profile places hub infrastructure in European commercial AWS regions and keeps customer workloads and enforcement within the customer-selected European boundary.
- EU-only regional topology
- Regional data and log storage
- Customer-local processing
- EU service endpoints and keys
- GDPR and EU AI Act-aligned controls
- Same Embassy and workload model
For customers whose threat model includes the host and operator.
The Sovereign profile adds stronger key custody, hardware-backed cryptographic operations, tighter administrative separation, and a path to host-resistant workload protection.
- CloudHSM or PKCS#11 custody
- Private keys that do not leave hardware
- TEE-capable workload path
- Stronger operator separation
- Higher-assurance evidence and attestation
Choose by threat model—not by feature shopping.
| Customer need | Recommended starting profile |
|---|---|
| Enterprise VPC execution, no inbound access | Commercial AWS |
| EU regional operation and residency | GDPR / EU |
| US government cloud boundary | US GovCloud |
| Hardware-held keys and hostile-host resistance | Sovereign / HSM |
| Unknown or evolving requirements | Commercial baseline with tier-ready controls |