Sovereignty
Sovereign by architecture, not by promise.
Most managed RAG platforms give you no choice: your documents must live in their account, embedded by their model, searched by their index. troveGEN offers a managed tier too — but it is an option, not the only door. Choose bring-your-own and every boundary where your data could leave becomes a connection you own; own all of them and nothing leaves at all.
Every boundary
Five places data could leave. You own all five.
This is the whole list, not a highlight reel. If a boundary is not here, it does not exist in the product.
Vector storage
Qdrant, Pinecone, pgvector or plain Postgres — yours. troveGEN upserts into it and keeps no copy of your embeddings. If you would rather not run one, the managed tier gives you a dedicated schema and namespace, not a shared table.
Embeddings
OpenAI, Azure, or any OpenAI-compatible endpoint — including a model on your own GPU. The keyless local stack in the repository runs a multilingual embedder with no API key at all.
Reranking
Cohere, a self-hosted text-embeddings-inference model, or an LLM you point at. All optional; retrieval degrades gracefully rather than failing if one is unavailable.
Generation
Off by default, per workspace. When enabled, point it at vLLM, Ollama, TGI or any compatible server. troveGEN never requires a hosted LLM to function.
Content sources
The HTTP manifest connector exists so an air-gapped install can sync from an internal system. It is deliberately never paywalled — putting it behind a plan would contradict the whole position.
Fully air-gapped
No egress. Not 'minimal' egress.
With a local embedder, a local reranker and a local LLM, troveGEN makes no outbound request whatsoever. This is a supported deployment mode with a keyless stack in the repository, not a workaround.
- Local embeddings via any OpenAI-compatible server, including the bundled keyless one.
- Local reranking via a self-hosted cross-encoder.
- Local groundedness scoring — hallucination checking runs on a small local NLI model, so verification never requires a third party either.
- Local generation via vLLM, Ollama or TGI — or no generation at all, which is the default.
- Web enrichment is off unless configured. A keyless install makes no external lookup, ever.
- The marketing site you are reading makes zero third-party requests. Fonts are self-hosted; there is no analytics script and no CDN.
Enforced, not asserted
Guarantees with a mechanism behind them.
Each of these is a specific implementation decision you can verify in the product, not a policy statement.
Credentials encrypted at rest
Every connection secret is sealed with AES-256-GCM and is write-only over the API. Once stored, no endpoint returns it — the console shows "already configured", never the value.
PII never reaches your vector store
Detection runs before embedding. Values are replaced with reversible tokens, and the mapping lives in a separate encrypted vault deliberately kept out of the data plane — so compromising the vector store reveals nothing. De-masking is permission-gated and audit-logged.
ACLs enforced inside the query
Principals are pre-filtered natively by every vector backend, never post-filtered after retrieval. A user filter is composed with AND, so a caller can never widen their own visibility. No principals under enforcement means public-only — it fails closed.
Deletion propagates
Removing a document purges its chunks, its vectors in your store, and its PII vault entries. If the vector purge fails, the whole delete aborts and stays retryable rather than silently orphaning vectors.
Tenant isolation is structural
Managed tenants get their own Postgres schema and vector namespace. Routing uses SET LOCAL, so a pooled connection can never be handed to the next request still pointing at another tenant's schema — and a static check fails the build if a data-plane query skips it.
Point-in-time, without breaking erasure
Re-ingesting supersedes rather than overwrites, so you can retrieve what a document said last quarter. A real delete still purges the entire lineage — history and the right to erasure are kept distinct on purpose.
Honest limits
What we don't claim.
A sovereignty page that lists only strengths is marketing. These are the real gaps.
No third-party certifications yet
No SOC 2 or ISO 27001 audit has been completed. If your procurement requires one today, we are not yet the right fit — and we would rather say so than imply otherwise.
Self-hosting is your operational burden
Air-gapped means you run Postgres, the vector store and the models. We document it and ship the compose stack, but the uptime is yours.
Encryption is at rest and in transit
Not homomorphic. A running troveGEN process necessarily sees plaintext to chunk and embed it — which is exactly why the PII vault keeps the mapping out of the data plane.
Run it on your own machine first.
The repository ships a keyless local stack — embeddings, reranking, groundedness scoring and a generation stub — so you can prove the whole pipeline works with no API key and no egress before you decide anything.