Sovereign deployment
OrthID runs as a managed, dedicated, isolated deployment in your region on 3verest's sovereign cloud - a managed sovereign cell. 3verest provisions, operates, upgrades and backs it up for you, in your region, while you keep custody of your keys and control over residency.
OrthID is not software you install. It is delivered as a fully managed service: 3verest stands up a dedicated, isolated deployment of OrthID - your sovereign cell - in the region you choose, and operates it for you. Sovereignty comes from that dedicated managed cell and from where it runs, not from you running the software yourself.
Every customer gets their own cell. Your identity data, encryption keys, audit logs and session state live inside it, inside your region, isolated from every other customer. There is no shared global control plane that can read your tenants’ data. For the residency model behind this, read Regions.
What you configure
A sovereign cell is yours to shape along the dimensions that matter for residency and key custody. You decide:
- Region. Where your cell runs. Identity data never leaves the region you pick. See Regions for the live region and the planned map.
- Key custody (BYOK). Whether OrthID manages your encryption key or you hold it yourself in your own Vault, KMS or HSM. With bring-your-own-keys, the key material never enters OrthID in usable form. See BYOK.
- Privacy mode. How sensitive fields and re-identification keys are handled, including pseudonymisation and the tamper-evident, hash-chained audit trail.
- Residency boundary. The jurisdiction your cell is pinned to and the guarantees that follow from it, so data at rest, keys and processing all stay in-region.
What 3verest operates
Everything underneath is run for you as part of the managed service. 3verest is responsible for:
- Provisioning your dedicated, isolated, region-pinned cell. See Provisioning.
- Zero-downtime upgrades. New versions are rolled out on your cell with no action required from you. See Upgrades.
- Encrypted, in-region backups and regularly tested restores. See Backups & continuity.
- Operations and monitoring of the request path, the database and the key integrations, with telemetry scrubbed of any tenant or subject data so nothing identifying leaves your boundary.
Next steps
- BYOK to encrypt identity data with keys you hold in your own Vault, KMS or HSM.
- Provisioning for how 3verest stands up your managed sovereign cell.
- Regions for residency and where your cell can run.