AI Sovereignty — your data, your models, your ledger
Retail operations data is your competitive alpha, and LumicIQ is built so intelligence never costs you control of it. Tenant isolation that fails closed instead of open; a model allowlist your compliance team owns — if a frontier lab can't see your data, it doesn't; Azure separation tiers all the way up to your own subscription; and an immutable ledger of every single AI call, inspectable and exportable by you.
Your dataIsolationModel governanceSovereignty ledgerYour controldata / control flow
02Where your data lives — pick your tier
Tier 1
Shared, tenant-keyed
One platform; every record partitioned by your tenant id and every state key carries it. Adversarial cross-tenant isolation tests gate every release.
Tier 2
Region-pinned
Your deployment pinned to a chosen Azure geography — EU Data Boundary compatible, for data-residency and regulatory requirements.
Tier 3
Dedicated silo
Your own Cosmos DB, Event Hubs, Redis, SQL and storage accounts. Identical code — only infrastructure parameters differ — so promotion is provisioning, not a migration.
Tier 4
Your Azure subscription
LumicIQ deployed into your own Azure tenant with keyless managed identity. We never hold your keys, and your data never leaves your cloud.
03The commitments
Tuning that serves you
Your data tunes your agent — the learning accrues to your stores, and it happens on the ledger. Frontier providers still qualify only with no-training terms; regulated tenants can force direct or local models.
Nothing hidden in code
Your configuration describes your business — it never encodes secret decision rules. The reasoning behind every suggestion sits on the ledger, readable end to end.
The exit right
Your events, knowledge, agent memory and every AI call export in one canonical JSON format. Leaving is a download, not a negotiation.
Named human access
Exactly two audited platform roles can cross a tenant boundary — enumerated, logged, and reportable to you. There is no quiet support backdoor.