Deployment & Sovereignty4 min read

Deployment modes: cloud, sovereign & hybrid

Same code, different data boundary. Choose where AI runs by tenant and by matter.

Because every external dependency sits behind a URL, the deployment mode is a configuration choice, not a different build. The AI boundary is what changes.

ModeAI boundaryUse case
Cloud (quality)Cloud frontier models; prompt-cached, no-trainingFastest, highest-capability; the default
SovereignFully local models; no model call reaches a third partySovereign deploys; confidential matters
HybridPer-tenant / per-matter; sovereign tenants stay localMixed estates; sensitivity-based routing
BYOKYour own cloud key on any modeOrg controls the model contract + billing

Trust

A sovereignty tenant never falls back to cloud — it is enforced at startup, and a hard sovereign-only switch refuses to even construct a cloud backend. See Data sovereignty.

Two editions, one product. The managed cloud is billed on usage against a credit wallet. LexCore Sovereign is licensed instead: you run it on your own servers, pay a licence fee, and there is no per-review charge — your AI capacity is limited by your hardware, not by a balance.

Verification Guarantee: LexCore rejects any AI assertion it cannot mathematically trace to character offsets within the source agreement. It serves as a mechanical review assistant and does not constitute formal legal advice. For technical architecture details, see the Security & Trust Center.