Sovereignty becausethe work happens here,not because we promise.
72% of IT leaders now name data sovereignty their top AI challenge. Every other answer is contractual: a promise about what someone else will do with your data. Ours removes the transfer entirely: the model runs on your machine, so there is nothing to govern.
Sovereignty, residency and localisation are three different things.
They get used interchangeably, and teams end up non-compliant despite “storing data in Europe”. Here is what we mean, precisely.
Data residency
Where the bytes physically sit. Satisfiable by choosing a region in a cloud console.
Data localisation
A legal requirement that certain data must not leave a jurisdiction at all.
Data sovereignty
Which legal authority can compel access. A US-incorporated provider can be compelled under the CLOUD Act regardless of where the data sits.
MeghaOS addresses all three by removing the transfer. Data that never leaves the device has no residency question, crosses no border, and is subject to no third party's jurisdiction.
Where your data actually goes.
The interesting question is not where data is stored. It is how far it travels to get an answer, and who else sees it on the way.
What we assume goes wrong, and what holds when it does.
Forrester expects a publicly known agentic-AI breach this year. The failure modes below are the ones worth designing against.
A compromised agent tries to exfiltrate your files
Run a local model and there is no outbound request in the reasoning path at all: nothing to intercept and nothing to leak to. Anything that does reach outside, a hosted model or a connected service, is something you configured and can see.
Generated code attempts to do damage
Generated code runs in the workspace you opened, under a command policy that refuses destructive operations outright and holds risky ones for your approval.
A web page tries to instruct the browsing agent
Page content is observed data, not commands. Irreversible actions (sending, purchasing, deleting, granting OAuth) stop and ask you first, quoting the exact details off the page so you are approving the real thing.
A connected MCP server behaves badly
Connecting a server is the approval; its tools then run without interrupting you on every call, because a prompt you click through a hundred times is not a control. Which servers you connect is the decision that matters, and it stays yours.
An agent makes a mess of your working files
The workspace is checkpointed before every turn, so undo rewinds the files and the conversation together. Exploration is only reasonable when a bad outcome is cheap.
Someone with physical access to the machine
Your platform’s full-disk encryption and screen lock cover this, and you should have both on. MeghaOS is not a substitute for either.
What we claim, and what we do not.
Where something is aspirational or unverified, it says so. A pre-beta product with overstated compliance claims is worse than one with honest gaps.
Processing is local
Memory and composition always run on the device. Inference runs there too when you select a local model at setup, and in that configuration there is no inference API call at all.
Bring your own model
A compact model is bundled so the first launch works offline. Point it at Megha, another open model through Ollama or vLLM, or a hosted provider; the choice is yours and it is visible.
Reversible agent actions
Workspace checkpoints before each turn, with undo that restores files and rewinds the conversation together.
Approval on irreversible actions
Sending, purchasing, deleting and granting access stop and ask, quoting the exact details off the page so you approve the real thing rather than a summary of it.
Runs fully offline
A model runtime and a compact model ship with the system. Selected at setup, the machine reasons with no network at all, including on an air-gapped install.
OS-level agent confinement
Kernel-enforced confinement and default-deny egress for the agent runtime. In development for the Linux editions; not in 0.1.10.
Fleet audit export
Per-tool-call logs with streaming export to a SIEM. In design with early enterprise partners; tell us your format and it will shape ours.
SOC 2 / ISO 27001
No certification claimed. We would rather say so plainly than imply one. Talk to us about your compliance requirements.
Why this became urgent in 2026.
EU AI Act Article 10
Data governance documentation is required for high-risk AI systems, with enforcement from 2 August 2026 and penalties reaching €35 million or 6% of global turnover. Local processing removes most of the data-transfer surface that documentation has to cover.
The US CLOUD Act
US authorities can compel American-incorporated cloud providers to produce data stored anywhere in the world, including in EU data centres. Choosing an EU region does not resolve this; not transferring the data does.
Machine identity outpacing human identity
By the end of 2026, most organisations will manage more agent and workload identities than human ones. Current IAM models were not built for autonomous non-human trust at scale, which is part of why keeping the work on a machine the organisation already owns is the tractable answer today.
The production gap
Roughly 11% of agentic use cases have reached production despite widespread piloting. The blocker is usually risk control, not capability, which is why keeping the data on the machine, and the actions reversible, matters more than model benchmarks.
Referenced against NIST SP 800-207 Zero Trust Architecture and ISO/IEC 27001 control principles.
Bring us your threat model.
If there is a control you need that is not here, that is a useful conversation for both of us.