Frequently asked questions

The basics

What does "sovereignty as a service" mean?
You get the control of running everything yourself (your keys, your code, your data in your jurisdiction) without having to build a security team to do it. We audit, build and operate, and cryptography proves we can't read what we run for you.

What's a trusted computing base (TCB)?
Everything that must behave correctly for your data to stay safe: hardware, software, vendors and people. The smaller it is, the fewer ways you can be breached. See Reducing your TCB.

Where are you based? Do you work outside the US?
We're based in Palo Alto, California, and we work with clients worldwide. Most work is remote. On-site work is available, and travel is billed at cost. We work in English and Spanish.

How fast can you start?
Usually within a week of signing. A Launch Audit takes 5 business days from kickoff.

Ownership and trust

Who owns the software you build?
You do: full source code, IP assignment, and your own keys and infrastructure. There are no license fees and no lock-in. See Build.

Can you read our data?
Not in confidential deployments. Secrets are released only to attested workloads, and the attestation proves which code is running. In other setups our access is scoped, time-limited, revocable and written to an immutable log.

Do you use our data to train models?
Never. And in our designs, no model provider sees your data either.

Can you guarantee we'll never be breached?
No, and be wary of anyone who says they can. We make your attack surface small, prove what's running, record everything tamper-evidently, and write down what remains out of scope.

Compliance

Can you make us SOC 2 / ISO 27001 / HIPAA compliant?
We build the controls and produce the evidence, and we get you audit-ready. Certification reports are issued by licensed CPA firms (SOC 2) and accredited bodies (ISO 27001). We don't give legal advice. Your counsel confirms your obligations.

Do you hold a SOC 2 report yourselves?
Not today. That's one reason our designs don't ask you to trust us: you hold the keys, attestation proves what runs, and the logs are verifiable without us.

Do you sign NDAs, DPAs and BAAs?
Yes. A mutual NDA comes before any technical deep dive, and we sign a DPA or BAA when the engagement needs one.

Technology

Which models do you use?
For private deployments, open-weight models sized to your hardware and task, running on-prem or inside confidential GPUs. We evaluate them on your own cases before choosing. When public, non-sensitive data is involved, a commercial API can be the cheapest right answer, and a routing policy you can read decides.

Which clouds and hardware?
AMD SEV-SNP and Intel TDX confidential VMs on the major clouds, NVIDIA confidential-computing GPUs (Hopper and Blackwell class), and your own servers, including air-gapped ones. See Deployment models.

Can you help us buy GPUs or find a data center?
Yes. We size the hardware for your workload, compare on-prem, colocation and confidential cloud on your threat model and budget, then source the GPUs and servers and colocate them in the jurisdiction you choose. See GPUs, hardware and colocation.

Do you do penetration testing?
Our audits include hands-on testing of your application and infrastructure, within an agreed scope and only with written authorization. If a customer requires a report from an independent pen-test firm, we can coordinate one.

We built our app with AI coding tools. Is that a problem?
No, but it usually leaves predictable holes. See For vibecoded startups.

Money

How much does it cost?
The Launch Audit is $2,900 fixed. Sovereignty Audits start at $14,500. A hardware and deployment plan is $4,900. Builds start at $9,500 per build week. Managed plans start at $2,500 per month. See Pricing.

How do payments work?
Audits are fixed price. Builds are 50% at kickoff and 50% on delivery of each sprint. Managed plans are billed monthly and are month to month after the first three months. We invoice in USD.

This website

Is the agent on this site private?
It's a public-information assistant that answers from these docs. It runs on a commercial model API. That's the same rule we'd give you: public data can go wherever it's cheapest, and sensitive data only goes somewhere you can verify. Please don't paste confidential information into it. We don't keep chat logs. The site itself runs on our own servers, and the call scheduler is self-hosted, with no third-party trackers.

Talk to a security expert, free. 30 minutes, no slides. Bring the thing that worries you most.
Book a call

© 2026 Yaya Tech PBC · Palo Alto, California · serving clients worldwide · andre@yaya.tech · Privacy · Terms