Public sector

AI that stays in-jurisdiction
and on the record.

Residency pinning, dedicated and VPC tenancy on Enterprise, an append-only audit trail for oversight, and procurement paperwork you can read before the first call.

DPA + SLA published · cross-region movement is opt-in only

  • 8Residency regionsUS + EU GA, more on request
  • 3Tenancy optionsManaged · dedicated · VPC
  • Append-onlyAudit trailEvery administrative action
  • DPA + SLALegal artifactsPublished and linkable
Residency & tenancy

Pin the region. Pick the isolation.

Most agencies run on the managed, RLS-isolated gateway. When shared infrastructure is not acceptable, Enterprise adds a dedicated single-tenant deployment — or runs nRouter inside your own GCP, AWS, or Azure account so prompts never leave your perimeter. Either way the region is pinned at provision time and data never moves across regions without an explicit migration request.

  • Managed: RLS-isolated, generally available, live in minutes
  • Dedicated: isolated database + routing engine, region-pinned
  • VPC / BYO-cloud: your account, your perimeter. We operate the control plane
  • Append-only audit trail with actor, IP, and diff. CSV/JSON export for the oversight file

Tenancy 03 — VPC / BYO-cloud

Inside your cloud account

GCP · AWS · Azure. Traffic never leaves your perimeter

Tenancy 02 — dedicated

Single-tenant deployment

Isolated database + routing engine · region-pinned

Tenancy 01 — managed

Shared, RLS-isolated gateway

Generally available · live in minutes · US default

Government Architecture

Zero-trust LLM execution for public sector agencies

Every agency interaction is inspected for CJIS data, filtered through regional residency boundaries, routed across accredited GovCloud models, and recorded to an immutable audit ledger.

Enterprise request lifecycle: client → gateway → guardrail filter → smart router → model provider

  1. Agency Intranet / Portal

    POST /v1/chat/completions

    Citizen benefits, public records redaction, agency ops.

  2. Gateway Preflight & Auth

    :4000 · Sovereign VPC

    Agency virtual key, cost-center budget, RBAC controls.

  3. Guardrail Filter

    CJIS / FOUO Masking

    Citizen PII, SSNs, and sensitive law enforcement data scrubbed.

  4. Smart Router & Residency

    GovCloud Pinning

    40–60% taxpayer cost savings via civic tier routing.

  5. Model Endpoints

    Azure Gov · AWS GovCloud

    99.99% availability; strictly zero foreign egress.

40–60%

Taxpayer Savings

Via civic tier routing

99.99%

Agency SLA

Continuous mission uptime

< 1 ms

Routing Overhead

Sovereign proxy latency

CJIS / FOUO

Data Safeguards

Citizen PII masked

Stage 01 — Sovereign Ingress & Network Isolation

Dedicated VPC / BYO-Cloud Ingress

Agency requests enter through private VPC endpoints or dedicated sovereign gateways. Virtual keys are bound to government sub-organizations and programmatic cost centers, preventing unauthorized access across inter-agency boundaries.

Stage 02 — Inline CJIS & Citizen PII Redaction

Pre-Egress Data Protection & Secret Scanning

Payloads pass through inline sanitizers designed to protect Criminal Justice Information (CJIS) and citizen PII. Social security numbers, tax identifiers, home addresses, and system credentials are systematically redacted before provider execution.

Stage 03 — Civic Workload Tier Routing (40–60% ROI)

Public Record Summaries vs. Policy Analysis

High-volume citizen inquiries and public document indexing route to high-efficiency tier-1 models, slashing taxpayer compute costs by up to 60%. Complex legislative analysis and regulatory research route to frontier reasoning models.

Stage 04 — Sovereign GovCloud Multi-Failover (99.99% SLA)

Zero Egress Beyond Approved Geographic Borders

Egress traffic is strictly pinned to authorized US GovCloud or sovereign national enterprise cloud tenants. Fallback chains preserve mission-critical agency uptime across independent cloud regions without any data leaving national boundaries.

Stage 05 — Immutable Oversight & Inspector General Audits

SOC 2 CC7.2 & Public Records Oversight Trail

Every transaction writes an immutable, timestamped record logging the authorizing officer, cost center, model parameters, and cryptographic input/output hashes for Inspector General review, FOIA tracking, and federal compliance audits.

Integration Guide

Deploying residency-pinned public sector gateways

Configure agency gateways with strict sovereign borders, CJIS redaction, and GovCloud model routing in less than five minutes.

Installpip install openai
1# Cache: enabled (org default). Pass nrouter_cache: false to skip.
2from openai import OpenAI
3import os
4
5client = OpenAI(
6 api_key=os.environ["NROUTER_API_KEY"],
7 base_url="https://api.nrouter.ai/v1",
8)
9
10response = client.chat.completions.create(
11 model="gpt-5.4-mini",
12 temperature=1,
13 max_completion_tokens=1024,
14 messages=[
15 {"role": "user", "content": "Hello! What models do you support?"},
16 ],
17 extra_body={
18 # "nrouter_cache": False, # Uncomment to skip cache
19 },
20)
21
22print(response.choices[0].message.content)

Header Configuration & Policy Spec

# Public Sector & Agency Integration (OpenAI Python SDK)
from openai import OpenAI

client = OpenAI(
    base_url="https://api.nrouter.ai/v1",
    api_key="sk-nrouter-gov-agency-live-5820",
    default_headers={
        "x-nr-residency": "us-gov",
        "x-nr-budget-scope": "citizen-services-bureau",
        "x-nr-guardrails": "cjis-pii-mask,secret-detect,prompt-injection",
        "x-nr-audit-compliance": "soc2-cc7"
    }
)

response = client.chat.completions.create(
    model="nrouter/auto",  # Sovereign-pinned tier routing
    messages=[
        {"role": "system", "content": "You are a public records assistant. Redact confidential citizen identifiers."},
        {"role": "user", "content": "Process public records request #4092 for municipal zoning archives."}
    ],
    extra_body={
        "allowed_clouds": ["azure-gov", "aws-govcloud"],
        "fallback_models": ["anthropic/claude-3-5-sonnet", "openai/gpt-4o"]
    }
)

Dedicated VPC & BYO-Cloud Deployments

Deploy nRouter directly into agency AWS GovCloud or Azure Government VPC environments so prompts and virtual keys never traverse the public internet.

Strict Sovereign Data Residency

Hard-pin request routing, token processing, and database persistence to continental US borders or sovereign European jurisdictions with zero international routing hops.

Cost-Center Budget Caps (HTTP 402)

Enforce congressional or agency fiscal allocations per bureau. Hard ceilings prevent unexpected overruns, returning HTTP 402 when grant or budget limits are reached.

All 8 residency regions
US East (Virginia)GA
European Union (Netherlands)On request
EU North (Stockholm)On request
United Kingdom (London)On request
Canada (Montréal)On request
Australia (Sydney)On request
SingaporeOn request
India (Mumbai)On request

Need a region not listed? Most major cloud regions can be pinned on a dedicated deployment — ask sales.

Also on every plan

Core enterprise capabilities on every plan

Guardrails on every request

Prompt-injection detection and PII redaction run inline on constituent-facing assistants. Included on every plan.

Program-level budgets

Hard and soft caps per org, team, and key, so AI cost is attributable to the program that incurred it.

Procurement-ready paperwork

DPA and SLA published and linkable; MSA on request, redlines welcome; completed security questionnaire available.

Compliance — honest status

What we hold, and what we do not.

  • No FedRAMP authorization today. We state this plainly. If your procurement requires a specific government authorization, raise it early and we will scope what is feasible.
  • SOC 2 Type II is in progress (status as of August 2026); SOC 2-aligned controls operate today. The infrastructure substrate is independently SOC 2 Type II and ISO 27001 certified.
  • GDPR-compliant, with a published DPA and EU Standard Contractual Clauses for subprocessors.

Running a procurement or security review? security@nrouter.ai will send a completed questionnaire and a controls walkthrough.

Public-sector questions, answered

Can government data be strictly pinned to sovereign US or regional borders?

Yes. nRouter allows public sector agencies to hard-pin data residency to continental United States infrastructure. Ingress routing, caching, and model provider execution are locked to domestic cloud regions (US-East and US-West).

EU and international sovereign zones (UK, Canada, Australia) are also available. Prompt data never transits overseas.

Can nRouter deploy inside an agency’s dedicated cloud VPC or GovCloud tenant?

Yes. On Enterprise plans, nRouter offers dedicated single-tenant VPC deployments for AWS GovCloud and Microsoft Azure Government.

In this configuration, the routing engine and control plane run entirely inside your agency’s accredited cloud boundary, giving your security team complete perimeter control.

What is nRouter’s formal compliance and authorization status (FedRAMP, SOC 2)?

We are completely transparent: nRouter operates SOC 2-aligned security controls today, with a formal SOC 2 Type II audit in progress as of August 2026. nRouter does not yet hold a direct FedRAMP ATO. However, for dedicated VPC deployments, nRouter runs atop underlying cloud substrates (Azure Government, AWS GovCloud, Supabase) that are fully FedRAMP High and SOC 2 Type II certified.

We will never overstate or misrepresent our certification status.

How does nRouter support CJIS requirements and citizen privacy protection?

The inline guardrail filter inspects citizen interactions for Criminal Justice Information (CJIS) and sensitive identifiers (social security numbers, home addresses, dates of birth, criminal record IDs), masking them prior to model inference. In addition, zero-content logging policies ensure that prompt text and model completions are never retained in persistent disk logs.

How do agency procurement teams review terms, DPAs, and SLAs?

Our Data Processing Addendum (DPA) and enterprise Service Level Agreement (SLA) are publicly published and reviewable before procurement calls. Custom MSAs, security architecture whitepapers, and completed FedRAMP/CAIQ security questionnaires are readily available by contacting security@nrouter.ai.

Explore industry solutions

Tailored AI gateway controls for every vertical

Public sector

Bring us your residency map and procurement checklist.

We will walk through tenancy options, the residency footprint, the audit trail, and the DPA. We will also be candid about any authorization we do not yet hold.

8 residency regions · dedicated + VPC tenancy · DPA + SLA published · SOC 2 Type II audit in progress (status as of August 2026)