industries · Public sector

The ENS and sovereignty: citizen data does not cross the Atlantic

Public-sector AI on European infrastructure, on-premise if needed, with zero logs: citizen data never travels to a foreign hyperscaler. Sovereignty by default, co-official languages included.

compliance

Compliance, built into the stack.

Every regulatory demand mapped to a platform capability that ships built in, with nothing to configure.

ENS

Royal Decree 311/2022 · basic / medium / high categories

RequiresSecurity measures scaled by category, with external certification every two years for medium and high systems.

HelmcodeAn auditable EU stack with documented data flows and an on-premise option that fits the category your system requires.

GDPR

Regulation (EU) 2016/679

RequiresCitizen data demands minimization, confidentiality and control over transfers.

HelmcodeZero logs by architecture and EU-only inference; on-premise for the most sensitive registries.

Sovereignty

EU-owned and operated infrastructure

RequiresCitizen data cannot realistically sit on hyperscalers subject to the US Cloud Act.

HelmcodeOpen weights run on European infrastructure or on-premise, outside the reach of foreign jurisdiction.

This page is an informational overview, not legal advice. For your obligations and the risk classification of each system, consult qualified legal counsel. AI Act Guide →

what the ENS actually says

What the ENS asks, and what it does not.

The ENS governs any information system serving a Spanish public administration, and it reaches the suppliers too. Reading it closely pays off in both directions: parts of it are stricter than people expect, and one thing everybody attributes to it is not in there.

01

Conformity travels down the chain

Article 2.3 brings private entities serving an administration inside the ENS, requires contracts to demand conformity of the information systems, and extends that to the supplier’s own supply chain as the risk analysis calls for it. Your inference provider is inside the rule, not beside it.

02

Media and alta get audited

Only básica systems may declare their own conformity. Article 38 sends media and alta through certification by audit, which means somebody reads how the whole system works, inference layer included. A component you cannot describe turns into a finding.

03

On-premise is a foreseen category

Article 30.4 says the technical instructions or the CCN-STIC guides will set the conditions for local-mode implementations of products and services originally provided in the cloud, and how those are evaluated and audited. Running it in your own datacentre is a contemplated route with its own rules.

04

What the ENS does not say

It does not require the system to run in Spain or in the EU. There is no general territoriality clause, so sovereignty is a decision you take and justify in procurement and in policy, not a box the ENS makes you tick. Anyone claiming otherwise is selling rather than citing.

CCN · Centro Criptológico Nacional (CNI) Royal Decree 311/2022 of 3 May, on the National Security Framework: Articles 2.3, 30.4 and 38. The framework is completed by the technical security instructions and the CCN-STIC guides, which the CCN issues per technology, among them CCN-STIC 884D on the secure configuration of AI services for category alta, updated in July 2024. read the report →

use cases

Your most common use cases.

The cases with the most traction in the sector, each with its own page in detail.

Recommended open models.

A starting point per task type. The full guide maps 80 cases to the open model for each one.

DeepSeek V4 FlashMIT · 1M ctx in Helmcode
Volume workhorse for citizen support and document extraction, on a flat rate.
Qwen 3.6Apache 2.0 · 256K ctx in Helmcode
The best open writing in Spanish and strong multilingual support for co-official languages.
qwen3-embedding + rerankApache 2.0 · embeddings in Helmcode
Semantic search over regulation and internal documentation.

in progressWe are distilling and quantizing these open models into small, tightly specialised versions, trained for one task rather than for all of them. A model like that runs on less hardware, answers faster and fits where the big one does not, your own datacenter included. If you have a process with volume and stable criteria, that is the conversation we want to have with you.

// faq

Questions, answered.

What the sector's technical, compliance and business teams ask.

Does this fit the ENS?

The ENS (Royal Decree 311/2022) scales security measures by category (basic, medium, high), with external certification every two years for medium and high. An auditable EU stack with documented data flows, and an on-premise option, is built to fit the category your system needs; the formal certification of each system is carried out by your organisation with an accredited entity.

Does citizen data leave our network?

Not unless you allow it. The default is EU-only inference with zero logs; on-premise runs the same models and API inside your own datacenter, so citizen data never leaves your perimeter.

Can it work in co-official languages?

Yes. Qwen 3.6 is the strongest open model for Spanish and handles co-official languages well, run privately at volume, without sending public content to a foreign API.

Why not a US hyperscaler?

Because citizen data processed on infrastructure subject to the US Cloud Act sits outside European sovereignty. Open weights run on EU infrastructure or on-premise keep the data and the jurisdiction European.

How does it integrate with our current stack?

The API is OpenAI-compatible: change the base URL and the key and existing SDKs and tools keep working unchanged.

// get started

START BURNING TOKENS

Skip the AI infra work. Deploy your first private inference endpoint today.

Flat rate. EU data. OpenAI API compatible.