The query is the intent
An agent's query is the question its operator is trying to answer, verbatim. A sovereign model that phrases its own retrieval hands that phrasing to whoever serves the results. The model stayed at home; the question did not.
Sovereign evidence infrastructure
Countries are funding sovereign compute and sovereign models. The information layer feeding those models is still a call to a search provider in someone else's jurisdiction, and every call carries the question. The unlob evidence layer deploys inside your boundary: your index, your source policy, your query record. Bring your own model.
A search API call looks like a lookup. Read it as the provider does and it is a disclosure, three times over.
An agent's query is the question its operator is trying to answer, verbatim. A sovereign model that phrases its own retrieval hands that phrasing to whoever serves the results. The model stayed at home; the question did not.
A stream of queries is a record of what an organisation is interested in and when. The names, places and dates that recur in it are a map of its attention, whether or not any single query is sensitive on its own.
Whatever a provider says it retains, it saw the query at the moment of the call, with the key that sent it. The record exists; the only question is who holds it and under whose law. That is the question this page is about.
unlob already runs its own index rather than reselling another provider's results, which is what makes a deployable edition possible at all: there is no upstream search engine for a query to be forwarded to. Inside your boundary, five things are yours.
A bounded, admission-controlled index of the open web, imported as snapshots and served from your environment.
Which hosts, owners and jurisdictions are admitted, which are excluded, and which licensed or private corpora sit beside the open web.
Handled entirely inside the boundary. No upstream provider, no telemetry channel back to unlob.
Every ground call returns what was searched, what was not, how fresh it is and which source classes are missing. Retained as your assurance record.
The query record and the receipts are kept for as long as your policy says, and deleted when it says.
And one thing is deliberately not ours: the model. The evidence layer returns structured evidence and a receipt, never a generated answer, so it sits beneath a national foundation model, an open-weights model on your own compute, or a commercial one. unlob answers what evidence exists. Your model answers what it means. That is what makes this infrastructure underneath a sovereign-model programme rather than a competitor to it.
This is the opposite of what unlob cloud does, and both are correct for where they run.
An audit trail that cannot say who asked what, when, and what evidence they were given is not an audit trail. That is what an assurance function needs from the layer beneath its models — and it is exactly what a foreign search provider holds about you today, at the moment of every call. The question is never whether your queries are recorded. It is only who holds the record.
Every shape runs the same closed product with the same API. What changes is who operates it, what crosses the boundary, and where the query record lives.
| Shape | Operated by | Crosses the boundary | Query record |
|---|---|---|---|
unlob cloud You want the evidence layer without running anything. | unlob | Your queries and the evidence returned. This is the metered product on the pricing page. | Held by unlob under the privacy policy: scoped to your tenant, retained in aggregate and fingerprinted form, and disclosed to no one. |
Customer sovereign cloud A national or regional cloud is the mandated home for government or regulated workloads. | unlob, or the customer under licence | Nothing at query time. Index snapshots come in on a schedule you set; no telemetry goes out. | Held by you, in full and attributed to the calling principal, on your retention policy. See the section on query data. |
Your VPC You already run your models and agents inside one cloud account and want the evidence layer beside them. | unlob, or the customer under licence | Nothing at query time. Index snapshots come in through an endpoint you control; no telemetry goes out. | Held by you, in full and attributed to the calling principal, on your retention policy. |
Disconnected The environment has no route to the internet by policy. | the customer | Nothing, ever. Index snapshots are carried in by hand. Crawl-on-miss is off, and why_not says so rather than reporting a page as absent from the web. | Held by you. Nothing leaves the enclave, including the record of what was asked. |
The sovereign edition is delivered as an installation, scoped with you, not switched on in the console. unlob cloud is the product that runs today on the metered plans; a sovereign installation starts from a written statement of the boundary — deployment shape, source policy, languages, retention and the cadence of index snapshots — and is priced per installation.
What a sovereign installation looks like from where you stand. Everything in the figure runs inside your environment.
Sources, under your policy
Open-web index snapshots
Imported on the schedule you set
Licensed corpora
Wires, archives, broadcasters you have rights to
Private documents
Marked private in every receipt
The evidence layer
Bounded index
Admission under your source policy
Coverage graph
Origins, owners, corroboration
Coverage receipts
What was searched, what was not, what is missing
Interface
REST
The same API as unlob cloud
MCP
The same tools, the same profiles
Query record
Full text, principal, receipt id — yours
Yours
Your sovereign model
Reasons over the evidence
Your agents
Ground, corroborate, act
Your reviewers
Replay any exchange from the record
unlob does not decide what is true and does not label content. It records what was reported, by whom, where a claim originated, which independent origins corroborate it and what is missing. The judgement stays with your model and your people.
There is no unlob model to adopt or to depend on. A sovereign-model programme keeps its model; this is the layer beneath it that says what the evidence is and when it is not enough.
The index is bounded on purpose and smaller than the well-funded competitors'. Inside a boundary that is a feature — the source policy is yours — but if raw coverage of the open web is the binding constraint, say so early and we will tell you where the gaps are.
Yes. The sovereign edition is the same closed product deployed inside your boundary — a national or regional cloud, your own VPC, or a disconnected environment — operated by unlob or run there under licence. At query time nothing crosses the boundary: not the query, not the evidence, not a telemetry record. Index snapshots come in on a schedule you control.
Not in the sovereign edition. On unlob cloud a query is sent to us and handled under our privacy policy — scoped to your tenant, retained in aggregate and fingerprinted form. In a sovereign installation the query is handled entirely inside your environment, and the record of it is yours: full text, attributed to the calling principal, on your retention policy.
No, and deliberately not. An audit trail that cannot say who asked what, when, and what evidence they were handed is not an audit trail. Each query event carries the full query, the calling principal and the id of the coverage receipt it produced, so a reviewer can replay the exchange. You are the data controller of that record, and nothing in it leaves the boundary.
No. unlob does not decide what is true and does not label content. It records what was reported, by whom, where a claim originated, which independent origins corroborate it, and what evidence is missing — and hands that to your model with a receipt. The judgement stays with your model and your people, which is the only arrangement a government, regulator or broadcaster can defend.
There is no unlob model. The evidence layer returns structured evidence and a coverage receipt, never a generated answer, so it sits beneath whichever model you run — a national foundation model, an open-weights model on your own compute, or a commercial one. unlob answers "what evidence exists"; your model answers "what it means".
No. unlob is not open source and the engine is not published; a sovereign installation is the closed product deployed inside your boundary, operated by unlob or run there under licence. What we do publish are the specifications of what a coverage receipt contains and how provenance is recorded, so an installation can be evaluated and its outputs verified without shipping the implementation.
Per installation, on a quote, not per credit. The metered plans on the pricing page are unlob cloud. A sovereign installation is scoped with you: deployment shape, source policy, languages, retention and the update cadence for index snapshots.
Tell us the jurisdiction, the deployment shape and the languages. We reply with a written boundary statement — what crosses it, what does not, and who holds the record — before anything else.