LLM Data Boundaries — Sovereign Stack, Private Endpoints, and SME Reality
Where does your data go when LLMs connect to CRM and ERP? Malaysia SMEs need clear boundaries — sovereign cloud, VPC, and what never touches a model.
Prospects test us with: "So our customer list goes to OpenAI?"
Correct answer: only if you designed it that way — and most production designs should not.
Data classes we use on every engagement
| Class | Examples | Default model path |
|---|---|---|
| Public | Marketing copy, published SOPs | Standard API OK with policy |
| Internal | Ops metrics, anonymized logs | Enterprise API or regional host |
| Confidential | Customer PII, pricing, contracts | Private endpoint, redaction, or no LLM |
| Regulated | Health, financial identifiers | Sandbox only or no cloud LLM |
Sovereign AI Cloud — what it does and does not do
Malaysia's sovereign push improves conversation with regulators and hosts — it does not replace your obligation to classify data and log access. We map workloads to residency requirements in blueprint, not slide 47 of a vendor deck.
MCP and connector security
Each MCP server gets:
- Least-privilege OAuth scopes
- Separate credentials per environment
- Read-only phase before any write tool is enabled
Common mistake
Running Copilot/ChatGPT on full CRM export in browser — no audit trail, no retention policy. Integrated paths fix that or we block them in governance review.