Sovereign Digital Workplace — exit Big-Tech cloud via public tender

A public body replaces its Big-Tech cloud office with a Gaia-X-aligned, self-hosted workplace — email, collaboration, messaging, calls — procured via an open EU/WTO tender and handed over to the in-house team.

Delivery via public tender (GATT/WTO)

A public authority — or a sovereignty-minded enterprise — decides its email, files, chat and calls should no longer live in a Big-Tech cloud outside its control. The goal: a Gaia-X-aligned, self-hosted digital workplace — the same user experience, data inside the perimeter, no lock-in. Because it is public money above the EU/WTO thresholds, the route runs through an open public tender.

Building blocks

LayerWhat we deploy / do
WorkplaceSovereign Email · Collaboration · Messaging · Voice & Video
Trust & networkSovereign Certificate Authority · Sovereign Edge Firewall
AssuranceSecurity & Observability Platform
PeopleEnterprise Architect · Public-Tender-Lead · Security Officer · DPO
DisciplinesDigital Sovereignty · Consulting · Security

The result: a workplace the organization fully owns and operates — Gaia-X-aligned by substance, NIS2/GDPR-defensible, free of Big-Tech custody. → Talk to us

What each stakeholder is really asking

CEO

Why take on a workplace migration now — what do we actually gain?
Control over a strategic asset. Big-Tech custody of your email, documents and calls is a price-, jurisdiction- and lock-in risk, and under NIS2/GDPR a governance exposure. A sovereign, Gaia-X-aligned workplace turns that into something you own — same experience for staff, data inside your perimeter. → Digital Sovereignty
Big Tech is convenient and everyone uses it — what is the real risk?
Convenience you do not control is the risk: unilateral price moves, data under foreign jurisdiction, forced product changes, and outages or policy shifts you cannot appeal. Under NIS2/GDPR that dependency is also a board-level exposure. Sovereignty turns something you rent into an asset you steer.
Will this slow our people down or change how they work?
No — the same modern experience (mail, shared documents, calendars, chat, calls) on the same phones and desktops. What changes is where the data lives and who controls it, not the daily workflow. → Sovereign Collaboration Platform

CFO

What does it cost, and is the spend predictable?
It trades per-seat SaaS subscriptions (which grow with headcount, often invisibly) for a fixed infrastructure cost you control. A little more deliberate engineering up front, lower and predictable over the lifecycle — plus an exit option that strengthens every future vendor negotiation. We model the TCO per workload, not from a vendor catalogue.
Per-seat SaaS is opex we already budget — why change?
Because per-seat opex scales with headcount, and you cannot leave without a migration anyway. A sovereign stack is a fixed, capacity-based cost decoupled from headcount — and a permanent exit option is negotiating leverage you do not have today.
What is the cost of NOT doing this?
Compounding lock-in: every year on the Big-Tech stack raises switching cost and concentration risk, so the next price rise or policy change lands with no alternative — plus the standing NIS2/GDPR exposure of foreign custody. Inaction has a price too.

CIO

How does it integrate with what we run, and who operates it after go-live?
Open standards (SMTP/IMAP, CalDAV/CardDAV, LDAP/SAML/OIDC) let it sit alongside your estate — federation, not a rebuild. Your team operates it after handover; we document everything and can run it transitionally. No lock-in, by design. → Consulting
We cannot afford downtime — how risky is the migration?
Low: service by service, run in parallel and cut over with rollback intact — never a big-bang. Each service is proven before the next begins. → see the timeline below.
Won't self-hosting just move the operational burden onto us?
It is built to be operable — HA clusters, automation, monitoring and documentation — and we train your team or run it transitionally. The burden is bounded and under your control, not an open-ended dependency. → Sovereign Email Platform

CISO

Can I prove control to auditors, insurers and regulators?
Yes — default-deny architecture, an internal Certificate Authority, and the Security & Observability Platform give detection, audit trails and dashboards mapped to NIS2 / ISO 27001. Control you can evidence, not just assert. → Security
Is self-hosted actually more secure than a hyperscaler?
Differently secure: you trade a vast shared-tenant attack surface and opaque provider access for a perimeter you control, default-deny, with your own trust roots and full visibility. The point is control and evidence sized to your real threat model.
How do we handle incidents without a vendor's SOC?
The Security & Observability Platform provides detection, alerting and a tested incident path; a fractional CISO supplies the oversight. You get the function and the evidence, not a black-box dependency.

Project lead

What is the plan, and when do we see the first result?
Phased and reversible: a scoped discovery, then service-by-service migration with rollback intact. You get a milestone plan (the steps below), a burndown/Gantt to track it, and the first service live early — progress visible from week one.
Public tenders are slow — how do you keep momentum?
We run discovery and target architecture in parallel with tender preparation, so build starts the day the award lands. The tender is the long pole (see the Gantt); we make everything around it fast and visible.
How do you keep scope and budget from drifting?
Fixed scope from the agreed target architecture, a fixed monthly retainer (no time-and-materials drift), reversible increments, and a burndown you can see. Change is a decision, not a surprise.

In-house architect

Will you respect our architecture, or impose a black box?
We model the target with you in TOGAF/ArchiMate and build on open standards — vendor-neutral, portable, documented. We augment your architecture and hand it over; you keep control. No proprietary lock-in. → Rent-an-Enterprise-Architect
We may have chosen different components — will you force yours?
No — the building blocks are proven defaults, not mandates. Where your choice is open and sound, we build on it. The criteria are open standards, no lock-in and operability — not our preferences. → Digital Sovereignty
After you leave, can we change and extend it ourselves?
Yes — open standards, documented decisions, no proprietary glue. You can read it, modify it and extend it without us. That is the definition of done. → Consulting

How it runs, end to end

flowchart LR
    A["Idea: sovereignty mandate"] --> B["Target architecture (TOGAF/ArchiMate)"]
    B --> C["Public tender (GATT/WTO)"]
    C --> D["Build and migrate the sovereign stack"]
    D --> E["Operate: monitoring and evidence"]
    E --> F["Handover: train the in-house team"]
  • The idea — sovereignty as a decision

    A digital-sovereignty mandate — board, regulator, or NIS2/GDPR pressure — makes Big-Tech custody of email, documents and calls untenable. The target is a workplace the organization controls, without losing the experience staff expect. See Digital Sovereignty.
  • Shape it — target architecture & risk

    A fractional Enterprise Architect models the target architecture (TOGAF/ArchiMate): which services, which data flows, which integration to the existing identity provider. A Security Officer and DPO frame the NIS2/GDPR requirements up front.
  • The public tender (GATT/WTO)

    Above the EU/WTO thresholds the build must be procured in an open procedure. A Public-Tender-Lead turns the target architecture into a defensible, non-discriminatory specification and evaluation grid — GATT/WTO-compliant — so the award stands up to scrutiny. See Consulting.
  • Build & secure

    The sovereign stack goes onto the organization’s own infrastructure: Email, Collaboration, Messaging and Voice & Video, behind a Sovereign Edge Firewall with its own Certificate Authority. Migration runs service by service, with rollback intact.
  • Operate — prove control

    The Security & Observability Platform provides detection, audit trails and dashboards — the evidence that the controls work, mapped to NIS2 / ISO 27001. See Security.
  • Handover — independence

    We train the in-house team, document every decision, and hand over. The organization runs its own workplace; we step back to support on retainer only if wanted. No lock-in, by design.

Indicative phasing (not a commitment)

gantt
    dateFormat YYYY-MM-DD
    axisFormat %b
    section Shape
    Discovery            :a1, 2026-01-05, 2w
    Target architecture  :a2, after a1, 3w
    section Procure
    Public tender        :crit, a3, after a2, 12w
    section Deliver
    Build and migrate    :a4, after a3, 10w
    Operate and assure   :a5, after a4, 3w
    Handover             :a6, after a5, 2w