A public authority — or a sovereignty-minded enterprise — decides its email, files, chat and calls should no longer live in a Big-Tech cloud outside its control. The goal: a Gaia-X-aligned, self-hosted digital workplace — the same user experience, data inside the perimeter, no lock-in. Because it is public money above the EU/WTO thresholds, the route runs through an open public tender.
Building blocks
The result: a workplace the organization fully owns and operates — Gaia-X-aligned by substance, NIS2/GDPR-defensible, free of Big-Tech custody. →
Talk to us
What each stakeholder is really asking
CEO
Why take on a workplace migration now — what do we actually gain?
Control over a strategic asset. Big-Tech custody of your email, documents and calls is a price-, jurisdiction- and lock-in risk, and under NIS2/GDPR a governance exposure. A sovereign, Gaia-X-aligned workplace turns that into something you own — same experience for staff, data inside your perimeter. →
Digital SovereigntyBig Tech is convenient and everyone uses it — what is the real risk?
Convenience you do not control is the risk: unilateral price moves, data under foreign jurisdiction, forced product changes, and outages or policy shifts you cannot appeal. Under NIS2/GDPR that dependency is also a board-level exposure. Sovereignty turns something you rent into an asset you steer.
Will this slow our people down or change how they work?
No — the same modern experience (mail, shared documents, calendars, chat, calls) on the same phones and desktops. What changes is where the data lives and who controls it, not the daily workflow. →
Sovereign Collaboration PlatformCFO
What does it cost, and is the spend predictable?
It trades per-seat SaaS subscriptions (which grow with headcount, often invisibly) for a fixed infrastructure cost you control. A little more deliberate engineering up front, lower and predictable over the lifecycle — plus an exit option that strengthens every future vendor negotiation. We model the TCO per workload, not from a vendor catalogue.
Per-seat SaaS is opex we already budget — why change?
Because per-seat opex scales with headcount, and you cannot leave without a migration anyway. A sovereign stack is a fixed, capacity-based cost decoupled from headcount — and a permanent exit option is negotiating leverage you do not have today.
What is the cost of NOT doing this?
Compounding lock-in: every year on the Big-Tech stack raises switching cost and concentration risk, so the next price rise or policy change lands with no alternative — plus the standing NIS2/GDPR exposure of foreign custody. Inaction has a price too.
CIO
How does it integrate with what we run, and who operates it after go-live?
Open standards (SMTP/IMAP, CalDAV/CardDAV, LDAP/SAML/OIDC) let it sit alongside your estate — federation, not a rebuild. Your team operates it after handover; we document everything and can run it transitionally. No lock-in, by design. →
ConsultingWe cannot afford downtime — how risky is the migration?
Low: service by service, run in parallel and cut over with rollback intact — never a big-bang. Each service is proven before the next begins. → see the timeline below.
Won't self-hosting just move the operational burden onto us?
It is built to be operable — HA clusters, automation, monitoring and documentation — and we train your team or run it transitionally. The burden is bounded and under your control, not an open-ended dependency. →
Sovereign Email PlatformCISO
Can I prove control to auditors, insurers and regulators?
Is self-hosted actually more secure than a hyperscaler?
Differently secure: you trade a vast shared-tenant attack surface and opaque provider access for a perimeter you control, default-deny, with your own trust roots and full visibility. The point is control and evidence sized to your real threat model.
How do we handle incidents without a vendor's SOC?
The
Security & Observability Platform provides detection, alerting and a tested incident path; a fractional
CISO supplies the oversight. You get the function and the evidence, not a black-box dependency.
Project lead
What is the plan, and when do we see the first result?
Phased and reversible: a scoped discovery, then service-by-service migration with rollback intact. You get a milestone plan (the steps below), a burndown/Gantt to track it, and the first service live early — progress visible from week one.
Public tenders are slow — how do you keep momentum?
We run discovery and target architecture in parallel with tender preparation, so build starts the day the award lands. The tender is the long pole (see the Gantt); we make everything around it fast and visible.
How do you keep scope and budget from drifting?
Fixed scope from the agreed target architecture, a fixed monthly retainer (no time-and-materials drift), reversible increments, and a burndown you can see. Change is a decision, not a surprise.
In-house architect
Will you respect our architecture, or impose a black box?
We model the target
with you in TOGAF/ArchiMate and build on open standards — vendor-neutral, portable, documented. We augment your architecture and hand it over; you keep control. No proprietary lock-in. →
Rent-an-Enterprise-ArchitectWe may have chosen different components — will you force yours?
No — the building blocks are proven defaults, not mandates. Where your choice is open and sound, we build on it. The criteria are open standards, no lock-in and operability — not our preferences. →
Digital SovereigntyAfter you leave, can we change and extend it ourselves?
Yes — open standards, documented decisions, no proprietary glue. You can read it, modify it and extend it without us. That is the definition of done. →
ConsultingHow it runs, end to end
flowchart LR
A["Idea: sovereignty mandate"] --> B["Target architecture (TOGAF/ArchiMate)"]
B --> C["Public tender (GATT/WTO)"]
C --> D["Build and migrate the sovereign stack"]
D --> E["Operate: monitoring and evidence"]
E --> F["Handover: train the in-house team"]The idea — sovereignty as a decision
A digital-sovereignty mandate — board, regulator, or NIS2/GDPR pressure — makes Big-Tech custody of email, documents and calls untenable. The target is a workplace the organization controls, without losing the experience staff expect. See
Digital Sovereignty.
Shape it — target architecture & risk
A fractional
Enterprise Architect models the target architecture (TOGAF/ArchiMate): which services, which data flows, which integration to the existing identity provider. A
Security Officer and
DPO frame the NIS2/GDPR requirements up front.
The public tender (GATT/WTO)
Above the EU/WTO thresholds the build must be procured in an open procedure. A
Public-Tender-Lead turns the target architecture into a defensible, non-discriminatory specification and evaluation grid — GATT/WTO-compliant — so the award stands up to scrutiny. See
Consulting.
Build & secure
Operate — prove control
Handover — independence
We train the in-house team, document every decision, and hand over. The organization runs its own workplace; we step back to
support on retainer only if wanted. No lock-in, by design.
Indicative phasing (not a commitment)
gantt
dateFormat YYYY-MM-DD
axisFormat %b
section Shape
Discovery :a1, 2026-01-05, 2w
Target architecture :a2, after a1, 3w
section Procure
Public tender :crit, a3, after a2, 12w
section Deliver
Build and migrate :a4, after a3, 10w
Operate and assure :a5, after a4, 3w
Handover :a6, after a5, 2w