
Build
Sovereign hosting
We settle where your workloads run, under whose jurisdiction, on whose hardware, and who can be compelled to produce your data — then build and operate it. Sovereignty here is a set of documented decisions with a named owner, not a label on a datasheet.
Duration
Design 3–4 weeks; build and migration scoped separately
Built on
ISO/IEC 27001:2022 · GDPR
Who this is for
CISO
Is being asked by a client or a regulator where the data sits and who can reach it.
General counsel
Needs the jurisdictional position to be accurate rather than reassuring.
CIO
Has to make a placement decision that will be hard to reverse.
Public sector or regulated buyer
Has a procurement requirement that a standard cloud answer does not satisfy.
Data residency and legal jurisdiction are not the same question
Almost every claim of sovereignty answers only the first one. The data sits in a European region, and that is true, and it is necessary, and it is not sufficient — because residency describes geography and jurisdiction describes who can compel disclosure. An organisation that has confirmed the first and assumed the second has answered the easy half.
The questions that actually determine your position are more specific. Who operates the control plane. Who holds the encryption keys, and can the operator access them. Where the support staff sit who can raise a privileged session into your environment. What the provider's parent company is subject to. And what actually happens, procedurally, if a legal instrument lands on their desk naming you.
For most of our European clients the right answer remains Microsoft Azure in EU regions, and we say so plainly. It is mature, it is certified against the standards your auditors already recognise, and residency can be enforced as a design constraint rather than a preference. Choosing something exotic to satisfy a requirement nobody wrote down is a way to spend money and reduce reliability.
Where a contract, a regulator or your own policy genuinely requires physical separation, we place workloads in colocation through local partners, on HPE and Lenovo hardware, and operate them to the same standard as the cloud estate. That is a real option and we run it — but it carries real cost and real operational burden, and we would rather you chose it deliberately than by reflex.
What we will not do is claim to put you beyond the reach of any legal instrument. Nobody can honestly promise that, and the promises circulating in this market do not survive contact with a lawyer. What we do instead is make the exposure explicit — this is who can compel what, under which law, through which route — and record the decision with the name of the person who made it. That document is what a regulator, a client and your own board will each ask for, and it is worth more than a badge.
How we do it
- 01
Requirement analysis
3–5 days
What is actually driving this — a contract clause, a regulator, a client's policy, a tender requirement, or an assumption. We ask to see the clause. A surprising proportion of sovereignty requirements dissolve on reading, and the ones that survive become much easier to design for once quoted exactly.
- 02
Placement options and trade-offs
1 week
Two to four realistic options, each with its jurisdictional position, cost, operational burden, resilience profile and what it would take to reverse. Written so that a non-technical decision-maker can choose between them.
- 03
Design
1–2 weeks
The selected option, designed: region and facility, network and connectivity, identity, key management and who holds what, backup and recovery locations, support model and where support staff are located.
- 04
Decision record
2–3 days
The placement decision, its reasoning, its residual exposure and its named owner, in a form that can be handed to an auditor, a client or a regulator without rewriting.
- 05
Build and migrate
scoped separately
Landing zone, workload migration, cutover and rollback. Where an existing estate is moving, this is scoped as a migration engagement.
- 06
Operate
ongoing
Run under the same operational standard as the rest of the estate, with the placement decision reviewed annually or whenever the legal position changes.
Named artefacts
What you receive
- Sovereignty requirement analysis, quoting the actual clauses in play
- Placement options paper with jurisdictional position, cost and reversibility for each
- Target design — region or facility, network, identity, key management, backup
- Key management model, stating explicitly who can access keys and under what process
- Data flow map, including support and administrative access paths
- Placement decision record with residual exposure and a named owner
- Support model documentation, including where support staff are located
- Annual review trigger list — the events that require the decision to be revisited
What we need from you
- The clause, policy or requirement that started this. Not a summary of it — the text.
- Your legal or compliance function in the room for the options session. This is not a purely technical decision and treating it as one is how organisations end up with an expensive answer to the wrong question.
- Current workload inventory and data classification, or an acceptance that establishing it is part of the work.
- A decision-maker with the authority to accept residual exposure, because some will remain whatever you choose.
What changes
- 01You can answer 'where is our data and who can reach it' with a document rather than a conversation.
- 02The placement is a deliberate decision with reasoning attached, not an inheritance from whoever signed first.
- 03Client and regulator questionnaires are answered from something that already exists.
- 04Residual exposure is stated and accepted rather than quietly assumed away.
- 05The decision has a review trigger, so it stays true as the legal position moves.
What it costs
On request
All prices exclude VAT.
Questions
Can you guarantee our data is beyond the reach of non-EU authorities?
No, and we would be cautious of anyone who says otherwise. What determines your exposure is the corporate structure of the operator, the location of the staff with privileged access, and the legal instruments available in each jurisdiction involved. We map that honestly, reduce it where it can be reduced, and document what remains. A claim you cannot defend is worse than an exposure you have written down.
Is Microsoft Azure sovereign?
Azure offers EU data residency and EU-based operation, and for most European organisations that is the right balance of jurisdiction, certification and reliability. Whether it satisfies your specific requirement depends on what that requirement actually says — which is why the first step is reading the clause rather than choosing a platform.
What does colocation actually change?
Physical separation, hardware you can point at, and an operator relationship under local law. It also means you carry more of the operational burden and the resilience is what you build rather than what you inherit. It is the right answer for some requirements and an expensive answer for others.
Who operates it once it is built?
We can, under Sovereign Secured Operations. Monitoring runs continuously. Out of hours, containment is automated and a named on-call engineer is reachable for severity-one events. Or your team can operate it, and we hand over with runbooks. We will tell you which we think fits your capacity rather than which we would prefer to sell.

Leave with your top three risks documented
Thirty minutes with a senior practitioner. No slideware, no sales engineer.