Home · Sovereignty

Our position

Sovereignty is an architecture decision, not a paragraph in a contract

Knowing where your data sits, who can compel access to it, and how you would leave a platform if you had to. These are engineering questions, and they get answered in the integration layer.

Sovereignty stopped being a philosophical debate the moment it became a contractual and regulatory one. The EU Data Act frames access, portability and switching. DORA asks financial entities for an annual register of their ICT third parties. NIS2 imposes registration and incident duties. The Cyber Resilience Act pushes security into the design phase. eIDAS 2 changes how identity and signature work across borders.

Every one of those obligations is answered with the same underlying artefact: an accurate, maintained map of your flows, and control over where they run. That is our trade. We write the routing rules, hold the certificates and plan the cut-over. Sovereignty is decided in those artefacts.

Where to start

A sovereignty assessment, in 10 days

Book an assessment

Offices

  • Brussels
  • Luxembourg
  • Paris

What we actually mean

5 questions a sovereign architecture has to answer

Where does the data rest, and where does it transit?

Residency is not only about the database. A message crossing a managed service in another jurisdiction has left, even if it comes back. We map transit as carefully as storage.

Who holds the keys?

Encryption is only as sovereign as key custody. We design for customer-managed keys and document who can technically decrypt what, and under whose law.

What happens if you have to leave?

Reversibility is the sovereignty test most projects fail. Exit plans, exportable formats, no proprietary lock in the transformation layer, and a rehearsed migration path.

Can you prove it to a regulator?

Lineage, logs, the ICT third-party register, and evidence that the control described in the policy is the control running in production.

Does the AI layer respect the same boundary?

A retrieval pipeline that quietly ships documents to a model outside your perimeter has moved your data. Permissions and residency have to propagate all the way to the prompt.

European by construction

A European firm, in a European group, delivering from European offices

3 offices, one delivery organisation

Brussels, Luxembourg and Paris. Our engineers work from these locations, inside a European group, under European employment and data protection law.

A group that is European too

Satisco belongs to the Alan Allman Associates ecosystem: 4,000+ talents and 17 firms, with specialist centres of excellence we can call on without leaving the perimeter.

Sovereign-ready deployment topologies

On-premise, European cloud, or hybrid where the sensitive leg stays inside your walls. We have built all three, and we will tell you when the simple answer is good enough.

Vendor plurality on purpose

IBM, Axway, WSO2, Microsoft and open source. Holding several partnerships is what lets us design an exit rather than defend a licence.

Sovereign blockchain layer

A ledger is a sovereignty decision before it is a technology decision

Putting a payment on a public chain answers the transit question in a new way. The transaction becomes visible to everyone, permanently, and the validators sit wherever they sit. That is either exactly what you want or exactly what you cannot accept, and the answer depends on the flow rather than on the technology.

So we design the boundary explicitly, with the same five questions asked of a ledger: what goes on chain and what stays off it, whether the chain is public, permissioned or private, where the nodes run and under whose jurisdiction, who holds the signing keys, and what happens the day you have to leave.

Sovereign blockchain layer

Read the Blockchain Integration offer

On chain or off chain

Payload minimisation by design: references and proofs on the ledger, personal and commercial data in your systems. It is also what makes a permanent ledger and the GDPR right to erasure compatible.

Public, permissioned or private

An arbitration with real consequences for cost, finality, confidentiality and regulatory exposure. We document it rather than default into it.

Node residency and key custody

Where validating or observer nodes run, who operates them, and where the signing keys live. HSM and key management designed in from the start, not bolted on afterwards.

Reversibility on chain

An exit plan for the ledger itself, because chains fail, fork and lose liquidity. If leaving has not been designed, the architecture is not sovereign.

Sovereignty and AI

An unscoped AI pilot moves your data outside your perimeter

AI is the newest and least governed path out of your perimeter. A well-meaning team connects a document library to an external model, permissions do not propagate, and suddenly a contract clause is training material. The AI Act now makes data governance a condition of deployment rather than good practice.

We treat the AI layer as part of the integration architecture, because that is what it is. The corpus is a flow. The refresh is a schedule. The permissions are a mapping. All three can be built inside your boundary, and all three can be evidenced.

Where to start

  • An inventory of flows leaving the European perimeter, transit included
  • Key custody and decryption capability, mapped per platform
  • The ICT third-party register, structured from real contracts
  • A reversibility rating per critical platform, with the exit cost stated
  • The AI and retrieval paths, with their permission and residency gaps

Our position

Why the market is moving

Sept. 2025EU Data ActData access, portability and interoperability, with contractual clauses framed by regulation.
Dec. 2024MiCAMarkets in Crypto-Assets Regulation fully applicable: authorisation of crypto-asset service providers and stablecoin rules in force.
Aug. 2026AI ActTransparency obligations applicable, and data governance requirements for AI systems.
Sept. 2026Cyber Resilience ActReporting of actively exploited vulnerabilities, and secure-by-design obligations.
14 Nov. 2026SWIFT CBPR+End of MT101 coexistence and rejection of unstructured addresses.
2026–2027NIS2Transposition and first registration obligations across member states.
Nov. 2027–28camt / MT9xxProgressive retirement of reporting and statement messages.

Dates follow scheme and regulatory publications and are tracked per client as part of governance engagements.

Start with an honest map of where your data goes.

10 days, fixed price. You keep the map whatever you decide next.

Book an assessment