Home · Sovereignty
Our position
Sovereignty is an architecture decision, not a paragraph in a contract
Knowing where your data sits, who can compel access to it, and how you would leave a platform if you had to. These are engineering questions, and they get answered in the integration layer.
Sovereignty stopped being a philosophical debate the moment it became a contractual and regulatory one. The EU Data Act frames access, portability and switching. DORA asks financial entities for an annual register of their ICT third parties. NIS2 imposes registration and incident duties. The Cyber Resilience Act pushes security into the design phase. eIDAS 2 changes how identity and signature work across borders.
Every one of those obligations is answered with the same underlying artefact: an accurate, maintained map of your flows, and control over where they run. That is our trade. We write the routing rules, hold the certificates and plan the cut-over. Sovereignty is decided in those artefacts.
Offices
- Brussels
- Luxembourg
- Paris
What we actually mean
5 questions a sovereign architecture has to answer
Where does the data rest, and where does it transit?
Residency is not only about the database. A message crossing a managed service in another jurisdiction has left, even if it comes back. We map transit as carefully as storage.
Who holds the keys?
Encryption is only as sovereign as key custody. We design for customer-managed keys and document who can technically decrypt what, and under whose law.
What happens if you have to leave?
Reversibility is the sovereignty test most projects fail. Exit plans, exportable formats, no proprietary lock in the transformation layer, and a rehearsed migration path.
Can you prove it to a regulator?
Lineage, logs, the ICT third-party register, and evidence that the control described in the policy is the control running in production.
Does the AI layer respect the same boundary?
A retrieval pipeline that quietly ships documents to a model outside your perimeter has moved your data. Permissions and residency have to propagate all the way to the prompt.
European by construction
A European firm, in a European group, delivering from European offices
3 offices, one delivery organisation
Brussels, Luxembourg and Paris. Our engineers work from these locations, inside a European group, under European employment and data protection law.
A group that is European too
Satisco belongs to the Alan Allman Associates ecosystem: 4,000+ talents and 17 firms, with specialist centres of excellence we can call on without leaving the perimeter.
Sovereign-ready deployment topologies
On-premise, European cloud, or hybrid where the sensitive leg stays inside your walls. We have built all three, and we will tell you when the simple answer is good enough.
Vendor plurality on purpose
IBM, Axway, WSO2, Microsoft and open source. Holding several partnerships is what lets us design an exit rather than defend a licence.
Sovereign blockchain layer
A ledger is a sovereignty decision before it is a technology decision
Putting a payment on a public chain answers the transit question in a new way. The transaction becomes visible to everyone, permanently, and the validators sit wherever they sit. That is either exactly what you want or exactly what you cannot accept, and the answer depends on the flow rather than on the technology.
So we design the boundary explicitly, with the same five questions asked of a ledger: what goes on chain and what stays off it, whether the chain is public, permissioned or private, where the nodes run and under whose jurisdiction, who holds the signing keys, and what happens the day you have to leave.
Sovereign blockchain layer
On chain or off chain
Payload minimisation by design: references and proofs on the ledger, personal and commercial data in your systems. It is also what makes a permanent ledger and the GDPR right to erasure compatible.
Public, permissioned or private
An arbitration with real consequences for cost, finality, confidentiality and regulatory exposure. We document it rather than default into it.
Node residency and key custody
Where validating or observer nodes run, who operates them, and where the signing keys live. HSM and key management designed in from the start, not bolted on afterwards.
Reversibility on chain
An exit plan for the ledger itself, because chains fail, fork and lose liquidity. If leaving has not been designed, the architecture is not sovereign.
Sovereignty and AI
An unscoped AI pilot moves your data outside your perimeter
AI is the newest and least governed path out of your perimeter. A well-meaning team connects a document library to an external model, permissions do not propagate, and suddenly a contract clause is training material. The AI Act now makes data governance a condition of deployment rather than good practice.
We treat the AI layer as part of the integration architecture, because that is what it is. The corpus is a flow. The refresh is a schedule. The permissions are a mapping. All three can be built inside your boundary, and all three can be evidenced.
Where to start
- An inventory of flows leaving the European perimeter, transit included
- Key custody and decryption capability, mapped per platform
- The ICT third-party register, structured from real contracts
- A reversibility rating per critical platform, with the exit cost stated
- The AI and retrieval paths, with their permission and residency gaps
Our position
Why the market is moving
Dates follow scheme and regulatory publications and are tracked per client as part of governance engagements.
Start with an honest map of where your data goes.
10 days, fixed price. You keep the map whatever you decide next.