DIGITAL SOVEREIGNTY

Whoever controls your infrastructure controls your business. I built Struktura so no one else controls mine.

Data sovereignty isn’t an add-on for Struktura — it’s the foundation Struktura is built on, and it is fast becoming the foundation every European company will stand on. Here is what it means when the question reaches your boardroom.

A lone server in a dark room — control over your own infrastructure. *AI

What happens the day access is switched off?

Treat it as a board risk, not an IT detail. A sanction, a trade dispute, a change of ownership, a political order — and a provider under American or Chinese control can be compelled to cut your access, hand over your data, or simply turn your systems dark. Your ERP, your invoicing, your customer records: reachable by someone whose interests aren’t yours — or unreachable to you. This isn’t hypothetical leverage; it is written into law (the US CLOUD Act and FISA; China’s National Intelligence Law). The question a CFO must be able to answer: if that switch were flipped tomorrow, what would still be ours?

A hand reaching for a physical switch. *AI

This is not a thought experiment

Every example below is documented — sources are linked throughout — and none of it required anyone to break a law. Your CTO probably knows them already. The point is that they belong in the risk register, next to currency and supplier risk — which makes them CFO and CEO territory.

  • 2019 — the platform that vanished overnight. One US export decision, and Google cut Huawei off from the Android ecosystem. A business built on someone else’s platform lost it in a day (CNBC).
  • 2025 — the sanction that reached an inbox. When the US sanctioned the International Criminal Court’s chief prosecutor, international media reported that he lost access to his Microsoft-hosted email account and moved to a Swiss provider. Microsoft has denied shutting the account off — but the case prompted the Dutch government to reassess its dependence on American technology (Computer Weekly) (the denial: Techzine).
  • 2025 — under oath in the French Senate. Microsoft France confirmed it cannot guarantee that European data stays out of American hands when US law demands it — European data centres notwithstanding (heise).
  • 2026 — the AI models switched off three days after launch. In June, citing export controls, US authorities directed Anthropic to suspend all access to its newest Claude models (Fable and Mythos) for foreign nationals, inside and outside the US — three days after launch. Access was only restored almost three weeks later. If your processes had depended on the models, they would have stood still (Anthropic’s statement) (Fortune).

The legal floor moves too: twice, the EU Court of Justice has struck down the framework for transatlantic data transfers (Safe Harbor, Privacy Shield). Today’s version rests on a US executive order — changeable with a single signature. If your continuity plan assumes the rules of 2024 still apply in 2027, that is a risk entry, not an assumption.

I have done it myself: Struktura’s own foundation

Struktura sells compliance, so I don’t outsource my own sovereignty: the entire digital backbone runs on European and open-source platforms: hosting in Germany (Hetzner), self-hosted deploy and backend (Coolify, PocketBase), passwords in Switzerland (Proton Pass), DNS in Denmark (Simply.com), mail in Germany (Mailbox.org), privacy-first analytics (Plausible), my own files (Nextcloud). No US hyperscaler. No Google. And this was no weekend experiment: I moved service by service while the business kept running — every choice had to survive daily operations. For a compliance firm the clean stack isn’t a cost line — it is the proof — and it typically runs 30–60% cheaper than the American default; independent price comparisons of European providers against the hyperscalers find savings in that range or larger (price comparison, 2026).

DEVICE Jolla FI E-MAIL Mailbox.org DE PASSWORDS Proton Pass CH ANALYTICS Plausible EU FILES Nextcloud OSS BACKEND + DB PocketBase OSS DEPLOY Coolify OSS DNS / DOMAIN Simply.com DK HOSTING / COMPUTE Hetzner DE
The European stack — layer by layer. From hosting at the base to the device on top.

The honest ledger: frictions — not lost control

Sovereignty has a price, and I won’t pretend otherwise. My mail lives with Mailbox.org in Germany instead of Google — it works, but I feel the difference: search is slower, the ecosystem is smaller, and things that simply “happened by themselves” in Google’s world occasionally need a manual or a workaround. Calendar invitations across ecosystems can be stubborn. And 100% purity doesn’t exist: silicon is global, and some layers will never be fully European — anyone promising total independence is selling something.

But look at what is actually on that list: inconveniences — not lost capability, not lost data, not lost control. The switching cost is real, bounded and paid once; dependency is paid every day, and that invoice arrives at the worst possible moment. The point isn’t purity but direction and control: knowing exactly where every dependency sits, who could reach it, and having a way out. Most organisations have never mapped that. I have — and that is exactly where an engagement starts.

FROM PROBLEM TO PLAN

Three ways to use Struktura

Data boundaries, NIS2, DORA and the push for European digital infrastructure: sovereignty is moving from “nice to have” to a baseline expectation — and boards will be asked to show their work. Struktura has walked this path. Here are the three ways I walk it with you:

01 MAPPING

Sovereignty review with a mapping report

I map your dependence on American and Chinese technology — cloud, SaaS, hardware, apps — and who can legally reach what. You get a report that goes straight into the risk register and onto the board’s table: here is the exposure, here are the exit options.

02 RECOMMENDATIONS

A prioritised transition plan

Concrete recommendations in order: what can move now, what needs maturing — and what it costs. Typically the bill lands 30–60% below the American default. The plan includes the certification track: labels such as Software Hosted in Europe and Software Made in Europe from the European DIGITAL SME Alliance (digitalsme.eu) make your sovereignty verifiable — for customers, auditors and the board. This is home ground for me: I have worked with the European frameworks for e-invoicing, compliance and data security — including in Brussels.

03 PROJECT LEADERSHIP

Leading the transition — at your place

Once the plan is approved, Struktura can take project leadership: vendor selection, migration, security and handover to operations — end to end. I have moved a business service by service while it kept running. Your project gets the same rigour.

Together or separately — most start with the mapping.

Finally: from the server to the pocket

Sovereignty doesn’t stop at the data centre — the next dependency is the device in your hand. So I’m moving to a Jolla Phone (Sailfish OS, assembled in Finland): the European answer to the Android/iOS duopoly, with a physical privacy switch and no calling home. Even here the honesty holds — the chip isn’t European. That is the level of thoroughness a sovereignty project deserves, in every corner. If you face the same assessment, or have a sharper idea for closing the last gap, get in touch. That conversation is exactly the point.

Jolla’s orange Sailfish phone — the European answer to the Android/iOS duopoly. *AI

Where does your data really live — and who can switch it off?

Struktura can map your dependence on American and Chinese technology and lay out an exit plan — and/or build and migrate you to an EU-native, GDPR-clean stack. Together or separately. I don’t just describe the path — I walk it myself.

Book a sovereignty review →