DORA, NIS2 and data-residency turned cloud into a control-and-evidence problem: prove where data lives, who holds the keys, how far the supplier chain reaches. You need a platform where the answers are structural — your hardware, your jurisdiction, your keys. Ænix delivers it turnkey, or builds it with you.
Pairs with: DORA, NIS2 and data-sovereignty engagements, Ænix Private Cloud Platform, on open-source Cozystack.
Where you are right now
- DORA (in force 2025-01-17) and NIS2 put concentration-risk and supplier transparency on you.
- Auditors ask where each data class lives — including backups, logs and CI/CD artifacts.
- “We’re encrypted” isn’t enough when the provider holds the keys.
- You need an architecture you can evidence, not a vendor’s compliance slide.
What you’re actually trying to do
Move regulated workloads onto infrastructure where sovereignty is a property of the architecture: data residency demonstrable at every layer, encryption keys in your custody, supplier chain transparent past the first hop, and audit trails exportable — so you pass supervision rather than hope to.
Two ways Ænix helps you
1. Run a turnkey platform. Ænix Private Cloud Platform runs on your hardware in your jurisdiction, with customer-controlled keys at every data layer (primary, replicas, backups, observability) and an air-gap option — the regulated cloud you operate with our SLA.
2. Assess and build with our team. Cozystack is the framework; Ænix is your engineering and assessment team for DORA, NIS2 and data-sovereignty work — a control-level map of where data lives today, the gaps, and the remediation build.
Quick facts
- What it is: a sovereign-by-architecture cloud platform for regulated workloads.
- Who it’s for: CISOs, Heads of Compliance / Risk, DORA/NIS2 programme owners.
- Key dates: DORA in force 2025-01-17; NIS2 covers 18 sectors in Annex I/II.
- Control: customer-held encryption keys; cluster-level access; air-gap supported.
- Status: built on Cozystack, CNCF project (Sandbox 2025-02-28; Incubating expected late summer 2026), Apache 2.0.
- Common pitfall: production data is in-region but observability/backups leave the perimeter unnoticed.
[Source: EUR-Lex DORA, ENISA NIS2]
Why CISOs pick Ænix
- Sovereignty is structural. Your hardware, jurisdiction and keys — not a contractual promise on a hyperscaler.
- No provider bias. We aren’t tied to any cloud; the report’s bias is toward what we can demonstrate.
- Engineers who also build. The same team that assesses runs the remediation — EU-based.
FAQ
Is data residency the same as sovereignty? No. Residency is necessary but not sufficient — sovereignty also needs key custody, supplier-chain transparency and audit-readiness. A workload can be in-region and still fail.
Do we have to go fully on-prem? Not always. The engagement determines per data class what needs dedicated infrastructure versus what a sovereign arrangement can cover.
How does this map to DORA / NIS2 specifically? See DORA compliance and NIS2 compliance for the article-level control mapping.
Who holds the encryption keys? You do — at every data layer, with documented rotation and emergency access.
Can we run this under public-sector procurement? Yes — we accept RFI/RFP through standard EU member-state and Kazakhstan channels.
Start with a 30-minute discovery call
Free, no prep. We narrow the scope to the regulators and clauses that bind you, and tell you whether the assessment, the turnkey edition, or a build fits.
Ænix is the team behind Cozystack — a CNCF project (Sandbox today; Incubating expected late summer 2026), Apache 2.0. Ænix commercializes it as Ænix Platform as three platforms on one engine — Public Cloud, Private Cloud and AI — that combine rather than exclude each other.