Cloud platform for financial services — DORA-aligned, sovereign, AI-ready

Open-source Cozystack (a CNCF project we create and maintain) Ænix Platform, the supported commercial distribution Aenix builds, operates and migrates it.

Aenix builds and operates DORA-aligned, sovereign cloud platforms for financial-services organizations — banks, insurers, investment firms, and payment institutions — across the EU, DACH, and Central Asia. The foundation is Cozystack, an Apache 2.0 open-source platform (CNCF Sandbox project) that unifies virtual machines and containers on one Kubernetes API using KubeVirt, Cilium eBPF networking, LINSTOR/DRBD storage, and Tenant-CRD multi-tenancy. It runs on customer hardware with customer-controlled encryption keys and customer-owned audit trails, so data residency and operational resilience are structural rather than bolted on. Aenix sells the productized Ænix Platform plus engineering services, and typically engages through a Platform Readiness Assessment covering DORA Article 28 supplier risk, exit-feasibility, FinOps, and sovereign-AI architecture for sensitive financial data.

Quick facts

  • What it is A DORA-aligned sovereign cloud platform for banks, insurers, investment firms, and payment institutions, built on Cozystack and run on customer-controlled infrastructure.
  • License Apache 2.0 (no per-CPU / per-core licensing)
  • Status Cozystack is a CNCF project (Sandbox since 2025-02-28; Incubating expected late summer 2026)
  • Who it's for Financial-services organizations facing DORA enforcement, ICT third-party concentration scrutiny, VMware/Broadcom exit, and sovereign-AI requirements.
  • Key capability VMs and containers on one Kubernetes API (KubeVirt), Cilium eBPF networking, LINSTOR/DRBD storage, Tenant-CRD multi-tenant isolation, customer-held keys and audit trails.
  • Engagement Platform Readiness Assessment (DORA/sovereignty, cost, platform engineering, AI workstreams) plus a Phase 2 implementation roadmap.
  • Regulatory scope DORA (in force January 2025), NIS2, GDPR; EU member-state and Kazakhstan procurement channels.

Banks, insurers, investment firms, and payment institutions face the steepest combination of pressures in 2026: DORA enforcement (in force January 2025), sectoral regulator scrutiny on ICT third-party concentration, AI workload economics, and the post-Broadcom VMware exit. The architectural answer is not “another hyperscaler region” — it’s a coherent platform where sovereignty, audit-readiness, and operational discipline are structural rather than bolted on.

Ænix builds and operates platforms for financial-services organizations across the EU, DACH, and Central Asia. Same platform, Cozystack, running production workloads under DORA-aligned governance.

Pairs with: Ænix Private Cloud Platform for the regulated cloud foundation; AI Platform for claims AI / fraud detection / sovereign AI workloads. Free DORA Compliance Checklist →.


What financial services teams come to us for

The four most-common entry points:

  • DORA-aligned platform readiness — Article 28 supplier risk, exit-readiness, operational resilience testing. See DORA compliance.
  • Hyperscaler exit / repatriation — sustained workloads where public-cloud economics no longer fit. See Cloud repatriation.
  • Sovereign AI for sensitive data — GenAI / inference / analytics on customer or financial data that cannot leave the perimeter. See Sovereign AI.
  • VMware exit — VCF subscription pressure across the financial sector. See VMware alternative.

Most engagements combine two or more of these triggers.


Industry data points

  • LSEG Global Cloud Survey 2025: 82% of financial-services firms are in hybrid/multi-cloud. 84% adjusted cloud strategy due to regulatory developments.
  • Nutanix Financial Services ECI 2025: 92% rate their infrastructure as not ready for cloud-native or container workloads. 62% are hiring GenAI specialists.
  • Broadcom Private Cloud Outlook 2025: 53% prioritize private cloud for new workloads. 69% evaluating repatriation.

These trends concentrate in financial services first.


How Ænix engages with financial-services organizations

The standard engagement runs as a Platform Readiness Assessment with workstreams emphasized for the financial-services context:

  • Sovereignty + DORA workstream — Article 28 supplier risk, concentration analysis, exit-feasibility, audit-readiness, encryption posture.
  • Cost workstream — TCO honest model, FinOps maturity, repatriation candidates aligned with commitment ladders.
  • Platform engineering workstream — multi-tenant Kubernetes-native foundation, golden paths for finance product teams, observability suitable for regulator dialog.
  • AI infrastructure workstream (where applicable) — sovereign AI architecture for data classes that cannot leave the perimeter.

Output is a written report aligned with regulator-readiness and a Phase 2 implementation roadmap.


What runs on Cozystack in financial services

Financial-services references stay anonymous until the NDAs expire; these are live engagements:

  • A Tier-1 European bank running internal cloud platform with multi-tenant isolation under DORA Article 28 supplier-concentration controls.
  • A regional insurance carrier with sovereign-cloud requirements and AI-assisted claims processing on private LLM infrastructure.
  • A payment-institution operating critical-infrastructure workloads across two EU member-state regions with full data residency.
  • A fintech operating across the EU and Central Asia with a unified platform under multi-jurisdictional sovereignty controls.

Why Ænix specifically for financial services

Financial-services pressure
DORA enforcementICT third-party concentrationVMware / VCF exit
addressed by
Cozystack on customer hardware
VMs + containersOne Kubernetes APIApache 2.0
delivers
Structural sovereignty
Customer-controlled keysCustomer-owned audit trailsData residency
  • Regulator-aware engineering. Our team has direct experience with DORA / NIS2 / GDPR / sectoral regulatory dialog. We don’t deliver consulting that ignores the regulatory layer.
  • No hyperscaler bias. We’re not commercially aligned with AWS / Azure / GCP. Recommendations reflect substantive sovereignty, not partner economics.
  • Open-source platform foundation. Cozystack on customer hardware, customer-controlled keys, customer-owned audit trails. Sovereignty is structural.
  • EU + Central Asia teams. Time-zone friendly; aligned with EU + KZ regulatory frameworks.

Ready to scope your build? Book a call →

Pricing

Standard engagement structure (assessment + Phase 2) — see Platform Readiness Assessment for methodology and pricing detail. Financial-services engagements often use the 28-day variant for the broader scope.

Procurement: we accept RFI / RFP through standard procurement channels in EU member states and Kazakhstan.


How to start

Or read more:


Ænix is the team behind Cozystack (CNCF Project), and we offer Ænix Platform — our commercial productized offering based on Cozystack, Kubernetes Certified Distribution, OpenSSF Best Practices.

Frequently asked questions

Does the platform help with DORA compliance?

Yes. Engagements address DORA Article 28 ICT third-party risk, supplier-concentration analysis, exit-feasibility, operational resilience testing, and audit-readiness. Customer-controlled keys and customer-owned audit trails support regulator dialog. See the DORA compliance solution page and the free DORA Compliance Checklist.

Is this a viable VMware / VCF replacement for a regulated bank?

Yes. Cozystack runs both virtual machines (via KubeVirt) and containers on a single Kubernetes API, on customer hardware, under Apache 2.0 with no per-core licensing. It targets the VCF subscription pressure many financial-sector firms face after the Broadcom acquisition.

Can we run AI on sensitive financial data without it leaving our perimeter?

Yes. The sovereign-AI workstream architects GenAI, inference, and analytics on customer or financial data that cannot leave the perimeter — for example fraud detection or claims processing on private LLM infrastructure running on customer-controlled hardware.

How does an engagement start?

Most start with a Platform Readiness Assessment combining sovereignty/DORA, cost, platform-engineering, and (where applicable) AI-infrastructure workstreams. The output is a written, regulator-readiness-aligned report plus a Phase 2 implementation roadmap. Financial-services engagements often use the broader 28-day variant.

What is the licensing and lock-in model?

The platform foundation, Cozystack, is Apache 2.0 open source with no per-CPU or per-core licensing. It runs on customer hardware with customer-controlled keys and audit trails, so sovereignty and exit-readiness are structural. Aenix sells the productized Ænix Platform and services on top.

Which regions and regulatory frameworks does Aenix cover?

Aenix operates teams in the EU and Central Asia and engages with financial-services organizations across the EU, DACH, and Central Asia, aligned with DORA, NIS2, GDPR, and Kazakhstan frameworks. RFI/RFP is accepted through standard procurement channels in EU member states and Kazakhstan.

Ready to talk?

Book a 30-minute discovery call — no commitment. We confirm fit, the right platform, and the next steps.