A sovereign cloud builder designs and ships a substantively sovereign cloud product for regulated markets, going beyond regional data residency to deliver customer-controlled encryption keys, supplier-chain transparency, audit-ready trails, and an air-gap deployment option. It serves national and regional government IT services, telcos launching sovereign-cloud product lines, regional operators in jurisdictions with sovereignty mandates, and quasi-public entities. Aenix builds these products on Cozystack, an open-source Apache 2.0 CNCF project that runs virtual machines via KubeVirt and containers on a single Kubernetes API, with Cilium eBPF networking, LINSTOR/DRBD storage, and Tenant CRD multi-tenancy. Because the foundation is open source with no phone-home telemetry, the resulting product can demonstrate transparency and regulator-aligned operations that hyperscaler “sovereign” regions cannot match substantively.
Sovereign cloud is a procurement-mandated reality in 2026 across EU member states, Kazakhstan, and several APAC jurisdictions. Building one means designing for substantive sovereignty — not just marketing claims — including encryption-key custody, supplier-chain transparency, audit-readiness, and regulator-aligned operational model.
Ænix builds sovereign cloud products on Cozystack for governments, quasi-public entities, and regional operators serving sovereignty-mandated markets.
Pairs with: Ænix Private Cloud Platform for sovereign clouds with strict customer-controlled-keys + air-gap support; Public Cloud Platform for large sovereign-cloud product launches at hyperscaler-adjacent scale.
Who builds a sovereign cloud product
- National / regional government IT services offering shared sovereign cloud
- Telcos launching sovereign-cloud product line
- Regional operators in jurisdictions with explicit sovereignty mandates
- Quasi-public entities (transport, energy, banking-adjacent) building sectoral sovereign cloud
What sovereign cloud actually requires
Beyond regional residency:
- Customer-controlled encryption keys — HSM-based, with documented rotation and emergency access
- Open-source platform foundation — for transparency and audit-readiness
- Supplier-chain transparency to second hop minimum
- Air-gap deployment option for the most sensitive workloads
- Audit-trail completeness in regulator-consumable formats
- No phone-home telemetry — opt-in only
These are differentiation features for a sovereign-cloud product. Hyperscaler “sovereign” regions cannot match them substantively.
Engagement structure
Discovery + procurement-readinessBSI C5SecNumCloudEUCS
scopes
Ænix sovereign cloud buildSovereignty controlsProcurement-ready docs
delivered on
Cozystack platformKubeVirt VMsContainersOne Kubernetes API
runs on
Customer hardware / jurisdictionAir-gap optionCustomer-controlled keys
- Discovery + procurement-readiness assessment (4-8 weeks)
- Phase 2 build (8-24 months) — platform + sovereignty controls + procurement-ready documentation
- Phase 3 (optional) — managed operation under regulator-aligned governance
For specific sovereign-cloud requirements (BSI C5, SecNumCloud, EUCS) — discussed during discovery.
Procurement readiness
Ænix accepts RFI / RFP through:
- EU member states — TED, national e-procurement portals
- Kazakhstan — goszakup.gov.kz, mitwork.kz, zakup.sk.kz, Unified Procurement Platform
- Other jurisdictions — discussed per case
Ænix is the team behind Cozystack (CNCF Project), and we offer Ænix Platform — our commercial productized offering based on Cozystack, Kubernetes Certified Distribution, OpenSSF Best Practices.
Frequently asked questions
What makes a cloud substantively sovereign rather than just regionally hosted?
Beyond data residency, substantive sovereignty requires customer-controlled encryption keys (HSM-based with documented rotation and emergency access), an open-source platform foundation for audit-readiness, supplier-chain transparency to at least the second hop, an air-gap deployment option, complete regulator-consumable audit trails, and no phone-home telemetry.
Why build a sovereign cloud on Cozystack instead of a hyperscaler sovereign region?
Cozystack is open source under Apache 2.0, so the platform can be inspected and audited end to end, runs with no mandatory phone-home telemetry, and supports air-gap deployment. Hyperscaler sovereign regions cannot match these transparency and custody properties substantively because their control planes remain proprietary.
Who typically engages Aenix to build a sovereign cloud product?
National and regional government IT services offering shared sovereign cloud, telcos launching a sovereign-cloud product line, regional operators in jurisdictions with explicit sovereignty mandates, and quasi-public entities in transport, energy, and banking-adjacent sectors building sectoral sovereign clouds.
How long does a sovereign cloud build take?
Engagements start with a discovery and procurement-readiness assessment over 4-8 weeks, followed by a Phase 2 build of 8-24 months covering the platform, sovereignty controls, and procurement-ready documentation. An optional Phase 3 provides managed operation under regulator-aligned governance.
Which sovereignty frameworks and procurement channels are supported?
Specific requirements such as BSI C5, SecNumCloud, and EUCS are addressed during discovery. Aenix accepts RFI/RFP through EU TED and national e-procurement portals, and through Kazakhstan platforms including goszakup.gov.kz, mitwork.kz, zakup.sk.kz, and the Unified Procurement Platform; other jurisdictions are handled per case.
What is the technical foundation of the platform?
The product is built on Cozystack, which runs virtual machines via KubeVirt and containers on a single Kubernetes API, with Cilium eBPF networking, LINSTOR/DRBD storage, and Tenant CRD multi-tenancy. The Private Cloud Platform adds strict customer-controlled-keys and air-gap support for the most sensitive workloads.