Data sovereignty for cloud infrastructure — make jurisdictional control demonstrable

Open-source Cozystack (a CNCF project we create and maintain) Ænix Platform, the supported commercial distribution Aenix builds, operates and migrates it.

Data sovereignty for cloud infrastructure means proving, with evidence, that data lives in the jurisdiction a regulator requires at every layer — production storage, replicas, backups, observability, and CI/CD artifacts — with encryption keys held by the data owner and supplier dependencies transparent past the first hop. It is the operational requirement behind DORA, NIS2, GDPR, sectoral data-residency rules, and EU member-state sovereign-cloud mandates. Aenix runs a structured engagement that maps where each data class actually lives, identifies gaps, and defines sovereignty-by-design for regulated organizations. Aenix is the company behind Cozystack, an Apache 2.0 CNCF project that runs on the customer’s chosen hardware in the chosen jurisdiction, with the customer holding cluster-level access — making sovereignty structural rather than contractual.

Quick facts

  • What it is A structured engagement to take a data-sovereignty position from claim to demonstrable architecture across every data layer
  • License Apache 2.0 (no per-CPU / per-core licensing)
  • Status Cozystack is a CNCF project (Sandbox since 2025-02-28; Incubating expected late summer 2026)
  • Who it is for Banks, insurers, public-sector and quasi-public bodies, healthcare, telecom and critical-infrastructure operators, and multinationals under data-localization rules
  • Engagement timeline 14-day focused scope or 28-day full sovereignty plus adjacent regulatory overlap; fixed-price, single invoice, mutual NDA at kickoff
  • Standards covered DORA, NIS2, GDPR, sectoral data-residency rules, and EU member-state and non-EU sovereign-cloud mandates
  • Delivered by Aenix engineers across the EU, DACH, and Central Asia, with no hyperscaler commercial alignment

Data sovereignty is no longer a procurement clause — it is an operational requirement: prove, with evidence, that your data lives where the regulator says it must, at every layer and not only in production.

Ænix runs a structured engagement that produces a control-level map of where your data actually lives today, where the gaps are, and what sovereignty-by-design looks like for your stack.

Pairs with: Ænix Private Cloud Platform for regulated enterprises consuming sovereign cloud internally, or Public Cloud Platform for operators offering it as a product — customer-controlled keys at every layer, air-gap optional.

EU-based engineers · Apache 2.0 platform · Written deliverables · Mutual NDA at kickoff

Who has a data sovereignty problem

Data sovereignty pressure shows up in different language depending on the buyer’s seat, but the underlying constraint is the same.

  • Banks and insurers under DORA / sectoral supervision facing concentration-risk and data-residency obligations.
  • Public-sector and quasi-public organizations subject to procurement-mandated sovereign-cloud requirements (EU member states, Kazakhstan, several APAC jurisdictions).
  • Healthcare and life-sciences operators with patient-data residency rules under national health-data frameworks.
  • Telecom and critical-infrastructure operators under NIS2 with sectoral data-handling rules.
  • Multinational enterprises with data-localization requirements that vary by country (India, China, Russia, Brazil, several EU member states).
  • AI / analytics teams working on sensitive data classes that cannot be processed by non-EU model providers.

If you can name a specific regulator, sectoral rule, or procurement clause that triggered this for your team — this engagement is built for that situation.


What “data sovereignty” actually requires of your architecture

1. Demonstrable data-residency at every layer Production storage is the easy part. Backups, observability data, CI/CD artifacts, and managed-service telemetry frequently leave the regulator’s perimeter without anyone noticing. Sovereignty applies to all layers, not just the production database.

2. Encryption and key custody under your control Encryption alone is not sovereignty. The keys must be held by the data owner — not the cloud provider — with documented rotation, emergency access, and an audit trail.

3. Supplier transparency to the second hop Hyperscalers run on data centres and connectivity providers; SaaS providers run on hyperscalers; managed services depend on shared infrastructure. Sovereignty requires knowing the chain past the first hop.

4. Audit and supervisory access Audit trails must be exportable in regulator-consumable formats, retained per the regulator’s requirement, and tamper-evident. Supervisor access processes must be documented and tested.

For practical detail with control-level checks, see data residency requirements 2026.


Where most cloud setups fail the sovereignty test

Observability and telemetry leak the perimeter Production database is in the right region. The SaaS observability stack collecting logs from it processes them through US-based regions because that’s where the vendor’s infrastructure runs. The compliance officer doesn’t know.

Backups are sovereign — until they’re tested Backup storage tier is in the right region. The DR test pulls backups across regions to a different DR site that turns out to be in a non-compliant jurisdiction. Sovereignty fails under stress.

Encryption keys are with the cloud provider Default encryption looks compliant on paper. Until the regulator asks who controls the keys — and the answer is the same vendor that holds the data.

Supplier chain is a black box past hop 1 The hyperscaler is named in the contract. The hyperscaler’s data-centre operator, networking sub-contractors, and shared platform services are not. DORA Article 30(2)(a) requires the subcontracting chain to be described in the contract; NIS2 Article 21(2)(d) requires supply-chain security to cover direct suppliers and service providers.


How Ænix helps

Sovereignty requirement
Data-residency at every layerKey custodyChosen jurisdiction
met by
Cozystack
Customer's chosen hardware in the chosen jurisdictionCustomer-controlled keys at every layerCluster-level access
makes it
Structural, not contractual
Audit-readiness

The data-sovereignty engagement runs as part of our Platform Readiness Assessment, with the sovereignty-and-regulator-gap workstream as primary focus. The 14- or 28-day engagement produces:

  • Data-residency map — where each data class actually lives today, including production, backup, observability, and CI/CD artifacts. Per-class jurisdiction with evidence.
  • Encryption and key-custody review — current encryption posture, key-custody arrangements, gap identification per data class.
  • Supplier-chain map to second hop — every ICT third-party arrangement traced to its underlying providers and shared dependencies.
  • Audit-readiness assessment — what supervisor access processes are documented, what tested, what missing.
  • Architecture-level remediation plan — what to fix, in what sequence, with effort estimates and regulatory deadline alignment.

Delivered by Ænix engineers — the team behind Cozystack — across the EU, DACH, and Central Asia, with no hyperscaler commercial alignment.


Why Ænix specifically

  • EU-based engineers and operations. Our team works across the EU, DACH, and Central Asia. We understand the difference between sovereignty as a US marketing term and sovereignty as it is enforced under EU sectoral rules and EU member-state procurement clauses.
  • No hyperscaler bias. Sovereignty consulting from Big-4 firms is shaped by their hyperscaler partnerships. Our recommendations are not commercially tied to any cloud provider — we recommend the architecture that actually meets the sovereignty requirement, even when that means full on-prem.
  • Open-source platform foundation. We are the company behind Cozystack — a CNCF Project running on your chosen hardware in your chosen jurisdiction, with cluster-level access held by you. Sovereignty is structural, not contractual.


Ready to scope your build? Book a call →

What the engagement looks like

Day 0 is a free 30-minute discovery call that fixes the scope. Days 1-13 (or 1-27) run four parallel workstreams with the sovereignty-and-regulator-gap workstream emphasized, on daily async updates and three sponsor checkpoints. Day 14 (or 28) is a 60-90 minute executive readout against the written report — data-residency map, key-custody review, supplier-chain map, audit-readiness and remediation plan. Full day-by-day methodology: Platform Readiness Assessment.


Sovereignty engagements we’ve run

We have run data-sovereignty assessments and platform-engineering programs for banks, insurers, public-sector organizations, and ICT third-party providers across the EU, DACH, and Central Asia. Outcomes range from full on-prem sovereign-cloud builds to selective repatriation of regulated workloads.


Pricing and engagement scope

The sovereignty-emphasized engagement runs as a Platform Readiness Assessment.

14-day (focused sovereignty scope)

Sovereignty workstream depth, single regulatory framework, single domain. Data-residency map, key-custody review, supplier-chain (to second hop), remediation plan. On request

28-day (full sovereignty + adjacent)

Sovereignty + adjacent regulatory overlap (DORA / NIS2 / sectoral / GDPR mapping). Multi-BU stakeholder interviews. Vendor shortlisting where applicable. Phase 2 implementation roadmap. On request

Fixed-price. Single invoice. Mutual NDA at kickoff. Phase 2 implementation cost: assessment fee credited subject to scope.

We accept RFI / RFP through standard procurement channels in EU member states and Kazakhstan; the discovery call covers procedural fit.



Start with a 30-minute discovery call

We confirm fit, narrow the scope to the regulators or procurement clauses that bind you, and name the 14-day or 28-day variant.

Or read more:


Ænix is the company behind Cozystack — a CNCF Project, Kubernetes Certified Distribution, OpenSSF Best Practices.

Frequently asked questions

Is data sovereignty the same as data residency?

No. Data residency is necessary but not sufficient. Sovereignty also requires control of encryption keys, supplier-chain transparency past the first hop, audit-readiness, and operational independence from a single provider. A workload can be in the right region and still fail the sovereignty test.

Do we need to go fully on-prem to be sovereign?

Not necessarily. The right answer depends on the data class, the regulator, and operational realities. Some workloads achieve sovereignty under hyperscaler sovereign-cloud arrangements with caveats; others require dedicated infrastructure under the customer’s control. The engagement determines which is which per data class.

How does this differ from a Big-4 sovereignty assessment?

Big-4 advisory is usually delivered by management consultants, handed off to a separate implementation team, and shaped by the firm’s hyperscaler partnerships. Aenix engineers do both the assessment and the implementation and are not commercially tied to any provider, so the report’s bias is toward what can be demonstrated and operated under your governance.

What does the engagement produce?

A data-residency map per data class (production, backup, observability, CI/CD), an encryption and key-custody review, a supplier-chain map traced to the second hop, an audit-readiness assessment, and an architecture-level remediation plan with effort estimates and regulatory-deadline alignment.

Why does Cozystack help with data sovereignty?

Cozystack is an Apache 2.0 CNCF project that runs KubeVirt VMs and containers on one Kubernetes API on the customer’s chosen hardware in the chosen jurisdiction, with the customer holding cluster-level access and customer-controlled keys at every data layer. There is no per-core licensing and no provider lock-in, so sovereignty is structural rather than contractual.

Can we run this under a public-sector procurement process?

Yes. Aenix accepts RFI / RFP through standard procurement channels in EU member states and Kazakhstan. The 30-minute discovery call covers procedural fit and confirms which 14-day or 28-day variant matches your situation.

Ready to talk?

Book a 30-minute discovery call — no commitment. We confirm fit, the right platform, and the next steps.