Home · Sovereignty
Our position
Data sovereignty and IT architecture
We translate data residency, access control and exit requirements into your IT architecture. This covers stored data, data transfers and the cloud or AI services you use.
Sovereignty requirements affect hosting, data access and exit options. We translate requirements agreed with your legal and compliance teams into architecture and operational controls.
An up-to-date flow map helps document data locations, platforms and controls. We support routing, certificate management and migration planning.
Offices
- Brussels
- Luxembourg
- Paris
What we actually mean
Data sovereignty architecture criteria
Data residency and transit
Residency is not only about the database. A message crossing a managed service in another jurisdiction has left, even if it comes back. We map transit as carefully as storage.
Encryption key management
Encryption is only as sovereign as key custody. We design for customer-managed keys and document who can technically decrypt what, and under whose law.
Reversibility and exit strategy
We prepare exit strategies covering export formats, technical dependencies, migration procedures and recovery tests on a target platform.
Traceability and control evidence
Lineage, logs, the ICT third-party register, and evidence that the control described in the policy is the control running in production.
AI access and service controls
AI services must respect document access and residency rules. These controls apply to document pipelines and model requests.
European by construction
A European organisation
Three offices, one delivery team
Brussels, Luxembourg and Paris. Our engineers work from these locations, inside a European group, under European employment and data protection law.
A group that is European too
Satisco is part of the Alan Allman Associates ecosystem and can draw on complementary expertise according to the engagement scope.
Hosting and deployment options
We assess on-premise, European cloud and hybrid options according to data sensitivity and project requirements.
A multi-vendor approach
IBM, Axway, Microsoft and open source. Holding several partnerships is what lets us design an exit rather than defend a licence.
Sovereign blockchain layer
Blockchain architecture and data controls
Choosing a blockchain requires assessing transaction visibility, validator locations and confidentiality requirements for the specific business flow.
So we design the boundary explicitly, with the same five questions asked of a ledger: what goes on chain and what stays off it, whether the chain is public, permissioned or private, where the nodes run and under whose jurisdiction, who holds the signing keys, and what happens the day you have to leave.
Sovereign blockchain layer
On chain or off chain
Payload minimisation by design: references and proofs on the ledger, personal and commercial data in your systems. It is also what makes a permanent ledger and the GDPR right to erasure compatible.
Public, permissioned or private
An arbitration with real consequences for cost, finality, confidentiality and regulatory exposure. We document it rather than default into it.
Node residency and key custody
Where validating or observer nodes run, who operates them, and where the signing keys live. HSM and key management designed in from the start, not bolted on afterwards.
Reversibility on chain
Exit planning covers ledger changes, dependencies, data access and conditions for migration to another solution.
Sovereignty and AI
Data governance for AI services
Using external models requires checking the data transmitted, access rights and processing terms. We include these controls when scoping AI services with security and compliance teams.
AI services are part of the IT architecture. We document corpus sources, update frequency, access rights and processing within the agreed scope.
Assessment and scoping
- An inventory of flows leaving the European perimeter, transit included
- Key custody and decryption capability, mapped per platform
- The ICT third-party register, structured from real contracts
- A reversibility rating per critical platform, with the exit cost stated
- The AI and retrieval paths, with their permission and residency gaps
Assess data sovereignty in your architecture
10 days, fixed price. You keep the map whatever you decide next.
The SWIFT timeline is changing
In August 2026, Swift announced a deferral of SR2026 payment changes. The structured address timeline is under review. We assess the impact for your messages, partners and applicable rules.
Read the Swift announcement