Vision
Sovereign infrastructure, built piece by piece.
We name openly which open-source tools replace which paid tools. We give away what is genuinely reusable — protocols, reference implementations, educational content. What we keep is the opinionated assembly that makes it all work together. That is our product. The honesty is our practice.
The long arc
Sovereign infrastructure should include every layer: the hardware under the desk, the OS on the laptop, the cloud services in between, and the AI agents running through all of them. Nobody in UK and EU currently offers this integrated at independent-firm scale with approachable pricing.
We are building it piece by piece. Four waves. Specific dates. Below.
Now — Q2 2026 — current
IT ownership for UK and EU organisations
Genitco builds and manages self-hosted, EU-sovereign IT infrastructure for UK and EU organisations, primarily regulated ones that carry real compliance obligations: NHS-adjacent care groups, SRA-regulated law firms, and UK businesses migrating from Microsoft 365.
The core offering is three pillars: Generate (fixed-fee projects), Operate (managed infrastructure retainers), and Govern (compliance advisory and fractional CTO). Open-source throughout, EU-hosted, zero trust by default. Your data is not our business model.
The platform we sell is the same platform we run our own operations on. That is not a marketing claim. It is the development constraint we imposed on ourselves from day one.
Q3 2026
Pre-configured hardware
The next wave extends ownership down to the physical layer. Pre-configured Dell refurbished desktop and laptop units (OptiPlex / XPS) with Genitco Linux preloaded. Pre-configured server and GPU nodes for organisations that want on-premises AI inference.
The pattern: hardware cost at our procurement price, fixed setup fee, optional managed retainer. No margin on hardware. No subscription to the operating system. You own what you buy.
The GPU path in particular targets regulated organisations (research institutions, NHS-adjacent care groups) that want local AI inference with no data leaving the building. The hardware is the enabler.
2027
Homestack — consumer and family
Homestack is a separate brand for the consumer market. A sovereign home stack: private email, family document storage, a local AI assistant, and parental-control-grade infrastructure, on hardware you own, in your home, without a monthly SaaS dependency.
The architecture is the same as the commercial stack. The audience, the pricing, and the interface are different. Homestack is accessible to non-technical families, not just IT-aware buyers.
We are building towards Homestack, not announcing it. The commercial platform has to work at scale before the consumer product is credible.
2027–2028
The ambient layer
The long arc: sovereign infrastructure should include the AI agents running through it, not just the servers and the software. The ambient layer is an MCP (Model Context Protocol) gateway that connects AI agents to the systems any organisation runs, with credentials from their own secrets manager, audit trails in their own logs, and write operations gated by their own approval flow.
MCP is the emerging standard for connecting AI agents to external systems. In 2026, it has no enterprise authentication story. No audit trail. No per-agent authorisation. The mcp-gateway repository (AGPL-3.0) will be the reference implementation of the pattern that fills that gap.
Guardian (AI for schools, audited for minors) follows from the same infrastructure: a change-request gate that every write must pass before it lands, audit trails that regulators can inspect, models that do not update without a change control. Different brand, same technical foundation.
Where we are now
Sovereign Stack
The live inventory of every service Genitco runs on its own infrastructure.
genitco/micro-stacklaunching
Apache-2.0. Docker Compose bundle for Nextcloud + Stalwart + Mattermost + local LLM on one box. Educational, not the full orchestration.
genitco/mcp-gatewaylaunching
AGPL-3.0. MCP credential broker — auth, audit, per-agent authorisation. For agent builders who need enterprise-grade access control.
What sovereign actually means
The concrete controls: where your data lives, who holds the keys, CLOUD Act exposure, and what you keep when you leave.
Work with us now
The hardware and consumer waves come later. The infrastructure, the compliance advisory, and the AI deployments are available today.