Skip to main content

What sovereign actually means

Your data stays on infrastructure you control, in the geography you choose.

This is not a manifesto. It is a set of concrete controls with specific answers.

Where is your data? Who holds the keys? What happens on a legal request? What do you keep if we disappear? These are the questions that matter for regulated organisations. The answers are below.

Where does your data live?

On infrastructure in a named EU jurisdiction. For most engagements, that means Hetzner datacentres in Germany or Finland. The exact facility is named in your service agreement: a specific legal address, not a general 'EU region' reference.

You can ask us at any time where your data is. The answer will be a named provider, a named country, and a named data-centre region. If we cannot give you that answer, something has gone wrong.

We do not use US hyperscale infrastructure at runtime. AWS, Azure, and Google Cloud are not in the default stack. If a specific engagement requires integration with a US-hosted service (because you already use one, because a required API lives there) we scope it explicitly, you approve it, and it is documented in the data processing record.

Who holds the keys?

You do. Or, more precisely: the keys to your data live in a secrets manager (OpenBao, the open-source Vault fork) that you control or that we manage on your behalf with full key escrow to you.

Genitco does not have a master key that decrypts all client data. Each client's data is encrypted with keys scoped to that client. Our operational access is logged, scoped, and requires your consent.

If you choose the you-host retainer model, the infrastructure is in your cloud account. We have operator-level access to run the control plane. That access is scoped, audited, and revocable by you. It does not extend to your data at rest.

When you leave, the keys leave with you. The data leaves with you. The export is yours.

What happens on a CLOUD Act request?

Nothing reaches us. The US CLOUD Act (Clarifying Lawful Overseas Use of Data Act) allows US law enforcement to compel disclosure of data held by US-incorporated companies, regardless of where the data is physically stored.

Genitco is not US-incorporated. Genitco OÜ is an Estonian company and the contracting entity for all engagements. Genitco Ltd (UK, company no. 17150696) is incorporated but not yet a contracting entity. Neither entity is subject to CLOUD Act jurisdiction.

Microsoft's UK data centres do not solve this problem. Microsoft Corporation is US-incorporated. A CLOUD Act request goes to the parent company, not the data centre. The data's physical location is irrelevant to the legal exposure.

For law firms concerned about legal privilege, for regulated healthcare organisations concerned about patient data, and for any organisation that carries confidential client relationships: the structural answer matters, not just the geography of the server.

What happens if Genitco stops trading?

You keep everything. The software is open-source. The infrastructure is yours (or migrates to your control at termination). The data is yours. The runbooks are documented.

There is no kill switch. If we disappear tomorrow, your Nextcloud keeps running. Your email keeps running. Your AI assistant keeps running. Nothing requires a Genitco-controlled service to stay operational.

The exit clause is in every service agreement. You can ask to see it before signing anything. We make leaving straightforward because that is the only honest way to prove the platform is worth staying for.

What do we mean by open?

Open-source stack. Every major component (Nextcloud, Stalwart, Mattermost, Jitsi, LiteLLM, OpenBao) is open-source software with public source code and no proprietary lock-in at the component level.

Open runbooks. We publish educational walkthroughs of the patterns we use: how to replace M365, how to run self-hosted AI, how to pass a DSPT audit with self-hosted infrastructure. These are on this site and licensed CC BY 4.0.

Open exit. The micro-stack repository (Apache-2.0) is a deployable version of the core stack. It is not our full orchestration. The opinionated glue that makes everything work together is how we earn our fee. But the repo is a real, functional starting point if you want to run it yourself.

What we do not open: the orchestration recipes, the Helm values and integration glue, the management dashboards, and the custom MCP servers we build for clients. That is our product. The honesty is our practice.

What we do not mean.

We are not anti-US. We integrate US SaaS where it serves a legitimate purpose: a specific API you already procure, a social-media distribution channel, a payment processor. We bring it in transparently, with your consent, scoped to that purpose. We document it.

We are not anti-cloud. Hetzner is a cloud provider. The difference is jurisdiction, ownership model, and structural US exposure, not cloud versus not-cloud.

We are not ideological about this. The default is EU-sovereign, self-hosted, open-source because it is the cleanest foundation for regulated organisations with compliance obligations. It is an engineering decision, not a political one.

If the honest answer for your situation is 'Microsoft 365 is fine for your compliance requirements', we will say that. If the honest answer is 'your use of a US-hosted email provider is a legal-privilege risk you should understand and document', we will say that too.

Self-referential proof

We run on the same stack we sell.

Genitco's own operations run on the same self-hosted, EU-sovereign infrastructure we sell to clients. Email: Stalwart. Documents: Nextcloud. Chat: Mattermost. Video: Jitsi. AI: open-weight models on Hetzner EU infrastructure.

The sovereign-stack case study on this site is our own deployment. It is not a demo. It is in production. The Sovereign Stack tool lists every service we run.

We do not have a separate corporate Microsoft 365 tenancy for internal use and a sovereign pitch for clients. The architecture is the same one end to end.

Questions about your specific situation?

The scoping call is 30 minutes. We will tell you what your current exposure is, what controls would close it, and whether we are the right team to build them. If we are not, we will say that.

Global infrastructure·Your data, never ours·AI and infrastructure you control·GDPR by design