Data sovereignty assessments for Swiss and European organisations
Sovereignty is a set of concrete questions. Where is this data stored? Which company runs the machine? Which courts can order that company to hand it over? Which sub-processors sit behind it? A sovereignty assessment answers them for each system in scope and sets the answers against the Swiss nLPD and, where it applies, the GDPR.
The report is a technical document for your data protection officer, your legal counsel and your board. It does not replace legal advice. It gives the people who make the decision the facts they need. For the background, read our guide to data sovereignty, and how we handle data residency, the nLPD and jurisdiction.
SaaS dependency audits
Most organisations know their large SaaS contracts. Fewer know the automation tool a team signed up for with a card, or the spreadsheet a nightly script reads from a public cloud drive. The audit lists every SaaS in use, what it holds, what connects to it and what leaving would take. Where an open-source or source-available app fits, it names one from the catalogue and says why.
The audit is often the first step of an exit plan or a move off SaaS. For EU financial entities, DORA requires exit strategies for ICT services that support critical or important functions.
Architecture and implementation by the day
When you already know where you are going, our engineers help you get there. Target designs cover machines, the private network, identity, backups and monitoring, for estates on your premises, in Pilae Cloud or hybrid. Implementation days put our engineers next to yours to build it, and leave runbooks your team can follow.
When the work turns into running apps, it continues as fixed-price onboarding, a migration or managed operations. To scope an engagement, contact us.