Open-source and data sovereignty consulting

Engineers who operate open-source apps in production review your architecture, assess your sovereignty and SaaS dependencies, and implement the result with your team, by the day.

Start with one workloadBook a 30-minute briefing

Billing
By the day, or a fixed price per assessment
Deliverables
Written reports and designs you own
Where
On site in Switzerland, or remote
Pricing
Day rate on request

What consulting covers

Some questions come before any contract to run apps: what depends on which SaaS, which data falls under which law, what the target architecture should be. Consulting answers them in writing, with engineers who run these systems every day.

Architecture

Target designs for self-hosted, hybrid and air-gapped estates: machines, private network, identity, backups and monitoring, sized for your load.

Sovereignty assessments

Where each data set is stored and processed, which provider and which jurisdiction it sits under, and what that means under the nLPD and the GDPR.

SaaS dependency audits

Every SaaS your teams rely on, what it holds, what connects to it, what leaving would take and which open-source or source-available app could replace it.

Security and resilience reviews

Exposure, access, patching, backup and restore practice on estates you already run, with findings ranked by risk.

Exit planning

Written exit plans for critical providers, with data formats, export steps and responsibilities, as DORA requires of financial entities for critical ICT services.

Implementation by the day

Our engineers work with yours to build what was designed, from a Keycloak realm to an n8n workflow estate, and leave the runbooks behind.

Data sovereignty assessments for Swiss and European organisations

Sovereignty is a set of concrete questions. Where is this data stored? Which company runs the machine? Which courts can order that company to hand it over? Which sub-processors sit behind it? A sovereignty assessment answers them for each system in scope and sets the answers against the Swiss nLPD and, where it applies, the GDPR.

The report is a technical document for your data protection officer, your legal counsel and your board. It does not replace legal advice. It gives the people who make the decision the facts they need. For the background, read our guide to data sovereignty, and how we handle data residency, the nLPD and jurisdiction.

SaaS dependency audits

Most organisations know their large SaaS contracts. Fewer know the automation tool a team signed up for with a card, or the spreadsheet a nightly script reads from a public cloud drive. The audit lists every SaaS in use, what it holds, what connects to it and what leaving would take. Where an open-source or source-available app fits, it names one from the catalogue and says why.

The audit is often the first step of an exit plan or a move off SaaS. For EU financial entities, DORA requires exit strategies for ICT services that support critical or important functions.

Architecture and implementation by the day

When you already know where you are going, our engineers help you get there. Target designs cover machines, the private network, identity, backups and monitoring, for estates on your premises, in Pilae Cloud or hybrid. Implementation days put our engineers next to yours to build it, and leave runbooks your team can follow.

When the work turns into running apps, it continues as fixed-price onboarding, a migration or managed operations. To scope an engagement, contact us.

How an engagement runs

  1. Frame

    A first call to agree the question, the people involved, the systems in scope and the form of the deliverable.

  2. Propose

    A written proposal with the number of days, or a fixed price for a defined assessment, and the dates.

  3. Investigate

    Interviews, configuration reviews and data-flow mapping, on site or remote, under a confidentiality agreement.

  4. Report

    Findings, options and a recommendation, presented to your team and delivered as a document you own.

  5. Implement

    If you want help acting on it, our engineers join your team by the day, or the work moves into onboarding or a migration.

What your contract includes

Scope
The question, the systems in scope and the deliverables, stated before work starts.
Effort
A day budget or a fixed price. Days beyond the budget are agreed with you before they are spent.
Deliverables
Written reports, designs and runbooks, owned by you and free to share with auditors, boards or other suppliers.
Confidentiality
A confidentiality agreement covering everything we see, signed before any access is granted.
Engineers
Named engineers who operate open-source apps in production, not generalists.

The apps behind it

Questions

What does a data sovereignty assessment cover?

For each system in scope: where the data is stored and processed, which company operates it, which jurisdiction that company answers to, and which sub-processors it uses. The report maps this against the Swiss nLPD and, where relevant, the GDPR, and lists the options for each risk it finds.

What is a SaaS dependency audit?

An inventory of every SaaS your organisation relies on, including the integrations and automations between them. For each one it records what data it holds, what would break if it disappeared, and what leaving it would take, with an open-source or source-available alternative where one fits.

How is consulting priced?

Implementation work is billed by the day. Defined assessments, such as a sovereignty assessment or a SaaS dependency audit, can be quoted at a fixed price once the scope is agreed. The day rate is on request.

Do we have to use Pilae to run our apps afterwards?

No. The reports and designs are yours, and you can act on them with your own team or another supplier. If you want Pilae to implement or operate the result, the work moves into onboarding, a migration or managed operations.

Is a sovereignty assessment legal advice?

No. It is a technical assessment of where your data goes and who can reach it. It gives your legal counsel and data protection officer the facts they need, and we work alongside them when you want.

Can your engineers work on site?

Yes. Engineers work on site in Switzerland when the work needs it, and remotely otherwise. Air-gapped environments are handled through an access path you control.

Related

Bring us the question.

Tell us what you need to decide. We come back with the scope, the days it takes and what you will have at the end.