Exit plan for critical SaaS and cloud providers, documented and tested

For each critical SaaS or cloud dependency, a documented fallback on open-source or source-available apps you control: the target, the runbook, the data export and a test that proves it works.

Start with one workloadBook a 30-minute briefing

Covers
Critical SaaS, cloud and outsourced ICT services
Deliverable
Exit plan, runbook and test record per provider
Fallback
Open-source or source-available apps, on your premises or in Pilae Cloud
Supports
DORA Article 28, FINMA outsourcing rules

An exit strategy your auditor can test

Most exit plans are a paragraph in a vendor file. A supervisor now asks whether it would work. We turn each one into a fallback that exists, with data that has been exported and a switch-over that has been rehearsed.

Dependencies mapped

Each SaaS and cloud service is listed with the functions it supports, the data it holds, its contract terms and how it is reached.

A named fallback

For each critical service, an open-source or source-available replacement, or an alternative provider, chosen and sized, with the gaps written down.

Data out, regularly

Scheduled exports from the provider in open formats, stored in your chosen country, with counts checked against the source.

A runbook per provider

The steps, owners, timings and decisions for a switch-over, written so that someone other than the author can follow them.

Tested, not assumed

Each plan is exercised on a schedule you set: a restore of exported data into the fallback, up to a full switch-over rehearsal.

Evidence on file

Every test produces a dated record of what ran, how long it took and what failed, ready for your register and your auditors.

Why exit plans are now tested

For years, an exit strategy was a clause in the contract and a paragraph in the vendor file. Regulators now ask for more. DORA requires EU financial entities to hold exit strategies for ICT services that support critical or important functions, and to test them. In Switzerland, FINMA expects supervised institutions that outsource significant functions to stay able to bring them back or move them elsewhere.

The question behind both is the same: if this provider stopped tomorrow, what would you run instead, and how long would it take? Outside finance, the same question comes up after a price rise, a change of terms or a new foreign law.

A fallback that exists

A plan only works if the fallback is real. For each critical service, we name an app you control, open source or source-available: Nextcloud for file storage, Open WebUI for an AI assistant, Keycloak for identity, n8n for automation, Mattermost for chat, Garage for S3 object storage, vLLM for a model API, Forgejo for code hosting. We run it on your premises or in Pilae Cloud, from a warm standby to a documented cold start, depending on the recovery time you need.

Data leaves the provider on a schedule, in open formats, and is stored in your chosen country with the same backup regime as the rest of your estate.

Proof for your register

Each exercise leaves a dated record: what ran, how long it took, what failed and what was fixed. That record goes into your ICT third-party register and in front of your auditors. When you decide to leave a provider for good, the plan becomes the project; see leaving a SaaS. To start, book a call.

How we build an exit plan

  1. Map

    We list your ICT providers, the functions each one supports and which of them are critical or important.

  2. Design

    For each critical provider we choose the fallback, the export method, the switch-over trigger and the target recovery time.

  3. Build

    We stand up the fallback on your premises or in Pilae Cloud, from a warm standby to a documented cold start, and schedule the exports.

  4. Test

    We run the agreed exercise, record the result and fix what did not work.

  5. Keep current

    Plans are reviewed when a provider, contract or function changes, and retested on the agreed schedule.

What your contract includes

Scope
The providers and functions covered, listed with the fallback chosen for each.
Documents
An exit plan and a switch-over runbook per provider, versioned and delivered to you.
Exports
Scheduled data exports in open formats, stored in the country named in the contract.
Testing
An exercise per plan at the frequency you set, each with a dated test record.
Review
Plans updated after any change to a provider, contract or critical function.
Leaving Pilae
A full export of your data, configuration and runbooks in open formats, and help moving to another operator or back in-house.

The apps behind it

Nextcloud

Files, calendars and shared documents for the whole organisation, on storage you can point at in a room you control.

Replaces Google Drive, Dropbox, SharePoint

Garage

S3-compatible object storage that keeps every object in three zones, on your own hardware or in the Pilae regions you choose.

Replaces Amazon S3, MinIO, Wasabi

Open WebUI

A chat interface over models you host, so prompts and the documents people paste into them never leave your network.

Replaces ChatGPT Team, Microsoft Copilot

vLLM

An OpenAI-compatible inference server for open-weight models, run on GPUs in Switzerland, the EU or your own datacentre, so prompts and answers never reach a model vendor.

Replaces OpenAI API, Azure OpenAI

Keycloak

Single sign-on for everything else you run, with your own directory as the source of truth and no per-seat bill between you and it.

Replaces Okta, Microsoft Entra ID

n8n

Workflow automation your own team writes, running next to the systems it talks to instead of reaching them across the internet.

Replaces Zapier, Make

NocoDB

A spreadsheet interface over a real database, so a department can build the tool it needs without anyone provisioning a new system.

Replaces Airtable

Mattermost

Team chat, channels and calls on a server in the country you choose, with the message history stored in your own database.

Replaces Slack, Microsoft Teams

Forgejo

Git hosting, code review, issues, packages and CI in one service, run in Switzerland, the EU or your own datacentre, with CI runners on machines of their own.

Replaces GitHub, GitLab.com, Bitbucket

Questions

What does DORA require for ICT exit strategies?

DORA, the EU Digital Operational Resilience Act, applies to EU financial entities from 17 January 2025. Article 28 requires exit strategies for ICT services that support critical or important functions, and expects them to be comprehensive, documented, sufficiently tested and reviewed periodically. Pilae delivers the plans, fallbacks and test records; responsibility for compliance stays with the financial entity.

What does FINMA expect for outsourcing exits?

FINMA Circular 2018/3 on outsourcing expects banks, securities firms and insurance companies that outsource significant functions to keep control of them, and to be able to transfer the function back in house or to another provider without disrupting it. A tested exit plan is how you show that. Your compliance team decides how the plan fits your own obligations.

Which dependencies should have an exit plan?

Start with the services that support critical or important functions: collaboration and email, file storage, identity, AI assistants, CRM and the automation that moves data between them. We help you rank them during the mapping.

Does an exit plan mean we have to leave the provider?

No. You can keep the provider and hold the fallback in reserve. The plan exists so that leaving is possible on your terms, whether the trigger is a price change, a legal change, an outage or the end of a contract.

What if Pilae itself is the provider we need to exit?

The apps we run are open source or source-available, and your contract gives you your data, configuration and runbooks in open formats. Another operator, or your own team, can take over the same apps without rebuilding them.

How much does an exit plan cost?

Pricing is on request. It depends on the number of providers, the depth of each fallback and how often the plans are tested. We quote at a fixed price after the mapping.

Related

List the providers you could not do without.

A call with an engineer: we look at your critical dependencies, propose a fallback for each and quote the exit plans at a fixed price.