Sovereign & hybrid cloud
Hosted in Europe says nothing until you say which jurisdiction the provider answers to. Sovereignty is a placement rule, written per class of data and enforced by the infrastructure rather than by a policy document.
The jurisdiction follows the provider, not the datacentre.
Since 2018, data held by a provider subject to US law can be reached wherever it physically sits. A European region is therefore an answer to the wrong question, and it is the answer most contracts still give.
We start from the data instead. Each class gets a written rule saying where it may live, who holds the keys, and what happens to its backups. The rule then lives in the infrastructure, where a wrongly placed workload is refused at creation rather than discovered in an audit.
What we do
Four workstreams so where the data lives becomes a decision rather than a consequence.
Classification and placement rule
Each class of data gets a written rule: allowed hosting, forbidden hosting, who holds the encryption keys and which framework applies. The rule is negotiated once, then applied everywhere.
an exception is named, dated and reviewed, never implicit
- Allowed and forbidden hosting per class
- Keys held by you where sensitivity demands it
- Exceptions dated and reviewed twice a year
Qualified and private hosting
Public European cloud, private infrastructure or SecNumCloud-qualified hosting, chosen by class rather than for the whole estate. Most estates need all three.
the choice follows the data, not a preference for one provider
- Qualified hosting where the framework requires it
- Private infrastructure for what must not leave
- Public European cloud for the rest
Interconnection
Hybrid does not mean two platforms side by side. The two halves talk over a private link, with a latency budget and an explicit list of what is allowed to cross.
everything not listed is refused by default, and the refusal is logged
- Private link, end-to-end encryption
- One directory of record, short-lived tokens
- A latency budget, beyond which sync calls are barred
Residency control
Placement is audited against the rule, backups included. A backup inherits the sensitivity of its source, and this is where sovereignty most often leaks without anyone deciding it.
a default option can move a copy out of the perimeter on its own
- Placement audited against the written rule
- Backups and cross-region replication inspected
- Refusals and exceptions readable in the log
What you get
One project runs through the four deliverables below: the hybrid foundation of a public-service operator, forty-seven workloads across three zones. Each line states what is actually handed over, in the order it is handed over.
The classification, and its placement rule
Per class of data: allowed hosting, forbidden hosting, applicable framework and who holds the keys. This is the file the whole rest depends on, and the only one the business has to arbitrate.
The rule inside the infrastructure
Zones declared with the jurisdiction each answers to, and a wrongly placed workload refused at creation. Backups inherit the sensitivity of their source, which is what most rules forget to say.
The interconnection between the two halves
A private link, end-to-end encryption, one directory of record, and an explicit list of what may cross in each direction. Everything else is refused by default and appears in the log.
The residency audit
Workloads, volumes and backups inspected against the rule. What the audit finds is rarely a decision someone made: it is usually a provider default that nobody turned off.
How we deliver
Inventory
depending on the number of workloads, dependencies and residency constraints
- Inventory and dependencies per workload
- One strategy per workload, retirement included
- Costed trajectory with hidden costs modelled
First wave
depending on the landing zone to lay down and the workloads selected
- Landing zone described as code
- Cutover rehearsed, fallback proven
- Fourteen days of comparison before switch-off
Following waves
depending on the workloads left and how coupled they are
- Following waves on the same template
- Workloads rewritten where moving is not enough
- Team upskilling
Operate
service commitment defined with you
- Cost attached to the workload and tracked
- Guardrails enforced at creation
- Reversibility proven, not declared
Where the European market stands
Enterprise-grade AI: sovereign and compliant
Adservio runs your AI platforms on sovereign cloud, with European models and native compliance: the security and control large organisations need
Learn moreSovereign cloud
OVHcloud, Scaleway, HDS hosting and SecNumCloud: your data and your models stay under European jurisdiction.
European models
Self-hosted models (Mistral, Llama), with no dependency on US hyperscalers, operated right next to your systems.
Native compliance
A stack compliant by default: AI Act, DORA, NIS2 and GDPR, with model traceability and governance.
24/7 cyber-resilience
SOC and SIEM monitored around the clock, AI red teaming and tested continuity plans for your critical systems.
Sovereignty under real constraint

An augmented IT department on a critical public-service network
12,000 employees covered · Critical systems kept in service
A gas distribution network operator whose systems fall under essential-service obligations, where an interruption is not an incident report but a service outage, and where data residency is a constraint rather than a preference.
An augmented IT department built around the existing teams, with the engineering standards and the governance that let critical systems evolve without the availability commitment being renegotiated each time.

Fraud caught in real time, under compliance and sovereignty constraints
+40% fraud detection · −60% KYC time
Detecting fraud on massive volumes in real time and making regulatory data reliable, under compliance and sovereignty constraints that rule out sending the data anywhere convenient.
A governed data foundation with detection models wired into the flows and a copilot whose every answer carries its sources, hosted according to what each dataset allows rather than according to what is easiest.
Insights & Perspectives

Database-as-a-Service (DBaaS)
Running a database without managing it: managed hosting, usage-based billing and delegated security, with the question of where the data actually sits.

Infrastructure as Code: where are we today?
An interview with Kief Morris on the evolution of infrastructure as code: platform, self-service and day-two challenges.

Data governance in digital transformation
What governing data means day to day: ownership, quality, lineage, and the arbitration between compliance and the pace the business needs.
Decide where your data lives
A classification, a placement rule enforced at creation, and a residency audit that inspects the backups too.
Frequently asked questions
No. Since the Cloud Act, data held by a provider subject to US law can be reached wherever it physically sits. The question is not where the datacentre is but which jurisdiction the provider answers to, and who holds the encryption keys.
That a provider meets the security and immunity-to-extraterritorial-law requirements set by the French ANSSI. It applies to an offer, not to a company, so a provider can hold it on one service and not on another. It is checked per service, not per logo.
No, and treating the whole estate the same way is what makes sovereignty unaffordable. Public data does not need qualified hosting. The cost comes from the classes that do, so the value of the exercise is in drawing the line precisely.
In the backups. The database sits in the right zone, and its automatic backup replicates to a second region outside it, because the provider enables cross-region replication by default. Nobody decided it, and an audit that only inspects workloads will not see it.
Not if the placement is arbitrated per class. What costs is running two full platforms in parallel out of caution. What works is one rule, three zones, and each workload in exactly one of them, with an explicit list of what may cross between them.
You do, on anything the framework or the sensitivity requires, with the keys managed on your own hardware module. A provider that can decrypt on request has not removed the risk, it has moved it into a contract clause.
Framing takes 2 to 6 weeks depending on the number of workloads, dependencies and residency constraints, and produces the classification and the placement rule. The rule is then enforced by the infrastructure within 4 to 10 weeks, along with the first residency audit, backups included.
