Reversibility & portability

Know the way out before you need it

Reversibility is not about leaving. It is about knowing, before signing, what leaving would take and how long it would run. A dependency you have named and costed is a decision; the same dependency discovered on the day of departure is an incident.

An exit plan that has never been played is an intention.

Nobody builds a platform expecting to leave it, which is exactly why the question never comes up at a good moment. It arrives when a provider changes its terms, when an acquisition moves the hosting, when a board asks where the data actually sits. At that point the only thing that matters is knowing what leaving would take, and how long it would run.

We make that answer available before anyone needs it. Dependencies named, classified and costed rather than avoided on principle: a managed service that saves an operations team months is worth its dependency, provided somebody wrote it down. Clauses that list by name what can be exported. And a rehearsal run at real volume, because what an exit plan gets wrong is almost never the export: it is everything that has to be rebuilt rather than transferred.

What we do

Four workstreams so leaving stays a decision rather than a project nobody dares start.

WORKSTREAM 01Named, then costed

Naming the dependencies

Every managed service, proprietary format and access model listed, with what it would cost to leave it. A dependency is not a defect; it is a choice that has to be known and revised, not discovered.

classified as accepted, to be reduced, or ruled out

  • One line per managed service, with its way out
  • Proprietary formats, and whether an export exists
  • The access model described outside the console
WORKSTREAM 02Described, not clicked

Portable foundations

Infrastructure described in code, open protocols, container images and data in formats readable without the tool that produced them. What is described replays elsewhere; what lives in an interface does not replay at all.

portability proven on a second target, not asserted

  • Infrastructure as code, replayed on a second target
  • Open protocols wherever an equivalent exists
  • Data in formats readable without the original tool
WORKSTREAM 03Beyond the regulation

Clauses that say something

The exportable scope listed by name, an open and documented format, a lead time measured at real volume, and exit assistance costed rather than promised. The regulation sets a floor; the contract has to apply it to your estate.

negotiated at renewal, not at departure

  • Exportable scope listed by name, not by category
  • Lead time measured at real volume, not at pilot volume
  • Exit assistance costed, with a named counterpart
WORKSTREAM 04Played, not reviewed

Rehearsing the exit

The switch executed at real volume, durations measured, rollback written and played. A rehearsal usually finds a delay rather than a blocker, and a delay found in advance is negotiable.

replayed at each contract renewal

  • The switch run at production volume
  • What is rebuilt counted apart from what is exported
  • A rollback written, then actually played

What you get

One project runs through the four deliverables below: preparing and then rehearsing an exit plan. Each line states what is actually handed over, in the order it is handed over.

01

The inventory of dependencies

Managed services, proprietary formats and the access model, each with what leaving would cost and a classification: accepted, to be reduced, or ruled out. The one most often forgotten is the entitlement model that only exists in a console.

02

The clauses to obtain

The exportable scope listed by name, an open format readable without the original tool, a lead time measured at real volume and costed exit assistance. The regulation is the floor, not the contract.

03

The switching procedure

A sequence written to be executed rather than read, with success criteria that require the same service level and not merely a system that starts, and a rollback that exists before the first step.

04

The rehearsal, at real volume

The export runs in four days. What the rehearsal finds is the nineteen days of rebuilding nobody had counted inside a thirty-day window, which is a duration to negotiate rather than a blocker.

How we deliver

PHASE 012 to 6 weeks

Inventory

depending on the number of managed services and the age of the contracts

  • Dependencies named, classified and costed
  • Proprietary formats and their documented way out
  • The access model, described outside the console
PHASE 024 to 10 weeks

Contract

depending on the negotiating room and the renewal dates

  • Exportable scope listed by name
  • Open format and lead time measured at real volume
  • Exit assistance costed, not promised
PHASE 033 to 6 months

Rehearse

depending on the data volume and what has to be rebuilt rather than transferred

  • The switch executed at real volume
  • Durations measured, rebuilds included
  • The rollback written and played
PHASE 04continuous

Maintain

service commitment defined with you

  • The inventory revised with each new service
  • The rehearsal replayed at each renewal
  • Gaps closed before the next deadline

Free to move, and rarely needing to

Reversibility is rarely used and always worth holding. A platform you could leave is a platform you negotiate from, and most of what makes it leavable makes it easier to operate in the first place.

A dependency you have named. Every managed service and proprietary format listed with its cost of exit, classified and revised at each renewal rather than avoided on principle.

Platforms built to be left

A delivery chain described in code rather than in scripts
Ageas FranceInsurance
IaC & portability
Case(01)

A delivery chain described in code rather than in scripts

18 squads on one chain · −72% time-to-market

The challenge

Legacy Jenkins pipelines, proprietary shell scripts and manual deployments accumulated over the years: nothing that could be replayed anywhere else, and a production release that took several days.

Our answer

A chain rebuilt on Terraform, Ansible, Docker and Kubernetes, with compliance controls wired into the pipeline. What is described in code can be replayed on another foundation; what lives in a console cannot be replayed at all.

Read the case study
Fourteen modules, open bricks, hosted in France
ZUPDECOEducation & non-profit
Open standards
Case(02)

Fourteen modules, open bricks, hosted in France

14 modules in production · 100% open source

The challenge

Informal tooling of spreadsheets and free SaaS products that no longer held the volume, on data belonging to minors, with a non-profit budget that ruled out recurring proprietary licences.

Our answer

A modular information system built on Postgres, Symfony, Strapi, Metabase and Mailtrain, hosted in France and compliant with GDPR and WCAG 2.1 AA. Open formats and documented bricks, so nothing is held by a licence.

Read the case study
TALK TO AN EXPERT

Know the way out before you need it

Dependencies named and costed, clauses measured at real volume, and an exit plan played once rather than written twice.

By submitting this form, you agree to our privacy policy.

Frequently asked questions

No, because a contract sets a deadline and never says what fits inside it. European rules now cap notice periods and transition windows, which is a floor worth having. What neither the regulation nor the contract measures is how long your own data takes to come out, and how much of it has to be rebuilt instead.

No. A managed service that saves an operations team months is worth its dependency. What matters is knowing which ones have an equivalent elsewhere, which ones would have to be rebuilt, and how long that rebuild takes at your volume.

Rarely as a permanent architecture. Running everywhere at once multiplies the cost and the operating burden for a freedom you use once. What actually holds is a single platform described in code, proven replayable on a second target.

A duration, not a blocker. The export itself is rarely the problem. What surprises is everything that has to be rebuilt rather than transferred, a search index or a derived model, which can consume most of a thirty-day transition window on its own.

The entitlement model. Identities, roles and permissions frequently exist only inside a provider's console, so they cannot be replayed elsewhere. Data comes back and nobody can be authorised to use it, which stops a switch as effectively as a proprietary format.

At renewal, never at departure. A provider being asked for a costed exit commitment while a contract is being signed answers differently from one being asked once the customer has already announced they are leaving.

The inventory takes 2 to 6 weeks depending on the number of managed services and the age of the contracts, and produces the named dependencies, the proprietary formats with their way out and the access model described outside the console. Clauses and a first rehearsal follow in 4 to 10 weeks.