Reversibility & portability
Reversibility is not about leaving. It is about knowing, before signing, what leaving would take and how long it would run. A dependency you have named and costed is a decision; the same dependency discovered on the day of departure is an incident.
An exit plan that has never been played is an intention.
Nobody builds a platform expecting to leave it, which is exactly why the question never comes up at a good moment. It arrives when a provider changes its terms, when an acquisition moves the hosting, when a board asks where the data actually sits. At that point the only thing that matters is knowing what leaving would take, and how long it would run.
We make that answer available before anyone needs it. Dependencies named, classified and costed rather than avoided on principle: a managed service that saves an operations team months is worth its dependency, provided somebody wrote it down. Clauses that list by name what can be exported. And a rehearsal run at real volume, because what an exit plan gets wrong is almost never the export: it is everything that has to be rebuilt rather than transferred.
What we do
Four workstreams so leaving stays a decision rather than a project nobody dares start.
Naming the dependencies
Every managed service, proprietary format and access model listed, with what it would cost to leave it. A dependency is not a defect; it is a choice that has to be known and revised, not discovered.
classified as accepted, to be reduced, or ruled out
- One line per managed service, with its way out
- Proprietary formats, and whether an export exists
- The access model described outside the console
Portable foundations
Infrastructure described in code, open protocols, container images and data in formats readable without the tool that produced them. What is described replays elsewhere; what lives in an interface does not replay at all.
portability proven on a second target, not asserted
- Infrastructure as code, replayed on a second target
- Open protocols wherever an equivalent exists
- Data in formats readable without the original tool
Clauses that say something
The exportable scope listed by name, an open and documented format, a lead time measured at real volume, and exit assistance costed rather than promised. The regulation sets a floor; the contract has to apply it to your estate.
negotiated at renewal, not at departure
- Exportable scope listed by name, not by category
- Lead time measured at real volume, not at pilot volume
- Exit assistance costed, with a named counterpart
Rehearsing the exit
The switch executed at real volume, durations measured, rollback written and played. A rehearsal usually finds a delay rather than a blocker, and a delay found in advance is negotiable.
replayed at each contract renewal
- The switch run at production volume
- What is rebuilt counted apart from what is exported
- A rollback written, then actually played
What you get
One project runs through the four deliverables below: preparing and then rehearsing an exit plan. Each line states what is actually handed over, in the order it is handed over.
The inventory of dependencies
Managed services, proprietary formats and the access model, each with what leaving would cost and a classification: accepted, to be reduced, or ruled out. The one most often forgotten is the entitlement model that only exists in a console.
The clauses to obtain
The exportable scope listed by name, an open format readable without the original tool, a lead time measured at real volume and costed exit assistance. The regulation is the floor, not the contract.
The switching procedure
A sequence written to be executed rather than read, with success criteria that require the same service level and not merely a system that starts, and a rollback that exists before the first step.
The rehearsal, at real volume
The export runs in four days. What the rehearsal finds is the nineteen days of rebuilding nobody had counted inside a thirty-day window, which is a duration to negotiate rather than a blocker.
How we deliver
Inventory
depending on the number of managed services and the age of the contracts
- Dependencies named, classified and costed
- Proprietary formats and their documented way out
- The access model, described outside the console
Contract
depending on the negotiating room and the renewal dates
- Exportable scope listed by name
- Open format and lead time measured at real volume
- Exit assistance costed, not promised
Rehearse
depending on the data volume and what has to be rebuilt rather than transferred
- The switch executed at real volume
- Durations measured, rebuilds included
- The rollback written and played
Maintain
service commitment defined with you
- The inventory revised with each new service
- The rehearsal replayed at each renewal
- Gaps closed before the next deadline
Free to move, and rarely needing to
Reversibility is rarely used and always worth holding. A platform you could leave is a platform you negotiate from, and most of what makes it leavable makes it easier to operate in the first place.
A dependency you have named. Every managed service and proprietary format listed with its cost of exit, classified and revised at each renewal rather than avoided on principle.
Platforms built to be left

A delivery chain described in code rather than in scripts
18 squads on one chain · −72% time-to-market
Legacy Jenkins pipelines, proprietary shell scripts and manual deployments accumulated over the years: nothing that could be replayed anywhere else, and a production release that took several days.
A chain rebuilt on Terraform, Ansible, Docker and Kubernetes, with compliance controls wired into the pipeline. What is described in code can be replayed on another foundation; what lives in a console cannot be replayed at all.

Fourteen modules, open bricks, hosted in France
14 modules in production · 100% open source
Informal tooling of spreadsheets and free SaaS products that no longer held the volume, on data belonging to minors, with a non-profit budget that ruled out recurring proprietary licences.
A modular information system built on Postgres, Symfony, Strapi, Metabase and Mailtrain, hosted in France and compliant with GDPR and WCAG 2.1 AA. Open formats and documented bricks, so nothing is held by a licence.
Insights & Perspectives

Kubernetes vs Docker: two container technologies you should not oppose
Docker packages applications into containers, Kubernetes orchestrates them at scale: two complementary building blocks of the DevOps pipeline, not rivals.

Cloud adoption strategies
Cloud adoption is no longer a question of feasibility. Success means aligning technology with business objectives: seven strategies to adopt the cloud methodically.

Cloud backup and recovery: building a cyber-resilience strategy
The 3-2-1-1-0 rule, immutability, RPO and RTO: the guide to a recovery strategy that has actually been tested rather than merely documented.
Know the way out before you need it
Dependencies named and costed, clauses measured at real volume, and an exit plan played once rather than written twice.
Frequently asked questions
No, because a contract sets a deadline and never says what fits inside it. European rules now cap notice periods and transition windows, which is a floor worth having. What neither the regulation nor the contract measures is how long your own data takes to come out, and how much of it has to be rebuilt instead.
No. A managed service that saves an operations team months is worth its dependency. What matters is knowing which ones have an equivalent elsewhere, which ones would have to be rebuilt, and how long that rebuild takes at your volume.
Rarely as a permanent architecture. Running everywhere at once multiplies the cost and the operating burden for a freedom you use once. What actually holds is a single platform described in code, proven replayable on a second target.
A duration, not a blocker. The export itself is rarely the problem. What surprises is everything that has to be rebuilt rather than transferred, a search index or a derived model, which can consume most of a thirty-day transition window on its own.
The entitlement model. Identities, roles and permissions frequently exist only inside a provider's console, so they cannot be replayed elsewhere. Data comes back and nobody can be authorised to use it, which stops a switch as effectively as a proprietary format.
At renewal, never at departure. A provider being asked for a costed exit commitment while a contract is being signed answers differently from one being asked once the customer has already announced they are leaving.
The inventory takes 2 to 6 weeks depending on the number of managed services and the age of the contracts, and produces the named dependencies, the proprietary formats with their way out and the access model described outside the console. Clauses and a first rehearsal follow in 4 to 10 weeks.
