Concept
What data sovereignty is
The idea in plain terms and why it decides who really controls your data.
Can you prove you own your data?
Why now
Regulation, geopolitics, and cost make data ownership urgent.
67%
67% of the Dutch (semi-)government and vital-sector domain names examined are linked to at least one US cloud service.
Regulatory pressure
EU rules influence architecture choices on portability, oversight, and third-party risk.
Geopolitical uncertainty
Access can be denied due to geopolitics.
Rising costs
Lock-in compounds: cloud and migration costs keep rising.
Ethical considerations
Who benefits from data, who bears risk, and how do decisions stay explainable and fair?
What we do
We work with regulated organisations end to end: we map where your data lives, set the strategy, then build and run the platform that ties it together. You keep the keys and can leave whenever you choose.
Advise
We map your data and platform landscape, surface the dependencies and set a sovereignty strategy you can act on.
Build
We design and build a portable data platform on open standards and hand over the source code that runs it.
Run
We keep it running with security and governance built in and get your own team ready to take over whenever you want.
How we work
In three phases, we make dependencies visible, decisions explicit, and execution provable.
01 · Visualize
We draw the map
Our flagship project
Co-developed with Next Learning Valley, TNO and NLR: a training platform for 200,000 soldiers meeting NATO security requirements and embedded compliance.
The platform
We are building what we wish existed: a data platform designed for sovereignty from day one.
Portable
Container-based, standards-first. Move between clouds, on-prem, or air-gapped without rewrites.
Mature
Security, governance, and compliance built in, not bolted on after launch.
Turnkey
Configure, don't build: one artefact set per target and GitOps bootstrap, so a small team can operate it.
Click a component to learn more
Free and open. No sign-up.
A practical field guide to owning your data and the systems around it. Plain-language concepts, checklists, vendor questions and AI prompts you can use today.
Concept
The idea in plain terms and why it decides who really controls your data.
Checklist
A step-by-step check of how easily you could leave a supplier.
Vendor questions
The questions to put to any supplier before you commit.
AI prompt
Paste a contract and let AI flag the lock-in clauses.
Insights
Writing on data sovereignty, ownership, and keeping control of your data.

Vendors reassure mental-healthcare providers that patient records are safe and secure, stored according to NEN7510 and ISO27001 standards. We checked what that means across the EPD market, supplier by supplier. Location is not control.

You can own the hardware, the software and the data and still not control them. The fourth layer of data sovereignty is the contract, and it decides whether you can exercise the other three.

You cannot hold legal title to data. But strip ownership to its core and three rights remain: to possess, use, and dispose. Those you can hold, and that is data sovereignty.
We're here to help. Ask us a question or schedule a conversation.
Answers to common questions about data sovereignty and our approach.
Copyright 2026HOIST IT. All Rights Reserved