Skip to content
← Back to the toolkit
EducationalArchitect

Review an architecture for sovereignty risks

Maps practical control, dependencies and evidence gaps across data, software, infrastructure and organisational arrangements, then ranks the risks that matter most.

Prompt for your AI
Do not include credentials, secrets, personal data, internal addresses, undisclosed controls or exploitable architecture details. Redact them, or use an approved private or local assistant.

Architecture description: [least sensitive detail needed]. Scope: service or release [version], deployment [profile], operating model [description], relevant agreements and governance [details], customer-control boundary [boundary] and review date [date]. Include evidence references where safe; do not paste confidential evidence.

Act as a sovereignty-focused architecture reviewer. Examine practical control questions across data, software, hardware or cloud infrastructure, and organisational arrangements. Use Possess, Use and Dispose as prompts for investigation: what can the customer obtain and retain, operate and change, revoke or delete, transfer or replace? Do not turn the review into a score or formal verdict.

Produce one row for each meaningful capability or dependency: area | practical control question | supplied evidence | who controls it in practice | assumptions and missing or conflicting evidence | operational consequence | smallest verification exercise. A component may appear in several rows when it creates different dependencies. Missing evidence is a gap to investigate, not permission to guess success or failure.

Then:
- rank the five most material gaps by operational loss and difficulty of reversal, not likelihood alone;
- flag managed services, proprietary interfaces and data or control-plane dependencies that would not survive a provider change, and name plausible alternatives without claiming drop-in equivalence;
- map every path to plaintext, key policy, key custody and provider or operator access, with lawful-access questions marked for qualified legal review;
- identify the dependency whose withdrawal would most damage continuity and the evidence for whether operation could continue;
- separate data-compliance questions for qualified review from data-ethics considerations for customer governance.

Be specific about the supplied scope and explicit about uncertainty. Do not let a strong feature hide an unrelated dependency, and do not produce an overall sovereignty score, badge, legal or ethical verdict, or certification.
---
Use the toolkit as a practical way to examine who can possess, use and dispose of data and the software, hardware and organisational arrangements around it. Keep weak points visible instead of hiding them in one overall judgement.
Examine the organisational side through two complementary perspectives. Data compliance covers applicable rules, contracts, policies, authority, duties and supplier commitments. Data ethics asks whether choices are proportionate, fair, transparent and explainable. Governance operates across both.
Keep compliance questions and data-ethics concerns separate. Leave applicability and legal interpretation to qualified counsel, and do not present ethical considerations as a certification or universal verdict.
Scope every conclusion to the described service, deployment, operating model, agreements, customer boundary and date. Separate supplied facts from assumptions and missing or conflicting evidence. Do not produce an overall score, legal or ethical verdict, or certification.
Data handling: do not include personal data, credentials, secrets or confidential contractual, security or architecture details. Redact them and use an approved private or local assistant when redaction is insufficient.
Background and definitions: https://hoist-it.nl/toolkit
Relevant concepts: https://hoist-it.nl/toolkit/vendor-lock-in  https://hoist-it.nl/toolkit/key-management  https://hoist-it.nl/toolkit/the-four-layers  https://hoist-it.nl/toolkit/data-compliance  https://hoist-it.nl/toolkit/data-ethics
Copy this into an assistant of your choice. The links give it context. Replace the [bracketed] parts with your own, and do not paste anything confidential.

Use the least detail needed for a useful review. Keep sensitive specifics inside an approved private review environment.

Keep going

Related concept

Vendor lock-in

The state where switching provider is so costly, slow or contractually blocked that you cannot leave in practice, whatever the contract says you may do.

Related concept

Encryption key custody

Who controls key material, key policy, decryption requests and revocation, and which technical or operational paths can still reach plaintext.

Copyright 2026HOIST IT. All Rights Reserved