Skip to content
← Back to the toolkit
DisposeUseSoftwareOrganisational

Vendor lock-in

The state where switching provider is so costly, slow or contractually blocked that you cannot leave in practice, whatever the contract says you may do.

Lock-in is the quiet way sovereignty is lost, by an accumulation of conveniences that harden into constraints.

Lock-in rarely arrives as a choice. It accumulates. A managed service here, a proprietary format there, a control plane you build your runbooks around, and one day leaving would cost more than staying, so you stay. That is the mechanism, and it is why a workload that cannot move cannot really be owned.

It has several faces: proprietary services with no open equivalent, data formats only the vendor can read, provider-specific APIs woven through your code, identity and secrets tied to the provider’s control plane, skills and tooling that assume one supplier and commercial terms such as egress fees or minimum commitments. Each one is a switching cost, and the total switching cost is the real measure of lock-in.

The defence is to build the ability to leave before you need it. Portability, open formats and an executable exit clause are the three levers that keep switching a genuine option.

Common misconceptions

We are not locked in, we can export our data whenever we like.

Data export is one dimension. Proprietary APIs, managed services with no equivalent, identity tied to the provider and egress fees can each turn leaving into a project.

Open source means no lock-in.

You can be locked into a specific managed distribution, a control plane or an operational model even when the source is open. Lock-in is a property of the whole system, and an open licence does not settle it.

Put this to work

Apply this checklist

Can you leave? The exit-readiness checklist

Twelve checks that tell you whether you could actually move off a critical supplier, before you need to. Print it, take it into a stand-up, and mark honestly.

Questions for your vendor

Questions to ask a vendor before you sign

The questions that make a supplier prove data sovereignty, and what a real answer versus an evasive one sounds like. Copy them into an RFP, or read them down a vendor call.

Related concept

Data portability

The ability to extract the data and context required within the stated scope in a documented, usable form and transfer or load them into an independently chosen system.

Related concept

Exit clause

The contractual terms that decide what happens to your data and your access to it, when the arrangement ends, on any terms including the ones you did not choose.

Related article

A Dutch data centre is not (per se) a sovereign one

Vendors reassure mental-healthcare providers that patient records are safe and secure, stored according to NEN7510 and ISO27001 standards. We checked what that means across the EPD market, supplier by supplier. Location is not control.

Related article

The layer you sign first and read last

You can own the hardware, the software and the data and still not control them. The fourth layer of data sovereignty is the contract, and it decides whether you can exercise the other three.

Copyright 2026HOIST IT. All Rights Reserved