No migration project
Your tenant, licences and workflows stay exactly where they are. Nothing has to be exported, remapped or retrained.
Solutions · Cloud encryption
A cloud encryption gateway sits between your people and the cloud. Documents, mail and fields are encrypted before they ever reach Microsoft, Google or AWS, and the keys stay with you. The provider stores ciphertext it cannot read, index or hand over. Your teams keep working in the same tools.
Most organisations cannot abandon Microsoft 365, Google Workspace or AWS overnight. The licences are signed, the workflows are built, and the people know the tools. At the same time, the legal ground has moved: a US provider remains subject to the CLOUD Act no matter which country the data centre stands in, and since Schrems II a European organisation has to be able to explain what actually protects the data, not merely where it sits.
That leaves a gap that contracts do not close. Data-processing agreements govern behaviour, not capability. As long as the provider holds readable data, the provider can be compelled to produce it. Encryption is the only measure that changes what is technically possible rather than what is contractually promised.
Together with our partner eperi we put a gateway in front of the cloud service. Nothing about the user's day changes.
Writing an email, saving a file, filling a field in a cloud application — the ordinary work, in the ordinary tool.
Encryption happens before the data leaves your network. The keys are generated and held on your side, never by the cloud provider.
What arrives in the cloud cannot be read, indexed, analysed, used for training or produced in response to a foreign order.
Search, sorting and the familiar interface keep working, because the gateway decrypts on the way back for the people you have authorised.
This is the fastest of our four routes to sovereignty, because it changes the risk without changing the platform. It is often the first step, taken while a longer migration is still being planned.
Your tenant, licences and workflows stay exactly where they are. Nothing has to be exported, remapped or retrained.
Instead of relying on assurances about provider behaviour, you remove the provider's ability to read the data at all.
Encryption today does not lock you in. When you do move workloads to sovereign infrastructure, the gateway comes with you.
Where leaving is not realistic in this budget year but the risk assessment still has to hold up.
Healthcare, finance, public bodies and research, where the question is not whether data is in the cloud but who could be made to read it.
Where PIPEDA obligations and a US-headquartered provider have to coexist in the same architecture.
Tell us which services you run and where the risk assessment hurts. We will tell you what a gateway would and would not solve — honestly, including the cases where a migration is the better answer.