SEAL-4 aligned cloud foundation

The foundation Europe can own.

Foundix is a fully transparent, SEAL-4 aligned secure private cloud. You hold the keys, operators are European, and the critical path does not run through a non-EU control plane. SOVNC and SOVGO are the first two product solutions.

The problem is not a region tick-box.

A workload in a hyperscaler’s ‘EU region’ is not sovereignty. Jurisdiction, update chain, identity, key custody and recovery often remain outside EU control. For DORA, NIS2 and ISO 27001 that is the risk, not a footnote.

Foundix is the answer at foundation level.

Not another dashboard on someone else’s cloud. A foundation you can audit, exit, and operate without us if you must. On top sit the first products: SOVNC for the network path, SOVGO for governance and operations.

Why Foundix

EU operations

Operators and operations under EU law. No mandatory non-EU service in the critical path.

Customer-controlled cryptography

Keys stay with the customer or the EU operator. Encryption is not a marketing layer.

Open and auditable

Proxmox VE, ZFS, OPNsense, Linux. The chain can be inspected.

Exit is designed

Independent recoverability. No rewrite of the business to leave.

First product solutions

SOVNC en SOVGO eerst. SovTooling en Cloud Spawn maken de zone compleet.

SOVNC

Sovereign Network Cloud

Zero-trust network fabric: segmentation, operator-controlled DNS, east-west control. The path that isolates tenants.

More

SOVGO

Sovereign Governance Operations

Policy, evidence, access and verifiable backups. The control layer for DORA and NIS2 evidence.

More

SovTooling

GPU / AI

Local inference and GPU tooling under your keys. Prompts are not a product for a non-EU model vendor.

More

Cloud Spawn

Framework

The framework that spawns sovereign landing zones: isolated, encrypted tenants without a hyperscaler control plane.

More

Architecture

Foundix architecture: SOVNC, SOVGO, SovTooling, Cloud Spawn on Proxmox, ZFS, OPNsense, PBS

What the foundation stands on

Proxmox VE

Clustered compute you can run and audit yourself.

Encrypted ZFS

Multi-tenant storage with isolation and snapshots.

OPNsense

Zero-trust fabric under SOVNC.

Rocky / Debian

Hardened Linux baselines.

PBS + sanoid

Independent recoverability under SOVGO.

Local AI

SovTooling: inference under operator control.

Residency is not ownership of the control plane

QuestionHyperscaler EU regionFoundix
Who owns the control plane?The vendor, under its group structureEU operator; you can take it over
KeysOften provider-managed, with escrow riskCustomer- or operator-controlled
Network pathShared fabric + vendor policySOVNC: zero-trust under your policy
Supervisory evidenceContract annexes and region claimsSOVGO: logs, backup verification, access trails
ExitExport plus rebuildThe same open stack, portable

Questions a CISO asks

Where do data and the control plane live?

Workloads in a Dutch/EU datacentre or on-prem. The critical control plane is designed without a mandatory non-EU dependency.

Who holds the keys?

Cryptography is customer- or operator-controlled. Foundix does not sell a ‘we can always reach your data’ model.

How do Foundix, SOVNC and SOVGO differ?

Foundix is the foundation. SOVNC is the network product. SOVGO is the governance and operations product. SovTooling and Cloud Spawn sit above them.

Is this datacentre-only?

No. The same model can run on-prem if network, storage and backup paths pass the same SEAL-4 tests.

Do you put AI in the path?

SovTooling is local. There is no mandatory non-EU model API in the critical path. This website has no AI chat widget.

How do you prove backups?

PBS and sanoid, with verification under SOVGO — not a snapshot nobody ever restores.

May we audit?

Yes. Open stack, documentable configuration, exit path. That is a design goal.

Are you ISO 27001 certified?

Not claimed on this site. The foundation is designed to support evidence for ISO 27001, DORA, NIS2 and GDPR. Status: [CERT_STATUS].