SEAL-4

Transparent. Under EU law. Ownable.

SEAL-4 requires full EU control over technology and operations, subject to EU law, with no critical non-EU dependency in the path that creates, isolates, encrypts or recovers a tenant.

Foundix applies the same test to every component: does this create a critical non-EU dependency? Can EU operators fully own and evolve it? Are keys customer-controlled? Is the chain auditable? Is there an exit?

SOV-1 StrategicEU-controlled foundation, not a reseller of a non-EU control plane.
SOV-2 LegalCritical path under EU law. NL/EU operators.
SOV-3 Data & AIData and inference stay under operator control via SovTooling.
SOV-4 OperationalWe can run Foundix for you — or you can take it over.
SOV-5 Supply chainHighest weight: open, inspectable components.
SOV-6 TechnologyProxmox, ZFS, OPNsense, Linux — no black-box lock-in.
SOV-7 SecurityDesigned to carry DORA, NIS2 and ISO 27001 evidence.
SOV-8 EnvironmentalEU DC or on-prem; no greenwash, measurable footprint later.

Where pure SEAL-4 is currently impractical

Some firmware, CPU microcode, optional GPU drivers and upstream security feeds originate outside the EU. That is residual risk. Compensation: pin and verify artifacts, minimise runtime contact, document the chain, keep a replacement path. Foundix does not hide this behind ‘100% sovereign’.

Exit statement

The foundation is open. Configuration is documentable. Backups are independently restorable. Products (SOVNC, SOVGO, SovTooling, Cloud Spawn) must not trap you in a closed control plane. When you leave, you take the stack — not only an export file.