Sovereign by design.

EU infrastructure, an open-source stack, and no foreign dependencies in your runtime. Looking for the technical security controls instead? Read the security page.

An EU-only stack

Every layer of the platform is open-source software running on European infrastructure. No American-owned dependencies in the runtime path, no phone-home telemetry, no managed control plane reaching in from outside.

Run nodge in our EU cloud, on your own servers, or fully air-gapped. Self-hosted deployments work entirely offline after install. All organisation data and metadata stay inside the environment you chose.

Built for organisations where data residency, GDPR compliance, NIS2 obligations, and Schrems II rulings are non-negotiable. No exposure to the US CLOUD Act on the platform itself.

what's in the box

Reverse proxy     routing, SSL, DNS
Git hosting       repos, access control
CI/CD runner      build, test, deploy
Image registry    container storage
Metrics engine    per-project monitoring
Dashboards        pre-configured, built-in
Log aggregation   query by project, time
Event bus         pub/sub, audit trail
LLM proxy         budget enforcement
Platform          auth, API, control

Where your data lives, and who can reach it

Residency is not just hosting location. It is the full list of who can touch your data and from where.

Hosted in the Netherlands

Our cloud runs in the Netherlands. Organisation data, metadata, logs, and backups stay within the EU. No replication to regions outside the boundary you chose.

No US-controlled dependencies in the runtime

The runtime path has no American-owned services in it. There is no US-controlled component that could be compelled to hand over or interrupt access under the CLOUD Act.

Self-hosted or air-gapped

Install on your own servers, fully offline, with no internet egress requirement. Self-hosted deployments have zero external dependency after install.

Your code, your formats

Standard Git repositories, standard container images, standard databases. Export and leave at any time. No proprietary format, no exit barrier.

What nodge does not do

Sovereignty is mostly about what a platform refuses to collect, send, or depend on.

No telemetry

Nothing is sent to us. No analytics, no usage tracking, no "anonymous" metrics. The platform does not phone home.

No vendor control plane

Some "self-hosted" platforms still reach back to a central control plane. nodge has zero external dependency after install.

No US dependencies in the runtime

No American-owned service sits in the path that serves your apps, so there is nothing to compel under foreign law.

No training on your data

Your prompts, your agent conversations, your code. None of it is used to train anything. It stays in your environment.

No forced updates

You control when and if you update. No silent background patches. No surprise changes to your running platform.

No exit barrier

Everything you build is in standard formats. Export your repositories, images, and data and leave whenever you want.

Most of what a platform can leak is what it chose to collect.
We chose not to.

Backups you control, keys we never hold

Platform databases, Git repositories, and certificate material are backed up nightly. Backups are encrypted before they leave the platform host, using a key the platform itself does not hold.

Off-host copies sit on a separate backup target that the platform can write to but cannot read back or delete from. The decryption key lives in a vault and never sits on the platform, so restore is a deliberate human action taken outside the platform.

The result is that even full control of the platform does not grant access to historical backups or the ability to silently restore attacker-chosen data into your environment.

backup posture

Platform host
  -> nightly bundle assembled
  -> encrypted before it leaves
  -> pushed to backup target

Backup target
  -> write-only for the platform
  -> platform cannot read back
  -> platform cannot delete

Restore
  -> key held in vault, off-host
  -> deliberate human action
  -> initiated outside platform

How nodge maps to the sovereignty rules you answer to

Procurement officers and auditors arrive with a checklist. Here is how nodge lines up on residency and sovereignty.

RequirementHow nodge addresses it
NIS2
Essential services obligations
EU hosting, no American cloud dependencies in the runtime path, full audit log, documented incident response.
Schrems II
Data sovereignty
Hosted exclusively in the Netherlands, on-premise option, no US-controlled dependencies in the runtime path.
GDPR Article 32
Security of processing
Encryption at rest, TLS in transit, access control, full audit log. Detailed on the security page.
US CLOUD Act
Foreign access risk
No US-controlled component in the runtime path, so there is no party that can be compelled to hand over your data.
Data residency
Where data physically lives
All organisation data and metadata stay inside the environment you chose: our EU cloud, your own servers, or air-gapped.

Evidence for procurement and compliance

For vendor reviews and compliance questionnaires, we share a documented pack under NDA.

Available under NDA

For procurement, compliance reviews, and vendor questionnaires, we share a documented pack including:

  • ISO 27001:2022 certificate copy and Statement of Applicability
  • External penetration test report, performed annually
  • Software Bill of Materials (CycloneDX) per release
  • Incident-response runbook
  • Key-rotation runbook
  • Recovery-drill log with date of the last successful drill

Email info@nodge.ai to start the review.

Run it your way.

Cloud, on-premise, or fully air-gapped. Your cluster, your data, your rules.