Sovereignty Assessment + migration from AWS, Azure or GCP to a Swedish data center in 2 weeks. We map your cloud dependencies, produce an exit plan and carry out the move – while you keep working.
Many Swedish SaaS companies and fintechs chose AWS or Azure because it felt secure, scalable and cheap. But the regulatory landscape has changed radically – and US cloud providers are subject to American legislation regardless of where the data is physically stored.
NIS2 (the cybersecurity act) came into force in January 2026 and affects an estimated 8,000 Swedish organizations. If you sell to banks, insurance companies, municipalities or energy companies, you must be able to prove where your data resides – the supply chain is an audit point.
DORA (Digital Operational Resilience Act) requires full control over ICT third-party risks. The requirement is simple: the cloud must be in the EU and you must be able to prove it to auditors. Concentration risk towards US hyperscalers must be justifiable – and phased out.
More and more procurements require it in black and white: “prove that your data resides in Sweden”. Under the CLOUD Act, US authorities can demand data from US providers – the only robust protection is a European provider on European soil.
A common objection is "but we use managed services in AWS". Here is how the most common services map to sovereign equivalents in our data center.
| In the US cloud today | With us in a Swedish data center |
|---|---|
| EC2 / Azure VM / Compute Engine | Virtual machines on our VMware/KVM platform – same OS, same applications, often better performance per krona |
| RDS / Azure SQL / Cloud SQL | PostgreSQL, MySQL or SQL Server as a managed database – we handle patching, backup and replication |
| S3 / Blob Storage | S3-compatible object storage in the data center – your applications often only need a new endpoint and new keys |
| EKS / AKS / GKE | Kubernetes clusters that we operate – your manifests and Helm charts work as before |
| CloudWatch / Azure Monitor | Monitoring stack with alert chain – included in Managed EU Drift |
| Route 53 / Azure DNS | Redundant DNS operations – or you keep your external DNS provider |
Serverless services (Lambda, Functions) and proprietary PaaS services require rebuilding – this is captured in the assessment with a time estimate per service, so you know exactly what moves as-is and what needs adaptation.
A structured exit – not a risky lift-and-hope project.
Fixed price, fixed delivery in 2 business days. You get decision material you can take to the board – and a plan that can be executed immediately.
| Time | 2 business days |
|---|---|
| Cost | Fixed price – free of charge if you proceed with the migration |
| Next step | The migration takes approx. 2 weeks if you say yes |
Three days from start to decision material.
We map which systems you have (applications, databases, APIs, storage), where your data resides right now (region, provider, replication), which data flows are most sensitive (PII, financial information, customer data) and which compliance requirements you already meet or must meet. Deliverable: a detailed environment description.
The systems are mapped against NIS2/DORA and your industry regulations, gaps are identified (e.g. encryption at rest but not in transit) and we build a step-by-step plan: what is migrated first (low-risk systems), what is migrated last (critical databases), which tests are required and how long systems may be offline – if at all.
We present the decision material, a quote for migration and operations (Managed EU Drift), and propose a timeline. You set the pace – the migration typically starts within 1–2 weeks.
We never migrate everything at once. Each step is verified before the next begins, and a rollback plan is in place the whole way.
Check of hypervisors, network configuration and security. Cryptographic verification of all volumes and databases. Redundancy test – can the system handle a failure during an ongoing migration?
Each virtual machine is copied from AWS/Azure to our data center: exact disk image (byte-for-byte), bootloader and kernel intact, network remapped to our switches. Each machine is verified to boot correctly before the next is moved. Order: test systems first, production systems during low load, full traffic last.
New IP addresses in your dedicated VLAN, your existing firewall rules reproduced, VPN tunnels to offices and partners set up as needed. DNS is updated gradually – not all at once – to avoid cache problems.
Traffic is switched over outside business hours. We monitor 24/7 during the first week. If anything goes wrong, traffic is sent back to your old environment in under 15 minutes.
| Expected downtime | 0–5 minutes – DNS propagation only |
|---|---|
| Total time to "everything in a Swedish data center" | 2–3 weeks for a typical environment |
| Rollback | Back to the old environment in < 15 minutes, throughout the entire migration period |
After the migration you receive the three documents that reviewers, auditors and procurement teams ask for.
Formal certificate: your data resides physically in Sweden, in our data center, and never leaves the jurisdiction without your explicit approval. The appendix you present in a procurement, saying: "here is the proof from the host".
Legal agreement covering GDPR (we are your data processor), subprocessor requirements, incident notification within 24 hours and your right to audit us – at any time.
All system changes are logged (who, what, when), access logs for everyone touching your data, documented security updates and monthly updated compliance status.
Fixed price per package – you know the cost before we start. The assessment is always free of charge if you proceed with the migration.
< 50 GB data, 5–10 VMs
50–500 GB data, 10–50 VMs
> 500 GB, 50+ VMs or multi-region
If the cutover takes longer than 5 minutes, we cover the cost in the form of extended support.
Not satisfied within 30 days? We restore your systems to your old environment and refund the migration fee.
Throughout the migration period you have a dedicated engineer on your team – plus 30 days of burn-in support after go-live.
Prices are indicative, excl. VAT. Post-migration support and knowledge transfer to your IT team are included, followed by an optional transition to Managed EU Drift.
Anonymized customer – we're happy to share details in a call.
A typical migration takes 2 weeks for a small system (< 50 GB, 5–10 VMs) and 3–4 weeks for larger environments. We always migrate in stages: non-critical systems first, production systems last.
Expected downtime is 0–5 minutes – DNS propagation only at cutover, which we schedule outside business hours. We provide a zero downtime commitment: if it takes longer than 5 minutes, we cover the cost of extended support.
The Sovereignty Assessment is free of charge (fixed price SEK 15,000 if you don't proceed, otherwise deducted). The migration costs from SEK 50,000 for a small system and from SEK 150,000 for a medium system. Larger environments are quoted separately.
Every migration has a rollback plan: traffic can be sent back to your old environment in under 15 minutes, throughout the entire migration period. In addition, a 30-day money-back guarantee after go-live is included.
You receive a data residency certificate (DLI), Data Processing Agreement (DPA) and auditable logs – the documentation auditors and procurement teams ask for. Responsibility for your applications and processes remains with you, but the infrastructure part is documented as compliant.
Yes. Databases are continuously replicated to the target environment and the cutover is synchronized so that no transaction is lost. Cryptographic verification ensures that every byte matches.
No. We migrate in stages and can run hybrid during the transition. Many customers start with their most compliance-sensitive systems and move the rest in phases.
Yes. Managed databases are moved to the equivalent managed service with us (PostgreSQL/MySQL/SQL Server) and S3 is replaced with S3-compatible object storage – your applications usually only need a new endpoint and new keys. Serverless functions require rebuilding, which is time-estimated in the assessment.
It remains untouched until you have approved that everything works in the new environment. We then help you decommission it in a controlled manner – including documented deletion of data at the old provider, a GDPR requirement many miss.
Minimally. VMs, containers and databases work as before. CI/CD pipelines are repointed to the new environment – that's included in the migration. Kubernetes manifests and Helm charts are reused as-is.
Yes – that's our service Managed EU Drift: patching, backup, 24/7 monitoring and NIS2 reporting from SEK 5,000/mo. 30 days of burn-in support is always included after the migration, whether or not you choose managed operations with us.
One call is enough for us to give you an initial picture of your exit path – with no obligations.