Summary
The core message of the provided session excerpt is that “sovereignty” becomes meaningful only when organisations translate it into concrete technology choices, migration work, supplier checks, and operational trade-offs. Moderator Earth framed the panel as deliberately less “holistic” and more practical: four founders or founder-like decision-makers would explain how sovereignty looks different depending on company type, stack, customer needs, and technical scale. The room itself became part of the opening joke—hosted in the “Amazon Room” rather than the “Europe room”—before the discussion moved into the real point: choosing technology is not just branding, but a set of dependencies that must be inspected layer by layer.
Ellen Mok introduced De Digitale Doetank as a mission-driven, steward-owned, vendor-neutral strategy advisory firm focused on reducing dependency on big tech and increasing freedom of choice through European technology. She described the organisation’s principle of “public money, public knowledge,” meaning intellectual property developed with public funding is given back to society. Her practical stack examples were modest but instructive: Nextcloud, OpenProject, and a website originally built with Framer through a Dutch company. The team later discovered the website was hosted on AWS and that self-hosting would cost around a thousand euros, so they began moving toward Ghost and Pocalyx, including relocating GoodCloud environments.
Sanno de Graaf brought the perspective of Passguard, an infrastructure monitoring company processing and extracting large volumes of data. He explained that Azure-specific services had been attractive because they could handle requirements such as roughly 200 terabytes of database storage, whereas many European providers struggled to price or support that scale. Passguard’s migration was split into phases: extraction, bot network and dark web extractors; then API infrastructure, front door and CDN; and finally the user-facing application, which was still in progress. His experience showed that sovereign migration is not a single switch, but a phased technical programme shaped by capacity, data architecture, and provider maturity.
Jens focused on small and medium-sized companies, especially regional production businesses that may not yet recognise sovereign IT as a relevant issue. He described moving away from his former Google-heavy setup, while still acknowledging Gmail’s quality, and transitioning email toward Amsterdam-based CIRFXX. He also noted that Obsidian keeps data local but is made by a Canadian company, illustrating how sovereignty checks can reveal unexpected details. Earth then added Merlon Security’s experience: doing sovereign cybersecurity invites detailed scrutiny, from slides and phones to SSL certificates, and can expose “sovereignty washing” or hidden non-sovereign dependencies. The visible discussion concludes with the lesson that claiming sovereignty requires continuous research, not one-time vendor selection.
Key Topics
5 key topics from Earth Grob, Jens Kooij, Sanno de Graaf, Tamara Dauvilier and Ellen Mok at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Audit hosting layers before choosing local-looking SaaS vendors.
- Phase migrations by separating extraction, APIs, and user-facing applications.
- Test provider capacity and pricing against real storage needs early.
- Move easier workloads first, then tackle sticky tools like email.
- Expect scrutiny when branding products or services as sovereign.
“All all intellectual property that we develop with public money, we give back to society”
Up Next


Next in agenda
Difficulties of non-intrusive scanning as NCSC

Also on digital sovereignty
Digital Sovereignty and Cloud Computing: technical criteria as one pillar of the European way forward
Philipp Holzmann


Also on digital sovereignty
