Summary
The core message of the provided session excerpt is that “sovereignty by design” should be treated as a practical operating model for SaaS resilience, not as a vague policy slogan. Emma Wright and Navroop Mitter frame the discussion from both legal-policy and technology-provider perspectives: European buyers are increasingly asking whether critical SaaS products can keep operating if infrastructure, data access, or geopolitical relationships fail, while software companies selling across borders must be prepared for similar questions from foreign markets. Navroop opens by connecting the topic to shrinking total addressable markets for founders and investors, constrained solution choice for technology buyers, and policy risk for governments that may move faster than technical, talent, and resource realities allow.
The speakers then ground the problem in a concrete case: a European island nation worried about natural disasters, lava flows, a foreign adversary severing undersea cables, and insufficient European satellite bandwidth. In that scenario, major SaaS and cloud services such as Microsoft, Azure, and O365 could stop functioning if the country were cut off from the global Internet. ArmorText had already been used for incident response, SecOps, and threat sharing, but the customer challenged the company to ensure those capabilities would still work locally during isolation. That forced the team to distinguish between data sovereignty, which Navroop says ArmorText addressed through end-to-end encrypted scopes of review, and infrastructure sovereignty, meaning the ability to run a globally available multi-tenant service inside the customer’s country in parallel with North American infrastructure.
Emma emphasizes that this is where legal, operational, and technical realities collide. A contract alone is insufficient if the practical operating model cannot support a country or company during a critical incident. The discussion moves into questions such as who holds encryption keys, whether key escrow solves or creates problems, who can access data and under which laws, and whether a provider can keep customers from being cut off. Navroop argues that broad terms like “digital resilience” and “digital sovereignty” often mask the real underlying issues: infrastructure sovereignty, data sovereignty, and operational sovereignty each require separate analysis.
The excerpt closes by expanding the lens beyond European concern about U.S. providers, the Patriot Act, and the Cloud Act. Emma notes that the same questions can be inverted: as Europe grows its own technology sector, other regions will ask European providers comparable questions about data access, legal reach, resilience, and control. GDPR’s extraterritorial influence is presented as an example of how regulatory models spread. Navroop concludes the provided segment by identifying operational sovereignty as the newest addition to their framework, driven by the previous eighteen months of news and by questions about ownership, boards, and where a company is actually run.
Key Topics
5 key topics from Navroop Mitter and Emma Wright at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Break sovereignty into infrastructure, data, and operational requirements.
- Test SaaS resilience against isolation and critical-incident scenarios.
- Ask providers who can access data and under what law.
- Design operating models before relying on contract language.
- Invert buyer questions to prepare for selling abroad.
“This isn't just a buyer perspective, it's also a seller perspective.”
Up Next



Next in agenda
TaHiTI, threat hunting methodology.

SAlso on european tech
Sovereignty: From Promise to Practice



Also on european tech
