01 The promise // your data, your rules
Sovereignty

Modernise without giving up control.

You want to use AI and modern software — but not at the price of suddenly someone else holding your data, knowing your processes and dictating the terms. That doesn't have to happen.

The worry

„If I adopt this — where does my data actually live, who can see it, and can I ever get back out?“

Our answer

You keep sovereignty — over every step.

Four guarantees, a clear hosting model, and full visibility into what the AI does in your systems. No trust on faith — verifiable.

02 Four guarantees // what we commit to

Sovereignty isn't a feeling. It's four concrete commitments.

Guarantee 01

You can always get back out.

Your data can be exported in full — in a usable format, whenever you want. Whoever can switch can't be held hostage. Where possible, we use self-hostable solutions instead of platforms that lock you in.

Principle · No vendor lock-in
Guarantee 02

No black box.

Where possible we build on open-source software — Plane, Seafile, Forgejo and more. You can see what runs, operate it yourself, and aren't at the mercy of a single vendor's whims.

Principle · Open source as the starting point
Guarantee 03

Your data sits in Germany.

Our infrastructure runs at Hetzner in Falkenstein: German law, German data centre. The legal location decides which rules apply to your data — not another country's CLOUD Act.

Principle · Hosting in Germany / EU
Guarantee 04

GDPR is the minimum.

GDPR compliance is a given — our actual standard is higher: fair handling of your data and that of third parties. No data quietly flowing abroad, no algorithmic pestering.

Principle · GDPR+
03 Where your data lives // a clear hierarchy, no grey zone

If Germany isn't possible, a clear order applies.

Not every service can run in Germany. But the decision is never random — it follows a hierarchy we disclose.

1
Germany
First choice. German law, GDPR, no access by foreign authorities. Our own infrastructure: Hetzner, Falkenstein.
First choice
2
EU
GDPR applies across Europe. As long as we stay within the EU, the protection holds.
GDPR applies
3
US vendor, EU data centre
Location EU, but the CLOUD Act remains a problematic factor — only with a clear trade-off.
with reservations
4
USA
Only when unavoidable — e.g. for certain AI APIs that don't exist anywhere else today.
only if needed

The same goes for AI. Instead of automatically reaching for US models, we work with European inference where we can.

MistralScaleway · EU inferenceSelf-hosting where economicalUS APIs only where indispensable
04 Control over the AI // sovereignty in the AI age

An AI that works in your systems — and that you oversee at all times.

Sovereignty doesn't end at the server location. Once an AI agent works across your software, the next question counts: Can you see what it does, and limit it? That's exactly what the layer beneath is built for.

Monitoring

You see every access.

Every step of the agent is auditable live — which systems, which data, what it searches and writes.

Permissions

You set the boundaries.

Fine-grained at the route level: what may be read, what may be written. The agent may only do what you allow.

Secrets

Credentials stay safe.

Never in the agent context — no leaks via prompt injection, no arbitrary access from the sandbox.

Undo

Nothing is final.

Write actions are reversible. The human decides, the AI prepares and executes — supervised.

In the live demo you see the chat and the monitoring side by side — in real time, which systems the agent is accessing.

See control live →

Honestly: AI is strong at preparing, researching, structuring — but poor at deciding. So we deliberately draw a line. Business relationships, strategy and important decisions stay with people. The AI assists, it doesn't take over.

05 Where this comes from // the architecture beneath

Sovereignty is built into Daedalus — not bolted on afterwards.

None of this is an add-on. It's the architecture of the layer on which an agent works across your entire software: open source, EU-hosted, with permissions, audit and per-user isolation from the ground up. The infrastructure underneath is concretely set up and run in the Tech Setup.

Daedalus
One agent across ~40 systems. Open source · EU-hosted · route-level permissions · audit & monitoring · no lock-in.
Daedalus in detail →
Open SourceEU-hosted · HetznerGDPR+no vendor lock-inMistral / Scalewayper-user isolationopen MCP standard

Your data. Your rules.
Verifiable.

EU-hosted · GDPR+ · Open Source · no lock-in