Pragmatic, sovereign security. Defense by a good offense.

We build defensible security for the new age of AI threats. Practical, EU-sovereign, and shaped by people who attack systems for a living. Less paperwork, more security you can actually stand behind.

EU-only
Hosting & jurisdiction
Fully Private
Encrypted and for your eyes only
Offense-led
Built by people who break in
ISO · NIS2 · DORA
Frameworks, mapped

Security should be something you operate, not paperwork you file. And the best defense is built by the people who know how to break in.

The Soveryne conviction
What we stand for

Four convictions, no compromise.

01

Sovereign by default

EU-hosted, on our own cloud. Your data stays in jurisdiction by architecture, not by promise.

02

Defense by a good offense

We are offensive specialists first. We find the weaknesses real attackers would, then turn them into controls you run. The best defense is built by people who know how to break in.

03

Defensible in the AI age

Attackers now move at machine speed and use AI. Defense has to be AI-assisted, continuous and provable. We build security you can demonstrate, not just claim.

04

Pragmatic over paperwork

Security that lives in spreadsheets protects no one. We make it operational: owned, mapped, evidenced, and actually used.

From the founder

Why I built Soveryne.

I'm Ilke Tosunoğlu, an ethical hacker and penetration tester based in the Netherlands. I spent years on the offensive side of security, hired to break in. Across countless penetration tests and red team engagements, the same pattern showed up: getting in was rarely the hard part. The hard part sat upstream, in the maze of frameworks and compliance an organization had to cross long before anyone touched a single system.

For the better part of a decade, working alongside CISOs and security officers, I watched that maze get worse, not better. NIS2, DORA, ISO 27001, the CRA. More frameworks, more overlap, more evidence to keep current, and almost no tooling that turned any of it into something you operate instead of paperwork you file. The pentest finds the hole. Nobody was helping teams close the gap that let it exist.

That gap is why I built Soveryne. Security you operate, drafted, mapped and evidenced as you work, built by someone who has spent a career finding exactly where things break. And EU-sovereign by architecture, because a compliance program should never be the reason your data ends up under someone else's jurisdiction.

Ilke Tosunoğlu, founder of Soveryne
Ilke TosunoğluFounder
A good offense, for the age of AI threats

Security that keeps up with machine-speed adversaries.

AI changed both sides. We put it to work for the defender: an AI agent you can ask about any control, framework or asset, and a threat feed that assesses risk to your controls and assets.

Your security AI, in context

Put your question to the Command agents. They draw on knowledge bases spanning frameworks and laws like ISO 27001, DORA, NIS2 and NIST, and answer in the context of your own controls and assets.

app.soveryne.eu/chat
Your security AI, in context, grounded in frameworks and laws like ISO, DORA, NIS2 and NIST.

Counsel: answers you can verify

Ask Counsel in plain language and get an answer grounded in your own frameworks and documents, with every claim cited to its source.

app.soveryne.eu/chat
Counsel answering with inline citations.

Threat intelligence, triaged by AI

A curated feed summarized and risk-assessed against your controls and assets, so you act on what matters, not on noise.

app.soveryne.eu/threat-intel
Threat intelligence, summarized and risk-assessed by AI.

Counsel: a knowledge base that grows

Frameworks and regulations like ISO/IEC, DORA, NIS2, GDPR, CRA, NEN and the Dutch government baseline, ready to answer from today, with more knowledge added over time.

app.soveryne.eu/knowledge
Counsel's curated compliance knowledge base.

Collaborate, in context

Comment, discuss and review each control right on its page, where the work lives. Every control maps automatically to the assets it protects, the framework controls it satisfies, and its evidence.

app.soveryne.eu/controls
A control page with team comments, mapped assets, framework controls and evidence.
The platform

One platform, across People, Organization and Technology.

Soveryne is one operated security program on a sovereign foundation, anchored by the live Command product. Each capability deepens the same platform, in deliberate order.

F
Foundation

Soveryne Cloud

The ground everything else stands on. Not a product we sell, but the reason the rest stays sovereign.

  • Our own EU cloud, operated end to end, inside EU jurisdiction.
  • Geographically distributed compute clusters across the EU.
  • Sovereign by architecture, not by promise.
  • Operational knowledge transferred to your team, so sovereignty never means dependence.
1

Command

Our flagship, live now. Every control maps automatically to your assets, to framework controls, and to its evidence, so tracking framework coverage becomes easy.

Command
Command
Command
2

Counsel

A private AI assistant for security and compliance, live now. It answers from the frameworks that apply to you and your own documents, cites every source, and never leaves the EU.

Counsel
Counsel
Counsel
3
Coming soon

Governance and policy

Policy the controls actually stand on, so Command sits on governance that works in practice.

  • Practical policy design, tied directly to your controls.
  • Operating governance workflows that teams actually follow.
4
Coming soon

Awareness: phishing and smishing

The human layer. Behavior change you can measure, tied to your people controls.

  • Continuous phishing simulation and behavior reinforcement.
  • A mobile-focused smishing program.
  • Detection of real phishing and smishing campaigns in the wild, to keep scenarios realistic.
5
Coming soon

Offensive testing

The good offense, as a service. Specialists who break in for a living, with findings that flow straight back into your controls.

  • Continuous external attack-surface reconnaissance.
  • Structured threat modeling tied to practical controls.
  • Pragmatic penetration testing cycles with clear remediation.
  • Adversary emulation and red teaming to validate response and resilience.

Continuous validation runs through all of it.

It is core to how we work, not a finish line. Each solution we ship is a step toward the same goal: security that is checked and proven on an ongoing basis, not filed once a year. It is a continuous effort, and every stage moves it forward.

Be first in line for sovereign security.

Join the early-access waitlist and we will run a free intake, mapping your real posture across the frameworks that apply to you. Not the right fit? We will tell you straight.