Pragmatic, sovereign security. Defense by a good offense.
We build defensible security for the new age of AI threats. Practical, EU-sovereign, and shaped by people who attack systems for a living. Less paperwork, more security you can actually stand behind.
Security should be something you operate, not paperwork you file. And the best defense is built by the people who know how to break in.
Four convictions, no compromise.
Sovereign by default
EU-hosted, on our own cloud. Your data stays in jurisdiction by architecture, not by promise.
Defense by a good offense
We are offensive specialists first. We find the weaknesses real attackers would, then turn them into controls you run. The best defense is built by people who know how to break in.
Defensible in the AI age
Attackers now move at machine speed and use AI. Defense has to be AI-assisted, continuous and provable. We build security you can demonstrate, not just claim.
Pragmatic over paperwork
Security that lives in spreadsheets protects no one. We make it operational: owned, mapped, evidenced, and actually used.
Why I built Soveryne.
I'm Ilke Tosunoğlu, an ethical hacker and penetration tester based in the Netherlands. I spent years on the offensive side of security, hired to break in. Across countless penetration tests and red team engagements, the same pattern showed up: getting in was rarely the hard part. The hard part sat upstream, in the maze of frameworks and compliance an organization had to cross long before anyone touched a single system.
For the better part of a decade, working alongside CISOs and security officers, I watched that maze get worse, not better. NIS2, DORA, ISO 27001, the CRA. More frameworks, more overlap, more evidence to keep current, and almost no tooling that turned any of it into something you operate instead of paperwork you file. The pentest finds the hole. Nobody was helping teams close the gap that let it exist.
That gap is why I built Soveryne. Security you operate, drafted, mapped and evidenced as you work, built by someone who has spent a career finding exactly where things break. And EU-sovereign by architecture, because a compliance program should never be the reason your data ends up under someone else's jurisdiction.
Security that keeps up with machine-speed adversaries.
AI changed both sides. We put it to work for the defender: an AI agent you can ask about any control, framework or asset, and a threat feed that assesses risk to your controls and assets.
Your security AI, in context
Put your question to the Command agents. They draw on knowledge bases spanning frameworks and laws like ISO 27001, DORA, NIS2 and NIST, and answer in the context of your own controls and assets.

Counsel: answers you can verify
Ask Counsel in plain language and get an answer grounded in your own frameworks and documents, with every claim cited to its source.

Threat intelligence, triaged by AI
A curated feed summarized and risk-assessed against your controls and assets, so you act on what matters, not on noise.

Counsel: a knowledge base that grows
Frameworks and regulations like ISO/IEC, DORA, NIS2, GDPR, CRA, NEN and the Dutch government baseline, ready to answer from today, with more knowledge added over time.

Collaborate, in context
Comment, discuss and review each control right on its page, where the work lives. Every control maps automatically to the assets it protects, the framework controls it satisfies, and its evidence.

One platform, across People, Organization and Technology.
Soveryne is one operated security program on a sovereign foundation, anchored by the live Command product. Each capability deepens the same platform, in deliberate order.
Soveryne Cloud
The ground everything else stands on. Not a product we sell, but the reason the rest stays sovereign.
- Our own EU cloud, operated end to end, inside EU jurisdiction.
- Geographically distributed compute clusters across the EU.
- Sovereign by architecture, not by promise.
- Operational knowledge transferred to your team, so sovereignty never means dependence.
Command
Our flagship, live now. Every control maps automatically to your assets, to framework controls, and to its evidence, so tracking framework coverage becomes easy.






Counsel
A private AI assistant for security and compliance, live now. It answers from the frameworks that apply to you and your own documents, cites every source, and never leaves the EU.






Governance and policy
Policy the controls actually stand on, so Command sits on governance that works in practice.
- Practical policy design, tied directly to your controls.
- Operating governance workflows that teams actually follow.
Awareness: phishing and smishing
The human layer. Behavior change you can measure, tied to your people controls.
- Continuous phishing simulation and behavior reinforcement.
- A mobile-focused smishing program.
- Detection of real phishing and smishing campaigns in the wild, to keep scenarios realistic.
Offensive testing
The good offense, as a service. Specialists who break in for a living, with findings that flow straight back into your controls.
- Continuous external attack-surface reconnaissance.
- Structured threat modeling tied to practical controls.
- Pragmatic penetration testing cycles with clear remediation.
- Adversary emulation and red teaming to validate response and resilience.
Continuous validation runs through all of it.
It is core to how we work, not a finish line. Each solution we ship is a step toward the same goal: security that is checked and proven on an ongoing basis, not filed once a year. It is a continuous effort, and every stage moves it forward.
Be first in line for sovereign security.
Join the early-access waitlist and we will run a free intake, mapping your real posture across the frameworks that apply to you. Not the right fit? We will tell you straight.

