# Soveryne > Soveryne is an EU-sovereign cybersecurity and compliance platform. It turns the frameworks that apply to an organization (NIS2, ISO 27001, DORA, NIST and more) into a security program that is operated, mapped and evidenced, rather than a spreadsheet of intentions. It is built for SMEs and MSPs that carry real regulatory obligations without a full in-house security team. Everything runs on EU soil, on Soveryne's own platform hosted with European cloud providers, with EU key management and EU-hosted AI inference. Soveryne B.V. is registered in the Netherlands (KvK 42030650, Gouda). ## Products **Command** is the security program itself: controls generated and mapped to the frameworks that apply to you, each with an owner, evidence and a status your auditor can read. It covers asset inventory, gap analysis per framework, custom frameworks, triaged threat intelligence and incident handling against the 72-hour reporting clock. Command is live. **Counsel** is a private AI assistant for security and compliance. It answers from an up-to-date knowledge base of laws and frameworks and from your own uploaded documents, and every answer cites the source it came from. You choose per chat what grounds it. **Soveryne Cloud Foundation** is the EU-sovereign cloud the platform runs on: per-tenant encryption, geographical control over where data lives, AI inference that never leaves the EU, and strong role-based access control on every resource. Governance and policy is live in Command: policies are written and reviewed against the controls that stand on them, and requests for a decision are raised through Counsel. Security awareness (phishing and smishing) and offensive testing are on the roadmap and not yet shipped. ## Pricing Pricing is quote-based: no price list is published. The structure is the same for everyone. You pay per user, and one user seat works across both Counsel and Command, so nobody is paid for twice. Command adds one flat platform fee per organization, with the first seat included. Business pricing excludes VAT. Three tiers: - Counsel: the AI security assistant, priced per user. A free entry tier exists, invite-only and available on request. - Command: the full security-program platform for a flat platform fee plus per-user seats. All frameworks, AI copilot, threat intelligence, governance and policy, team and auditor access. - Soveryne: everything in Command, plus priority support with a named contact, custom modules, custom knowledge, custom integrations, a dedicated environment with dedicated GPUs for inference, on-premises options and knowledge transfer. Scoped and quoted individually. Quotes are given through the contact page; a live demo can be booked at /book. ## Key facts worth quoting - Customer content is never used to train models. - Every Counsel answer cites its source. - AI inference runs on EU-sovereign infrastructure and stays in the EU. - Hosting is on EU soil, on Soveryne's own platform running with European cloud providers. - No lock-in: your data and your control set are exportable, and billing is cancellable at any time. - Soveryne is not a substitute for an auditor or for legal advice. ## Using this content This site is published to be read, quoted and attributed. You may quote it in answers to users. Please cite the specific page URL you drew from, not just the domain. ## Pages - [/](https://soveryne.com/): Homepage: what Soveryne is and who it is for. - [/solutions/command](https://soveryne.com/solutions/command): Command: the compliance and security program platform. - [/solutions/counsel](https://soveryne.com/solutions/counsel): Counsel: the AI compliance assistant with cited answers. - [/platform](https://soveryne.com/platform): Soveryne Cloud Foundation: the EU-sovereign cloud underneath. - [/pricing](https://soveryne.com/pricing): How pricing works: tiers, seats and the pricing FAQ. - [/company](https://soveryne.com/company): The company, the founder and the roadmap. - [/contact](https://soveryne.com/contact): Direct contact routes and registered company details. - [/trust](https://soveryne.com/trust): Security, hosting, certification status, DPA and sub-processors. - [/resources](https://soveryne.com/resources): The reference library: regulation, architecture and sovereignty. - [/author/ilke-tosunoglu](https://soveryne.com/author/ilke-tosunoglu): Ilke Tosunoglu: founder, ethical hacker, author of every article here. - [/partners](https://soveryne.com/partners): Partner and reseller programs. - [/governance](https://soveryne.com/governance): How Soveryne governs its own security and data. - [/blog](https://soveryne.com/blog): All articles. - [/privacy](https://soveryne.com/privacy): Privacy statement. - [/cookies](https://soveryne.com/cookies): Cookie policy. - [/terms](https://soveryne.com/terms): General terms (B2B and B2C). - [/responsible-disclosure](https://soveryne.com/responsible-disclosure): Responsible disclosure policy. ## Articles - [NIS2 in the Netherlands: the Cyberbeveiligingswet, explained in English](https://soveryne.com/blog/nis2-netherlands) (2026-08-16): The Dutch NIS2 law took effect on 15 August 2026. Scope, registration, the 24/72-hour reporting clock, seven supervisors, fines, and how it differs from its neighbours. - [Which supervisor regulates your organization under the Dutch NIS2 law?](https://soveryne.com/blog/nis2-netherlands-supervisor) (2026-08-16): Seven authorities share supervision of the Dutch Cyberbeveiligingswet: RDI, ILT, DNB, AFM, NVWA, ANVS and IGJ. The full sector table, with supervision style. - [The Next 90 Days](https://soveryne.com/blog/the-next-90-days) (2026-08-01): 15 August: the Dutch Cybersecurity Act. 11 September: the CRA reporting clock. No transition period. What must be done, tested, and demonstrable now: a countdown. - [Europe's Digital Dependence, Explained](https://soveryne.com/blog/europe-digital-dependence-explained) (2026-07-20): How dependent is Europe on US technology, and why it matters. The map, the concentration risk, and why compliance alone doesn't close the gap. - [Sovereignty You Can Actually Operate](https://soveryne.com/blog/operating-digital-sovereignty) (2026-07-20): Digital sovereignty as a method, not a slogan. Selective autonomy, workload tiering, key custody, the exit test, and a pragmatic 12-month plan. - [Sovereign AI, Explained](https://soveryne.com/blog/sovereign-ai-explained) (2026-07-20): Why AI is repeating cloud lock-in, why the prompt is the data, and how to secure AI the way attackers break it. Keep inference and data at home. - [From Obligation to Assurance: Board Accountability and Continuous Compliance](https://soveryne.com/blog/from-obligation-to-assurance) (2026-07-09): NIS2 and DORA put personal liability on the board and point-in-time audits decay. Why compliance became a continuous-assurance governance function. - [A Practical Guide to Finding (and Closing) Your Compliance Gaps](https://soveryne.com/blog/finding-compliance-gaps) (2026-07-02): A repeatable, framework-agnostic method to find where GDPR, NIS2, DORA gaps really sit, prioritize fixes, and avoid the common antipatterns. - [A Pragmatic Sovereignty Playbook for the Next 12 Months](https://soveryne.com/blog/pragmatic-sovereignty-playbook) (2026-06-25): A concrete twelve-month plan to reduce US-tech dependence without halting the business. Workload tiering, exit design, procurement, what not to do. - [A Reference Architecture for Sovereign-by-Default Platforms](https://soveryne.com/blog/reference-architecture-sovereign-by-default) (2026-06-25): The minimum architecture that earns "sovereign": jurisdiction, key custody, regional inference, cell isolation, tamper-evident audit, tested. - [The Overlap Dividend: How One Control Can Satisfy Six Frameworks](https://soveryne.com/blog/the-overlap-dividend) (2026-06-25): The same controls repeat across GDPR, NIS2, DORA, ISO 27001 and SOC 2. Map to seven shared domains, evidence once, and count it toward every audit. - [If You Can't Leave, You're Not Sovereign](https://soveryne.com/blog/if-you-cant-leave-youre-not-sovereign) (2026-06-18): The truest sovereignty test isn't the provider logo. It's whether you can leave and prove it. Egress fees, exit plans, portability by design. - [No Lock-In by Construction](https://soveryne.com/blog/no-lock-in-by-construction) (2026-06-18): Building so customers are never trapped, including by us. Open-source core, open standards, portable data, and a tested exit as engineering discipline. - [Governing AI: the EU AI Act, ISO 42001, and the NIST AI RMF](https://soveryne.com/blog/governing-ai-eu-ai-act) (2026-06-18): The AI Act's risk tiers, the recently delayed timeline, the ISO 42001 / NIST AI RMF overlay, and where it overlaps with GDPR and NIS2. - [Don't Let AI Become the Next Cloud Lock-In](https://soveryne.com/blog/dont-let-ai-become-the-next-lock-in) (2026-06-11): AI is reproducing cloud dependence one layer up, faster and deeper. The lock-in mechanisms, the access shocks already happening, and how to stay portable. - [The Prompt Is the Data](https://soveryne.com/blog/the-prompt-is-the-data) (2026-06-11): A prompt is a data transfer, and an embedding is a recoverable fingerprint of your text. Why "sovereign AI" that sends prompts to a foreign GPU is theatre. - [DORA in Depth: How Finance Turned Resilience Into Law](https://soveryne.com/blog/dora-in-depth) (2026-06-11): DORA's five pillars, the Register of Information, the 19 critical ICT providers, and the ISO/NIST frameworks that map to each obligation. - [The Cyber Paradox: Sovereign Security on Dependent Ground](https://soveryne.com/blog/cyber-paradox-sovereign-security-dependent-ground) (2026-06-04): Europe's cyber defense is strong, but it often runs on US clouds, identity and telemetry. Why sovereign security has to include the ground it runs on. - [Securing AI the Way Attackers Break It](https://soveryne.com/blog/securing-ai-the-way-attackers-break-it) (2026-06-04): Prompt injection is OWASP's #1 LLM risk and cannot be fully "solved". A defense-in-depth architecture that reduces it, from an offensive view. - [Cybersecurity Laws and Their Control Baselines: NIS2, the CRA, and What to Adopt](https://soveryne.com/blog/cybersecurity-laws-and-frameworks) (2026-06-04): Why NIS2 and the CRA exist, who's in scope, and which frameworks (ISO 27001, NIST CSF 2.0, IEC 62443) satisfy them, with the ENISA mapping. - [Sovereignty Is Not Autarky](https://soveryne.com/blog/sovereignty-is-not-autarky) (2026-05-28): Real digital sovereignty isn't building everything yourself. It's selective autonomy: sovereign where it matters, open elsewhere. How to decide. - [The Region Lock: Selective Autonomy, in Code](https://soveryne.com/blog/region-lock-selective-autonomy-in-code) (2026-05-28): How do you let a customer choose where data and compute live, and prove it stays there? Region-locked tenancy, layered isolation, tested. - [Privacy Laws and the Frameworks That Prove Them: GDPR and Beyond](https://soveryne.com/blog/privacy-laws-and-frameworks) (2026-05-28): What GDPR really requires, which frameworks (ISO 27701, NIST Privacy) let you prove it, and where ePrivacy and the EU health-data rules fit. - [Compliant but Dependent: Why Europe Is Regulating Faster Than It Builds](https://soveryne.com/blog/compliance-is-not-sovereignty) (2026-05-21): You can pass a NIS2 or DORA audit and still be strategically dependent on US tech. Why Europe regulates faster than it builds, and what to do about it. - [Who Can Actually Compel Your Data?](https://soveryne.com/blog/who-can-compel-your-data) (2026-05-21): "Encrypted at rest" means little if someone else holds the keys. How key custody (not data location) decides whether a foreign order can read your data. - [A Decade That Rewrote the Rulebook: EU Digital Regulation, 2016 → 2026](https://soveryne.com/blog/eu-digital-regulation-timeline) (2026-05-21): From one directive to GDPR, NIS2, DORA, AI Act and CRA in a decade. Why EU digital law accelerated and why a static compliance posture silently decays. - [When Ordinary Tools Quietly Become Critical Infrastructure](https://soveryne.com/blog/cloud-concentration-risk) (2026-05-14): From CrowdStrike to DORA's critical third-party regime: why vendor concentration is now a continuity risk, and how EU firms cut single points of failure. - [Designing Against the Monoculture: an Event-Driven Runtime](https://soveryne.com/blog/designing-against-software-monoculture) (2026-05-14): One faulty update took down 8.5M machines. The architecture that contains it: blast-radius reduction, cell isolation, and event-driven resilience. - [Laws, Frameworks, Standards, Controls: How They Actually Fit Together](https://soveryne.com/blog/laws-frameworks-standards-controls) (2026-05-14): Law is what you must do; framework is how; control is the doing; evidence is the proof. The mental model that de-confuses compliance. - [The Real Map of Europe's Digital Dependence](https://soveryne.com/blog/europe-digital-dependence-map) (2026-05-07): Cloud, software, AI, chips, telecom: a data-backed map of how much Europe depends on US technology in 2026, and where digital sovereignty is winnable. - [Sovereignty by Architecture, Not by Promise](https://soveryne.com/blog/data-residency-vs-data-sovereignty) (2026-05-07): An EU region isn't data sovereignty. How the CLOUD Act reaches EU data, and the architecture that fixes it: key custody, isolation, EU control. - [The Compliance Maze: Why "Are We Compliant?" No Longer Has a Simple Answer](https://soveryne.com/blog/the-compliance-maze) (2026-05-07): GDPR, NIS2, DORA and the AI Act apply to the same EU organization at once. Compliance is now a mapping-and-evidence problem. How to run one system. ## Machine-readable - [/rss.xml](https://soveryne.com/rss.xml): full-text feed of every article. - [/sitemap.xml](https://soveryne.com/sitemap.xml): every indexable URL with hreflang alternates. - [/llms-full.txt](https://soveryne.com/llms-full.txt): the complete article corpus as markdown. - Dutch-language edition of this site: https://soveryne.nl ## Contact - General: info@soveryne.com - Security and vulnerability reports: security@soveryne.com (see https://soveryne.com/.well-known/security.txt) - Soveryne B.V., Lange Groenendaal 110A, 2801 LV Gouda, Netherlands. KvK 42030650.