SOVEREIGN INFRASTRUCTURE · THE FIRST STEP

Find out where your
data actually lives

The Sovereignty Audit is an investigation of your infrastructure: what runs where, what it really costs, what you could reclaim, and where GDPR and AI expose you. You get a written report that stays useful whatever you decide next. €850 fixed, excl. btw, and fully credited against a migration signed within 60 days.

I · THE PROBLEM

“Honestly, we don’t know what we’re running”

Ask a small company where its data lives and you rarely get an answer; you get a pause. Somewhere between Google, Microsoft, the CRM, the invoicing tool, a former employee’s Dropbox, and whatever the marketing agency signed up for, the map was lost. Nobody decided that; it accumulated.

The same is true of the costs. Each subscription looked small when someone added it. Together they are a four- or five-figure annual line that nobody owns, growing with every seat and every price increase. And the GDPR processor register, if it exists, was last touched when someone needed it for a client questionnaire.

You cannot fix what you cannot see, and you should not sign a migration proposal, mine or anyone’s, without seeing it first. That is what the audit is for.

II · WHAT IT IS, CONCRETELY

An investigation with a written verdict

The audit is phase one of the five-phase method, sold on its own for €850 fixed, excl. btw. Sign a migration within 60 days and the full €850 is credited against it. It runs one to two weeks for a typical small company. Your time investment is a kickoff conversation and a walkthrough; the digging is mine.

The report · what you hold afterwards

I.Inventorysystems & data flows
II.Cost baselineper seat, per year
III.ExposureGDPR & AI
IV.Roadmapprioritized, with quick wins
V.Timeline & numbersfor whatever comes next

Written in plain language · yours to keep

The report is written to stay useful even if we never work together again. That is the design requirement, and it keeps me honest: if your current setup is fine, the report says so. If only one system is worth moving, it says that. If a migration makes sense, it comes with an exact timeline and the fixed numbers for the proposal, so nothing that follows is a guess.

See the full price register for how the audit fits with everything else.

III · A FAIR MATCH

Who this is for, and who it is not for

FOR YOU IF
  • You suspect you pay too much for tools nobody fully uses, and want the actual number.
  • “Where is our data?” is a question you currently cannot answer by pointing.
  • You are considering a move away from US cloud and want the decision grounded before spending real money.
  • A client, auditor or insurer just asked about your processor register and it got quiet.
NOT FOR YOU IF
  • You already have a complete, current map of your systems, costs and processors. Then you do not need me for this, and I will say so.
  • You want a formal certification audit (ISO 27001, SOC 2). This is an engineering investigation, not a compliance stamp.
  • You have already decided nothing will change. The report would be a well-written shelf ornament.

IV · WHERE IT SITS

The entry for clarity

Everything at Ironstack starts from knowing what is true. The audit is that start. If the findings point to a fresh build, the Stack follows; if they point to moving an existing environment, Migration does, both executed through the five-phase method and both ending in Managed Sovereignty, where I stay responsible for what we built.

And if the findings point to a single quick win instead, an automation, a replaced tool, a cancelled subscription, that is a fine outcome too. The audit is the low-risk first step precisely because it does not commit you to anything.

Fair questions

How long does the audit take?

One to two weeks for a typical small company, depending on how scattered the environment is. Most of your time investment is a kickoff conversation and a walkthrough of what you use; I do the digging.

What do we get at the end?

A written report: an inventory of your systems and data flows, a cost baseline, your GDPR and AI exposure, and a prioritized roadmap with quick wins. It is written in plain language and it is yours to keep, whatever you decide next.

Is the audit a disguised sales pitch?

No. The report has to stay useful even if we never work together again; that is the design requirement. If your current setup is honestly fine, the report says so. If only part of it is worth moving, the report says that too.

What does the audit cost?

€850 fixed, excl. btw, and it does not move. If you sign a migration within 60 days, the full €850 is credited against it, so looking first costs you nothing extra.

Do you need access to our systems?

Read access where it exists, and a walkthrough where it does not. I do not need admin rights to your production systems to map them, and anything you share is covered by the agreement and never leaves my own self-hosted systems.

Can the audit cover our AI use as well?

Yes. The biggest AI risk in most companies today is employees pasting client data into free chatbots. The audit maps which tools are in use, sanctioned or not, and what data flows through them.

Start a conversation

Tell me what runs where and what bothers you about it. You will get a straight answer. Sometimes the honest answer is that you do not need me.