Cloud exitRepatriationEU jurisdiction

Cloud exit: repatriating from the public cloud

A cloud exit is the controlled move of applications, data and workloads out of the American public cloud to a Dutch or European environment or to your own infrastructure. Appfront carries out that exit: phased, application by application, and always with a fallback option. We handle the application and data migration ourselves; for data centres, IaaS and colocation we work with specialised Dutch infrastructure partners. Not yet sure exactly what needs to move? Start with the sovereignty assessment.

What is a cloud exit?

A cloud exit, also known as repatriation, is the planned move of applications, data and workloads from the public cloud of an American hyperscaler to an environment you choose yourself: a Dutch or European cloud provider, a private cloud or your own infrastructure. The difference from an ordinary migration lies in direction and reason: you leave deliberately and want that departure to proceed in a controlled way, without disrupting service and without data loss.

The trigger is often legal. American cloud providers fall under the US CLOUD Act and FISA, even when their servers are in the EU: jurisdiction follows the parent company, not the server location. For organisations with sensitive or regulated data, that is becoming harder to justify under the GDPR, NIS2 (the Dutch Cybersecurity Act takes effect on 15 August 2026) and sector standards such as NEN 7510 in healthcare and the BIO in government.

Cost control and obligations play a part too. Public cloud costs grow with usage and are hard to predict; for stable workloads, an own or European environment often gives more grip on the cost profile. And increasingly, a prepared exit is simply required: the revised Dutch central government cloud policy of 3 July 2026 asks government organisations to store and process data within the EEA, to carry out a mandatory risk assessment and to maintain an exit plan tested annually, and DORA requires financial institutions to have exit strategies for critical ICT services. Whoever has such a plan wants to be able to carry it out. This service is about that execution; for the analysis beforehand there is the sovereignty assessment.

How we approach this

1
Making the exit plan concrete
We start from your exit plan or assessment: which applications and data move, in what order, and where they land. If that picture is missing, you begin with the sovereignty assessment.
2
Design per application
For each application we choose the strategy: move as is, adapt or rebuild. We plan the data egress in detail and, together with Dutch partners, set up the landing environment.
3
Controlled migration
Where possible we run in parallel, synchronise data and switch over application by application in a controlled way. The old environment remains available as a fallback until everything has proven itself.
4
Closing out and managing
We shut down the old environment properly: data demonstrably deleted, contracts terminated, documentation in order. After that we take care of management and ongoing development on the new environment.

What we build and manage

Application migration
We move applications out of AWS, Azure or Google Cloud: from lift-and-shift to targeted rebuilding where cloud-native services make that necessary.
Data migration and egress planning
We plan data egress carefully: volumes, bandwidth, sequence and integrity checks, so that the data arrives complete and verifiable.
Replacing cloud-native services
We replace managed services such as queues, functions and databases with open alternatives that run on any environment.
Cutover runbook and fallback
A runbook per application for the switchover, including a rollback scenario, acceptance criteria and a go/no-go moment.
Integrations
We build integrations with your existing systems and test the entire chain end to end before we switch over for good.
Operations and ongoing development
After the exit we provide monitoring, maintenance, security updates and ongoing development on the new environment.

For whom

Government and public sector

The revised Dutch government cloud policy requires storage and processing within the EEA, advises against email and document management in the public cloud, and requires an annually tested exit plan. We carry out that exit plan.

Healthcare

Institutions that process medical data under NEN 7510 and no longer want to host it with an American hyperscaler.

Financial sector

DORA has applied since 17 January 2025 and requires exit strategies for critical ICT services. We make that strategy workable and carry it out.

Organisations with rising cloud costs

Businesses with stable workloads for which the hyperscaler's flexibility adds little, but whose invoices keep growing with usage.

Technology and approach

We repatriate to open, portable technology. We replace cloud-native building blocks with open alternatives, so that your applications run on any environment and a future move no longer requires a rebuild. For the landing infrastructure we work with specialised Dutch partners; control over architecture, migration and applications rests with us.

Kubernetes / containers
Infrastructure as Code
PostgreSQL and open databases
S3-compatible object storage
Encryption in transit and at rest
Dutch data centres via partners
Monitoring and logging
Open standards

Why Appfront

Appfront is an independent software and app agency. We do not sell hosting ourselves and have no stake in where your workloads end up, so our advice on the landing environment is not coloured by that. We combine migration experience with the development capacity to adapt or rebuild applications where that is needed for the exit.

  • Phased approach with a fallback per application
  • Application and data migration handled in-house, infrastructure via Dutch partners
  • Experience replacing cloud-native services with open alternatives
  • Management and ongoing development after the exit

Related services

Start with the sovereignty assessment if you don't yet have an exit plan. Also see migrating applications to a sovereign cloud, migrating from AWS to a sovereign cloud and building a sovereign cloud.

If your exit also raises the question of who has the right to the data your systems and equipment generate, the European Data Act applies: it obliges providers to enable switching without unnecessary barriers and gives users the right to their own product data.

Frequently Asked Questions

What exactly is a cloud exit or repatriation?
A cloud exit or repatriation means moving your applications, data and workloads out of the public cloud in a controlled way, into an environment you choose: a Dutch or European cloud provider, or your own infrastructure. It is the execution of an exit plan, with a migration approach for each application and a fallback option during the transition.
Do we need to carry out an assessment before we can move?
We recommend one if you don't yet have a clear picture of what needs to move. Our sovereignty assessment maps applications, data flows and dependencies and produces a prioritised plan. If you already have an exit or migration plan, we start executing it straight away.
Where will our applications and data be hosted after the exit?
That depends on your requirements: a Dutch or European cloud provider, a private cloud or your own infrastructure. Appfront handles application and data migration; for data centres, IaaS and colocation we work with specialised Dutch infrastructure partners.
What happens if a migration goes wrong during the transition?
We carry out every migration with a fallback option: the old environment stays available until the new one has proven itself in production. Where possible we run in parallel, synchronise data and only switch over permanently after acceptance. If something goes wrong, we roll back without data loss.
Do you move everything at once?
No. We migrate in phases, per application or per coherent group of applications. This keeps services running and keeps the risk small at each step. We determine the order based on dependencies, risk and the sensitivity of the data.
Do you also manage the environment after the exit?
Yes. After the exit we provide monitoring, maintenance, security updates and ongoing development of your applications on the new environment. This keeps the solution current and lets you demonstrate, with a working and tested exit plan, that you meet requirements.

Get started with your cloud exit

Do you have an exit plan that needs executing, or do you want to know what repatriation would look like for your applications? We're happy to think along with you about a controlled route out of the public cloud.

Edit content