DORADNB outsourcingEU jurisdiction

Sovereign cloud for the financial sector

Banks, insurers, asset managers and fintechs handle data that regulators and customers hold to strict standards. US hyperscalers fall under the US CLOUD Act and FISA, even when their data centres are in the EU. Appfront builds and migrates financial applications, client portals and data flows to sovereign infrastructure under EU jurisdiction. We are not a hosting provider ourselves: the infrastructure runs through specialist Dutch partners, and we handle the architecture, the build and the integrations.

What is a sovereign cloud for the financial sector?

A sovereign cloud is cloud infrastructure that falls entirely under European jurisdiction and European ownership. That goes beyond the location of the data centres: a US provider is subject to the US CLOUD Act and FISA, even if the servers are in the EU, because jurisdiction follows the parent company. For financial institutions, there is a supervisory dimension on top of this that other sectors do not face.

Since 17 January 2025, DORA has applied: financial institutions must have their ICT risk management in order, have exit strategies for critical outsourcing, and direct European oversight now applies to critical ICT third-party providers. In addition, the DNB assesses outsourcing of critical processes against its outsourcing policy, and the GDPR sets requirements for the processing of customer data. Anyone who hosts customer portals, policy administration or transaction data with a US hyperscaler must be able to explicitly justify that risk. A sovereign set-up makes that justification easier: the data demonstrably falls under EU law, with a party that is not subject to foreign disclosure legislation. Appfront builds and migrates the applications and data flows that run on it; if you first want to know where you currently stand, start with a sovereignty assessment.

Sovereignty doesn't mean everything has to be kept in-house, however. Many institutions take a tiered approach: the most sensitive data flows and client applications run on sovereign infrastructure, while less sensitive workloads run elsewhere. AI applications fit this approach too. If you want to analyse client files or transaction data without sending that data to US AI services, you can build private AI within your own sovereign environment. This keeps the benefits of modern cloud technology while leaving control of sensitive data with your organisation.

How we approach this

1
Inventory and risk analysis
We map applications, data flows and dependencies: which systems touch customer data, which outsourcings are critical, and what requirements DORA, the DNB and the GDPR place on your situation.
2
Architecture and partner selection
We design a target architecture on EU-sovereign infrastructure and, together with you, select a suitable Dutch infrastructure partner, including an exit strategy for each component.
3
Build or migrate
We build new applications or move existing systems in phases, preserving integrations with core banking, policy administration and payment infrastructure.
4
Operations and ongoing development
After go-live, we provide monitoring, maintenance and ongoing development, so the environment keeps pace with changing regulation and your products.

What we build and manage

Financial applications and customer portals
My-environments, policy and mortgage portals, onboarding and advisory applications, built or rebuilt sovereignly.
Migration of existing systems
Phased relocation of existing applications and workloads from hyperscalers to EU-sovereign infrastructure.
Integrations with core systems
Integrations with core banking, policy administration, payment infrastructure and reporting systems, retested in the new environment.
Private AI on sensitive data
AI applications on client files, documents and transaction data within your own environment, with nothing sent to American AI services.
Sovereign data flows
Data minimisation in the architecture, encryption, audit logging and clear legal bases for processing per data flow.
Exit strategy and portability
Open standards, containers and infrastructure as code, so the exit strategy DORA requires is also technically feasible.

For whom

Banks

Client portals, onboarding and data flows around core banking that must demonstrably fall under EU jurisdiction, with a workable exit strategy for every outsourcing arrangement.

Insurers

Policy administration, claims handling and client portals with sensitive personal and health data that should not be subject to foreign disclosure laws.

Asset managers

Portfolio and reporting systems with confidential client positions, where discretion and control over processing location carry significant weight.

Fintechs

Growing platforms that want to build sovereign from the outset, or that are asked by banking partners and regulators to adopt an EU setup. See also our overview of the best fintech developers in the Netherlands.

Technology and approach

We build with open, portable technology so your solution isn't locked into a single vendor and your exit strategy isn't just a paper exercise. Where possible we use containers and Kubernetes, infrastructure as code and open standards, so that moving between sovereign providers stays possible. The underlying infrastructure runs with specialist Dutch partners; we retain control over architecture, security and integrations.

EU-based infrastructure
Dutch infrastructure partners
Kubernetes / containers
Infrastructure as Code
Encryption in transit and at rest
Open standards
OWASP security
Monitoring and audit logging

Why Appfront

Appfront is an independent software and app agency. We do not sell hosting ourselves, so our advice on infrastructure and architecture is not coloured by a platform of our own. We combine the build of financial applications with knowledge of the requirements that DORA, the DNB outsourcing policy and the GDPR place on your environment, and for infrastructure we work with specialist Dutch partners.

  • Independent of hosting parties and hyperscalers
  • Experience with migrations and integrations with core systems
  • Privacy, data minimisation and audit logging from the architecture stage
  • Open standards so the exit strategy remains workable

Related services

You may also be interested in building a sovereign cloud, our sovereignty assessment and building private AI. If you're looking more broadly, read our overview of the best fintech developers in the Netherlands.

Frequently Asked Questions

What does a sovereign cloud mean for a financial institution?
A sovereign cloud is cloud infrastructure that falls entirely under European jurisdiction and European ownership. For financial institutions there is also a supervisory dimension: DORA and the DNB outsourcing policy set requirements for managing outsourced ICT, from risk analysis to exit strategy. A sovereign setup makes it demonstrable where data is stored, who can access it and under which law that falls.
Does Appfront provide the cloud infrastructure itself?
No. Appfront is a software and app agency, not a hosting provider or data centre. We build and migrate your applications and set up the architecture; for data centre and IaaS capacity we work with specialist Dutch infrastructure partners.
How does this relate to DORA?
DORA has applied since 17 January 2025 and sets requirements for ICT risk management, contracts with ICT providers and exit strategies for critical outsourcing. Critical ICT third-party providers are also subject to direct European oversight. A sovereign architecture under EU jurisdiction makes it easier to meet those requirements, although responsibility for compliance remains with your institution.
Will integrations with our core banking or policy system keep working?
Yes. We build and migrate while keeping integrations with core banking, policy administration, payment infrastructure and reporting systems intact. Every integration is retested in the sovereign environment before anything goes live, so service continues without interruption.
Can we use AI without sending client data to American services?
Yes. We set up private AI environments within your sovereign infrastructure, using open models that run on EU infrastructure. Client data, documents and prompts never leave your environment, and nothing is sent to American AI services.
Does our entire environment have to move over in one go?
No. Most organisations migrate in phases: first the most sensitive data flows and applications, then the rest. We draw up a migration sequence based on risk and dependencies, so clients and supervisory reporting notice nothing.

Getting started with a sovereign cloud for the financial sector

Would you like to bring client portals, data flows or AI applications under EU jurisdiction, or do you want to understand what DORA and the DNB outsourcing policy mean for your cloud choices? We are happy to think along with you independently about the approach.

Edit content