Sovereign rebuildEU jurisdictionOpen source

Rebuilding software on a sovereign stack

Some applications simply cannot be made sovereign by migrating them: they are intertwined with proprietary services from American hyperscalers, run on legacy technology or are essentially American SaaS you want to move away from. Appfront designs and rebuilds such software on an open, sovereign stack under EU jurisdiction, phased alongside the existing system. We build the application, the data migration and the integrations ourselves; for data centre and infrastructure services, we work with specialised Dutch infrastructure partners.

What does it mean to rebuild software sovereignly?

A sovereign rebuild means redesigning and building an application that is technically or contractually tied to American technology on a stack that falls entirely under European jurisdiction. This differs from migration: when migrating applications to a sovereign cloud, the software largely moves across unchanged. Where that is feasible, migration is usually the more logical route. A rebuild becomes the right choice when the application is deeply intertwined with proprietary hyperscaler services, when legacy technology can no longer be run or maintained properly outside the current platform, or when you want to replace a US SaaS product with software you control yourself.

The motivation is often legal and strategic. American providers fall under the US CLOUD Act and FISA, even when their servers are located in the EU. The revised Dutch government cloud policy of 3 July 2026 requires central government to store and process data within the EEA, mandates a risk assessment and an annually tested exit plan, and advises against public cloud for email and document management; state secrets and base registries do not belong there. In addition, the GDPR, NIS2 via the Cybersecurity Act (entry into force 15 August 2026), DORA for the financial sector, NEN 7510 in healthcare and the BIO for government set concrete requirements on where and how data is processed.

In such cases, migrating an interwoven application simply reproduces the problem: the same dependencies, just in a different location. Rebuilding on an open stack is then the shortest route to an application that demonstrably falls under EU law and that you can later move without another rebuild.

How we approach this

1
Inventory and dependencies
We map out the current application: which proprietary services, integrations and contracts are woven into it, which data is sensitive, and which legal requirements apply to your sector.
2
Defining core functionality
We analyse what your organisation actually uses. Not everything needs to come across: the rebuild focuses on the functionality that delivers value, without the baggage of years of legacy.
3
Building in phases alongside the old system
We build the new application on an open, sovereign stack, alongside the existing system. Functionality switches over component by component, with data synchronisation where needed, so the work carries on.
4
Switching over and continued development
Only once the new system has proven itself do you switch over, and we decommission the old one. Afterwards we take care of management, monitoring and ongoing development on the sovereign environment.

What we build and manage

Rebuilding tightly coupled cloud applications
Applications that rely on proprietary hyperscaler services we redesign on open alternatives, so they run on any EU infrastructure.
Replacing US SaaS
We build a dedicated application for the functionality you actually use, with your data and your software in your own hands.
From legacy to an open stack
Outdated systems that can no longer run anywhere else we rebuild on modern, maintainable technology.
Data migration and integrations
We migrate your data to the new system in a controlled way and rebuild the integrations with your other applications.
Open-source foundations
The rebuild uses open-source components and open standards as its starting point, so the solution is portable and controllable.
Operations and ongoing development
After the switchover, we provide maintenance, security updates and new functionality on the sovereign environment.

For whom

Government and public sector

Organisations falling under the revised Dutch government cloud policy and the BIO that have applications tightly coupled to US services and need to migrate.

Healthcare

Institutions that must comply with NEN 7510 and the GDPR and want to move medical data out of US SaaS environments.

Financial sector

Entities under DORA that want to reduce their dependence on critical US ICT providers.

Organisations under NIS2

Businesses in critical sectors that must secure their digital supply chain under the Cybersecurity Act and want to replace locked-in software.

Technology and approach

Open source and portability are the starting point of every rebuild. We choose components you can inspect, have audited and, if necessary, run yourself: open-source frameworks, PostgreSQL instead of proprietary databases, containers instead of platform-bound services. That way the new application is not only sovereign where it runs today, but remains movable between EU providers. The dependence on a single supplier, the lock-in that hyperscalers often create silently, we deliberately engineer out.

EU-based infrastructure
Open-source frameworks
PostgreSQL
Kubernetes / containers
Infrastructure as Code
Open standards and APIs
Encryption in transit and at rest
Monitoring and logging

Why Appfront

Appfront is a technical software and app studio that keeps the entire process in-house: from analysing the existing application through to design, build, data migration and ongoing management. For data centre, IaaS and colocation services we work with specialist Dutch infrastructure partners; we take the lead and ensure the software runs reliably on them. Because we do not sell hosting or licences ourselves, our advice on the stack is not coloured by a platform of our own.

  • Rebuild, data migration and integrations in-house
  • Open source and open standards as the starting point
  • A phased approach alongside the existing system
  • Infrastructure oversight through Dutch partners

Related services

If your application can largely stay as it is, look at migrating applications to a sovereign cloud. If you want to set up a new solution that is sovereign from the start, see building a sovereign cloud. For the broader issue of legacy systems, there is platform modernisation, and if you are comparing agencies, you will find an overview in the best software modernisation agencies.

Frequently Asked Questions

What is the difference between rebuilding and migrating?
When migrating, an existing application moves largely unchanged to sovereign infrastructure. When rebuilding, we design and build the application anew on an open, sovereign stack. Rebuilding is the right choice when the software is so intertwined with American cloud services or SaaS that migrating would only move the problem.
When is rebuilding a better option than migrating?
When an application relies heavily on proprietary services from a hyperscaler, when legacy technology can no longer be run or maintained properly outside that platform, or when you want to replace an American SaaS product with software you control yourself. In such cases, migrating merely produces a copy of the old dependencies, and rebuilding is the shortest route to genuine sovereignty.
Does the old system remain available during the rebuild?
Yes. We build the new application in phases alongside the existing system. Functionality transfers part by part, with data synchronisation where needed, so your organisation can carry on working and you only retire the old system once the new one has proven itself.
Can you replace an American SaaS solution?
Yes. We analyse which functionality your organisation actually uses, design a dedicated application for it and build it on sovereign infrastructure. You keep control of your data and software, with no subscription to a provider that falls under US jurisdiction.
Why do you build with open source?
Open source and open standards are the foundation of portability: the application can then run on any modern EU infrastructure and is not tied to the services of a single vendor. This prevents the rebuild from creating a new dependency.
Does Appfront itself provide the sovereign infrastructure?
No. Appfront designs and builds the software; for data centre and infrastructure services, we work with specialised Dutch infrastructure partners. We advise independently on the environment that suits your requirements and keep control of the overall solution.

Getting started with sovereign software rebuilding

Is your application tied to an American stack or SaaS, and do you want to know whether rebuilding or migrating is the better route? We are happy to examine the dependencies and approach with you.

Edit content