Rebuilding software on a sovereign stack
Some applications simply cannot be made sovereign by migrating them: they are intertwined with proprietary services from American hyperscalers, run on legacy technology or are essentially American SaaS you want to move away from. Appfront designs and rebuilds such software on an open, sovereign stack under EU jurisdiction, phased alongside the existing system. We build the application, the data migration and the integrations ourselves; for data centre and infrastructure services, we work with specialised Dutch infrastructure partners.
What does it mean to rebuild software sovereignly?
A sovereign rebuild means redesigning and building an application that is technically or contractually tied to American technology on a stack that falls entirely under European jurisdiction. This differs from migration: when migrating applications to a sovereign cloud, the software largely moves across unchanged. Where that is feasible, migration is usually the more logical route. A rebuild becomes the right choice when the application is deeply intertwined with proprietary hyperscaler services, when legacy technology can no longer be run or maintained properly outside the current platform, or when you want to replace a US SaaS product with software you control yourself.
The motivation is often legal and strategic. American providers fall under the US CLOUD Act and FISA, even when their servers are located in the EU. The revised Dutch government cloud policy of 3 July 2026 requires central government to store and process data within the EEA, mandates a risk assessment and an annually tested exit plan, and advises against public cloud for email and document management; state secrets and base registries do not belong there. In addition, the GDPR, NIS2 via the Cybersecurity Act (entry into force 15 August 2026), DORA for the financial sector, NEN 7510 in healthcare and the BIO for government set concrete requirements on where and how data is processed.
In such cases, migrating an interwoven application simply reproduces the problem: the same dependencies, just in a different location. Rebuilding on an open stack is then the shortest route to an application that demonstrably falls under EU law and that you can later move without another rebuild.
How we approach this
What we build and manage
For whom
Organisations falling under the revised Dutch government cloud policy and the BIO that have applications tightly coupled to US services and need to migrate.
Institutions that must comply with NEN 7510 and the GDPR and want to move medical data out of US SaaS environments.
Entities under DORA that want to reduce their dependence on critical US ICT providers.
Businesses in critical sectors that must secure their digital supply chain under the Cybersecurity Act and want to replace locked-in software.
Technology and approach
Open source and portability are the starting point of every rebuild. We choose components you can inspect, have audited and, if necessary, run yourself: open-source frameworks, PostgreSQL instead of proprietary databases, containers instead of platform-bound services. That way the new application is not only sovereign where it runs today, but remains movable between EU providers. The dependence on a single supplier, the lock-in that hyperscalers often create silently, we deliberately engineer out.
Why Appfront
Appfront is a technical software and app studio that keeps the entire process in-house: from analysing the existing application through to design, build, data migration and ongoing management. For data centre, IaaS and colocation services we work with specialist Dutch infrastructure partners; we take the lead and ensure the software runs reliably on them. Because we do not sell hosting or licences ourselves, our advice on the stack is not coloured by a platform of our own.
- Rebuild, data migration and integrations in-house
- Open source and open standards as the starting point
- A phased approach alongside the existing system
- Infrastructure oversight through Dutch partners
Related services
If your application can largely stay as it is, look at migrating applications to a sovereign cloud. If you want to set up a new solution that is sovereign from the start, see building a sovereign cloud. For the broader issue of legacy systems, there is platform modernisation, and if you are comparing agencies, you will find an overview in the best software modernisation agencies.
Frequently Asked Questions
Getting started with sovereign software rebuilding
Is your application tied to an American stack or SaaS, and do you want to know whether rebuilding or migrating is the better route? We are happy to examine the dependencies and approach with you.