arrow_circle_right NOVIARC – SPYROSOFT CLOUD FOUNDRY
From compliance pressure to a platform you own
Since 6 December 2025, Germany’s NIS2 implementation has made cybersecurity risk management a management-body responsibility, with fines of up to €10 million for essential entities and no grace period. We migrate your regulated workloads to a sovereign Kubernetes platform where residency and access are documented, built with NoviArc – Spyrosoft Cloud Foundry.
arrow_circle_right SOVEREIGN CLOUD MIGRATION
Why NoviArc?
$1 million a year
saved by consolidating workloads onto Kubernetes
up to 80%
lower total migration cost
weeks
to a tailored, orchestrated cluster
€0
in licence fees – you pay for the service, not software
arrow_circle_right THE REGULATORY REALITY
Compliance is no longer optional
Germany’s NIS2 implementation came into force with no grace period, and the scope has expanded significantly. Four facts now shape platform decisions.
Personal accountability
Risk-management measures must be demonstrable today, and responsibility sits with the management body, with fines of up to €10 million for essential entities.
Ownership matters
An EU subsidiary with a US parent may still fall within the US CLOUD Act’s scope. Your NIS2 documentation needs to address that risk clearly – without turning it into a criticism of the provider.
Licence and build trade-offs
Per-core licences, such as OpenShift or Tanzu, rise as you scale. A do-it-yourself build can leave you exposed for more than 12 months. Neither option is easy to defend under audit.
Evidence on demand
Every access request to sensitive data needs a documented trail. NIS2 incident reporting timelines start with an early warning within 24 hours.
arrow_circle_right WHAT WE BUILD
NoviArc – a platform that’s sovereign by construction
NoviArc – Spyrosoft Cloud Foundry is built around principles that regulated organisations need to satisfy simultaneously.
Sovereign
No US company in the ownership, control, or software layer – a clear answer for your auditor and board.
Portable
Upstream Kubernetes on European infrastructure, including OVHcloud, Scaleway, and on-premises environments. You control the stack, which removes the biggest switching barrier.
Production-ready
More than 20 mature open-source components, pre-integrated. No 12-month build, no configuration debt, and no avoidable architectural risk while the clock is running.
Hardened to the regulation
Aligned with NIS2 Art. 21 and BSI Act requirements, CIS-hardened, and delivered with SSO/MFA, secrets management, and a full audit trail from day one.
arrow_circle_right MAPPED TO THE REGULATION
No black boxes: every requirement maps to a control
Each NIS2 Art. 21 measure category maps to a specific, CNCF-grade open-source component your engineers already know.
Access control and MFA
NIS2 expectation: access-control policies, asset management, and multi-factor authentication for systems handling essential services.
- Single sign-on with enforced MFA across the platform – no shared or standing cluster credentials
- Role-based access control scoped per team, with least-privilege defaults
- Access changes are declarative and reviewable, with identity configured as code
Cryptography and secrets
NIS2 expectation: policies and procedures for cryptography and, where appropriate, encryption.
- Secrets, API keys, and certificates are kept out of source code or repositories
- Dynamic, short-lived credentials reduce the attack surface and simplify rotation
- Every request for a sensitive token is logged and added to the audit trail
Audit trail and effectiveness
NIS2 expectation: procedures to assess the effectiveness of cybersecurity risk-management measures, supported by evidence.
- A full audit trail documents access requests to sensitive resources
- Monitoring and alerting are pre-built and active from the first minute the cluster runs
- Full telemetry gives auditors clear evidence when they ask how a control works
Supply chain security
NIS2 expectation: supply chain security, including risks linked to direct suppliers and service providers.
- Upstream, CNCF-governed open source – no proprietary control plane you cannot review
- A private image registry with automated vulnerability scanning helps block images with known critical CVEs
- You can audit the full component list and its open-source governance (CNCF / Apache)
Data residency and routing
Compliance need: demonstrable control over where data resides, how traffic is routed, and who may be able to compel access.
- Sovereign ingress and load balancing inside your cluster – no third-country intermediary in the path
- Data resides on European infrastructure (OVHcloud, Scaleway, on-premises) under EU jurisdiction
- Full control of encryption certificates inside your own cluster
arrow_circle_right THE OWNERSHIP TEST
Sovereign by design vs. sovereign by ownership
The European Commission’s Cloud Sovereignty Framework evaluates factors that an operating model alone cannot change: strategic sovereignty, including ownership and governance (SOV-1), and exposure to non-EU laws such as the US CLOUD Act (SOV-2). Here is the side-by-side view.
arrow_circle_right HOW NOVIARC USES AI
AI with human oversight
AI-assisted migration
An agent inventories your estate, maps dependencies, and drafts the migration plan – reducing the slow, manual work behind discovery. Every recommendation is reviewed and approved by a Spyrosoft architect before it reaches you.
arrow_circle_right FROM ASSESSMENT TO MIGRATION
Your migration plan, generated as code – with your team approving every step
Migration and re-platforming projects often stall at the analysis stage, which can take weeks by hand. An AI agent scans your infrastructure, maps each service to a portable equivalent, and generates the migration as executable GitOps code. Your engineers review and approve every decision – they check the work, but don’t redo it.
Audit
The agent scans your existing infrastructure and produces a complete, machine-readable inventory of resources, dependencies, costs, and risks.
- Every managed service identified and classified
- Cost per service benchmarked against a European-operator equivalent
- Third-country access exposure flagged at component level, where relevant
Mapping
Each service is mapped to an open, portable equivalent on NoviArc, creating a substitution plan with a savings estimate. Your architects sign it off before any code changes are made.
- Managed functions → containerised workloads on upstream Kubernetes
- Managed databases → self-managed equivalents on EU infrastructure
- External CDN or WAF → in-jurisdiction open-source ingress, where required
Migration
The agent generates the plan as code: GitOps manifests, Helm charts, and a test suite. Execution is supervised and incremental, so you validate each stage before the next begins.
- Repeatable – the same process moves your first workload and your tenth
- De-risked – automated tests validate behaviour before cutover
- Auditable – every step is a Git commit with a clear change record
Migration stops being a one-off transformation project and becomes a repeatable service.
arrow_circle_right ENGINEERING HONESTY
When NoviArc is not the right answer
Check your workloads first. NoviArc is not a universal replacement for every hyperscaler service. It may not be the right fit if:
Your architecture is deeply dependent on proprietary serverless platforms.
You rely heavily on provider-specific managed databases.
Re-platforming would require substantial redesign that outweighs the benefits.
Sovereignty and portability are not material requirements for your workloads.
Want to optimise cloud cost? Here’s the fix
arrow_circle_rightCONTACT US
Book a 30-minute architecture review
In 30 minutes, our platform engineers will review your architecture, identify where third-country access risk may exist, and show what a sovereign substrate could change.