the fit

Pick the estate you actually run.

The engine is the same in all four. What changes is which part of it you get paid for.

sovereign cloud · hosting · managed services

You already sell trust. This makes it a feature you can show.

Isolation proof per tenant, generated continuously instead of rebuilt by hand every audit season. The evidence pack becomes something you attach to the offer, not something you scramble for.

  • Per-tenant evidence packs — dated, reproducible, one per scope.
  • 100% on your infrastructure. Open substrate, air-gap capable, no data leaves. A US-SaaS control plane structurally cannot say that to your compliance customers.
  • Provable segmentation as a differentiator on managed offers — and freed public IPv4 back into your inventory as a by-product.

network engineering · CISO · audit and DORA programme owners

DORA applies now. NIS2 controls arrive from 2027.

Financial entities are already in scope — and so are the ICT providers they audit. In France, ANSSI's ReCyF already defines the objectives the controls will land on. The question stops being “are we segmented” and becomes “can you show it, dated, for last Tuesday.”

  • The evidence pack your auditors keep asking for, produced continuously by the platform's own history rather than reconstructed per audit.
  • The first two weeks are read-only exports. Effort starts only after value is visible on your own numbers.
  • Sensitive flows wait for a named human — never auto-allowed, never silently dropped, always stamped user · time · event.

And the clock is already running.

  1. Jan 2025 DORA in application. Financial entities must audit their ICT third parties — now, not eventually.
  2. Mar 2026 ANSSI publishes ReCyF, translating NIS2 into concrete, checkable objectives.
  3. Late 2026 France's Resilience bill and the entity registration wave. Roughly 15,000 entities learn they are in scope.
  4. 2027 First ANSSI controls. The question becomes “show me, for this date”.

Regulatory dates verified Aug 2026; the French transposition has slipped before and may slip again — the controls calendar has not.

carrier network engineering

One control plane instead of five.

51

control planes carrying the same reachability decision

39,8000

tunnels of state for a 200-PE full mesh arithmetic, not a vendor claim

0 bytes

added header, up to six segments an SRH carrying the same six adds 104 bytes · RFC 8754 · RFC 8986
  • Path and jurisdiction assurance for slices and interconnects — per-segment counters turn “no undeclared segment was executed” into a provable negative.
  • Mobile user plane without per-session GTP-U tunnels (RFC 9433, pioneered by SoftBank).

The entry is still the read-only audit on what runs today. SRv6

CTO · platform lead · multi-cluster Kubernetes and VMs

The same decision, written five times, drifting five ways.

One reachability decision lives as a security group, a NACL, a NetworkPolicy, an IAM condition and a mesh rule. Five planes, five owners, five change windows — and no single place where the answer is true.

  • One policy plane: intent by role, compiled down to the endpoints. Security groups demote to a handful of static substrate rules.
  • Identity stays cryptographic — mTLS and SPIFFE. An address you can read is one anyone can spoof.
  • The honest boundary: IAM keeps the cloud API plane. We retire its network-shaped hacks, not IAM. Runs over transit you don't own, including a VPC.

what the evidence maps to

The regimes, and what each one actually asks for.

The claim is never “we make you compliant” — it is that we generate the segmentation evidence your auditors, and your customers' auditors, keep asking for. Continuously, on your infrastructure.

NIS2 · ANSSI ReCyF — continuous timestamped verification reports, a justification attached to each rule rather than a hit count, and human decisions recorded as they were taken.
DORA — an evidence pack per scope or per tenant, on demand, covering both the entity and the ICT providers it is required to audit.
SecNumCloud · HDS — machine-checkable proof that the policy actually enforced equals the intent that was declared, produced without anything leaving your infrastructure.
ISO 27001 · PCI-DSS — the change workflow itself as the artifact: proposal, verification, named approval, event log — for every widening of reachability.

Dated and reproducible is the operative property. An evidence pack that cannot be regenerated from the same exports on a different day is a screenshot, not evidence.

e000 End.DT6 deliver

See it against your own kit.

30–60 minutes. Read-only. We compare your declared intent to what is actually running, and hand back the gap list.

Nothing is installed to have this conversation.

See it on your estate — read-only