Development — not production
ENSNIS2GDPReIDAS

Operational sovereignty for the European public sector.

Sovereign European infrastructure to run daily operations without relying on providers outside the EU. And when non-European tools or models are needed, a layer that protects data before it leaves.

Operating principles

How Secyda operates.

01 / Europe by default

Built and operated on European infrastructure.

European datacentres, European providers. No third parties outside the EU in the data path, no operators who can read, retain or interrupt what passes through. Every new component is built inside the perimeter and stays inside.

02 / Data protected before it leaves

If a tool or model sits outside the EU, data does not reach it unfiltered.

Before it leaves, data passes through a layer that redacts personal information, enforces the policy your institution sets, and routes through European paths where they exist. The decision about what leaves is not made by the tool. It is made by your institution.

03 / Full audit trail

Every access, every outbound call, every query is recorded.

An immutable chain, verifiable by third parties and exportable to any audit. When a data protection regulator asks, the answer is ready in minutes, not weeks.

On top of that record, a behavioural detection layer identifies deviations before they escalate into incidents.

By type of institution

What is at stake, by type of institution.

Four situations lived every day, between ageing legacy infrastructure and SaaS platforms operating outside the EU.

01
Municipal and regional authorities.

Elected officials' email, citizen files and internal communications live between redundancy-free physical servers installed in the building itself and SaaS platforms operated under foreign jurisdiction. The institution loses control on both fronts: over the ageing hardware and over the data that leaves.

02
National and regional government.

Sensitive data from ministries and regional departments is split between own infrastructure that lacks the operational level sensitive data requires and SaaS platforms that may be compelled, by court order from a third country, to hand over information without notifying the affected institution.

03
Hospitals and health consortia.

Electronic health records, prescriptions and ENS High audits operate in practice between unrefreshed internal systems and providers whose chain of custody extends beyond the European perimeter that regulation itself demands.

04
Universities and research centres.

Academic email, scientific output and research data depend on both legacy platforms and commercial services that may modify access conditions, pricing or availability unilaterally.

In all four cases, the solution starts by moving the base layer.

Products / The operating stack

Two products. One jurisdiction.

Bastem / Operating suite

Daily operations of the institution, on a single European platform.

Email, calendar, drive, documents, spreadsheets, presentations, encrypted messaging and institutional AI queries. A single European suite instead of the usual patchwork of providers, each operating under its own jurisdiction.

Talk to the team
Abastion / Security layer

The full institutional security layer, within a single perimeter.

Federated identity, encrypted secrets management, encryption and verifiable immutable audit trail. AI governance layer with DLP, European routing and behavioural audit over the record. A single security layer, a single point of contact, a single contract instead of five.

Talk to the team
Manifesto / Solid / Secure / Sovereign

Why Secyda exists.

Europe built its prosperity on shared rules, but outsourced its digital foundations. The essential functions of the state, identity, communication, collaboration, now operate on infrastructure governed outside the European Union.

What started as convenience has become dependency. Every time a European institution negotiates with a non-European government or corporation, it does so from a position weakened by the infrastructure it uses.

Secyda exists to change that base layer. We build a verifiable, legal European operating stack so that every institution can act, store and communicate under Union law, principles and control.

Secyda defines how Europe works when it works for itself.

Digital autonomy is not isolation. It is the ability to engage, cooperate and negotiate on equal terms.

Pablo Bottero, founder

Regulatory framework / Institutional evidence

Built under:

RD 311/2022
Spanish National Security Framework, Medium Level
Directive EU 2022/2555
NIS2, security of network and information systems
Regulation EU 679/2016
GDPR, protection of personal data
Regulation EU 910/2014
eIDAS 2.0, electronic identification and trust services
Live metrics

Availability, data location, incidents and audits published in real time. Verifiable without going through the sales team.

Visit trust.secyda.eu
Built, governed and hosted in Europe.

Talk to our public sector team.

Data processed under GDPR, legitimate interest basis. Not shared with third parties. More information in our Privacy policy.