Sovereign Enterprise AI Platform
Named after Athena's shield — Aegis provides protection through intelligence. A single-tenant sovereign AI platform deployed on Finnish infrastructure, covering all 21 EU-regulated industries including dual-use critical raw materials. Dedicated Kubernetes cluster per customer. No shared tenancy. No US cloud. No CLOUD Act exposure.
The European Commission adopted a €1.5 billion EDIP work programme (30 March 2026). €700M+ for production ramp-up, €240M for joint procurement, €100M for defence SME equity. Aegis meets all EDIP Article 9 eligibility requirements.
| EU Establishment | Finland (Lifetime Oy, Y-tunnus 0772407-9) PASS |
|---|---|
| Third-Country Control | None — Finnish-owned, no US parent PASS |
| Buy European (65%) | UpCloud Helsinki, EU-only stack PASS |
| Defence Supply Chain | 21 regulated industries including dual-use CRM PASS |
| EDIP Compliance Stack | ETS + CBAM + CSRD + NIS2 + EU AI Act + dual-use export control (Reg. 2021/821) |
Aegis is the EU-origin enterprise's full-sovereign execution of the universal three-pillar × three-jurisdiction sovereignty model. See Sovereignty Field Note #2 for the full taxonomy.
| Data Sovereignty (KYA SIB-track) | Full — EU residency, EU-only access path, Finnish-owned infrastructure, zero CLOUD Act exposure PASS |
|---|---|
| Technology Sovereignty (KYA CSB-track) | Full — UpCloud + open Kubernetes + open Postgres stack; algorithm-rotation supported; no proprietary lock-in PASS |
| Operational Sovereignty (KYA EAB-track) | Full — Finnish escalation, EU-only on-call, Firecracker MicroVM isolation, hardware kill-switch authority PASS |
| Jurisdiction emphasis | J1 (EU) primary. J2 (US) and J3 (Singapore) market access via Connect tier. |
| Quantum readiness (R-Sac²) | R-Sac²-ready surface — Rightful Oy partnership instrument available for HNDL exposure assessment and NIST PQC migration (FIPS 203 / 204 / 205) before the 2030–2035 cutover |
| Deployment Model | Single-tenant Kubernetes (Helm chart) EU Sovereign |
| Infrastructure | UpCloud Managed Kubernetes (UKS), Helsinki DC (fi-hel1 / fi-hel2) |
| Sovereignty | Finnish-owned (Tesi-backed), ISO 27001, CISPE member, EU-only staff access |
| CLOUD Act Exposure | None — no US parent company, no US-owned infrastructure |
| Kubernetes | CNCF-conformant, full Helm support, HPA + VPA + Cluster Autoscaler |
| SLA | 99.999% (UpCloud infrastructure) |
| Database | UpCloud Managed PostgreSQL + pgvector (HA, automated backups, Helsinki DC) |
| Cache / Queue | UpCloud Managed Valkey/Redis |
| GPU | NVIDIA L40S nodes available for local LLM inference |
| Egress | Zero cost (UpCloud Essentials) |
| Load Balancer | Included (UpCloud Managed) |
| Agent Isolation | Firecracker MicroVM per agent (KYA v1.4) |
| AI Agents | 21+ industrial AI agents across 21 verticals (same codebase as DWS IQ 6) |
| CLI Access | dws CLI — all agents manageable via command line |
| EU AI Act | Article 12 logging, reasoning lineage, Aiwen compliance layer |
| Compliance | GDPR, NIS2, EU AI Act, CER Directive, EU CRM Act, KRITIS, dual-use export control (Reg. 2021/821) |
| Certifications Roadmap | ISO 27001 (Q3 2026), SOC 2 Type II (Q4 2026) |
| Security Audit | PiTuKri Audited Traficom NCSC-FI cloud security criteria v1.1 — 11 subdivisions, 52 criteria assessed |
| Agent | Capability |
|---|---|
| ComplianceAgent | EU regulatory compliance (CSRD, ETS, CBAM, Fit for 55, EU AI Act) |
| SovereigntyMonitor | CLOUD Act exposure detection, EU data residency verification |
| ArgusAgent | Orbital intelligence — SAR satellite industrial target detection |
| SiteSenseAgent | Site safety scoring, weather risk, worker capacity |
| MaterialOracle | Embodied carbon tracking, sustainable procurement |
| ScheduleGenius | Timeline optimization, resource allocation |
| CustomerSat | Customer health scoring, churn prediction |
| Viability | Unit economics, financial health, LTV |
| QualityGate | Deployment readiness, quality scoring |
| EmissionsDataAnalyst | Emissions analysis with EU regulatory context |
| LogisticsAgent | Fleet compliance, route optimization, supply chain carbon |
| ConstructionAgent | Construction project compliance orchestration |
| KYA Engine | Know Your Agent — identity, isolation, kill authority |
| Article12Logger | EU AI Act audit trails for all AI decisions |
| CrossVerticalIntel | Supply chain signal propagation — detects compliance cascades across 21 industries |
| GaiaAgent | Cement, lime & earth materials — dual-use critical raw material assessment |
| VulcanAgent | Steel & metals — ETS Phase 4, CBAM carbon declarations |
| + 5 more | Sales outreach, deep wiki extraction, compliance research, designer, Hermes logistics |
| Competitor | Gap Aegis Fills |
|---|---|
| Palantir AIP | US-based, CLOUD Act exposed. Not EU-sovereign. No EU AI Act compliance. |
| Anduril Lattice | Hardware-focused. No compliance agents. US-only. |
| C3.ai | Dashboard platform, not agent outcomes. US-hosted. |
| Big 4 consulting | Advisory only. No autonomous agents. No orbital intelligence. |
A factory fire at a Nordic lime facility. Local news dismissed it. Aegis traced the downstream cascade in seconds.
| Signal Stage | Industry | Impact |
|---|---|---|
| 1. Trigger | Lime (critical raw material) | Facility disruption — supply concentration risk |
| 2. Upstream | Steel | Flux shortage → CBAM cost spike for non-EU steel imports |
| 3. Midstream | Cement | Calcination feedstock constraint → clinker bottleneck |
| 4. Downstream | Construction | Embodied carbon increase → CSRD E1 disclosure gap |
| 5. Regulatory | Cross-vertical | CER Act blind spot identified — mineral processing not covered |
Five industries. Four EU regulations. One signal chain. Deterministic scoring — no LLM hallucination. Every data point verifiable from public EU sources.
| Tier | Onboarding + Integration | Monthly | Included |
|---|---|---|---|
| Aegis Standard | €59,990 | €999/mo | 18 agents, dedicated K8s cluster, Article 12 logging, KYA governance, standard support |
| Aegis Defence | €89,990 | €1,999/mo | Everything in Standard + NVIDIA L40S GPU, ArgusAgent SAR, priority support (4h SLA), EDIP compliance reporting |
| Aegis Sovereign | Custom | €4,999/mo | Everything in Defence + air-gapped / on-premises option, security clearance support, dedicated engineering team, custom SLA |
This product is one piece. The whole stack ties together: sovereign hardware at the edge, on-premise inference, an EU service team, and the recurring NVIDIA-model relationship that compounds. Pick the next rung you need.
The wider DWS IQ 6 platform covers 25 EU-regulated industries (see INDUSTRIES.md). The Aegis defence/dual-use tier activates 21 of them — excluding consumer-facing verticals like Healthcare, Financial Services, and Public Sector that aren't relevant to defence supply chains. The same sovereign topology — sensor edge → operations command → situation command, wrapped in service — repeats across every EU-regulated industry. Different bundle per workload, same moat underneath.