Industries

Sovereignty is a property of the whole stack.

Where the data sits is the easy question. The harder one is who owns each layer of the infrastructure holding it, and who could be compelled to act on it. STORViX and Vates answer that jointly, in Europe.

  • Swedish storage, French virtualisation
  • Open-source hypervisor, no licence lock-in
  • Named EU data locations

The problem

A sovereign data centre on a non-sovereign stack.

Defence and security procurement has moved past asking where a data centre is. The question now reaches through the stack: who owns the hypervisor, who owns the storage, whose licensing terms can change, and which jurisdiction each of those companies answers to.

That is a harder question than it was, because consolidation has moved much of the infrastructure market under a small number of owners outside Europe, and licensing terms have changed sharply and at short notice.

Meanwhile the operational requirements have not softened. Records must be provably intact years later, recovery must survive an adversary who already holds credentials, and the platform has to stay supportable across a procurement cycle measured in years rather than quarters.

What STORViX does about it

European at every layer that matters.

The storage and the virtualisation beneath it are supplied by two European companies working together, on an open-source hypervisor with no licence lock-in.

  • Storage: STORViX, Sweden

    STORViX AB is registered in Sweden, number 559074-0865, headquartered at Ideon Science Park in Lund. AiRE has been shipping since 2017.

    • Swedish limited company
    • Product shipping since 2017
    • Serving customers across EMEA
  • Virtualisation: Vates, France

    Vates is based in Grenoble and develops XCP-ng, a Type-1 hypervisor built on Xen, with Xen Orchestra for management and backup. It positions on infrastructure sovereignty and independence from closed ecosystems.

    • XCP-ng — open-source Type-1 hypervisor
    • Xen Orchestra for management and backup
    • Part of the Xen Project
  • AiRE is not tied to one hypervisor

    AiRE presents standard storage protocols — NFS and SMB for file, Fibre Channel and iSCSI for block — so any hypervisor that consumes those can use it. The Vates partnership is a commercial relationship for a fully European stack, not a technical dependency. STORViX's own published customer material describes an AiRE system serving as primary storage for a VMware cluster.

    • VMware — published STORViX customer deployment
    • XCP-ng — through the Vates partnership
    • Proxmox, Hyper-V, KVM and OpenStack consume the same protocols
  • No licence lock-in at the hypervisor

    XCP-ng is open source. That matters in a procurement horizon measured in years: the terms of the layer your estate runs on cannot be rewritten by an owner you did not choose.

    • Open source, no per-socket licence
    • Independent of closed vendor decisions
    • Transparent pricing model
  • Controls evidenced per data set

    Encryption and access privileges attach to the individual data set rather than the array, so a question about one classification of material has a specific answer rather than an estate-wide one.

    • Per-data-set encryption
    • Per-data-set access privileges
    • Two-factor authentication on administration
  • Recovery that survives a credentialled adversary

    Copy-on-write snapshots are immutable once taken, and Vault replication is one-way, so a compromised source cannot reach back into the off-site copy.

    • Immutable snapshots
    • One-way replication into Vault
    • FIDO2 multi-factor authentication on Vault drives
  • Integrity provable years later

    Every block is checksummed to the root node and verified on read, with automatic repair from redundancy. A record produced in evidence has been checked, not assumed.

    • End-to-end checksums
    • Self-repair from redundant copies
    • RAID-Z and mirror topologies

Outcomes

What changes for a sovereignty-constrained estate

  • The supply-chain question has an answer

    Both suppliers in the stack are European companies, and each can be named with its jurisdiction in a tender response.

  • The hypervisor cannot be repriced under you

    An open-source Type-1 hypervisor removes the class of risk where licensing terms change mid-cycle.

  • Evidence at the granularity of the question

    Per-data-set controls mean answering about one category of material does not require caveats about everything else.

  • A platform life that matches the procurement cycle

    Seven to ten years of hardware service life means fewer refreshes, and fewer migrations of material that should not move often.

About the STORViX and Vates partnership

STORViX and Vates work together to offer storage and virtualisation from two European suppliers as a combined proposition. The details of the joint solution — supported configurations, integration specifics, and how the two are sold and supported together — are being documented and should be confirmed with either company before being relied on in a tender.

What is established and independently checkable is the shape of it: STORViX AB is Swedish and supplies AiRE; Vates is French, develops XCP-ng and Xen Orchestra, and is the founder of the XCP-ng project within the Xen Project.

What this page does not claim

It does not assert that deploying this stack makes an organisation compliant with NIS2, with any national security framework, or with any procurement standard. Those assessments consider governance, process, personnel and technology together and belong to the organisation and its authority.

It does not claim any security certification or accreditation for either product. Where a specific control has to be evidenced for a submission, that is a conversation with an architect who can describe precisely how the mechanism behaves.

Any statement on this site not backed by supplied source material is visibly marked as requiring validation rather than presented as established.

Bring the tender questions.

Supply-chain jurisdiction, data location, immutability, integrity, and platform life. Those are answerable specifically — including where the honest answer is that it depends on your environment.