Digital Sovereignty & Data Ownership
Your data.
Your systems.
Your rules.
I plan IT landscapes that belong to your organisation and guide the way there: open standards, operated in your own house, hardened. Two questions, one answer — who owns your data, and who can reach it.
Years of systems engineering
Vendor-neutral, no commissions
Advice in German and English
- Cloud and AI applications
- Documents and knowledge base
- Backups and version history
- Access rights and audit logs
None of it sits with an outside provider.
Services
Four routes back to control
From assessment to running system — vendor-neutral, on open standards, operated in your own house.
Sovereignty check
We establish where your data actually sits, who has lawful access to it, and which dependencies would leave you unable to act in a crisis. The result is a prioritised order: what to change first, what later, and what to leave alone.
Out of someone else’s cloud
A staged move back to open source and systems you control: recover your data, cut licence costs, secure your ability to operate, with no big bang and no interruption to daily business.
AI in a cage
Language models and assistants working on your own documents, run locally, so your knowledge never lands with an outside provider. Here AI is a tool, not the point: it should use your data ownership, not break it.
Hardening & defence
Close the attack surface before it is found: separate access, switch off unused services, automate updates, rehearse recovery. I have run servers across many providers for over twenty years, including the incidents you learn from.
Security
Attacks are automated. Are your defences?
What used to be a targeted attack is now production-line work: automated systems probe every reachable address for every known weakness, around the clock. You are not attacked because you are interesting — you are attacked because you are reachable. For a small organisation that is existential: one encrypted server and the business stops.
- Shrink the attack surface instead of buying products What is not running cannot be attacked. The most effective measures carry no licence fee — they cost decisions.
- Backups that actually restore A backup only becomes one once the restore has been rehearsed. Anything else is hope that consumes disk space.
- Access that makes no single person a risk Separated rights, traceable changes, and no shared administrator password sitting in a chat history.
Test questions
Sovereignty with an asterisk
Now that large providers call their data centres “sovereign”, the practice has a name: sovereignty washing. Four questions that separate a promise from a fact — including when you ask them of me.
- Who holds administrative access — and under which jurisdiction? A European data centre is not enough if the parent company answers to a foreign legal system.
- Can you inspect the source code? What cannot be verified has to be believed. Open source turns trust into something you can check.
- Can you change provider without losing your data? Open formats and documented interfaces decide whether a decision stays reversible.
- Does your system keep running if the provider shuts down? A system is sovereign only when its continued operation does not depend on a contract staying alive.
Track record
Built, not just advised
I have been responsible for digital systems since 1999 — from corporate projects to platforms for ministries, associations and member organisations. Many of them in settings with hard requirements on data custody, accessibility and longevity.
- Toshiba Electronics Europe
- Bosch Group
- Daimler Chrysler
- BMW
- Volkswagen
- Vitra
- Deutsche Fußball Liga
- IHK Munich · BMWi

Innovationstag Mittelstand
Federal Ministry for Economic Affairs
Digital platform for the German federal ministry's SME innovation day.

spurderhaeuser.de
Bavarian State Ministry of Finance
Interactive web platform for a statewide cultural programme.

portal-se.de
Portal for rare diseases
Concept, development and operation of a health information portal.

BGZ commenting tool
Public participation
Website and interactive commenting tool for a public consultation.

platformcoop.de
Platform Cooperativism
Web platform for the cooperative platform movement — concept, delivery, operation.

Hertha BSC
Digital members' assembly
Website and interactive voting tool for a digital members' assembly.
Projects from my work at Streampark Media Networks.
Projects
What I am working on
Current work where sovereign systems are not theory but the build specification.
In-house retrieval systems
Knowledge systems that answer questions from an organisation's own material. Embeddings and index run locally; the knowledge base never leaves the organisation. Currently in use at a cooperative.
Agentic AI integration
Assistants that do not merely answer but act — with defined rights, tested boundaries and traceable access. Here the frame is the actual work.
EUCUBE
Platform work in a European and cooperative context — where independence from large providers is a precondition of the undertaking.
InvestTracker
An application for evaluating and tracking investment and financial data. Sensitive figures, own infrastructure, nothing handed to third parties.
In your own house
Where your systems run
Models, index and logs on hardware that belongs to you. Not in someone else’s cloud.



Illustration. The hardware shown stands symbolically for locally operated systems. Images generated locally with AI.
systems engineering
About
Zsolt Thomas Szentirmai
Dipl.-Wirtsch.-Ing. · Systems engineer for digital sovereignty
I have been responsible for digital systems since 1999: as project manager for European change management at Toshiba Electronics Europe, as managing director of a federally funded eBusiness centre at the Munich Chamber of Commerce, and since 2008 with my studio Streampark Media Networks in Berlin.
Today I work on one question: who owns the systems an organisation depends on? I plan IT on open standards, guide the delivery and review the result. Artificial intelligence belongs in that picture, but as a tool — run locally, so it uses your data ownership rather than surrendering it.
What I recommend, I know from operating it. As senior consultant and founding member of Platform Coops Germany eG, I work in particular with cooperative and public-benefit organisations — where independence from large platforms is not merely an IT question but one written into the statutes.
Insights
Latest articles
Attacks in packs: what the OpenAI incident means for your security
In July 2026, AI agents organised themselves to attack a target for the first documented time — coordinated, at machine speed. Why that changes the maths for everyone, not just large corporations.
AI providers: the sovereignty test
Rankings of the best AI models go stale within weeks. The four questions that actually decide which provider you can trust with your data do not.
EU AI Act: what applies to SMEs since August 2026
Since 2 August 2026 the obligations for high-risk systems apply. For most small businesses the AI Act is still no cause for panic — but it is a reason to finally write down how AI is used in the company.
Contact
Let’s talk.
Whether it is an assessment, an exit from a dependency, or a system that has to stay in-house — write and tell me what you have in mind.