Most cybersecurity vendors ask you to trust that your data is safe because it's "encrypted" or "hosted securely." Fewer ask the harder question: safe from whom?
Roughly 80% of cybersecurity products are headquartered in the United States, which means they're subject to US law, including the CLOUD Act and FISA 702, both of which can compel a US company to hand over data it controls, regardless of where that data physically sits. Encryption at rest doesn't change who can be legally compelled to produce it.
Sovereignty is a full-stack property
We built NN Technologies in Paris, and we made a decision early on: sovereignty isn't a checkbox you tick with a data-residency clause. It's a property of the entire stack: the company, the hosting, the legal jurisdiction, the AI models, the support, and the billing all stay in Europe. If any one of those pieces sits outside European jurisdiction, the guarantee breaks.
That's why every product we ship, like Autodit's continuous attack surface monitoring, is built to run without ever sending data outside a jurisdiction our clients control.
AI-augmented, not AI-dependent
The other bet we made: AI should decide what to scan, not how. Our scanning engines are deterministic code we own end to end: reproducible, auditable, and not subject to a model's mood on a given day. AI agents sit on top, reducing noise and prioritizing what actually matters. That division of labor is why we can offer fully offline deployments with locally-hosted models for organizations that can't send anything outside their network at all.
We'll be writing more here as each product matures. If you want to talk sooner, get in touch.