EU Sovereignty Tier — Forgejo-Backed

Enterprise Git Without US-Cloud Lock-In

Managed Forgejo with EU data residency, cryptographic audit trail, SAML/SCIM via Authentik, HIPAA BAA-readiness, and AI training opt-out. Built for government, healthcare, finance, and legal.

Request a Demo View Compliance Docs
GDPR Data Residency SAML 2.0 / SCIM via Authentik Cryptographic Audit Trail (F9) SOC 2 Type I Readiness No Microsoft / No US-cloud lock-in AI Training Opt-Out (BYO-LLM) Dutch Government-Backed Forgejo Stack
Platform Capabilities

Every Regulated-Industry Requirement, Covered

Built on Forgejo, the open-source Git platform publicly backed by the Dutch government for digital sovereignty. Wrapped with enterprise SSO, immutable audit logs, and EU-resident compute.

🌍

EU Data Residency

Your repositories, CI artifacts, and metadata remain in EU jurisdiction. No data crosses to US-based cloud hyperscalers. Configurable per-namespace residency zone (EU-West, EU-Central).

🔐

SAML 2.0 & SCIM Provisioning

Powered by Authentik (live at authentik.eliteaiempire.com). Federate with Azure AD, Okta, Google Workspace, or any SAML IdP. Auto-provision users and groups via SCIM. No manual seat management.

📜

Cryptographic Audit Trail

F9 immutable audit log captures every push, review, merge, and admin action as a tamper-evident Redis stream. Append-only by design. SOC 2 Type I control evidence ready on demand.

🤖

AI Training Opt-Out (BYO-LLM)

Your code is never used to train AI models. Per-repo BYO-LLM keys (AES-256/Fernet, HKDF-derived) let you run AI code review against your own model endpoints — Anthropic, Groq, Azure OpenAI, or on-prem.

🔒

HIPAA BAA-Ready Infrastructure

Technical safeguards aligned to HIPAA Security Rule: encrypted at rest and in transit, access logging, minimum-necessary access controls, dedicated tenant isolation. BAA execution is a legal gate (Iskra/counsel required).

Forgejo Actions CI (Unlimited Minutes)

Self-hosted runners on EU compute. No per-minute billing. Full compatibility with GitHub Actions workflows. Bring your own runner labels for ARM, x64, GPU, or air-gapped environments.

🔍

AI Code Review Bundled

Semgrep OSS + multi-model LLM review cascade (Groq, Cerebras, Gemini, Anthropic). Inline PR comments posted by a dedicated bot user. Equivalent to CodeRabbit ($24/mo) included in every paid tier.

📊

SLA Status & Auto-Credit

99.9% uptime SLA. Public status page with real-time breach detection. Automatic SLA credits on breach — no ticket required. Uptime measured from the platform edge, not internal health checks.

Target Verticals

Built for Regulated Industries

Sovereign Git is purpose-positioned for buyers where data sovereignty, audit trails, and compliance posture are table stakes.

EU Government & Public Sector

GDPR Article 44 data transfer restrictions, NIS2 security controls, sovereign-cloud mandate. Forgejo is already backed by the Dutch government (2026).

Healthcare (HIPAA / HHS-2026)

PHI-adjacent code repositories, audit logging aligned to HIPAA Security Rule Technical Safeguards, BAA-ready infrastructure posture.

Financial Services

SOC 2 Type I control evidence, immutable commit history for regulatory examination, segregated environments for DORA compliance.

Legal & Professional Services

Client data isolation, attorney-client privilege-aware access controls, conflict-of-interest repo segregation, CCPA-aligned data handling.

Defense & Critical Infrastructure

Air-gapped runner support, on-prem LLM via BYO-LLM keys, no vendor dependency on US hyperscalers (AWS/Azure/GCP).

Pharma & Life Sciences

GxP-adjacent audit trail, validated system documentation support, 21 CFR Part 11-aligned electronic records posture.

Competitive Positioning

Why Not GitHub Enterprise or GitLab Ultimate?

Both run on US hyperscaler infrastructure by default. EU data residency is an add-on (GitLab) or unavailable at the Enterprise tier without custom contracts (GitHub). We built sovereignty-first.

Feature Sovereign Git GitHub Enterprise GitLab Ultimate
EU Data Residency (default) Yes No (US default) Add-on / custom contract
Open Source Core (Forgejo/Gitea) Yes No (proprietary) No (proprietary)
No Microsoft dependency Yes Microsoft-owned Yes
SAML 2.0 / SCIM (bundled) Yes (Authentik) Enterprise only (+$21/user) Premium+ (+$29/user)
Cryptographic Audit Trail Yes (append-only) Audit log, not cryptographic Audit log, not cryptographic
AI Code Review (bundled) Yes (no add-on) Copilot $19/user/mo add-on Duo Pro $19/user/mo add-on
BYO-LLM (no training on your code) Yes No No
HIPAA BAA-Ready Yes (infra posture) Enterprise + legal review Custom contract required
CI/CD Unlimited Minutes Yes (self-hosted runners) Billed per minute 50K min/mo then billed
Starting Price (per seat/mo) $149 $21 + $19 Copilot + $30 GHAS = $70+ $99 + $19 Duo = $118+
Compliance Posture

What Is Ready Today vs What Requires Legal Sign-Off

We are honest about the difference between "infrastructure-ready" and "audit-certified." The table below shows the current state without marketing inflation.

Framework Status What Is Ready What Requires Legal Gate
GDPR INFRA READY EU data residency architecture, no third-country transfers by default, access logging, data minimization controls, right-to-erasure tooling DPA (Data Processing Agreement) execution requires Iskra/legal; formal DPIA for high-risk processing
SOC 2 Type I SOC2-READY* F9 cryptographic audit trail (append-only Redis stream), Authentik access control, TLS everywhere, uptime monitoring, incident response runbooks Formal SOC 2 Type I audit requires a licensed CPA/auditor engagement (Iskra gate). "SOC2-ready" != "SOC2-certified."
HIPAA BAA-READY* Technical safeguards (encryption at rest/transit, access logging, minimum-necessary access), dedicated tenant isolation, audit trail, BYO-LLM no-training guarantee BAA (Business Associate Agreement) execution requires licensed legal counsel and Iskra signature. Not currently executed.
EU AI Act COMPLIANT BYO-LLM: no AI model trains on customer code. AI code review output is advisory (human-in-loop). No high-risk AI system deployment per Article 6/Annex III. If customer uses Sovereign Git to develop high-risk AI systems, customer-side conformity assessment applies.
NIS2 PARTIAL Incident detection + response runbooks, supply-chain code audit (F1 AI review), cryptographic audit trail, multi-factor authentication via Authentik Formal NIS2 Article 21 risk management documentation and registration with national authority (customer obligation).
ISO 27001 ROADMAP Access controls, audit logging, incident management posture Full ISO 27001 audit and certification requires formal audit body engagement. Not on current roadmap — available via custom enterprise contract.

Honest Disclosure: What "Ready" Means

We use "infrastructure-ready" and "BAA-ready" to mean: the technical controls are in place. This is meaningfully different from "certified" or "compliant."

View Full Compliance Docs Package
Pricing

Sovereign Tier Pricing

Per-seat monthly pricing. Annual contracts available at 15% discount. Volume pricing for large procurement (50+ seats) on request.

Standard
$149/seat/mo
For teams graduating from GitHub/GitLab wanting sovereignty without compromise.
  • Unlimited private repositories
  • EU data residency (configurable region)
  • SAML 2.0 + SCIM provisioning
  • AI code review (Semgrep + LLM)
  • BYO-LLM per-repo keys
  • F9 cryptographic audit trail
  • 99.9% SLA + auto-credit
  • SOC2-ready (infrastructure posture)
  • Forgejo Actions (unlimited CI minutes)
Request Demo
Government
$299/seat/mo
For EU public sector, defense, and critical infrastructure with air-gap or custom deployment needs.
  • Everything in Regulated
  • Air-gapped runner support (no outbound internet)
  • On-prem BYO-LLM (LLM runs inside your perimeter)
  • Custom SLA (99.95%+)
  • Named CSM + executive sponsor
  • DPA / BAA execution support (legal gate)
  • NIS2 control documentation
  • Procurement-friendly invoicing (PO, NET-30)
Contact Sales