01
Ariadnah Solutions, notes from the build
Ariadnah is not dora-solutions.com with a new name on the door. It is a different product, and the reason we started again has less to do with features than with dependency. The previous product sat on a supply chain we had inherited rather than chosen: packages nobody had evaluated in years, platform decisions made by whoever set them up first, data paths we could describe accurately but not really control. It worked. It also meant a fair amount of our resilience was somebody else’s to determine, and we would not have been able to answer a client asking us to prove otherwise.
This time every layer is a decision that belongs to us, from the packages we pull in to the infrastructure our clients’ data crosses and comes to rest in. That is a slower way to build and the only honest way to claim you are building for resilience. It also promotes the vendor question from procurement chore to design work. We sell software that makes financial entities map their own ICT supply chain, so running the exercise on ourselves was overdue.
We wrote the criteria down before looking at candidates: security posture and control maturity, independent audit evidence rather than assurances, operational track record, exit and portability, roadmap and support, cost.
That list has a property we did not notice until it started producing answers. Every criterion on it measures a provider. None of them measures us, our clients, or the environment the three of us operate in.
On the provider measures, US suppliers came first in several categories: object storage, managed database, identity, and observability. Not marginally, and not because we weighted things carelessly. We then applied the wider set of requirements our management system actually imposes, and the European alternative became the better organisational decision. Both of those sentences are true, and the gap between them is the part worth writing about.
We are not arguing that US software is dangerous. The CLOUD Act and the Patriot Act are real instruments with real reach, and anyone holding client data should understand what they permit. But the sentiment that has grown up around them generates more risk flags than the facts support, and the flags point in unhelpful directions. Quality has to come first, and for several of the services we need, the strongest suppliers are American-rooted. European alternatives are also better than the reflexive scepticism suggests; we found more credible ones than we expected once we actually looked.
Our own preference makes the point. We would rather have personal data held in the United States by a company with state of the art controls that are tested and audited by people paid to find fault, than sitting on a server somewhere in the EU while everyone assumes the GDPR will do its magical work. Jurisdiction is not a substitute for controls.
So why move toward European vendors at all?
Because of what our clients expect, and because we are obliged to listen. Anyone running an ISMS under ISO 27001 knows clause 4.2: identify your interested parties, understand their needs and expectations, and feed those into the system. It is one of the quieter requirements in the standard and one of the easiest to treat as paperwork. Read it seriously and it says something demanding, which is that client concern is an input to your security decisions even when you do not fully share the concern. What we hear, more often each quarter, is worry about the services they depend on being disrupted or switched off through government intervention. We still think those services are excellent. Our clients still lose sleep over them. Both things can be true, and only one of them is ours to manage.
And there is no such thing as Europe when it comes to immediate government action. It is not unimaginable that a European government, under political pressure, complies with a foreign request to hand over particular data or to close off particular access. Legal review would probably reverse such a thing in the end. That is genuinely reassuring and almost entirely useless if access has been unavailable for two years. Vindication on that timeline is not a continuity plan.
If our clients care about geopolitical risk, and they do, then our obligation is to handle their information so that it survives the scenario, not to relocate it somewhere that feels better. That means applying the same lens inside the EU that most people currently reserve for the US. In practice: the European provider is our primary environment, and our segregated restore capacity sits with a second European provider in a different jurisdiction, so that losing any single provider or any single country is an inconvenience with a runbook rather than an existential event.
Far fetched? We hope so, but that is the whole point. Resilience is not about choosing the right flag. It is about being able to keep going when the protection you assumed was there turns out not to be, and that is only possible if the decisions were yours to make in the first place. Planning for the unlikely is the job.