Ariadnah
Platform
DORA Understand the responsibilities, common operating gaps, and the path from shared knowledge to evidence. AML & KYC Customer due diligence with the ownership look-through resolved as data. Risk & Control One control catalogue, read through every framework it answers to. Governance & Policies Policies drafted, mapped to requirements clause by clause, and approved in the platform.

Platform

  • Platform overview
  • AI assistant
  • Security & trust
  • Impact & access

Domains and services

  • Register of Information
  • Suppliers & Contracts
  • Asset Management
  • Risk & Control
  • AML & KYC
  • AIFMD Reporting
  • Fund Administration
  • Trust & Investor Portal
  • Governance & Policies
  • Incident Management
  • All solutions →

By sector

  • Banking
  • (Re)Insurance
  • Investment Firms
  • Investment Management
  • Payment Institutions
  • Pension Funds
  • Crypto Services
  • All sectors →
About Pricing Insights Resources Contact
Book a Discovery Call
Home About Platform Solutions Sectors Pricing Insights Resources DORA Guide NIS2 Guide Contact
Book a Discovery Call
Insights

Two rankings, one decision

Menno Schaap Cross-regulation 21 Aug 2026 4 min read

On capability alone, a US hyperscaler came first. Once we applied the rest of what our management system requires, the European provider was the better call.

01

Ariadnah Solutions, notes from the build

Ariadnah is not dora-solutions.com with a new name on the door. It is a different product, and the reason we started again has less to do with features than with dependency. The previous product sat on a supply chain we had inherited rather than chosen: packages nobody had evaluated in years, platform decisions made by whoever set them up first, data paths we could describe accurately but not really control. It worked. It also meant a fair amount of our resilience was somebody else’s to determine, and we would not have been able to answer a client asking us to prove otherwise.

This time every layer is a decision that belongs to us, from the packages we pull in to the infrastructure our clients’ data crosses and comes to rest in. That is a slower way to build and the only honest way to claim you are building for resilience. It also promotes the vendor question from procurement chore to design work. We sell software that makes financial entities map their own ICT supply chain, so running the exercise on ourselves was overdue.

We wrote the criteria down before looking at candidates: security posture and control maturity, independent audit evidence rather than assurances, operational track record, exit and portability, roadmap and support, cost.

That list has a property we did not notice until it started producing answers. Every criterion on it measures a provider. None of them measures us, our clients, or the environment the three of us operate in.

On the provider measures, US suppliers came first in several categories: object storage, managed database, identity, and observability. Not marginally, and not because we weighted things carelessly. We then applied the wider set of requirements our management system actually imposes, and the European alternative became the better organisational decision. Both of those sentences are true, and the gap between them is the part worth writing about.

We are not arguing that US software is dangerous. The CLOUD Act and the Patriot Act are real instruments with real reach, and anyone holding client data should understand what they permit. But the sentiment that has grown up around them generates more risk flags than the facts support, and the flags point in unhelpful directions. Quality has to come first, and for several of the services we need, the strongest suppliers are American-rooted. European alternatives are also better than the reflexive scepticism suggests; we found more credible ones than we expected once we actually looked.

Our own preference makes the point. We would rather have personal data held in the United States by a company with state of the art controls that are tested and audited by people paid to find fault, than sitting on a server somewhere in the EU while everyone assumes the GDPR will do its magical work. Jurisdiction is not a substitute for controls.

So why move toward European vendors at all?

Because of what our clients expect, and because we are obliged to listen. Anyone running an ISMS under ISO 27001 knows clause 4.2: identify your interested parties, understand their needs and expectations, and feed those into the system. It is one of the quieter requirements in the standard and one of the easiest to treat as paperwork. Read it seriously and it says something demanding, which is that client concern is an input to your security decisions even when you do not fully share the concern. What we hear, more often each quarter, is worry about the services they depend on being disrupted or switched off through government intervention. We still think those services are excellent. Our clients still lose sleep over them. Both things can be true, and only one of them is ours to manage.

And there is no such thing as Europe when it comes to immediate government action. It is not unimaginable that a European government, under political pressure, complies with a foreign request to hand over particular data or to close off particular access. Legal review would probably reverse such a thing in the end. That is genuinely reassuring and almost entirely useless if access has been unavailable for two years. Vindication on that timeline is not a continuity plan.

If our clients care about geopolitical risk, and they do, then our obligation is to handle their information so that it survives the scenario, not to relocate it somewhere that feels better. That means applying the same lens inside the EU that most people currently reserve for the US. In practice: the European provider is our primary environment, and our segregated restore capacity sits with a second European provider in a different jurisdiction, so that losing any single provider or any single country is an inconvenience with a runbook rather than an existential event.

Far fetched? We hope so, but that is the whole point. Resilience is not about choosing the right flag. It is about being able to keep going when the protection you assumed was there turns out not to be, and that is only possible if the decisions were yours to make in the first place. Planning for the unlikely is the job.

Continue exploring

Put this question in context.

Browse Ariadnah Insights for analysis of the shared operating work behind overlapping regulatory obligations.

Recommended next Browse all Insights →
Explore the operating approach See the supplier and contract approach
Manage Consent
We use cookies to keep this site reliable and to understand how it is used. You can accept, deny, or adjust your preferences at any time.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ariadnah

Compliance advisory & technology

Regulatory specialists and technology that help organisations simplify compliance, strengthen operational resilience, and build lasting trust.

ISO/IEC 27001 certified (DNV)

Platform

  • Platform Overview
  • DORA Guide
  • NIS2 Guide
  • Regulatory Library
  • Register of Information
  • Risk & Control
  • Governance & Policies
  • Incident Management
  • Asset Management
  • Suppliers & Contracts
  • AML & KYC
  • AIFMD Reporting
  • Fund Administration
  • Trust & Investor Portal
  • AI
  • Security

Sectors

  • Banking
  • (Re)Insurance
  • Investment Firms
  • Investment Management
  • Payment Institutions
  • Pension Funds
  • Crypto Services

Company

  • About Ariadnah
  • Pricing
  • Our Experts
  • Impact
  • FAQ
  • Insights
  • Contact

Legal

  • General Terms
  • Data & Privacy
  • Cookie Policy
  • Accessibility

© 2026 Ariadnah Solutions B.V.