ES Technical meeting
Menu
Why Opendome

A data infrastructure for AI, built in Europe.

True sovereignty, atomic security and compliance by design — built on open standards, without relying on US hyperscalers.


A Europe-first solution

European data deserves European infrastructure.

US solutions were designed under a different legal and regulatory framework. Opendome was built from day one to meet the requirements of the European regulatory framework — without retrofitting.

The data belongs to the customer. Always.

Any architecture where data resides outside the customer's infrastructure creates a dependency that someone will eventually monetize. Since 2018, the CLOUD Act has also required US providers to hand data over to US authorities, wherever it is stored.

Opendome is deployed in the customer's cloud. The data never leaves its jurisdiction.

Security must be atomic or it is not security.

A permission model that cannot answer the question "can this identity see this specific field, for this task, on this entity?" is not enough for regulated enterprise environments. The Opendome Cell Model was designed to answer exactly that question — not as configuration, but as an infrastructure guarantee.

Regulatory compliance is not added. It is designed in.

GDPR, DORA and the EU AI Act have specific technical requirements — data residency, access traceability and human oversight. In Opendome, those requirements are addressed at the infrastructure layer, not the configuration layer.

Open source: verifiable assurance.

When code is auditable, claims about security and sovereignty can be verified. Any customer, auditor or regulator can inspect how Opendome works. That transparency is the only honest way to build trust in critical infrastructure.

Why now

Business demands AI. Regulators demand guarantees.

The pressure to deploy AI is leading many organizations to buy partial solutions from each vendor. The result is a fragmented architecture. AI needs a single access system: centralized, consistent and secure.

Build the data and security layer now. Deploy AI much faster.

95% of generative AI pilots fail to deliver measurable impact. According to MIT, the cause is not the models: it is data integration (State of AI in Business, 2025).

For twenty years, data was designed for people or purpose-built systems, always with predefined context. AI does not have that: it reasons across multiple systems, different naming conventions and implicit relationships. Without a centralized semantic foundation, it infers, interprets and gets things wrong.

Hyperscalers know what is coming. And they are already responding.

Salesforce, SAP, Oracle, Microsoft and other US hyperscalers are launching headless versions of their platforms. The reason is clear: AI does not consume per-user licenses. Their traditional revenue model is at risk — and their response is predictable. If they used to charge you for access to their interface, they will now charge you for access to your own data via API. With no added value. Your data, in their infrastructure, becomes their business.

Architecture

Built on the industry's open standards .

No proprietary technology. No closed formats. Every component was chosen because it is best in class, auditable and creates no dependency.

Storage in an open format

Data is stored in an open format compatible with any query engine and analytics tool. No proprietary formats, no dependency on any vendor to read your own information — now or ten years from now.

Modeling and semantic layer

A transformation and modeling layer that turns raw data into knowledge: deduplicated identities, corpora anchored to their metadata and a semantic graph that connects them. AI does not work on tables: it works on entities with relationships, context and meaning defined explicitly and auditably.

Atomic security and observability — developed by Opendome

The security and observability layer that makes the Cell Model possible. Every access is recorded with its full context in an immutable, append-only log. If an identity attempts to operate outside its scope, the system blocks it in real time. This is not monitoring — it is an infrastructure guarantee.

See the complete flow, step by step →
Regulatory compliance

The European regulatory framework is demanding. We designed Opendome to comply with it without exceptions.

This is not a checklist. It is a technical description of how each regulatory requirement is addressed in the product architecture.

GDPR — General Data Protection Regulation

What it requires

Data residency in the correct jurisdiction, access minimization, purpose limitation and the ability to demonstrate that personal data is processed in accordance with regulations.

How Opendome addresses it

Data resides in the customer's infrastructure — never in ours. The Cell Model ensures that each identity accesses only the data strictly necessary for its purpose. Access minimization is not a policy — it is a property of the system.

DORA — Digital Operational Resilience Act

What it requires

Complete traceability of access to critical systems, third-party technology provider risk management and the ability to demonstrate operational resilience to an auditor.

How Opendome addresses it

The observability layer automatically generates the record DORA requires: which identity accessed which data, for what purpose, at what time, and whether it attempted to operate outside its scope. That record is immutable and auditable.

EU AI Act

What it requires

AI systems that operate on sensitive data in financial environments are classified as high-risk. It requires human oversight, decision traceability and validation before production deployment.

How Opendome addresses it

The test environment allows AI to be validated against real data before it reaches production. Once deployed, the Cell Model and observability ensure that it operates within the defined boundaries at all times.

ISO 27001

What it requires

A documented information security management system, with auditable controls over access, traceability and risk management.

How Opendome addresses it

Opendome's architecture is compatible with the security controls defined in ISO 27001. Formal certification is on the roadmap for 2026.

ENS — Esquema Nacional de Seguridad

What it requires

The reference standard for Spain's public sector and for companies working with public authorities. It requires access controls, traceability and incident management.

How Opendome addresses it

The same mechanisms that address GDPR and DORA — the Cell Model, atomic observability and data residency — apply directly to ENS requirements.

What sets us apart

Two commitments that define how we work.

These are not marketing promises. They are architecture and business decisions we made before writing the first line of code.

Commitment 1

We deliver complete solutions. We do not delegate to partners.

Hyperscalers delegate services to partners: their business grows through licenses, not outcomes. We do the opposite. We take part in implementation, adapt the solution to each customer and take responsibility for the outcome. Services are not a necessary evil: they are the most honest way to learn and create real value.

Commitment 2

Open standards, EU-first, end to end.

We are EU-first in security and regulation. That is why we build on open-source technologies already running in the world's largest companies. Open source is not just a technical decision: it means transparency, auditability and the assurance that your data is never trapped in a proprietary format.

Let's talk

A technical team specializing in data, security and AI. When you call us, you speak with engineers.

Organizations that contact us are looking for a technical conversation about preparing their data infrastructure before deploying AI. If that is where you are, let's talk.

Request a technical meeting