Skip to content

Services, Wiki-Artikel und Blog-Beiträge durchsuchen

↑↓NavigierenEnterÖffnenESCSchließen

Our sovereignty promise

We do not just recommend digital sovereignty to our clients - we live it. A large part of our systems is open source, runs on our own infrastructure and stays in Germany. This page shows what that means in practice.

Six commitments we can keep

For us, sovereignty is not a marketing term but an architectural decision we carry ourselves every day.

Data stays in Germany

Website, forms, appointment booking and web analytics run on our own infrastructure in German data centres - not in US clouds.

No US tracking

No Google Analytics, no Tag Manager. We measure cookie-free with self-hosted Matomo - visitor data never leaves our servers.

Self-operated instead of rented

The central systems of our daily work are open source and run on our own servers. We know at any time where our data is and who can access it.

No vendor lock-in

Open standards, open interfaces, exportable data - in our own stack just as in the recommendations we give our clients.

AI without data leakage

Research, knowledge work and chat run through our own applications on our own hardware. Prompts and documents stay inside our network, and every result passes through a human before it leaves the building.

Our AI tools in detail

AI transparency

Illustrations and short summaries on a7.de are partly AI-assisted and editorially reviewed before publication - editorial responsibility remains with AWARE7. What the AI Act requires for AI content and when the EU icons apply is explained on our topic page.

AI labelling under Art. 50 AI Act

The stack we operate ourselves

A selection of the open-source systems in production use at AWARE7 - self-hosted and self-administered.

Web analytics

Matomo

Cookie-free visitor statistics, self-hosted on statistik.a7.de - instead of Google Analytics.

Newsletter

listmonk

Our S7 newsletter runs on self-hosted listmonk with native double opt-in.

Appointment booking

cal.diy

Initial consultations are booked through our self-hosted cal.diy on termin.a7.de - calendar data stays with us.

File exchange

Nextcloud

Reports and project data are exchanged through our own Nextcloud instance.

Knowledge base

BookStack

Our public wiki and internal knowledge run on self-hosted BookStack.

Identity & access

Keycloak

Single sign-on for internal systems - self-hosted instead of identity-as-a-service.

Automation

n8n

Workflows and integrations are orchestrated by a self-operated n8n.

This website

Astro

a7.de is built with the open-source framework Astro - static, fast and without third-party JavaScript.

Three AI tools that never leave our servers

Artificial intelligence is where digital sovereignty breaks fastest in practice: drag a document into a chat window and it sits on someone else's servers. That is why we built our own applications that run on our hardware.

For clients this means: whatever we analyse with these tools stays inside our infrastructure.

Knowledge research

Notebook7

Our counterpart to NotebookLM

Collect sources on a topic, query the material and receive answers with citations. The collection sits on our server, and the models answering on top of it run on our hardware as well.

AI research

Search7

Our counterpart to Perplexity

Ask research questions in plain language and get answers with source references. Search and analysis run entirely on our own infrastructure.

Chatbot

AWARE7GPT

Our counterpart to ChatGPT

The chatbot for everyday work, connected to our own knowledge: it answers from our wiki and internal repositories instead of the memory of a foreign model. No prompt ever leaves our network.

This is no side project: a dedicated AI team maintains and modernises the applications, which run on our own hardware worth around 50,000 euros. We decide ourselves which models run on it and swap them as soon as a better one becomes available - nothing changes for the people using them. Further applications are added continuously.

Why open source is a security gain

Auditability

Open source code can be audited independently - by us, by the community and by you. Together with a software bill of materials (SBOM), the supply chain becomes transparent.

More on SBOM

Independence

Whoever can operate their own systems does not negotiate from a position of dependence. Licence models, price increases or product discontinuations lose their sting.

Responsiveness

Security vulnerabilities in self-operated open-source software can be patched immediately - without waiting for a vendor maintenance cycle.

Tailwind for public authorities: open source may be required

For a long time, German administrations assumed that tenders were not allowed to demand open source specifically. A legal opinion by the Research Services of the German Bundestag (WD 7-010/26) clarifies: restricting a tender to open-source software is permissible where an objective, contract-related reason exists. IT security, interoperability and the goal of developing software independently are named explicitly.

Relevant for practice: as a rule the phrase "or equivalent" belongs in the specification, and the burden of reasoning and documentation lies with the contracting authority. In early 2025 the European Court of Justice also clarified that self-inflicted vendor lock-in does not justify later direct awards without competition.

For public authorities this means: digital sovereignty can be demanded in procurement on solid legal ground - and implemented with a partner who knows open-source operations from daily practice.

Three attestations backing the promise

Seal: IT Security made in Germany

IT Security made in Germany

TeleTrusT seal: IT security services from Germany, without hidden backdoors, GDPR-compliant.

Seal: IT Security made in Europe

IT Security made in Europe

The European counterpart: service delivery, data protection and support entirely within Europe.

Seal: AWARE7 GmbH committed to the Trusted Data Processor code of conduct

Trusted Data Processor

Where we process personal data on behalf of clients, we are committed to the officially approved Trusted Data Processor code of conduct (Art. 40 GDPR, approved by the data protection authority of Baden-Württemberg). Compliance is monitored by DSZ Datenschutz Zertifizierungsgesellschaft mbH as the accredited body under Art. 41 GDPR - our sovereignty does not stop at infrastructure but includes data processing itself.

Sovereignty can be planned

Public authority or private company: we show you what a sovereign, secure stack looks like for your organisation - based on our own operational experience.

Free · 30 minutes · No obligation

Rufen Sie uns an

Mo-Fr, 8:00-17:00 Uhr - persönlich und unverbindlich.

0209 8830 6764
Jetzt anrufen