European Union and EEA MSPs increasingly face buyer questions about digital sovereignty: reducing reliance on foreign-owned control planes for privileged automation, audit evidence, and operational data.
Trustholm is a European founder-led policy and evidence engine for MSP script governance-designed to run beside US RMM tools (NinjaOne, ConnectWise, N-able) rather than rip-and-replace the full stack. This resource helps procurement teams, DPOs, and MSP vCISOs evaluate residency, subprocessors, and stack architecture without marketing sovereignty slogans.
Why privileged automation is a sovereignty conversation
US hyperscaler and RMM dominance means many EU MSPs route signed PowerShell, approval workflows, and script audit through vendors subject to extraterritorial law and geopolitical supply risk. EuroStack and national Buy European procurement discussions focus on infrastructure-but application-layer governance matters when assessors ask who can see script content, audit rows, and administrator identities.
Trustholm concentrates on governed execution with exportable proof: signing policy, tenant-scoped security audit, and schema-per-tenant isolation.
We do not claim full RMM replacement, open-source product status, or automatic compliance with every EU public-sector classification. We provide evidence for your control matrix and honest gap rows.
What typically resides in tenant data plane
Per-tenant PostgreSQL schema holds:
- Agent registration and inventory metadata
- Script library content and versions
- Security audit rows (privileged actions plane)
- Monitoring configuration when module enabled
- Portal user and role records
Classification depends on what technicians put in scripts-credentials should follow secrets hygiene regardless of residency. MSPs remain controllers for many processing purposes; Trustholm typically acts as processor for operational platform data.
Production regions and EU roadmap
Trustholm production launched in Australia with documented hostnames (api-aus, portal-aus). EU data plane pilots deploy on European sovereign cloud (OVHCloud, Scaleway, Hetzner-compatible Kubernetes) with api-eu and portal-eu hostnames for enterprise and design-partner tenants.
Exact home region for your contract is confirmed during commercial onboarding with subprocessors table and architecture diagram-not inferred from hero banners.
Marketing site (www.trustholm.com) uses US-edge hosting (Vercel) for trial forms only-no tenant production data on marketing infrastructure. Separate production subprocessors from marketing subprocessors in DPIAs.
Deployment options for sovereignty buyers
| Option | Best for | Notes | |--------|----------|-------| | Shared multi-tenant SaaS (EU region) | Mid-market MSPs | Schema-per-tenant on EU-hosted Postgres | | DedicatedDatabase profile | Regulated MSPs | Separate database instance per tenant | | Self-hosted / air-gapped (Enterprise) | Public sector, strict residency | Same binaries, customer-operated infrastructure |
See /trust/downloads EU vendor pack and architecture overview for procurement packets.
US stack complement positioning
Pragmatic EU buyers often keep US RMM for patch, inventory, and monitoring while adding a governance layer for:
- Signed script enforcement before run
- Exportable security audit separate from RMM operational logs
- Agentic execution-intent gating (
POST /api/Governance/execution-intent) with attestation
Document stack roles in customer DPIAs: which vendor holds privileged automation evidence vs patch compliance.
What may leave the primary EU region
Subprocessors (email delivery, support tooling, optional analytics) may process metadata in other regions. Request the subprocessor list at /trust/subprocessors during trial. Enterprise DPAs document transfer mechanisms (SCCs, supplementary measures) where applicable.
Evaluation checklist for EU sovereignty buyers
- Request written confirmation of home region (EU vs AU) for tenant database and backups
- Map subprocessor countries and purposes; separate marketing from production
- Identify script content classification per customer rules
- Document audit export storage when copied to US GRC tools
- Pair residency with isolation architecture (schema-per-tenant) and JWT tenant binding
- Attach EU vendor pack to DPIA and ICT registers (GDPR, DORA, NIS2 as applicable)
- Run 30-minute pilot: one agent, one signed script, one audit export
Contractual beats marketing
Marketing pages orient buyers; DPA, subprocessor appendix, and hosting matrix in contract define enforceable commitments. MSPs reselling services must flow down residency accurately to end-customers.
Honest limitations
We do not claim Gaia-X certification, EU cybersecurity certification schemes, or sovereign cloud badges. WORM audit immutability and native SIEM connectors remain backlog. Open-source mandates in some public-sector tenders may require self-hosted Enterprise discussions-not SaaS-only answers.
Trust hub cross-reference
See /compliance/eu for GDPR, DORA, and NIS2 framework pages. Vendor origin and EU commercial contact appear on /trust and /trust/subprocessors. Contact security@trustholm.com for EU contracting entity details during procurement.
Appendix: evidence reproduction steps
Assign a reviewer to open trial tenant, confirm API hostname region, export audit JSON, and capture IAM screenshots with timestamps. Store in immutable GRC folder. Compare quarterly. When subprocessors or Shipped/Gap rows change, re-run within ten business days. Pair technical evidence with customer governance documents. Never substitute marketing copy for reproduced checks in front of assessors.