Skip to the contact form
Public sector

Linux support, migrations and sovereign infrastructure for public bodies

Municipalities, ministries, public agencies, hospitals and universities across Europe. A ticket that has stalled, a desktop migration, or the compute and storage in your own data centre, handed over so your own team can run it.

Madrid · Barcelona · Paris · Bruxelles. English, español, français. No account managers in between: whoever answers the email is the person who will be on your servers, and the tender documents do not have to be written yet.

Partners IBM Business Partner·Canonical·Red Hat·SUSE We also work with Rocky Linux, AlmaLinux, Debian, Proxmox and Ceph.

Come in through your problem, not our catalogue

Pick the one that looks like yours.

01 · KEEP IT RUNNING

Still working tomorrow

Specialist support, health reviews, change planning and diagnosis of the things a runbook does not cover.

First we scope the estate, its risks and who answers for what. The support agreement comes after that. Let us look at your estate
02 · MODERNISE

Change without a leap of faith

Linux migrations, leaving VMware, sovereign cloud, private AI or a compute refresh. Feasibility and full cost before anything moves.

An options appraisal and a pilot with written acceptance criteria, with coexistence and rollback planned in. Weigh up the options
03 · SCOPE IT

A decision you can defend

A view on scope, risk, cost, operations and deliverables, without turning an open requirement into a purchase decided in advance.

Twelve questions to pin down the need and compare bids. Without leaving us your details. See the questions
Local and regional governmentMunicipal IT, provinces and shared service organisations. Phased refreshes, at a pace the team that has to run them can absorb.
Ministries and agenciesCentral government, regional administrations and public agencies. Mixed estates, automation, interoperability.
Health, research and universitiesHospitals, research groups and higher education. Private cloud, distributed storage, HPC and inference under the institution's own control.

Projects rarely fail on the technology. They fail on what nobody costed before signing.

​

The third-year cost. The service that only works in one browser. The compliance tier that doubles the timeline. The node that was needed and was not in the budget.

Whatever eats the budget is usually already there before the project starts.

Five situations we keep running into

​

Ubuntu and Rocky, the desktop estate, electronic identity and where the data sits. For each one, the point where it stops being worth it.

Ubuntu and Ubuntu Pro

CANONICAL · LTS · ESM

Ubuntu Pro is a Canonical subscription: it takes security maintenance on an LTS from five years to ten and covers the universe packages. What we do is different — we administer the estate, diagnose and answer when something breaks.

Up to five machines Ubuntu Pro is free. If that is your size, we will say so and bill you only for the support. Canonical and Ubuntu support

Rocky Linux and AlmaLinux

RHEL COMPATIBLE

For estates that left CentOS and need RHEL compatibility without the subscription. Updates, lifecycle, hardening and high availability.

Since RHEL 9 they are not interchangeable: AlmaLinux dropped one-to-one binary compatibility in favour of ABI compatibility, Rocky keeps it tighter. Which one suits you depends on your applications. Ask us about your case

Windows 10 with no patches

DESKTOP ESTATE · BY USER PROFILE

Mainstream support ended on 14 October 2025. There are four routes and none of them is free: move to Windows 11 where the hardware allows it, pay for ESU — billed per device per year, and dearer at every renewal — replace machines, or migrate to Linux profile by profile.

For a standard administrative profile, migrating usually adds up. For anyone tied to old desktop applications, almost never. The decision is taken profile by profile. Linux migrations

Electronic signature and eID

eIDAS · EUDI WALLET · SMART CARD

It is the first thing we get asked, and the failure points are almost always the same: the smart card middleware and its reader, the certificate store each browser actually uses, and the trust chain behind your qualified certificates. Every country runs its own eID under eIDAS, and the European Digital Identity Wallet arrives on top of all of them — one more reason to know today which of your services depend on something installed on the desktop.

We test against your real transactions, one by one, before anybody is moved. If a service does not work, that profile does not migrate: it stays, and we isolate it. How we verify it

Where the data actually sits

NIS2 · SECNUMCLOUD · BSI C5 · ENS

The schemes differ and they are not equivalent: SecNumCloud in France and BSI C5 in Germany set criteria for cloud providers, while ENS in Spain certifies an organisation's own systems. NIS2 sits above them, but it does not reach everybody — it covers essential and important entities by sector and size, and each member state decided for itself how far down the local level it goes. Worth settling before anyone quotes you for a compliance project.

We certify nothing and qualify nothing: that has to be independent of whoever did the work. Ours is the layer underneath — hardening, segmentation, asset inventory, logging, and backups with a restore that was actually rehearsed — with the evidence written up. Ask us about your case

The AI can be yours, and so can the decisions

An assistant over your own documents needs GPUs in your data centre or an external provider, and what that means for the records is different in each case. It is what sets the budget, so it gets decided at the start.

None of that shows up in a demo. It shows up with the first real user.

Authoriseddocuments SOURCES Case files andregulations INDEXING Chunking andtraceabilityEMBEDDINGS:IN OR OUT,DECIDED HERE CONTROL Permissionsby role Evaluationagainst knownanswers MODEL In your DCor at a third party HUMAN Reviewed beforeacting The answerwith its source

The model that produces the embeddings need not be the one that answers: you can index in-house and query outside, or the other way round. What you cannot do is leave it undecided, because if the indexing model is external your documents leave the organisation before anyone asks a single question.

  1. SourcesAuthorised documents, case files and regulations.
  2. IndexingChunking and traceability. This is where you decide where the embedding model runs.
  3. ControlPer-role permissions and evaluation against known answers.
  4. ModelIn your data centre or at a third party.
  5. HumanReviewed before anyone acts.
  6. OutputThe answer, with its source.

Every phase ends in something you can hand an auditor

LISTEN

Before proposing anything

The estate, the constraints, who operates what, and what cannot be stopped.

Inventory, risks and sizing.
PROVE

A small pilot

With acceptance criteria written and agreed before it starts.

The pilot report, with the options compared.
DEPLOY

In phases

Each phase coexists with what was there and has its own rollback, rehearsed in test before production is touched.

A deployment plan, and how each phase reverses.
HAND OVER

While the project runs

Your team runs the critical tasks in front of us before we close.

The operations documentation. The training is already done.

Twelve questions before you sign for open infrastructure

The same twelve we use to put a bid together.

  1. Which version is in production, and until what date does it get security patches?
  2. If something breaks on a Sunday, who answers, within how long, and what happens if that is missed?
  3. If the supplier vanished tomorrow, what would it take to keep operating?
  4. Are the vendor subscription and the supplier service on separate invoices?
  5. What compliance tier applies to this system, and who signs off conformity?
  6. What happens to the smart card, its reader, and the services that only work in one browser?
  7. What does year three cost, counting licences, hardware and people?
  8. Is there a rollback? Rehearsed, or on paper?
  9. What knowledge stays with our team, and how do we verify that?
  10. If it includes Ceph, Kubernetes or OpenStack: how many nodes and how many people to run it?
  11. If it includes AI: where is the data processed, on whose hardware, and who reviews the output?
  12. Of all the above, what can we verify before signing?

How it is contracted: a block of hours, a monthly retainer, or a fixed-scope project with acceptance criteria. You can start with the smallest and widen it once the scope is clear.

Sovereignty also means being able to replace your supplier. Us included.

We measure total cost and the life left in what you already have before proposing anything. Sometimes keeping it wins; when replacing wins, we say which risk justifies it. We document what we deploy whether or not anyone asks, and the training happens during the project, with your people running the tasks in front of us.

IBM Business Partner·Canonical·Red Hat·SUSE

Madrid · Barcelona · Paris · Bruxelles. English, español, français. No account managers in between: whoever answers the email is the person who will be on your systems.

What you ask us

Can you advise us before a tender?

We can, without writing your specification and without asking for any advantage in return. What we bring is a view on scope, verifiable requirements and acceptance criteria, so that afterwards you can compare bids against each other. The twelve questions above come out of that.

What if we already have an incumbent or an in-house team?

We usually cover what gets escalated when the procedure does not resolve it, or support one specific migration while day-to-day work stays where it is. What each side carries is written down before we start.

Does this lock us in to SIXE?

Open source on its own locks nobody in; what locks you in is nobody else knowing how the thing was built. That is why we document what we deploy and train your team during the project. If you change supplier tomorrow, the infrastructure and the documentation stay with you.

Do you certify NIS2 compliance?

No, and nobody doing the implementation should. NIS2 is transposed differently in each member state, and the assessment has to be independent of whoever did the work. National sovereignty schemes — SecNumCloud in France, BSI C5 in Germany, ENS in Spain — qualify hosting providers rather than integrators. Our part is the technical work that goes in front of the assessor, with the evidence already written up.

Can public bodies actually migrate from Windows to Linux?

It depends on the line-of-business applications, the electronic signature stack and the peripherals. The operating system is almost never the deciding factor. That is why it is done by user profile and tested first with a small group against their real transactions; all at once and across the whole organisation, it almost never works.

Is open source always cheaper?

It removes the licence cost, which on a large estate is substantial, and adds the cost of running it and training people. The sums work or they do not on the full third year, never on the first. Anyone who promises you a saving percentage before looking at your inventory is making it up.

Do you offer 24/7 support?

For an outage there is emergency systems support, at a published rate and with no prior contract. If what you need is continuous cover, that is a retainer, with hours and response times agreed in writing.

Tell us about your estate

The kind of organisation, what you have deployed and what worries you is enough. We reply within one working day with an approximate scope and a way to contract it.

Please do not include third-party personal data or classified information in a first message.