A curated collection of free resources and open-source research on the topics of cybersecurity, digital compliance and sovereign technology.
SAFELY UTILISING LANGUAGE MODELS COMES WITH STRICT AUDITABLITY AND COMPLIANCE REQUIREMENTS.
Agents inherit the user's shell, tokens, and filesystem. One compromised session becomes a lateral movement ticket across repos, keys, and production paths.
Browse solutions:


















SAFELY UTILISING LANGUAGE MODELS COMES WITH STRICT AUDITABLITY AND COMPLIANCE REQUIREMENTS.
Agents inherit the user's shell, tokens, and filesystem. One compromised session becomes a lateral movement ticket across repos, keys, and production paths.
Browse solutions:
Routing, retention, and redaction follow the provider's platform defaults, not your documented policy. When those defaults change in a release, your effective controls change with them.
Browse solutions:
You cannot reconstruct why an agent chose a path after the fact. Opaque chains of tool calls hide privilege escalation, data reads, and exfiltration until the bill arrives.
Browse solutions:
API keys in your toolchain send prompts and full context straight to vendor endpoints with no redaction, no spend guardrails, and no central audit log. Teams route through different providers with no shared policy, so usage and data exposure only show up in invoices and incident reviews.
Browse solutions:
An agent with broad tool access will read secrets, write where it should not, and call outbound endpoints you never approved. Stochastic models do not fail politely; they fail at scale.
Browse solutions:
Model weights and inference often run on infrastructure outside your jurisdiction and contractual control. Data passes through subprocessors you never approved, and residency assurances are hard to verify once traffic leaves your network.
Browse solutions:
The German state of Bavaria replaced Microsoft software with open-source alternatives across public administration, part of a broader EU push for technological sovereignty and independence from US tech giants.
Resources:
Austria's Federal Ministry of Economics moved from Microsoft 365 to self-hosted Nextcloud on Austrian infrastructure. The Interoperable Europe Act mandates cross-border public-sector interoperability and reuse of open solutions.
Resources:
The Danish government is replacing Microsoft Office with LibreOffice to protect privacy and reduce dependence on US-based software. GDPR anchors data protection as a European constitutional priority.
Resources:
The International Criminal Court in The Hague is switching to the European OpenDesk suite. The Cyber Resilience Act recognises free and open-source software as critical infrastructure with a tailored compliance path.
Resources:
Schleswig-Holstein announced migration from Windows to Linux and from Microsoft Office to LibreOffice for ~30,000 employees, one of Europe's largest public-sector FOSS transitions.
Resources:
Mecklenburg-Vorpommern rolls out Nextcloud and OpenProject for 50,000+ public employees, citing digital sovereignty: "The EU runs on Microsoft. The US could turn us off inside one hour." The Data Act strengthens control over industrial and cloud data on EU terms.
Resources:
OMB Memorandum M-16-21 (2016) requires new federal custom code to be shared across agencies and published as open source where appropriate. At least 20% of new custom-developed code must be released as OSS each year, with inventories published on code.gov.
Resources:
The Source Code Harmonization And Reuse in Information Technology Act (H.R. 9566), signed in December 2024, mandates governmentwide sharing of custom-developed code. Agencies must publish metadata and make code available to other agencies to cut duplicate contracts and vendor lock-in.
Resources:
Since 2006, Massachusetts has required the OpenDocument standard across state entities, a long-standing policy ensuring public records stay accessible without dependence on a single proprietary office format.
Resources:
OMB M-16-12 directs agencies to manage commercial software licenses as a portfolio: eliminate duplication, use category-management vehicles, and prefer existing federal solutions before buying or building anew.
Resources:
The 2009 Open Government Directive required agencies to publish data and embrace transparency. The White House itself migrated to Linux servers and Drupal, an early signal that federal IT could run on open platforms, not only proprietary stacks.
Resources:
U.S. open-government policy emphasizes efficiency and innovation, not geopolitical decoupling. States jointly procure through collaboratives like the Intergovernmental Software Collaborative; Orange County, California completed an open-source migration; Oregon proposed default-to-open procurement legislation.
Resources: