Skip to content
Stribog

§02/Readiness

Sovereignty Readiness Assessment

Ten questions across the five pillars of engineering sovereignty. Scored instantly in your browser — nothing is sent anywhere — with a per-pillar profile and a clear read on where to focus next.

§01/Sovereignty as a discipline

You cannot improve what you refuse to measure.

Sovereignty is not a posture or a slogan. It is a set of engineering disciplines, each answering a concrete failure mode. This assessment turns those disciplines into ten plain questions and a profile you can act on.

Sovereignty (do you own the perimeter), open source as method (could you fork and self-support your core platform), audit-grade rigor (can you prove every control on demand), optionality (do you have tested exit ramps from each vendor), and the long game (are decisions documented for the team that inherits them). Each is a practice with a measurable failure mode — not an aspiration.

A low score in any single pillar is not a verdict; it is a specific, fixable exposure. The value of the assessment is precisely in finding which one to address first, before a vendor change or an audit finds it for you.

The score is only as good as your candour — which is exactly why it runs privately, on your machine, with nothing transmitted. There is no email gate and no result we are nudging you toward. Answer honestly and the weakest pillar will tell you where the next quarter of work belongs.

§A/Self-assessment

0 / 10 answered
Question 1

01Critical workloads run on infrastructure you fully control — owned hardware, colocation, or a sovereign cloud — not a single hyperscaler.

Question 2

02You hold the encryption keys and root of trust for your data, independent of any provider.

Question 3

03Your core platform runs on open-source components you could fork and self-support if a vendor changed its terms.

Question 4

04You avoid proprietary managed services whose data or formats you cannot cleanly export.

Question 5

05You can produce, on demand, evidence that every production control — policy, access, change — is actually enforced.

Question 6

06Your security and compliance posture is continuously verified, not assessed point-in-time.

Question 7

07For each major vendor, you have a documented, tested exit path.

Question 8

08You could move your primary workloads off your current provider within a planned quarter, without a rewrite.

Question 9

09Architecture decisions are documented with rationale a team a decade from now could audit.

Question 10

10You are not accumulating undocumented platform debt that only one person understands.

Scored in your browser · nothing is sent

§03/How scoring works

Transparent scoring, no hidden weighting.

There is nothing proprietary in the maths — it is deliberately legible so you can trust the result.

01

Two questions per pillar, scored 0/1/2

Each of the five pillars has two statements. You answer No (0), Partially (1), or Yes (2), for a maximum of 4 per pillar and 20 overall. No pillar is weighted above another.

02

Bands: Exposed / Developing / Resilient

0–8 is Exposed, 9–14 Developing, 15–20 Resilient. The band is a quick read; the per-pillar bars are where the actionable signal lives.

03

Weakest pillar drives the recommendation

The lowest-scoring pillar (or pillars, on a tie) is surfaced with a concrete next step — typically the relevant capability: cloud repatriation for ownership and optionality gaps, KSPM for audit gaps, open source and engagement for the rest.

04

Scored locally, stored nowhere

All scoring happens in JavaScript in your browser. Nothing is transmitted, logged, or persisted. Resetting or closing the tab erases it completely.

§06/FAQ

Questions, answered plainly.

The questions we hear most from CTOs, engineering directors, and founders considering a sovereignty engagement.

What is an engineering sovereignty assessment?

It is a structured self-evaluation of how much control you hold over your own infrastructure — across ownership of the perimeter, use of open source you could fork, audit-grade evidence of your controls, tested exit paths from each vendor, and decisions documented for the long game. It surfaces where a single vendor or undocumented dependency has quietly become a strategic risk.

Is my data from the assessment stored or sent anywhere?

No. The assessment runs entirely in your browser. Answers are scored locally in JavaScript and nothing is transmitted to a server, logged, or saved. Closing the tab discards everything — which is, fittingly, the sovereign default.

What do the five pillars measure?

Sovereignty (do you own the perimeter), open source as method (could you fork and self-support your core platform), audit-grade rigor (can you prove every control on demand), optionality (do you have tested exit ramps from each vendor), and the long game (are decisions documented for a team a decade out). A low score in any one pillar is a specific, fixable exposure rather than a vague worry.

What happens after I get my score?

You get a per-pillar profile and a recommendation pointing at the weakest areas — typically a link to the relevant capability, such as cloud repatriation for ownership and optionality gaps, or Kubernetes security posture management for audit gaps. There is no email gate and no obligation; the natural next step, if useful, is an executive briefing.

Executive Briefing

Thirty minutes to clarify your infrastructure risk

Walk us through your vendor footprint and regulatory constraints. We will tell you honestly where sovereignty creates leverage — and where it does not. No pitch deck. No obligation.