Sovereign stack. Deliberate defaults.
Every element of our default meets three criteria: production-tested under load, GDPR-ready at scale, no US hyperscaler lock-in. Here is the rationale — not the marketing diagram.
Default-Stack
Zehn Layer, eine Entscheidung pro Layer.
Default-Wahl plus Begründung. Wir weichen ab, wenn der Kunde gute Gründe nennt — nie aus Faulheit.
Frontend
Next.js (App Router) + React + TypeScript
Market standard, excellent DX, SSR/ISR for SEO
Backend
NestJS or Spring Boot
Spring Boot 6 years in production (Panasonic) — proven in Mittelstand and enterprise. NestJS for TypeScript-driven platforms.
Database
PostgreSQL via Supabase EU / managed Postgres
GDPR-compliant in EU region
CMS / Headless
Strapi
Self-hosted, EU, no US lock-in
Payments
Stripe
Market standard, EU datacenter enabled
Auth / IAM
Zitadel (self-hosted, EU)
GDPR-sovereign, alternative to Auth0/Clerk
Hosting
IONOS k3s Berlin + Traefik
Sovereign, EU datacenter, fully managed by Paeth
AI Layer
Azure OpenAI EU + Mistral, n8n orchestration
EU region, DPA available
Observability
OpenTelemetry, Grafana, Sentry EU
No US-vendor obligation
CI/CD
GitHub Actions
Standard, optional self-hosted GitLab for Mittelstand
Häufige Frage
Why not Vercel/Supabase US/OpenAI direct?
Because a GDPR incident in production is more expensive than 4 weeks of engineering for a sovereign default. We pick US tools only where it is the customer's deliberate decision — never out of laziness.
Entscheidungs-Matrix
Decision matrix.
Per layer a rating of realistic options. Scale 1 (weak) to 5 (strong).
Frontend
| Option | GDPR | DACH talent | Lock-in | Server-Comp. |
|---|---|---|---|---|
| Next.js | 4 | 5 | 4 | 5 |
| Remix | 4 | 3 | 4 | 4 |
| Astro | 4 | 3 | 5 | 3 |
| SvelteKit | 4 | 2 | 5 | 4 |
Backend
| Option | GDPR | DACH talent | Lock-in | Maturity |
|---|---|---|---|---|
| NestJS | 5 | 4 | 5 | 5 |
| Spring Boot | 5 | 5 | 5 | 5 |
| Express | 5 | 4 | 5 | 4 |
| FastAPI | 5 | 3 | 5 | 4 |
Hosting
| Option | GDPR | Latency EU | Lock-in | Cost |
|---|---|---|---|---|
| IONOS k3s | 5 | 5 | 5 | 5 |
| Vercel | 2 | 4 | 1 | 2 |
| AWS Frankfurt | 3 | 5 | 2 | 3 |
| Hetzner | 5 | 5 | 4 | 5 |
Auth / IAM
| Option | GDPR | Self-host | Standards | Cost |
|---|---|---|---|---|
| Zitadel | 5 | 5 | 5 | 5 |
| Auth0 | 2 | 1 | 5 | 2 |
| Clerk | 2 | 1 | 4 | 3 |
| Keycloak | 5 | 5 | 5 | 4 |
AI layer
| Option | GDPR | Maturity | Model variety | Cost |
|---|---|---|---|---|
| Azure OpenAI EU | 5 | 5 | 4 | 3 |
| OpenAI direct | 2 | 5 | 3 | 4 |
| Mistral EU | 5 | 4 | 3 | 4 |
| Anthropic | 3 | 5 | 3 | 3 |
Pragmatik
When we deviate from the default.
Customer already has AWS-certified compliance audits and migration is not economical. We build on AWS Frankfurt with documented data processing.
Latency requirement demands edge hosting (e.g. global end customers). Cloudflare Workers or Fastly Compute, with GDPR review per endpoint.
Customer has a Java team and engineering lead, NestJS adds no value. Spring Boot remains default.
Mittelstand with GitLab investment and internally maintained runners. GitLab self-hosted instead of GitHub Actions.
Mobile-first product with React Native team investment. We recommend staying native (no NestJS-frontend hack).
Migrationspfad
Stack migration from legacy.
For DACH Mittelstand with legacy stacks (PHP/WordPress, .NET monoliths, Django legacy). Three-phase model, no big bang.
- 1
Phase 1: Strangler pattern
Parallel Next.js pages alongside legacy. Customer routing via reverse proxy. No data migration. 4 to 8 weeks.
- 2
Phase 2: Data migration
PostgreSQL as a bridge between legacy and new. Gradual takeover of data models. Synchronization layer with audit. 8 to 16 weeks.
- 3
Phase 3: Legacy shutdown
Final endpoints migrated, legacy server decommissioned, read-only archive for compliance. 4 weeks.
Versions-Politik
Stack updates and versioning policy.
Stack-Sparring
Bewusste Defaults statt Marketing-Diagramm.
30 Minuten Erstgespräch — wir hören Ihren Stack, fragen scharf, sagen ehrlich, wo Risiken sind.