The US CLOUD Act Fallacy:
Many medium-sized industrial and service companies are lulled into a false sense of security: …

Cloud infrastructure is constantly evolving. That’s why we want to provide a monthly overview of what’s happening at ayedo—technically, entrepreneurially, and with a focus on digital sovereignty.
In this first edition, we discuss our new Edge Cloud, the renewed certification according to ISO 27001 and ISO 9001 , and why we’re still quite alone on a European social media platform.
In short: three topics worth reading about.
Enjoy the first edition! Your ayedo Team

Recently, ayedo joined wedium—a European social media platform aiming to be an alternative to Instagram, TikTok, and others.
Developed in Europe, hosted in Europe, and backed by European service providers. It fits us well. After all, at ayedo, we talk a lot about digital sovereignty, European infrastructure, and how we can reduce our dependency on major US tech companies.
So we should also be active where new European alternatives are emerging.
We’ve created a profile, published initial content, and had a look around.
Our current conclusion:
We still feel a bit alone. 👀
That’s why we want to know:
Who from our network is already on wedium?
Which companies, speakers, and content creators should we definitely get to know there?
And if you already have an account: Why aren’t you following us yet?
Of course, a new platform won’t become as big as LinkedIn, Instagram, or TikTok overnight. But a vibrant community doesn’t form by everyone waiting until enough others are already there.
Someone has to start.
That’s why we’d be delighted if more companies, social media managers, speakers, and creators try out wedium, bring their own content, and tell others about the platform.
We don’t have to shut down all existing channels immediately. But we can start building our reach not solely on platforms of American tech giants.
So: Check it out, follow us, and feel free to send us your profiles and recommendations.
Let’s work together to ensure that a strong European community also emerges on a European social media platform.
https://api.wedium.social/s/foVUndrt_9I2

Modern applications don’t begin in the Kubernetes cluster. From the user’s perspective, they begin where the first request hits the public infrastructure.
This entry layer is often underestimated in architectural decisions. DNS, BGP routing, TLS termination, DDoS protection, Web Application Firewalls, health checks, and Layer-4 and Layer-7 load balancing are often seen as independent services. In reality, they form a critical platform layer: It determines whether, where, and under what conditions an application is accessible.
With the ayedo Edge Cloud, we are transforming this layer into a unified operational and responsibility model.
In recent years, we’ve built the ayedo Compute Cloud as a platform for the productive operation of cloud-native applications. Managed Kubernetes, GitOps, observability, object storage, registry, identity, and backups follow a common architectural and operational model.
Before the Compute platform, responsibility remained fragmented.
A DNS provider doesn’t know the state of a backend. A classic load balancer has no influence on global routing paths. A Web Application Firewall doesn’t understand deployment states within a Kubernetes cluster. Each component fulfills a clearly defined task without necessarily mapping the complete path of a request.
This is technically manageable but creates additional interfaces, dependencies, and fault domains. At the same time, it becomes more challenging to consistently design availability, security, and data paths across the entire architecture.
The ayedo Edge Cloud is therefore not designed as an additional load balancer. It forms an independent platform layer between the public internet and the applications on the Compute Cloud.
The architecture doesn’t start with a reverse proxy but with its own Autonomous System.
Currently, we operate Points of Presence in Hamburg, Alsbach, and Frankfurt. These locations announce the same IP prefixes via BGP and work in productive active-active operation. Incoming connections thus reach the preferred available location from the internet’s perspective via Anycast.
The choice of entry point is not made by DNS-based redirection nor by a central geo-database. It results from the routing decisions of the participating autonomous systems.
This model also changes how failures are handled.
If a Point of Presence is no longer available, the corresponding route is withdrawn. The public IP address of the application remains unchanged. New connections reach one of the remaining locations after BGP convergence. There is no classic failover where a passive system first has to take on a new role. The remaining Points of Presence continue their already running productive operation; only the distribution of traffic changes.
Availability is thus not established by standby capacity but by an architecture where all locations continuously operate productively.
At each Point of Presence, the Edge Cloud terminates incoming connections and processes them depending on the protocol on Layer 4 or Layer 7.
This includes in particular:
The Edge thus decides before reaching the Compute platform whether a connection is accepted, which location processes it, and to which reachable backend it can be forwarded.
Kubernetes remains responsible for orchestrating the workloads. The Edge, on the other hand, takes responsibility for their public accessibility. This separation is deliberately chosen: Both layers receive clearly defined responsibilities and can evolve independently of each other.
For decision-makers, the number of technical functions is less decisive than how responsibility is distributed.
Those who operate applications productively need not only compute resources. They need a reliable architecture for the entire data path—from public routing to workload. Fragmented responsibilities complicate root cause analysis, increase integration effort, and create dependencies that often only become visible during disruptions.
With the Edge Cloud, we extend the responsibility of the ayedo platform to the public entry point of an application. Compute and Edge remain architecturally separate layers but are operated, monitored, and developed together.
The ayedo Edge Cloud is now available.
In upcoming posts, we will provide more detailed insights into the underlying decisions: operating our own Autonomous System, the properties of Anycast, the differences between Layer-4 and Layer-7 load balancing, and the interplay of BGP, health checks, and Kubernetes.
Because the availability of an application is not decided in the cluster.
It is decided along the entire path to it.

The management systems of Ayedo Cloud Solutions GmbH have been re-evaluated by the independent certification body GUTcert.
The result: Our certifications according to DIN EN ISO/IEC 27001 :2024 and ISO 9001 :2015 have been confirmed.
The certified scope includes the development, operation, and hosting of Container and software solutions, as well as the operation of IT infrastructures. Thus, the certificates directly relate to the services we provide for our customers in productive operation.
ISO 27001 defines requirements for an information security management system, or ISMS.
The focus is not on individual security products or isolated technical measures. Instead, it assesses whether information security is anchored as a systematic and ongoing process within the company.
This includes, among other things:
Especially when operating business-critical applications, it is not enough to view security solely from a technical perspective. Firewalls, encryption, backups, and access controls are necessary components of a robust infrastructure. Their effectiveness, however, depends on responsibilities, processes, and control mechanisms being equally robustly defined.
The certification confirms that ayedo has implemented such a management system and applies it within the certified scope.
The certificate according to DIN EN ISO/IEC 27001:2024 is valid until May 30, 2027.
In parallel, our quality management system according to ISO 9001:2015 was confirmed.
For an infrastructure operator, quality does not only mean that a platform functions under normal conditions. What matters is whether services can be delivered repeatedly and traceably under defined conditions.
This requires documented processes, measurable quality objectives, regulated responsibilities, and a structured approach to deviations. Equally important is the ability to derive concrete improvements from disruptions, audit results, and customer feedback.
ISO 9001 provides the organizational framework for this. It views quality not as a state to be achieved once but as a continuous control and improvement process.
The certificate according to ISO 9001:2015 is valid until June 23, 2028.
An ISO certification is not proof that errors or security incidents are fundamentally excluded.
It demonstrates something else: that risks are systematically assessed, responsibilities are bindingly regulated, processes are traceably documented, and the effectiveness of the management system is regularly reviewed.
For customers, this reduces the dependency on informal processes and the knowledge of individual persons. At the same time, it provides a reliable basis for their own requirements regarding information security, supplier management, compliance, and auditability.
The renewed certifi
Many medium-sized industrial and service companies are lulled into a false sense of security: …
TL;DR Open-source platforms, digital sovereignty, and Europe are inextricably linked. An open …
TL;DR A governance-first approach is the central lever for hybrid platforms in Europe. It reduces …