European Sovereign Agentic Coding Appliance

Agentic coding without data leakage.

On-premises. Air-gapped. Sovereign in Europe.

ESACA brings agentic coding into regulated enterprise environments, so your source code, secrets and know-how stay inside your own house.

The problem

AI coding exposes your most valuable asset

Cloud assistants send source code, secrets and know-how to US hyperscalers. In regulated environments, that's a no-go.

The solution: ESACA

Agentic coding, fully in-house

ESACA runs agentic coding on-premises and air-gapped in your own data centre — sovereign models, turnkey.

Your advantage

AI speed, zero loss of control

Full compliance (NIS-2, BaFin, ISO 27001, GDPR), complete data sovereignty and no vendor lock-in — provable with the Benchmark.

Let's explain ESACA

In the video, Jan Jikeli, Founder of ESACA, explains the project during his breakout session at the Fsas Technologies Summit 2026.

The video is in German.

Our mission

We help organisations build and run their digital business model
sovereignly, and with AI.

Coding is the starting point, sovereignty a requirement, and adoption happens step by step.

What is ESACA

Agentic coding that stays inside your house

ESACA — European Sovereign Agentic Coding Appliance — brings agentic coding into regulated enterprise environments. It runs fully inside your own data centre: no data egress, no external API calls, no hidden telemetry.

Coding is the core. ESACA gives your developers a production environment for coding agents on real projects. And because it runs safely, guided and under your control, it also enables people across the organisation to work with AI sovereignly.

In short: agentic coding power — without your IP ever leaving the building.

E
European
Hosted and run in Europe.
S
Sovereign
Fully under your control.
A
Agentic
Autonomous coding agents.
C
Coding
Built for real projects.
A
Appliance
Ready to run in your environment.

The platform

Build and prove: Workbench and Benchmark

ESACA starts with two tightly integrated tools: the Workbench and the Benchmark. The sovereign model infrastructure runs underneath, and nobody has to operate it.

Build

Workbench

A production environment for coding agents on real projects, with a binding review flow and audit trail. Human-in-the-loop stays binding.

  • Runs on your sovereign, on-premise models
  • Bitbucket and GitLab integration
  • Sandboxed execution, human-in-the-loop
Explore the Workbench

Prove it holds up

Benchmark

An evaluation framework that measures how well models perform on your own internal coding challenges.

  • Six scoring dimensions, reproducible runs
  • Runtime, static analysis and LLM-as-a-judge metrics
  • Your own scenarios, on your own hardware
Explore the Benchmark

The status quo

Cloud coding assistants are a risk in regulated environments

01

IP leaves the building

Source code, secrets and architectural know-how are sent to US hyperscalers, typically outside your own contractual framework.

02

Compliance conflict

NIS-2, BaFin/MaRisk, ISO 27001 and GDPR requirements cannot be reliably evidenced with SaaS coding tools.

03

Ban or shadow IT

The result: blanket bans slow development down, or teams use tools behind IT's back. Both are costly.

On-prem models are hot on the heels of the cloud

Benchmark results of on-prem and cloud models over time.

What benchmarks are tracking right now is, above all, how quickly open models catch up with the proprietary frontier. Every leap by a cloud model is matched by on-prem models within a few months — for two years the lag has mostly stayed below ten percentage points, widening only briefly after major frontier releases. And around 71 % of real-world LLM queries could already be answered locally today.*

Running on-premises is therefore no longer just a compliance obligation — it is increasingly worth it in its own right: full data sovereignty, predictable costs and no vendor lock-in, with results close to the cloud frontier. ESACA brings exactly these models to your data centre, turnkey — and with the Benchmark you can measure at any time which model is sufficient for your tasks.

100%80%60%40%20%0% 60 Pp50 Pp40 Pp30 Pp20 Pp10 Pp0 Pp Q4 2024Q1 2025Q2 2025Q3 2025Q4 2025Q1 2026Q2 2026Q3 2026 SWE-bench Verified Score Gap (percentage points) Cloud models (proprietary) Local models (open-weight) Gap Sonnet 3.549% o3-mini49,3% DeepSeek R149,2% DeepSeek V342% Gemini 2.5 Pro63,8% o164,6% DeepSeek R149,2% Devstral 24B46,8% Opus 4.174,5% GPT-574,9% Kimi K271,9% Qwen3-Coder 480B69,2% Sonnet 477,2% Opus 4.580,9% GLM-4.773,8% GLM-4.555,4% Opus 4.680,8% GLM-577,8% Devstral53,8% GPT-3.5 Codex85% Opus 4.787,6% MiniMax M2.580,2% Mistral M. 3.577,6% Kimi K2.576,8% Opus 4.888,6% GPT 5.588,7% DeepSeek V4 Pro80,6% Kimi K2.680,2% GLM-5.277,8% Qwen3.5 397B76,2% Fable95% Ornith-1.0-397B82,4% MiniMax M380,5% Qwen3.7 Max80,4%
* Saad-Falcon et al. (Stanford / Together AI, 2025): “Intelligence per Watt” — local models accurately answer 71.3 % of one million real-world chat and reasoning queries. Chart: best verified model per quarter (SWE-bench Verified), monotonically increasing; data points show the best value valid at the time. Chart sources: BenchLM.ai (7 July 2026), swebench.com, marc0.dev. arXiv:2511.07885

Why benchmark at all?

Before a single euro goes into GPUs, the Benchmark turns guesswork into evidence: it measures candidate models on the work your teams really do, not on a public leaderboard a vendor may have trained against.

Choose what to self-host

Measure candidate models on your own coding challenges and see which one earns a place on your infrastructure.

Explain the gap between teams

See why a model shines for one team and frustrates another by testing each team's real scenarios and stacks.

Re-test on every release

Define your scenarios once and replay them automatically whenever a new model appears, so an upgrade becomes a measured decision.

Promote with confidence

When a model proves itself, switch it straight into the Workbench.

The approach

Three pillars of sovereign coding

01

Air-gapped appliance

Runs fully offline inside your own data centre. No data egress, no external API calls, no hidden telemetry channel.

02

Sovereign models

European LLMs on your own hardware. Updates via a controlled supply chain: you decide what is rolled out, and when.

03

Audit-ready by design

A full audit trail of every agent action. RBAC, SSO and SIEM integration address NIS-2, ISO 27001, GDPR and BaFin requirements.

Why it matters

On your premises, under your control

Four things ESACA keeps firmly in your hands.

Sovereign on-premises perimeter A dashed perimeter representing your data centre encloses the workbench, a coding agent, server racks and a sovereign model chip; data flows between them while a lock badge seals the boundary and external clouds are blocked at the edge.
Agents, data and models stay inside your perimeter — sealed, sovereign, under your control.

01

AI on your own premises

Run AI on your own infrastructure — on-premises or fully air-gapped. The appliance operates inside your own data centre, not someone else's cloud.

02

Data stays in the company

Source code, secrets and architectural know-how never leave the building. No egress to external clouds, no hidden telemetry.

03

Independence from AI providers

European models on your own hardware mean no lock-in: no forced upgrades, no surprise price changes, no provider deciding your roadmap.

04

Safe, sovereign enablement

People across the organisation can work with AI safely and sovereignly — guided, with human-in-the-loop and a full audit trail.

Who it's for

Built for regulated, high-stakes environments

01

Critical infrastructure & utilities

Organisations that may use cloud in places, but cannot rely on it everywhere, and need an alternative they fully control.

02

Public sector & administration

Teams with recurring processes and strict data boundaries that want to automate safely without sending data abroad.

03

High-security & regulated industries

Environments — from defence to legal to healthcare — bound by NIS-2, BaFin, ISO 27001 and GDPR, where AI must stay inside their own data centre.

Kontakt aufnehmen


An initiative by mgm technology partners Fsas Technologies, a Fujitsu company