The problem
AI coding exposes your most valuable asset
Cloud assistants send source code, secrets and know-how to US hyperscalers. In regulated environments, that's a no-go.
European Sovereign Agentic Coding Appliance
On-premises. Air-gapped. Sovereign in Europe.
ESACA brings agentic coding into regulated enterprise environments, so your source code, secrets and know-how stay inside your own house.
The problem
Cloud assistants send source code, secrets and know-how to US hyperscalers. In regulated environments, that's a no-go.
The solution: ESACA
ESACA runs agentic coding on-premises and air-gapped in your own data centre — sovereign models, turnkey.
Your advantage
Full compliance (NIS-2, BaFin, ISO 27001, GDPR), complete data sovereignty and no vendor lock-in — provable with the Benchmark.
In the video, Jan Jikeli, Founder of ESACA, explains the project during his breakout session at the Fsas Technologies Summit 2026.
The video is in German.
Our mission
We help organisations build and run their digital business model
— sovereignly, and with AI.
Coding is the starting point, sovereignty a requirement, and adoption happens step by step.
What is ESACA
ESACA — European Sovereign Agentic Coding Appliance — brings agentic coding into regulated enterprise environments. It runs fully inside your own data centre: no data egress, no external API calls, no hidden telemetry.
Coding is the core. ESACA gives your developers a production environment for coding agents on real projects. And because it runs safely, guided and under your control, it also enables people across the organisation to work with AI sovereignly.
In short: agentic coding power — without your IP ever leaving the building.
The platform
ESACA starts with two tightly integrated tools: the Workbench and the Benchmark. The sovereign model infrastructure runs underneath, and nobody has to operate it.
Build
A production environment for coding agents on real projects, with a binding review flow and audit trail. Human-in-the-loop stays binding.
Prove it holds up
An evaluation framework that measures how well models perform on your own internal coding challenges.
The status quo
Source code, secrets and architectural know-how are sent to US hyperscalers, typically outside your own contractual framework.
NIS-2, BaFin/MaRisk, ISO 27001 and GDPR requirements cannot be reliably evidenced with SaaS coding tools.
The result: blanket bans slow development down, or teams use tools behind IT's back. Both are costly.
Benchmark results of on-prem and cloud models over time.
What benchmarks are tracking right now is, above all, how quickly open models catch up with the proprietary frontier. Every leap by a cloud model is matched by on-prem models within a few months — for two years the lag has mostly stayed below ten percentage points, widening only briefly after major frontier releases. And around 71 % of real-world LLM queries could already be answered locally today.*
Running on-premises is therefore no longer just a compliance obligation — it is increasingly worth it in its own right: full data sovereignty, predictable costs and no vendor lock-in, with results close to the cloud frontier. ESACA brings exactly these models to your data centre, turnkey — and with the Benchmark you can measure at any time which model is sufficient for your tasks.
Before a single euro goes into GPUs, the Benchmark turns guesswork into evidence: it measures candidate models on the work your teams really do, not on a public leaderboard a vendor may have trained against.
Measure candidate models on your own coding challenges and see which one earns a place on your infrastructure.
See why a model shines for one team and frustrates another by testing each team's real scenarios and stacks.
Define your scenarios once and replay them automatically whenever a new model appears, so an upgrade becomes a measured decision.
When a model proves itself, switch it straight into the Workbench.
The approach
Runs fully offline inside your own data centre. No data egress, no external API calls, no hidden telemetry channel.
European LLMs on your own hardware. Updates via a controlled supply chain: you decide what is rolled out, and when.
A full audit trail of every agent action. RBAC, SSO and SIEM integration address NIS-2, ISO 27001, GDPR and BaFin requirements.
Why it matters
Four things ESACA keeps firmly in your hands.
01
Run AI on your own infrastructure — on-premises or fully air-gapped. The appliance operates inside your own data centre, not someone else's cloud.
02
Source code, secrets and architectural know-how never leave the building. No egress to external clouds, no hidden telemetry.
03
European models on your own hardware mean no lock-in: no forced upgrades, no surprise price changes, no provider deciding your roadmap.
04
People across the organisation can work with AI safely and sovereignly — guided, with human-in-the-loop and a full audit trail.
Who it's for
Organisations that may use cloud in places, but cannot rely on it everywhere, and need an alternative they fully control.
Teams with recurring processes and strict data boundaries that want to automate safely without sending data abroad.
Environments — from defence to legal to healthcare — bound by NIS-2, BaFin, ISO 27001 and GDPR, where AI must stay inside their own data centre.