Insights · Architecture · Security

Foundra Blog

Practical articles on digital sovereignty, security & governance—for teams building and operating platforms in regulated environments.

Illustration: Security Sovereignty

Blog · Security

Security as the foundation of digital sovereignty

Why robust security measures, identity management, and data protection are crucial for digital sovereignty.

July 2026·approx. 5 min read
Digital SovereigntySecurityAWS
Illustration: Data Sovereignty

Blog · Data Sovereignty

Confidence in the Cloud with Data Sovereignty

Learn how to ensure data sovereignty in regulated industries using AWS.

July 2026·approx. 4 min read
Digital SovereigntySecurityAWS

Security

Secret Scanning in Repositories: Gitleaks vs TruffleHog

Strategies for secret scanning: Comparing Gitleaks and TruffleHog, and best practices for CI/CD pipelines.

July 2026·5 min read
SecurityCI/CDGit
Illustration: BSI C3A Cloud Sovereignty

Blog · Cloud Compliance

BSI Publishes C3A: New Sovereignty Criteria for Cloud Services

With the Criteria enabling Cloud Computing Autonomy (C3A), the BSI provides a framework for evaluating the sovereignty characteristics of cloud services.

Published: April 2026·approx. 3 min read
Digital SovereigntyBSIC3ACloud
Infographic: OWASP Top 10 (2025) vs AWS WAF Managed Rule Groups

Blog · Application Security

OWASP Top 10 (2025) and AWS WAF: Putting Managed Rules in Context

This blog post provides a pragmatic mapping of the OWASP Top 10 (2025) to the managed rule groups of AWS WAF, including anti-DDoS rules. We explain what the WAF can enforce, where its limitations lie, and how it can be operated in an auditable manner.

Published: February 2026·approx. 5 min read
OWASP Top 10AWS WAFApplication SecurityCloud Security
Illustration: IAM guardrails and automated governance

Blog · Governance Automation

IAM Auto-Remediation: Enforcing Least Privilege Automatically

Technical guide: detect over-privileged IAM roles (e.g., AdministratorAccess) and remediate automatically-using CloudTrail, EventBridge, Access Analyzer (ValidatePolicy), and CDK.

Published: January 2026·approx. 4 min read
IAMLeast PrivilegeGovernanceAuto-Remediation
Illustration: digital sovereignty

Blog · Digital Sovereignty

Securing Digital Sovereignty for Regulated Industries

How regulated industries (KRITIS, Finance) ensure data sovereignty, technological independence, and security using the AWS cloud.

Published: January 2026·approx. 4 min read
Digital SovereigntyComplianceSecurity
Illustration: trustworthy AI in regulated environments

Blog · AI Governance

AI-TRiSM: Trustworthy AI as an Architectural Principle

AI-TRiSM unifies trust, risk, and security: explainability & monitoring, ModelOps, AI application security, and privacy-treated as one system for regulated AI.

Published: January 2026·approx. 8 min read
AI-TRiSMAI GovernanceSecurityPrivacy

Architecture

Enhancing Your AWS CDK Projects with Testing

Experiences in Writing and Running Tests for AWS CDK Applications: Insights and Tips.

December 2025·6 min read
AWSCDKTesting