Back to Insights
Governance

We can't sell control if we don't build with control

We've chosen not to build Bounded on Amazon, Google or Microsoft. Not because we're against American technology, but because we help customers understand and manage their digital dependencies. That means we can't build in dependencies of our own that would make it hard to act if the conditions change.

Martin Lichstam
Martin Lichstam
Co-Founder & Chief Architect
May 31, 2026·5 min read
We can't sell control if we don't build with control

Bounded helps organisations gain visibility into the digital dependencies their operations actually rest on: suppliers, products, sub-suppliers, contracts and risks. This lets our customers act faster when something changes, follow up on their suppliers more systematically, and be better prepared when an incident, legal change or supplier change affects the business.

It also means it matters which dependencies we build into the platform ourselves.

It would have been easier to build Bounded on one of the large American cloud platforms. Microsoft, Google and Amazon offer strong infrastructure, ready-made modules and services that make it fast to develop modern SaaS products. For many companies, that's a reasonable choice.

For us, it would have created the wrong starting point. We can't sell control over digital dependencies if we don't have equivalent control over our own platform. That's why we've built Bounded differently.

When technology choices become dependencies

A dependency is rarely just a name on a supplier list. It's often built into the architecture itself: where data is stored, which functions rest on the supplier, and how easy or hard it is to replace one part without affecting the rest of the service.

There's a big difference between being able to swap out a contained part of the platform and, in practice, having to rebuild the entire service. That difference doesn't arise on its own. It requires deliberate technology choices, clear boundaries between the different parts of the system, and the in-house expertise to understand and change the architecture when needed.

Otherwise, "we can switch suppliers" remains mostly a theoretical possibility. If the platform is built as a black box, or on top of services no one masters internally, there is no real freedom to act when the law, the threat landscape or the supplier's terms change.

That's why our own technology choices start in the most fundamental parts of the platform: operations, storage and control over the environment where customer data is processed.

European operations

Bounded is a Swedish company built for European organisations that need to work systematically with information security, data protection and supplier governance. That's why we've built the platform with European operations as the starting point.

Bounded's platform is hosted with Hetzner, a German company with data centres within the EU. Customer data and contract files are stored encrypted on that infrastructure. We do not use Amazon, Google or Microsoft for the platform's systems or operations.

The question is not whether American technology is good. Often it is very good. The question is what you build into your own platform when you choose it. That is also how we view digital sovereignty. Not as isolation from the outside world, but as practical freedom to act: knowing where the critical dependencies are and being able to act when conditions change.

So the goal is not to be independent of everything. The goal is to avoid having the platform's most central parts rest on dependencies that are larger or harder to leave than they need to be. That does not make the platform immune to risk, but it gives us better control over the underlying infrastructure, over where data is stored, and over how we can act if conditions change.

The same principle applies to how we use AI. The question is not whether AI should be used, but how we can use it in a contained and controlled way, without more of our customers' information than necessary leaving our own environment.

Contained and controlled AI

AI is an important part of Bounded. We use AI to analyse contracts and supplier documentation that are often long, complex and hard to take in manually.

But our use of AI is contained. When we review customers' contracts, for example, we don't send any original files to AI models. We first process the document in our own environment: relevant text is extracted, the material is structured, and information not needed for the analysis is removed or masked. Only the limited text excerpts needed for the assessment at hand are then sent.

This lets us use AI to create concrete value without our customers' entire contracts becoming part of the AI flow. It would have been easier to let an external model receive whole documents and analyse them directly, but when the material concerns contracts, security requirements, suppliers and business-critical dependencies, the easiest route is not always the most responsible one.

Security you can see in the product

In Bounded, customer data and contract files are stored encrypted. Access to customer data is restricted, permission-controlled and logged, and users log in with two-factor authentication. We also keep production, test and development environments separated, so that customer data is not drawn into development work or test flows.

These are fundamental controls, and they matter a great deal. Many security risks arise not because organisations lack ambition, but because in practice it is unclear where data is, who has access, and which external services are involved.

Why we build differently

Bounded is built to give organisations better visibility into and control over their dependencies. For that to be credible, our own platform needs to be built in a way that gives us equivalent visibility and freedom to act.

That means technology choices are not judged only by what is fastest to build, but also by which dependencies they create, how customer data is affected, and whether we can act if conditions change. That principle applies both to our underlying architecture and to the choices we will make going forward.

It is not always the fastest route. But if we are going to help others gain control over their digital dependencies, we have to start with our own.
Martin Lichstam

Martin Lichstam

Co-Founder & Chief Architect

Engineered high-performance products at Apple and Twilio. Now building the sovereign defense layer for European critical infrastructure, focusing on operational precision.