Skip to main content

KeenGen

ONE PLATFORM · THREE BUILDING BLOCKS

Sovereignty

without a clear cut.

The transition to secure, digitally sovereign communication does not require a company-wide migration. Our solutions are designed to run smoothly alongside your existing communication infrastructure.

Our solution acts as a fully-fledged Office 365, Webex & Co. client. For your teams, this means highly sensitive departments can communicate internally via our sovereign, shielded infrastructure—while remaining seamlessly connected to the rest of the organization through your existing communication solutions.

Full security for critical data, without creating information silos.

Become sovereign without migrating.

89 % call sovereignty essential. 12 % have done something. Here is why.

01 — THE FOUNDATION

Your identity stays yours.

One user, every system. Identities are decoupled from the target platform, making Teams, Zoom, Webex and the rest interchangeable.

Switch vendors in a click — not in 18 months.

ID Austria
Anti-Lock-in
Multi-Tenant
GDPR

02 — THE COMMUNICATION

One client. Every channel.

Every conversation gets the right level of security: open topics over open tools, sensitive matters over sovereign, end-to-end encrypted channels.

Fully auditable. The end of shadow IT.

MS Teams
Matrix
MLS
WhatsApp
Audit proof

03 — THE CONTINUITY

Stay operational, whatever fails.

A permanent parallel operation alongside your stack, continuously mirrored. When the worst happens, your team simply keeps working.


Always On
Carrier-Grade
Tamper-proof
NIS-2

Identity → Collaboration → Continuity

Three building blocks. Stacked, and usable one at a time.

Identity, communication, continuity. Each tier solves a problem of its own and runs on its own. Together they add up to a communication estate that no longer depends on any single vendor.

Fully EU-sovereign. Fully under your control.

Our solutions are fully customizable – share your specific requirements with us!

WHY SOVEREIGNTY MATTERS

Dependency comes at a price.

Sometimes a very steep one.

Someone else's identities, someone else's clouds, a single vendor for everything: it works — until it doesn't. The past 18 months have shown how fast communication collapses when control sits elsewhere.

19.07.2024

CrowdStrike Outage

A faulty update knocked out roughly 8.5 million Windows devices, according to Microsoft. Airports, hospitals and banks ground to a halt.

≥ 10 Mrd.

estimated damage (USD)

29.10.2025

Azure Front Door

A single faulty configuration change triggered a global outage — Microsoft 365, Outlook and Teams all affected.

~ 8 h

worldwide disruption

DACH 2024

Ransomware in hospitals

According to Sophos, ransomware hit two-thirds of healthcare organizations in 2024 — a four-year high.

67 %

of hospitals affected

Outage, dependency, foreign access: The causes differ.

The answer is always the same: take back control!

NIS-2

NIS-2 explicitly requires "secure voice, video and text communication and secure emergency communication systems" — in other words, a channel that doesn't depend on the system under attack.

THE SOLUTION

Continuity that's already running.
Not at the push of a button.

KeenAct runs next to your communication solution: synchronized, mirrorred, fully under your control. Your full context is already sovereign, when the incident hits!

How it works: All KeenGen solutions run in parallel to your existing solution, but fully integrated, so you can keep working together.

Sovereign.

EU-only per Architektur, nicht per Konfiguration. On-Prem oder EU-souveräne Cloud. Kein CLOUD-Act-Risiko.

Compliant by Design.

NIS-2, DORA, revisionssicher. Jede Nachricht, jede Entscheidung: Auditfest dokumentiert.

Carrier-Grade.

99.99% availability. Failover from on-prem to the sovereign cloud in under 5 minutes.

Whitelabel able

Make it your own, thanks to full whitelabel capability.

How you get there

No cut-over date. No rebuild. No migration project.

The most common assumption about sovereign communication: that it costs you a year of project work first. Here is what actually happens and which parts sit with you.

 

What sits with you

  • Access to your tenant so the connection can be set up
  • The decision on which sign-in paths apply in an outage
  • Choosing a pilot group
  • Assigning a tier per user — who needs their context, who needs only a channel
  • A date for the failover exercise

Was nicht passiert

  • No migration of existing mailboxes, teams or file stores
  • No cut-over date on which everything switches
  • No second interface your users would first have to learn
  • No intervention in your existing stack — it keeps running unchanged
  • No switching off Teams, Webex or whatever you run today

Info

The parallel environment grows alongside your estate, not in its place. That is why there is no moment at which anything could tip over.

Operating models

You decide where your data sits. Not the vendor.

Sovereignty is not a switch in the settings but a question of the operating model. Four are available. The functionality is identical in all four — what differs is who owns the machine it runs on.

On-premises

Everything in your own data centre

For operators with their own infrastructure and hard requirements. Nothing leaves your building, not even the control plane.

EU Cloud

Operation without your own data centre

EU-only by architecture, not by a region setting that somebody could change.

Hybrid

Control plane in the cloud, data with you

Data sovereignty without the operational effort of a full installation. The content stays in your own building.

Air-Gap

No connection to the outside

For isolated environments where no line to the outside exists — and none may come into being.

The same holds in every model: conversations are end-to-end encrypted. Administration manages access and policy — it cannot read content.

Moving between models is not a fresh start: because identities are held centrally, a move is a provisioning step and not a migration.

Built for those who can't go dark.

KRITIS & DEFENSE

Won't go down with the ship. Carrier-grade, on-prem, failover in under 5 minutes. Even when the primary stack is compromised.

PUBLIC SECTOR

Legally sound citizen requests via ID Austria and ELAK. Communication and records — never over private channels, always audit-proof.

HEALTHCARE

Clinical workflows, legally binding — ELGA, QES, MLS. When ransomware strikes, patients still get treated.

SYSTEM INTEGRATORS

Multi-tenant, white-label. Offer sovereignty — under your own brand!

Verifiability

What is required. And what carries it.

NIS-2, DORA and the GDPR place concrete requirements on communication. Most of the time they get quoted as badges. Here you get the opposite: which requirement is carried by which tier — and what you actually show in an audit.

 

This overview maps functions to requirements and does not replace legal review in the individual case. What governs is the wording of the legal acts and the respective national implementation.

Info

Management responsibility under NIS-2 cannot be delegated. It can be evidenced.

Let's talk!

Send us a message - we're looking forward to hearing from you.

Not a fan of forms? Just send us an email: office@keengen.eu

What is a secure emergency communication system under NIS-2?

It's a communication channel that operates independently of your primary IT. NIS-2 Article 21 calls for secure voice, video and text communication that remains available even when your main system is compromised, shut down or offline. The key point: crisis communication must never depend on the very system that's affected.

With KeenAct, there's nothing to "activate" — the parallel stack is already running. Your identities, chats, emails and files are continuously mirrored, so your team simply keeps working in the same client with the same login. 0 downtime, 0 clicks, 0 bytes lost.

Beyond secure emergency communication systems, NIS-2 requires business continuity (backup, recovery, crisis management) and reporting duties: an early warning within 24 hours and a full notification within 72 hours. Management is held personally liable.

 

The platform supports flexible deployment: on-premises, in private or public clouds, hybrid hosting (management in the cloud, data on-premises), and fully air-gapped environments for maximum security.

KeenHub decouples your identities from the target platform. You create a user once and provision them across every platform. Switching providers becomes a click instead of an 18-month project — which also satisfies DORA's requirements for tested exit strategies and managing concentration risk.

Yes. KeenCollab is accessible from desktop clients (Mac, PC, browser) and mobile devices (iOS, Android), ensuring seamless collaboration anywhere, anytime.

US providers are subject to extraterritorial US law (the CLOUD Act) — even when data sits in EU data centers. "Sovereign by architecture" means your data stays EU-only or on-prem, with no possibility of outside access. Here, sovereignty isn't a configuration toggle — it's built into the architecture.