There is a particular kind of admiration in European defense IT circles for Platform One. It is deserved. A national defense establishment set out to fix military software delivery, built its answer on open source, and — unusually — did it in public. The Big Bang documentation is open. The repository is readable. You can study exactly how a defense software factory was assembled.
The admiration occasionally turns into a proposal: why don’t we just use it?
That is the wrong conclusion, and it is wrong for reasons this brand exists to name.
What Platform One got right
Three things, and Europe should take all of them.
It treated software delivery as the mission problem. Not “which Kubernetes” — how does working software reach operators repeatedly and provably. That framing is the actual insight.
It built on open source rather than a bespoke stack. The public documentation shows ordinary CNCF-ecosystem components — Istio, Kyverno, Keycloak, External Secrets Operator, Prometheus, Grafana — composed into a hardened baseline. Nothing exotic. That is why the pattern is reproducible at all.
It made disconnected operation first-class. Air-gapped installation is a documented, supported path in the docs, not a footnote. Anyone who has watched a “supports air-gap” claim collapse during a PoC understands how rare that is.
Why copying it fails for Europe
The architecture is transferable. The dependencies are not.
The supply chain starts under a foreign government
Hardened images come from Iron Bank, which is US-operated. Adopt it and the very first link in your software supply chain — the base layers everything else inherits — belongs to another state. For a commercial workload that is a procurement decision. For a defense programme premised on sovereignty it is a contradiction at the most sensitive layer you have.
An authorisation under US law does not discharge a German obligation
Accreditation is jurisdictional. Whatever authority approves a system under a US framework has no standing before BSI, and a US authorisation does not satisfy IT-SiG 2.0, NIS2, or a national defense accreditation regime. You would inherit the work of accreditation without inheriting its validity.
The operator is the control point
Whoever runs the platform holds effective root. That is true when the operator is a US government programme exactly as it is true when the operator is a hyperscaler — which is the argument we make about “EU regions”. The principle does not change because the operator is an ally.
None of this is a criticism of Platform One. It is a correct design for the United States. The error would be assuming that a design optimised for one nation's sovereignty automatically serves another's.
“Our own” doesn’t mean “from scratch”
The productive reading is that Platform One is a reference implementation, not a product to procure. What Europe should replicate:
- A hardened supply chain operated in Europe — curated base images with SBOMs and verifiable provenance, under European law.
- Policy as code, mapped to European baselines — the same engines, but with BSI IT-Grundschutz and NIS2 as the control set.
- Air-gap delivery as a first-class path — releases that cross a boundary as reviewable, reproducible artefacts.
- Continuous, machine-readable evidence — accreditation as an ongoing property, not a biannual document exercise.
- Open source throughout — because auditability is what makes any of this verifiable.
Every one of those is achievable with components available to anyone today. What is missing is not technology.
The uncomfortable part
What is missing is institutional: Europe has no widely-adopted equivalent of a hardened image source, and its accreditation regimes are fragmented across nations in a way the US model simply does not have to solve. Pretending otherwise would be its own kind of sovereignty washing.
We are a platform vendor. We build the platform, delivery and secrets layers — and we say plainly that we do not operate an accredited image registry and we do not grant authorisations. Those gaps need European institutions and a European supplier ecosystem, not a vendor claiming to be a whole factory.
The point
Platform One’s real export is not software. It is proof that a defense establishment can build a software factory on open source, publish it, and improve faster than the procurement cycle that used to constrain it.
Europe should take the proof and the patterns — and build the factory under its own law, with its own supply chain, run by its own people. Copying the platform would mean solving the delivery problem by acquiring a sovereignty problem.
Read the reference architecture for the five layers this requires, or the sovereignty-washing test for the five questions we apply to any platform — including our own.
