STACKIT
Mendix on STACKIT: choose European cloud sovereignty
Less dependency starts with a single choice
Many organizations are further into their cloud than they would like to be. Choosing American cloud services once made sense, but now it feels like dependency. That dependency runs on three levels. Legal, technical and operational.
- Legally it means your data falls under foreign legislation. With American cloud providers, a government can demand access to data, even when the organization is based in Europe.
- Technically you keep building further on a single platform. You use specific services, integrations and tooling. The more you build, the harder it gets to move it.
- Operationally, your whole organization ends up built around that one cloud. Teams, processes and governance all line up with it. Changing course then takes more than technology, it takes organizational change.
Still, action often fails to follow. Because it is complex, or because there seems to be no clear alternative. Meanwhile the dependency grows with every new application.

Calm and control with Mendix on STACKIT
Mendix applications run in the Mendix Cloud by default. But you can also deploy them in a managed cloud such as STACKIT. That gives you a concrete choice: leave your infrastructure to Mendix, or take the lead yourself.
Choose STACKIT and your application runs entirely inside a European cloud environment. Your data stays in Europe and falls under European legislation. That way you combine the speed of Mendix with control over your infrastructure and compliance.
For four years now, LINKIT has been a STACKIT implementation partner and a specialist in rolling out Mendix applications on this cloud service. Within the Schwarz Group, which Lidl is part of, this combination is already in use. That shows it works at scale and in complex environments.

Less manual work. More control where it really counts.
In regulated sectors it is not only about efficiency, but about demonstrable control.
- In government you work with citizen data and sensitive information. You have to be able to show where the data sits and who can reach it. An application on a non-European cloud makes that complicated.
- In finance and healthcare similar demands apply. Data, audits and compliance are part of your daily operation. Processes have to be correct, and defensible too.
- In industry and logistics it looks different. There it is about collaboration across the chain: suppliers, partners and systems that have to work together. Data flows across several parties and you want to keep a grip on that exchange.
With Mendix you bring those processes together in one application. With STACKIT you decide where it runs, and therefore under which legislation.
Your existing systems stay in place. But you add a layer that brings oversight, control and less dependency on a single cloud provider.

LINKIT as your Mendix-STACKIT partner
Want to roll out applications with more control over your data and infrastructure? With our 4D model: Discover-Design-Develop-Drive, we take you from insight to a working solution on the right cloud.
We do not start with technology, but with your question. Where does the risk sit? Which processes are critical? And where do you want to keep control over data and compliance? Only then do we settle on the right solution.
We make sure you do not just build something, but choose deliberately where and how you set it up. That gets you to a solution that works now and still holds up in the long run.
LINKIT is not a supplier of the platform, but an independent technology partner. Both Mendix and STACKIT nominated us as the focus partner for Mendix on STACKIT. That means we help you make the right choice and carry it out: from an initial exploration of digital sovereignty through to the migration and the management that follows.
Our role shifts with the market. Mendix is bringing the capabilities of its own cloud to STACKIT step by step and will increasingly handle the management and monitoring itself. Our value therefore lies not only in developing applications, but also in the work around them: setting up the STACKIT environment, building data solutions such as data lakes and data warehouses, and integrating systems.







Clients already relying on Mendix & STACKIT




What is your long-term cloud strategy?
Want more control over where your applications run and how you handle data? We are glad to think along about the right use of STACKIT. Get in touch and tell us about your challenge.


Justin Bunnik
Frequently asked questions about STACKIT
Does a Mendix or OutSystems app always have to run on a hyperscaler?
No. By default your app runs in the platform’s own managed cloud, the carefree option. Under the bonnet, though, that environment sits with an American hyperscaler. If you want sovereignty, you take the route where you decide on the infrastructure yourself: your own data centre or a European cloud such as STACKIT. That gives you more control, and it asks more of your own cloud expertise. Mendix is also working on a managed variant on STACKIT, and support on STACKIT is coming for OutSystems too. That way you combine the convenience of the managed cloud with European sovereignty.
Which certifications and compliance frameworks does STACKIT support?
STACKIT is certified to BSI C5 Type 2, the most demanding German standard for secure cloud services, and to ISO 27001, ISO 27017 (cloud security) and ISO 27018 (protection of personal data). There are also SOC 2 reports (ISAE 3000 and ISAE 3402). This means the platform meets stringent requirements, including those for the public sector and regulated sectors such as healthcare and finance.
How does STACKIT relate to BIO, NIS2 and ISO 27001 requirements?
ISO 27001 is demonstrably covered through certification. For the Dutch government, what matters most is that the Dutch central government signed a framework agreement with STACKIT, with data stored within the EEA and audit rights in place. That is a strong signal that the platform aligns with government requirements.
BIO and NIS2 sit a level above certification. The Dutch government baseline, now in its BIO2 version, is built directly on ISO 27001 and ISO 27002, so STACKIT’s ISO 27001 certification already covers much of the technical foundation BIO2 requires. NIS2, transposed into Dutch law through the Cyberbeveiligingswet, which applies from August 2026, places duty-of-care and reporting obligations on your own organization, not on the platform. A certified, EEA-resident provider such as STACKIT supports that duty of care, including its supply-chain security requirements, but demonstrating compliance remains your responsibility.
How do the costs compare to AWS and Azure?
Cost is not the reason to choose STACKIT. For a comparable standard setup, STACKIT is more expensive than the large hyperscalers. How much more depends heavily on the type of application and the resources required. With different cluster sizes or data volumes, the comparison works out differently. Set against the cost of a Mendix licence, for example, the difference is also limited. So you choose STACKIT for sovereignty and continuity, not for the lowest price.
Can we keep our existing DevOps, monitoring and identity tooling?
STACKIT is built on open standards, so much common tooling fits straight in. One current exception: Mendix’s own monitoring standards cannot yet be used on STACKIT.
What about contract terms, data ownership and exit strategy?
The Dutch central government framework agreement offers a good benchmark. It sets out that data stays within the EEA, that audit rights apply, and that the contract can be terminated should the provider come under control from outside the EEA. Individual organizations will have their own arrangements, but this shows what safeguards are achievable.
Which migration scenarios are most common?
Phased migrations are the norm. What determines the phasing is the complexity of the environment, the available migration windows and the risk you want to limit. A thorough Discover phase up front prevents most surprises.