1. The New Architecture: Sovereign by Design
Atos manages the workloads. Chunk Works owns the data.
Atos Cloud Platform (ACP)
Single Control Plane & Orchestration
CHUNK WORKS
"Ciphertext-only, Distributed, Customer Key Custody"
Public Cloud Providers
Private, EU & On-Prem
2. The Sovereign Exit Lane
Minimal egress through data locality makes multicloud realistic
True multicloud doesn't exist as long as egress fees penalise you for moving data. With Chunk Works as an intermediary layer, you pay no additional egress fees* to the data layer itself. This means you can migrate workloads (VMware, Azure, AWS) without having to "buy back" data from the provider.
Paradigm Shift
Sovereignty no longer depends on where the server is, but on who owns the encryption.
Why this works for Atos:
- ✔ Buffer layer: Absorbs shocks such as VMware licensing changes or hyperscaler price increases.
- ✔ Zero Trust: Even Atos cannot access the data (ciphertext-only + customer key custody).
- ✔ True Multicloud: Data is available across 3 locations simultaneously (Parity).
The Workflow: From Cloud to Control
Atos Orchestrates
ACP manages the VMs, containers and applications on Azure, AWS or OpenShift.
Chunk Works Secures
Before data is written, it is encrypted and chunked. The key stays with the client.
Infrastructure Stores (Blind)
The encrypted chunks land on AWS S3, OVH or IONOS. The provider only sees noise, not data.