EU jurisdiction · No US CLOUD Act exposure

Your code and your pipelines, under European law.

Hosted Forgejo with CI/CD built in. No VPS to bring, none to babysit. The Git platform you can put in a bank's security questionnaire.

Open-source core EU-only data residency No build server to run
borgmark.eu / acme-agency / core-banking-api
DATA RESIDENCY Frankfurt, DE 🇩🇪
JURISDICTION EU · GDPR
SUB-PROCESSORS EU-based only
SOURCE Open · auditable
pipeline #418 · main running in EU ●
1
build
2
test
3
scan
4
ship
The conversation you're already having

Your enterprise clients now ask where the code lives.

Banks, insurers and energy operators are pushing jurisdiction questions down to their suppliers. As their agency, that question lands on your desk — and "it's on GitHub" is no longer an answer that passes.

Schrems II

A legal grey zone

EU case law put thousands of organisations using US-controlled tooling into an unclear position on lawful data transfer. Your clients' lawyers know this.

US CLOUD Act

Reach across borders

US-parented providers can be compelled to hand over data even when it sits on European disks. Jurisdiction, not server location, is the real question.

NIS2 · DORA

Supply-chain accountability

Regulated clients must account for their suppliers' security posture. Your toolchain is part of their attack surface — and their audit.

What you get

A familiar Git forge. Sovereign by construction.

BorgMark is hosted Forgejo with the parts agencies actually need bolted in — so you adopt it in an afternoon, not a quarter.

Forgejo, not a fork you'll regret

The open-source Git forge your team already knows. Pull requests, issues, code review, mirroring — nothing to relearn.

CI/CD with no VPS to bring

Build runners are included and managed. No Hetzner box to provision, patch, or explain in an audit. Push, and it runs.

EU data residency, on the record

Repositories, artifacts and logs stay on EU infrastructure under EU jurisdiction. A location you can name in a contract.

Open core, no lock-in

Standard Git underneath and an open-source core means your exit is a clone away. Auditable, not a black box.

One-step migration

Mirror in from GitHub or GitLab with history, issues and CI intact. Move one client project, or all of them.

SSO & per-client isolation

SAML/OIDC sign-in and hard org boundaries, so each client's code stays walled off — the way their security team expects.

Every build, in the EU

The pipeline never leaves the jurisdiction.

Source, runners, artifacts and logs all stay on EU infrastructure. There's no hidden hop to a US region, and nothing for you to wire up to make that true.

deploy · core-banking-api region: eu-central
clone
build
test
scan
ship
No egress outside the EU · logged & exportable
The differentiator

Answers for your client's security questionnaire.

The actual line items that stall agency deals with regulated clients — and what BorgMark lets you write in the box.

01 Where is source code and build data stored?
EU data centres only, region named in the contract. No replication to non-EU regions.
02 Is the provider subject to non-EU jurisdiction?
EU-operated, no US parent, outside the reach of the US CLOUD Act.
03 List all sub-processors and their locations.
Short, EU-based sub-processor list, published and versioned.
04 Can the platform be independently audited?
Open-source core — reviewable, not a black box. Audit logs exportable.
05 What is the exit / portability plan?
Standard Git plus open formats. Full export on demand, no proprietary trap.
Pricing

Priced per seat. Billed in the EU.

Placeholder figures — set your real numbers before launch. Structure is what matters here.

Studio
€19 / seat / mo

Small agencies moving their first regulated client off GitHub.

  • Up to 15 seats
  • Managed CI runners included
  • EU data residency
  • Email support
Start a trial
Regulated
Custom

Named region, contractual SLAs, audit support for DORA/NIS2 scope.

  • Everything in Agency
  • Dedicated EU region
  • Contractual SLA & audit support
  • Security questionnaire help
Talk to us
Questions

The objections, answered.

Yes — the open-source Forgejo forge, hosted and operated by us in the EU, with managed CI runners and the agency-grade access controls bolted on. No proprietary fork you'd be stuck with.

Yes. Repos mirror in with full history; issues and pipelines come across. You can move a single stuck client project first and expand from there.

On EU infrastructure, in a region we name in your contract. No replication to non-EU regions, and the build pipeline runs in the same jurisdiction.

Only under EU legal process. There's no US parent company, so the US CLOUD Act doesn't reach it — which is the point you can put in writing for clients.

It removes a recurring finding: an externally-controlled toolchain under foreign jurisdiction. It's not a certificate by itself, but it's an answer your client's auditor accepts.

Standard Git plus open formats means a full export on demand. Your exit cost is a clone, not a renegotiation.

Limited onboarding

Stop explaining where your code lives.

We're onboarding a small group of agencies first. Bring the client deal that's stuck on the security review — that's the one we want to unblock.

Request access