Modular platform infrastructure for sovereign-ready public-sector deployment.
Identity, payments, mobility, workforce, education, government services and financial operations — orchestrated through the FlyttGoTech Core. Three deployment modes: managed SaaS, customer cloud, sovereign national datacenter.
Public-sector platform infrastructure, deployed under your jurisdiction.
FlyttGo Technologies Group AB designs and operates modular cloud platform infrastructure deployed across European, African and Middle Eastern public-sector programmes. The capability surface this page describes is in production today; the deployment posture is the same one our regulator-bounded installations operate under.
Eight independently licensed modules — identity, payments, mobility, workforce, education, government services, financial operations and a regulated marketplace — are orchestrated through the FlyttGoTech Core. Three deployment modes accommodate every sovereignty posture from managed SaaS in EU primary regions through to sovereign national datacenters under national HSM and national-eID integration.
- BR.01Ministry of Digital AffairsNational digital-strategy programmes · cross-ministry data infrastructure
- BR.02Ministry of TransportTransport-data backbones · regional dispatch · statutory mobility reporting
- BR.03Ministry of EducationAdmissions consolidation · scholarship orchestration · institutional analytics
- BR.04Central Digitalisation AgencyNational-eID rollouts · government-services portals · sovereign cloud programmes
- BR.05Municipal Modernisation ProgrammeCitizen services unification · council operations · residents portals
- BR.06Public-Sector Procurement OfficeFramework agreements · pilot procurement · multi-tier deployment commitments
Four service postures. Pick the one your jurisdiction operates under.
Every public-sector deployment lands against one of these postures. Each is a contractual frame, not a marketing category — the sovereignty, key custody and regulator-hand-off framework all derive from the chosen posture.
- SM.01SaaS capabilityManaged regional tenants
FlyttGo operates the platform; the recipient consumes operational services with statutory residency. Region-aware tenants in EU primary regions, with optional regional uplift to AF, MENA or APAC.
Managed deployment posture - SM.02PaaS orchestration architectureFlyttGoTech Core substrate
The FlyttGoTech Core exposes an orchestration substrate — identity broker, audit log, event bus, policy engine, workflow runner — that the recipient extends with internal services or in-house modules.
Orchestration architecture - SM.03IaaS-compatible deployment environmentsCustomer cloud or sovereign substrate
Platform installs into the recipient's existing AWS, Azure, GCP or bare-metal sovereign environment under their tenancy. BYOK / HYOK key custody. Audit and patch cadence honour the recipient's change control.
Customer-cloud posture - SM.04Sovereign national infrastructure readinessCertified national datacenter
Installation inside certified national datacenters under national HSM, national-eID integration, regulator-bounded change windows, and Cloud-Act-exempt operations. Full data residency in jurisdiction.
Sovereign deployment posture
One orchestration layer. Six interoperability planes.
FlyttGoTech Core is the runtime that lets the modules behave as one platform. Identity authenticates, payments settle, mobility dispatches, workforce executes, education routes, financial operations close the books — every event traversing the same audit envelope. Deployable as SaaS, customer-cloud, or sovereign environments.
- OR.IDN
Identity layer
Identra anchors every cross-module call — SSO, MFA, eIDAS-LoA, qualified-signature flows. Every audited action carries the same identity envelope.
- OR.PAY
Payments layer
Payvera handles SCA, open-banking endpoints, and transaction monitoring. Settles into Ledgera with VAT-coded line detail in the same orchestration step.
- OR.MOB
Mobility layer
Transify dispatches fleet, telematics and corridor coordination. Acts as the runtime under the FlyttGo marketplace and any third-party transport authority.
- OR.WRK
Workforce layer
Workverge plans rosters, qualification states, and field-team assignments. Identra-bound; logs into the same audit trail as financial events.
- OR.EDU
Education layer
EduPro routes admissions, scholarships and ministry-grade reporting. Federates identity with Identra and emits payments via Payvera for fees and stipends.
- OR.FIN
Financial operations layer
Ledgera receives every monetary event from the planes above, posts double-entry, and emits SAF-T XML / VAT-100 / GAAP bundle / IFRS package on demand.
Every plane composes the same way under each deployment mode — FlyttGo-managed SaaS, customer-controlled cloud, or sovereign national environment. The orchestration contract is identical; the substrate is the variable.
The dimensions your procurement team actually compares.
Pre-shaped per deployment mode. Data residency, key custody, identity boundary, regulator posture, SLA and audit retention — tabulated so security, legal and ops can sign off in one review cycle.
- Data residency
- In-region (EU primary, opt. AF/MENA/APAC)
- Encryption-key custody
- FlyttGo KMS · per-tenant DEK
- Identity boundary
- FlyttGo IdP · SSO federated
- Regulatory posture
- GDPR · SOC 2 II · ISO 27001
- Patch cadence
- 14-day rolling · region-windowed
- Uptime SLA
- 99.95% per region
- Audit retention
- Append-only · 7-year default
- Pilot-to-production
- 60–90 days
- Data residency
- In customer tenancy region
- Encryption-key custody
- Customer KMS · BYOK / HYOK
- Identity boundary
- Customer IdP · OIDC/SAML in tenant
- Regulatory posture
- + customer FedRAMP / DORA / NIS2 perimeter
- Patch cadence
- 14-day rolling · customer change window
- Uptime SLA
- 99.95% per region
- Audit retention
- Append-only · customer retention policy
- Pilot-to-production
- 75–120 days
- Data residency
- 100% in-jurisdiction · national datacenter
- Encryption-key custody
- National HSM · sovereign key root
- Identity boundary
- Sovereign eID · national trust list
- Regulatory posture
- + jurisdictional (NSM · SDAIA · NCA · Cloud Act exempt)
- Patch cadence
- 30-day staged · sovereign ops window
- Uptime SLA
- 99.9% per facility · DR pair
- Audit retention
- Append-only · regulator-defined (often 10y+)
- Pilot-to-production
- 120–180 days
Eight modules. One orchestration core.
Service-delivery surface · FlyttGoTech Core (PaaS) · deployment substrate (IaaS-compatible) · sovereignty posture. The same architecture every public-sector deployment lands against, regardless of which module mix the programme licenses.
Sovereignty as a contractual instrument.
The four declarations below are not marketing posture. Each is a clause carried in every contract instrument FlyttGo executes for a public-sector deployment, with a corresponding artefact furnished on procurement request.
- SV.01Data residencyPer-mode jurisdiction declaration
Managed SaaS keeps personal data in EU primary regions with optional regional uplift. Customer-cloud deployments inherit the recipient's tenancy region. Sovereign deployments operate 100% in-jurisdiction with explicit non-replication clauses across borders.
- SV.02Encryption-key custodyFlyttGo KMS · BYOK / HYOK · National HSM
Managed deployments use FlyttGo KMS with per-tenant data encryption keys. Customer-cloud deployments support BYOK and HYOK with the recipient's KMS as root. Sovereign deployments operate against a national HSM under regulator-supervised key ceremony.
- SV.03Cloud-Act exposureDeclared per deployment mode
Managed SaaS is potentially exposed to extraterritorial subpoena in line with the host hyperscaler's legal posture. Customer-cloud follows the recipient's tenancy. Sovereign deployments inside certified national datacenters are Cloud-Act-exempt by construction.
- SV.04Right-to-audit framework30-day notice · regulator-bounded
Every contract instrument carries a standard right-to-audit clause. The recipient or its national audit office may audit on 30-day notice. FlyttGo furnishes SOC 2 Type II report, ISO 27001 certificate, penetration-test executive summary, GDPR DPIA and configuration baseline on request.
Full sovereignty posture detailed under NDA in the Government Capability Brief (GCB.00) · §4 of the Pilot Deployment Partnership Proposal (PP.00) · per-deployment addenda.
Security, compliance & deployment readiness.
Certification alignment enables FlyttGo deployments to operate within enterprise security frameworks and regulated-sector infrastructure environments.
- CR.01SOC 2–aligned infrastructure controls
Logging, change management and access governance modelled on the SOC 2 trust-services criteria.
- CR.02ISO 27001–aligned security architecture
Information-security management surface mapped to ISO 27001 Annex A controls.
- CR.03GDPR-compliant data handling architecture
EU data residency, processor agreements, subject-access workflows; lawful-basis tagging in the audit log.
- CR.04WCAG 2.1 AA accessibility targets
Keyboard, screen-reader, contrast, motion and language requirements met across the platform UI.
FlyttGo platform infrastructure is designed to support regulated-sector deployments and certification-aligned operating environments across public-sector and enterprise implementations.
- ISO 27001
- SOC 2 Type II
- Public-sector sovereign deployment compliance environments
Pathways indicate engineered capability to operate inside the named compliance environment. Formal third-party attestation lands separately and is published on the security architecture page.
From pilot to national infrastructure.
FlyttGo deploys at five procurement tiers — pick the tier that matches your programme. Frameworks, scope, cadence and statutory artefacts are pre-shaped per tier; engineering response within one business day.
- PR.01Pilot deployments60–90 days
- PR.02City rollouts90–150 days
- PR.03Regional deployments4–9 months
- PR.04National infrastructure programmes6–18 months
- PR.05White-label platform licensingPer agreement
Three programme shapes, anonymised for public circulation.
Full reference details — recipient, contract instrument, statutory metrics, audit outcomes — are released only under NDA. Request the reference dossier via the engagement intake below.
- RF.01Mid-size Nordic transport authority
- Scale
- 5 cities · 2.4M passenger records / year
- Modules
- Transify · Workverge
- Deployment mode
- DM.02 customer cloud (Azure tenancy)
- Statutory mobility reporting consolidated to a single export pipeline
- Dispatch latency on 95th-percentile route below contractual ceiling
- Right-to-audit exercised once during pilot — no findings
- RF.02National ministry of education
- Scale
- Multi-institution · scholarship cohort 18,000 / year
- Modules
- EduPro · Identra · Payvera
- Deployment mode
- DM.03 sovereign datacenter (national HSM)
- National-eID integration certified by the trust list authority
- Scholarship disbursement cycle reduced to single-business-day SLA
- Sovereign-deployment posture sustained through two regulator audits
- RF.03European municipal modernisation programme
- Scale
- Metro population ~600,000 residents
- Modules
- Civitas · Identra · Payvera
- Deployment mode
- DM.01 managed SaaS (EU primary region)
- Citizen-services portal unified across 14 council departments
- GDPR DPIA refreshed on the agreed annual cadence — no breach
- Decision package supported promotion to 5-year framework agreement
Three steps from capability brief to signed contract instrument.
The engagement model is a documented sequence — each step has a named output and a defined duration. No step is skipped; no step is shortened to accommodate quarterly targets. Public-sector procurement runs on evidence, not on momentum.
- EG.01Capability deep-dive60 minutes
A working session between the recipient's technical lead and the FlyttGo platform team. Walks the capability brief against the recipient's stated programme, names the constraints, and tests the deployment posture against the recipient's regulatory frame.
Output: working notes · capability scoring - EG.02Pilot scoping2–4 weeks · NDA-bound
A formal scoping engagement under NDA. Defines the pilot scope, success criteria, sovereignty posture, integration anchors, and the commercial envelope. Output is a written pilot brief and a price-shape proposal — both reviewable by the recipient's procurement and legal offices.
Output: written pilot brief · price-shape proposal - EG.03Procurement engagementPer tier · 60 days – 18 months
Moves to one of the five procurement tiers — pilot, city, regional, national, or white-label — with the corresponding contract instrument. The pilot proposal (PP.00) becomes the master scope reference; the contract instrument anchors data residency, key custody, audit rights and sovereignty posture.
Output: signed order form · contract instrument
Public-sector engagement desk · platform@flyttgotech.com · audit log retains every authentication and engagement event