AWS Public Sector Blog
Safekeeping your data anywhere: How AWS and Expando help European governments protect data from the edge to the cloud

Across Europe, governments and public sector organizations face a challenge that is both timeless and increasingly urgent: how do you keep sensitive data secure, accessible, and under your control no matter where your people are operating?
The answer is the same regardless of the mission: civil emergency teams operating without network connectivity, defense organizations managing classified data across security domains, and government agencies navigating strict data sovereignty requirements all need a data strategy that works at every layer, from the far edge or a data center to the cloud.
Amazon Web Services (AWS) is collaborating with Expando, a Swedish defense technology company, to help European public sector organizations build exactly that kind of layered, resilient data infrastructure. Together, AWS and Expando offer a connected approach to data protection that spans rugged edge deployments, disconnected field operations, customer-owned secure locations, and the full power of the AWS Cloud.
The Expando Avalanche platform is a ruggedized, mission-ready edge storage and computing device certified to military durability standards and deployed across European armed forces.
Figure 1: The Expando Avalanche Platform—a MIL-STD 810 certified edge storage and computing solution offering up to 3360 TB of Amazon S3 compatible object storage in a ruggedized enclosure
The challenge: Data that must be protected everywhere
Public sector organizations, particularly those in national security, defense, and critical infrastructure, operate across environments that commercial IT was never designed to handle. Data must be available in the field, where connectivity is unreliable or nonexistent. It must be protected at the highest security levels, even when hardware is physically at risk. And it must remain under the sovereign control of the organization that owns it—not a vendor, logistics chain, or foreign jurisdiction.
At the same time, these organizations need to connect field-collected data back to central systems for analysis, decision-making, and long-term storage. The gap between the tactical edge and the cloud has historically been a weak point: data either stays siloed in the field or must be physically transported in ways that introduce delay, risk, and complexity.
For member states of the EU or NATO, these challenges are compounded by the need to maintain control over data at every stage of its lifecycle, from collection to archival, while supporting interoperability with allied organizations.
The Avalanche platform is engineered for deployment in austere environments, with a ruggedized aluminum chassis, sealed connector panels, and a rack-mountable form factor for integration into mobile or fixed command infrastructure.
Figure 2: Technical overview of the Expando Avalanche enclosure showing the ruggedized chassis, sealed carry handles, I/O connector panels, and 2U rack-mount configuration (482.6 × 88 mm front profile)
A layered approach to data protection
AWS and Expando address this challenge with a three-layer architecture that gives organizations consistent data management, security, and sovereignty across environments.
Layer 1: The rugged edge, Expando Avalanche
The Expando Avalanche platform is a mission-ready edge storage and computing solution built for the most demanding environments. Certified to MIL-STD 810 military durability standards and deployed across European armed forces, Avalanche provides up to 3360 TB of storage in a ruggedized enclosure designed to withstand shock, vibration, extreme temperatures, and dust.
Critically, Avalanche is customer-owned hardware. Organizations retain full sovereignty over their data and their devices. There is no dependency on vendor logistics, mandatory certificate rotations that require hardware to be returned, or requirement for cloud connectivity to keep the system operational. Avalanche can run indefinitely in a fully disconnected state, making it suitable for field deployments, austere environments, and mission-critical operations where network connectivity is unavailable or undesirable.
Avalanche uses Amazon Simple Storage Service (Amazon S3) compatible object storage and AWS Identity and Access Management (IAM) compatible authentication, which means data stored on Avalanche integrates naturally with AWS Cloud services when connectivity is available, without requiring custom integration work.
Layer 2: Secure transport and data upload
When data needs to move from the field to a central data center or to the AWS Cloud, Avalanche supports multiple secure transport options that give organizations flexibility and control.
Organizations can physically move Avalanche units to their own secure facilities, such as a national data center, classified processing site, regional office, or data embassy established for the purpose of data staging and synchronization. A data embassy is a secure, customer-controlled facility where data can be staged, processed, and selectively transferred while remaining under the organization’s sovereign control throughout. This model keeps sensitive data under sovereign jurisdiction at every stage of its lifecycle.
Some organizations have also established their own secure transfer terminals at edge locations, partner sites, or government offices. Avalanche is designed to work seamlessly in these environments because it uses Amazon S3 compatible APIs and IAM compatible authentication, allowing data to be uploaded without custom integration work. For organizations that prefer to use AWS managed secure transfer infrastructure, Avalanche supports data migration through AWS Data Transfer Terminals, providing a governed, auditable pathway for moving large volumes of data into the AWS Cloud without relying on public networks.
The importance of protecting government data, and having a clear plan for how it moves and where it lives, has never been more apparent than in recent years. When Ukraine needed to protect its critical government data following Russia’s invasion in 2022, AWS helped migrate and safeguard more than 15 petabytes of data to keep government services running and citizen records protected. To learn more about that work, refer to Safeguarding Ukraine’s data to preserve its present and build its future. The lesson for European governments is clear: a layered data strategy with sovereign staging points, secure transport options, and cloud resilience is now an operational requirement, not a planning aspiration.
Layer 3: The AWS Cloud and the AWS European Sovereign Cloud
Once data reaches the AWS Cloud, organizations can apply AWS services across analytics, AI, security, compliance, and collaboration to their workloads. AWS operates data centers across Europe, with multiple AWS Regions giving public sector customers worldwide the ability to keep data within the EU while benefiting from the scale, security, and innovation of the world’s most comprehensive cloud.
For organizations that need to process data closer to where it is generated, AWS Local Zones extend AWS infrastructure to specific in-country locations, enabling low-latency compute and storage within national borders. This is particularly relevant for EU member states with strict data residency requirements, where workloads must remain within a specific country rather than a broader regional boundary.
For organizations with the most stringent data residency and operational autonomy requirements, the AWS European Sovereign Cloud provides a dedicated cloud environment designed to operate independently within the EU. It’s built for public sector customers and regulated industries that need a clear data boundary, EU-based operational staff, and governance structures aligned with European sovereignty requirements.
AWS supports more than 143 security standards and compliance certifications globally. European public sector customers can apply security principles, including zero-trust architectures, encryption at rest and in transit, and fine-grained access controls, to their AWS Cloud deployments.
Hypothetical scenario 1: Forest fire response
Let’s imagine a scenario in which a national emergency management agency deploys field teams to a remote forested region during a large-scale wildfire. Teams use Avalanche devices to collect aerial drone imagery, sensor readings, and incident logs in areas with no mobile coverage. When teams rotate back to a regional coordination center, devices are transported to a secure staging facility where data is reviewed and selectively synchronized to the AWS Cloud. Analysts use AWS services to process imagery at scale, model fire spread patterns, and push updated situational maps back to field teams for the next operational period, all without sensitive operational data leaving sovereign control.
Hypothetical scenario 2: Cross-border data sharing between allied agencies
In this hypothetical use case, two EU member states need to share operational data as part of a joint civil protection exercise. Each nation collects data on its own Avalanche devices and transports it to its own national data embassy. At the embassy, each nation reviews its data, applies its own classification policies, and selectively transfers agreed datasets to a shared AWS Cloud environment. Neither nation’s raw data ever leaves its own sovereign infrastructure. The shared cloud environment contains only the data each nation has explicitly approved for sharing, with full audit trails maintained throughout.
These scenarios illustrate the same closed-loop workflow: collect at the edge, transport through sovereign channels, analyze in the cloud, redeploy to the edge. The combination of Expando Avalanche and AWS makes this possible.
Why this matters for EU and NATO member states
With this solution, architects and solution designers can build data pipelines that span the full operational spectrum without compromising on security or sovereignty at different layers. Data collected in the field on an Avalanche device uses the same Amazon S3 compatible APIs and IAM based access controls as data stored in the AWS Cloud, reducing integration complexity and making it simpler to build consistent security policies across your entire data estate.
CIOs and technology leaders can meet data sovereignty requirements without sacrificing operational capability. Your data stays under your control at every layer, on hardware you own in the field, in transit through customer-controlled facilities or secure transfer terminals, and in the cloud under your own AWS account and security policies.
For national security and defense decision-makers, your organizations can operate with confidence in disconnected or contested environments, knowing that data is protected, accessible to authorized users, and ready to be synchronized with central systems when connectivity is restored.
For EU and NATO member states, this architecture supports interoperability and collaboration while maintaining national sovereignty. Data can be shared across allied organizations using AWS Cloud services and secure edge infrastructure, with each nation retaining control over its own data and infrastructure.
Built for Europe, backed by AWS
Expando is a Swedish company with more than 20 years of experience delivering rugged technology to European armed forces and defense organizations. The Avalanche platform is developed and supported in Sweden, with a supply chain and support model designed for the European market. Expando products are deployed in military aircraft, satellites, submarines, combat vehicles, and naval vessels across Europe.
AWS has been investing in European infrastructure and the European public sector for years. With data center Regions across Europe and a growing portfolio of services designed for regulated industries, AWS is committed to helping European governments modernize their IT infrastructure while maintaining the security and sovereignty their missions demand.
European governments shouldn’t have to choose between innovation and control. With AWS and Expando, you don’t have to.
What comes next
The Expando Avalanche roadmap extends the platform’s capabilities further, with Version 2 adding full edge compute support, including containers, edge virtual machines, and machine learning (ML) inference directly on the device. This helps organizations run AI models in the field without any cloud connectivity, processing data locally and synchronizing only the most relevant outputs to the AWS Cloud when connectivity is available.
Getting started
AWS and Expando want to hear from you. If you have specific use cases, capability requirements, or questions about how a layered edge-to-cloud data strategy could work for your organization, reach out to your AWS account team or contact Expando directly at expando.se.
To learn more about the Expando Avalanche platform, visit expando.se.
To learn more about AWS for public sector in Europe, visit aws.amazon.com/government-education.

