European Sovereign No telemetry No lock-in

European. Sovereign.
Built to stay yours.

H2 Labs is a European technology and social lab serving clients worldwide. We build defensive security and run principled experiments, with software you host yourself and a human in the loop where it matters.

What we do
Many fronts, one foundation

We build sovereign software: free and open for individuals, with subscriptions for the enterprises and institutions that want support, updates, and someone accountable on the other end. That is what keeps the lights on, and it all answers to one rule: build things people can actually own and trust.

Defensive security

Security that defends, not exploits. Threat models in the design review, not the post-mortem. Tools you can audit, run yourself, and keep running after the vendor is gone.

Principled experimentation

We publish the middle of the work: the detour, the dead end that taught us something, the moment a hunch became a decision. Measure, then decide. Failure is data.

Technology & social labs

Not just systems, but the economics around them: who pays for software, what it takes to truly own it, and the human side of the machines we build.

How we build
The non-negotiables

These are constraints, not slogans; they decide what we will and will not ship. Two come before the rest: your data stays yours (privacy), and your stack stays yours (sovereignty).

01 / sovereign

Sovereign by default

Your data and your tools stay yours. No dependency dressed up as convenience.

02 / self-hosted

Runs on your hardware

It works on infrastructure you control, under your jurisdiction, on your terms.

03 / human-in-loop

Humans are the source of truth

On anything that matters, a person stays in the loop and has the final word. The machine proposes; people decide.

04 / no telemetry

No telemetry

We don't phone home. What runs on your machine is not a sensor for ours.

05 / no lock-in

Stops paying ≠ stops working

The software keeps running if the subscription ends. Enterprises pay for support, updates, and accountability, never for permission to use what they already have.

06 / european

European by design, global by reach

European engineers, European legal frameworks, clients anywhere. Where we stand is our decision; where you run is yours.

What we run
Running code, and work built to fit

These run today, built on the principles above. Beyond them we do custom implementations, and we start by understanding your needs before building or recommending anything. We build for years, not quarters: tools meant to stay in service for a long time, easy to maintain, and still returning value long after the initial work.

agent

Zoya

A sovereign personal agent: one Zig binary, memory that never resets, channels we own.

platform

Servo

The self-hosted app platform this site runs on: every app a folder, no build step.

confinement

Isolation stack

Landlock, egress allowlists, sandboxes that fail closed: the layers under the agent.

access

askd

Single-packet authorization: dial out, expose no inbound port, silent to scans until a signed knock. A blind relay brokers bytes it can't read; SSH rides end-to-end on top. Working code, pre-release. EUPL-1.2 at publication.

Work with us
The lab takes engagements

The tools above run in production because we operate them, for real fleets and real security teams. We take a small number of engagements at a time, so the people who built your system are the ones who answer when you call. Every engagement is custom-built for one client: the most effective tool or service for your situation, not a template and not a configuration copied from the last customer. While we're engaged, you don't run it. The upkeep, the patching, the pager, are our responsibility. And we build so you can take it over whenever you choose: when you're ready to go on without us, or when we need to move on. It obeys the principles above. It runs on your hardware, and it keeps running without us.

SOC & MSSP automation

Detection engineering and playbook automation for teams that want to own their stack instead of renting it per seat. We build on open tooling, document everything, and hand it over. If we disappear tomorrow, your playbooks still run.

Sovereign agent infrastructure

AI agents on your infrastructure, under your jurisdiction, not as a sensor for someone else's cloud. Deployment, memory, and the confinement underneath: sandboxes that fail closed, egress allowlists, a human in the loop where it matters.

OT fleets & locked-down enclaves

Access, audit, and patching for machines that cannot dial out: manufacturing sites, egress-locked enclaves, boxes behind four jump hosts. Built on askd and years of operating exactly these environments.

Engagements begin with a fixed-scope assessment: two weeks, a report you keep either way. It's an investment, not a subscription: you own what we build, it outlives the contract. We're not building something you have to pay for forever just to use. If it makes sense, we can also move to a retainer.