Merlon Launched European-Owned Cybersecurity Service
The new service aims to provide sovereign threat detection, bypassing foreign legal reach.
Updated on Oct. 6, 2026 in Cybersecurity

Live Poll
Do you trust foreign-owned companies to manage your nation's critical infrastructure and security?
Dutch cybersecurity firm Merlon has launched a fully European-controlled threat detection and response service. The offering is designed to maintain local jurisdiction over the entire technology chain, avoiding reliance on foreign parent companies.
Why it matters
The platform serves as a direct response to risks posed by geopolitical dependencies on foreign technology providers. It offers an alternative for government and defense clients concerned by the potential data access implications of legislation like the US CLOUD Act.
Merlon reports that its service maintains 100% European ownership and control, exceeding the performance and policy requirements of the European Commission's Cloud Sovereignty Framework at the SEAL-2 level.
The players
Merlon
A Netherlands-based cybersecurity company focused on developing sovereign infrastructure for defense and government sectors.
The details
The service operates by keeping the entire technology and service chain strictly within European borders. This architecture eliminates reliance on non-European investors or parent companies, which the firm states prevents foreign legal access to sensitive client data. The system is specifically engineered to support government, defense, and critical infrastructure operators that require high-assurance data sovereignty.
Timeline
October 6, 2026: Merlon officially launched the service at the ONE cybersecurity conference in The Hague.
The Tech Race
This launch represents a shift toward regional digital independence, following the benchmarks established by the European Commission Cloud Sovereignty Framework. It contrasts with global providers by prioritizing legal isolation from non-European jurisdictions.
The service is currently available to government, defense, and critical infrastructure clients who face stringent sovereignty requirements. These organizations will gain a threat detection platform that avoids the foreign legal entanglement risks associated with non-European software providers.
The takeaway
Merlon's new service highlights the growing pressure on critical sectors to decouple their digital operations from foreign legal jurisdictions. Clients should monitor future certification audits to confirm how the company maintains its SEAL-2 compliance status over time.
Further reading
For broader trends in regional data control, see our coverage in Cybersecurity.
Source note: This article includes information reported by IO+.
Live Poll
Do you trust foreign-owned companies to manage your nation's critical infrastructure and security?






