An:Bundesamt für Sicherheit in der Informationstechnik (BSI)
An:Bundesministerium für Digitales und Staatsmodernisierung (BMDS)
An:Europäische Kommission — DG CONNECT und DG FISMA
Nachrichtl.:ENISA, BaFin, Deutsche Bundesbank, EZB, Bundesnetzagentur
Wir schreiben diesen Brief öffentlich, weil die Sache zu wichtig ist für geschlossene Gesprächsräume.
Europa befindet sich an einem Wendepunkt, der sich nicht durch weiteres Abwarten auflöst. Die Gesetze sind in Kraft. Die Fristen sind real. Die ersten Bußgelder werden verhängt. Aber die Infrastruktur, die Finanzinstitutionen, Behörden, PropTech-Plattformen und den europäischen Mittelstand in die Lage versetzen würde, diese Vorschriften technisch nachweisbar, rechtlich belastbar und souveränitätswahrend einzuhalten, existiert noch nicht als anerkannter Standard.
Wir haben sie gebaut. Und wir fordern die hier angesprochenen Institutionen auf, das zu prüfen, zu zertifizieren und letztlich als verbindlichen Maßstab zu setzen.
Dieser Brief ist kein Produktpitch. Er ist ein technisches und rechtliches Argument für eine neue Infrastrukturkategorie, die wir Institutional Trust Infrastructure nennen.
Teil I
Das Problem, das niemand klar genug benennt
Der Digital Operational Resilience Act. NIS2. Das EU AI Act. Die DSGVO. AMLD6. PSD3. DORA Artikel 17. Das deutsche Geldwäschegesetz. Das KI-Durchführungsgesetz, das dem BSI und der Bundesnetzagentur explizit Marktüberwachungsaufgaben für Hochrisiko-KI-Systeme zuweist.
Jedes einzelne dieser Regelwerke verlangt im Kern dasselbe: technisch verifizierbaren Nachweis, dass Compliance genau in dem Moment vorlag, in dem eine regulierte Handlung ausgeführt wurde.
Nicht einen Bericht, der drei Wochen später geschrieben wurde. Nicht ein Policy-Dokument. Nicht einen Screenshot. Technisch verifizierbaren, kryptographisch unveränderlichen, zeitgestempelten Beweis.
Die Wahrscheinlichkeit, dass ein europäisches Kreditinstitut diesen Nachweis für die vergangenen 36 Monate vorlegen kann: konservativ geschätzt unter zwanzig Prozent.
Die Regulierung ist in Kraft. Die Durchsetzung hat begonnen. Die Infrastruktur fehlt.
Teil II
Der Trugschluss der digitalen Souveränität
Lassen Sie uns über etwas sprechen, das in der politischen Debatte regelmäßig zu unscharf bleibt.
Digitale Souveränität ist kein Versprechen. Sie ist entweder mathematisch erzwungen oder sie existiert nicht.
Der US CLOUD Act von 2018 berechtigt US-amerikanische Strafverfolgungsbehörden, US-Technologieunternehmen zur Herausgabe von Daten zu zwingen, unabhängig davon, wo diese Daten physisch gespeichert sind. Das gilt für AWS, Azure, Google Cloud und jeden anderen Anbieter mit US-amerikanischer Rechtsperson. Vertragliche Zusagen über Datensouveränität sind genau das: vertragliche Zusagen. Der CLOUD Act ist ein Bundesgesetz. Wenn beides kollidiert, gewinnt das Gesetz.
Das gilt auch für Angebote wie STACKIT, den Cloud-Dienst der Schwarz-Gruppe, der sich dezidiert als europäische Alternative positioniert. STACKIT ist ein seriöser Schritt in die richtige Richtung: europäisches Unternehmen, europäische Rechtsordnung, DSGVO-konformer Betrieb. Aber selbst hier gilt: Souveränität über die Daten ist nur dann vollständig, wenn die kryptographischen Schlüssel zu diesen Daten ausschließlich beim Kunden liegen und nicht rekonstruierbar beim Anbieter.
Das ist Zero Key Custody. Und es ist das einzige Prinzip, das digitale Souveränität technisch erzwingt statt vertraglich verspricht.
In der immo.quick-Architektur verlassen kryptographische Signing-Keys niemals die Infrastruktur des Kunden. Sie werden nach dem 2-von-3-Shamir-Verfahren auf drei geographisch getrennte Standorte aufgeteilt, alle innerhalb der EU-Jurisdiktion. Das US-Justizministerium kann jeden erdenklichen Beschluss senden. Es gibt nichts herauszugeben. Die Schlüssel existieren schlichtweg nicht auf Infrastruktur, die dem CLOUD Act unterliegt.
Das ist keine Marketingaussage. Das ist Mathematik.
Teil III
Das neue BSI-Mandat und warum unsere Architektur exakt das liefert, was gefordert wird
Das KI-Durchführungsgesetz weist dem BSI eine explizite Rolle bei der Marktüberwachung von Hochrisiko-KI-Systemen zu.
Hier liegt ein Steilpass, den wir direkt ansprechen wollen.
Die immo.quick Sovereign Compliance Engine verwendet keine KI für Compliance-Entscheidungen. Sie verwendet deterministische, rein mathematische Funktionen. 67 Rechtsregeln, kodiert als unveränderlicher Code. Null probabilistische Inferenz. Jedes Ergebnis ist vollständig erklärbar, vollständig reproduzierbar und vollständig auditierbar.
Aber das System schafft genau das, was das BSI-Mandat strukturell benötigt: das Beweissubstrat, auf dem Aufsicht überhaupt erst technisch fundiert ausgeübt werden kann. Jede Prüfung, jede Entscheidung, jede Regelanwendung erzeugt einen kryptographisch signierten, manipulationssicheren Receipt.
Teil IV
Was ein Receipt ist — und warum er noch in dreißig Jahren vor Gericht standhält
Da dieses Konzept das Fundament aller unserer Argumente bildet, wollen wir es ohne technischen Fachjargon erklären.
Jede Transaktion durchläuft sieben sequentielle Verifikations-Gates: Rechtsidentität (GLEIF), Sanktionen (OFAC, EU, UN, OpenSanctions), Rechtsregeln (GwG, DORA, KWG, FINMA u.a.), Risikoscore, Dual-Approval-Prüfung, Witness Record, Ausgabe und Speicher-Nullung.
RECEIPT: SLE-2026-00003847
TIMESTAMP: 400000006849a1c3 (TAI64N)
ENTITY: Deutsche Industrieholding GmbH
LEI: 5299001XXXXXXXXXXXXXX (GLEIF verifiziert)
GATE_1: PASS — LEI aktiv, Entität registriert
GATE_2: PASS — kein Sanktionstreffer (EU/OFAC/UN)
GATE_3: WARN — GwG §10 EDD ausgelöst
GATE_4: RISK_SCORE: 0.62 / LEVEL: MITTEL
GATE_5: DUAL_APPROVAL: nicht erforderlich (< 0.70)
GATE_6: WITNESS_HASH: a3f7c9d2...
GATE_7: AUSGESTELLT · PROCESSING_TIME: 41ms
HMAC_SHA256: c7f3a19b8e2d4061...
RULE_VERSION_HASH: 8b2d14f1...
Dieser Receipt kann von jedem, überall, jederzeit, ohne Zugang zu unserer Infrastruktur, ohne Internetverbindung, ohne immo.quick als Unternehmen verifiziert werden. Ein Receipt aus 2026 ist mathematisch verifizierbar in 2036, 2046, 2056. Nicht weil wir versprechen, die Server am Laufen zu halten. Weil die Mathematik kein Ablaufdatum hat.
Teile V – X
Öffentliche Datenbeweis · Post-Quantum · Haftungsbefreiung · Mittelstand · Geopolitik · Standardisierung
Das Bedrohungsmodell „harvest now, decrypt later" macht CRYSTALS-Kyber und CRYSTALS-Dilithium (NIST FIPS 203/204) heute schon zur Pflicht — nicht erst in sieben Jahren. Wir integrieren beide parallel zur klassischen HMAC-SHA256-Kette.
Ein Receipt ist keine Dokumentation. Er ist Exkulpation. Der Compliance-Officer, der diesen Receipt einem BaFin-Prüfer vorlegt, argumentiert nicht, dass seine Institution versucht hat zu entsprechen. Er beweist mathematisch, dass sie es getan hat.
Ein Mittelstandsfonds mit 200 Jahrestransaktionen gibt vierundzwanzig Euro pro Jahr für technisch verifizierbaren, gerichtsfesten Compliance-Nachweis aus — statt vierhunderttausend Euro für eine interne Compliance-Funktion, die ihre erste ernsthafte Regulierungsprüfung zu vierzig Prozent nicht besteht.
Hier sprechen wir einen strukturellen Punkt an, der selten offen ausgesprochen wird: DORA-Enforcement hat im Januar 2025 begonnen. Institutionen werden heute geprüft, nach Standards, die nicht auf einer technischen Infrastruktur basieren, die als Referenz existiert. Die Europäische Union kann sich diesen Ansehensverlust nicht leisten.
Was wir fordern
Vom BSI
Prüfen Sie unsere Architektur als Referenzimplementierung für die Beweisanforderungen des neuen KI-Überwachungsmandats. Setzen Sie Zero Key Custody und Post-Quantum-Hybrid-Signaturen als verbindliche Anforderungen. Beschleunigen Sie den Normierungsprozess mit realen Systemen als Grundlage.
Vom BMDS
Erkennen Sie Institutional Trust Infrastructure als eigenständige und strategisch bedeutsame Kategorie in der deutschen Digitalinfrastrukturstrategie an. Adressieren Sie die Kosten-Asymmetrie zwischen Großinstitutionen und Mittelstand als Marktversagen, das Regulierung beheben, nicht vertiefen muss.
Von der EU-Kommission
Erklären Sie CLOUD-Act-Risiko zu einem formalen Compliance-Aspekt unter DORA und NIS2. Schreiben Sie Zero Key Custody für Compliance-Daten kritischer Infrastrukturen vor. Setzen Sie einen Zeitplan für Post-Quantum-Bereitschaft, der Dringlichkeit schafft, ohne Panik auszulösen.
Die Alternative
Das Dokumentationsvakuum wird von einer neuen Generation KI-generierter Berichte gefüllt werden, die sophistiziert, plausibel und technisch nicht verifizierbar sind. Regulatoren werden sie nicht von echten Nachweisen unterscheiden können. Durchsetzung wird zum Theater. Und europäische digitale Souveränität wird eine Wendung in Politikdokumenten bleiben, während die tatsächliche Infrastruktur der Rechtsjurisdiktion einer fremden Macht unterworfen ist. Wir haben die Alternative gebaut. Die Receipts sind real und mathematisch permanent.
immo.quick Global
Hattingen, Deutschland
Rami Cherri, Gründer & CEO
To:Federal Office for Information Security (BSI)
To:Federal Ministry for Digital Transformation and Government Modernisation (BMDS)
To:European Commission — DG CONNECT and DG FISMA
cc:ENISA, BaFin, Deutsche Bundesbank, ECB, Bundesnetzagentur
We are writing this letter publicly because the matter is too important for closed-door conversations.
Europe is at a turning point that does not resolve itself through further waiting. The laws are in force. The deadlines are real. The first fines are being issued. But the infrastructure that would actually allow financial institutions, government bodies, PropTech platforms, and the European Mittelstand to comply with these regulations in a technically demonstrable, legally defensible, and sovereignty-preserving way does not yet exist as a recognized standard.
We built it. And we are asking the institutions addressed here to examine it, certify it, and ultimately establish it as the binding benchmark.
This letter is not a product pitch. It is a technical and legal argument for a new infrastructure category that we call Institutional Trust Infrastructure.
Part I
The Problem That Nobody States Clearly Enough
The Digital Operational Resilience Act. NIS2. The EU AI Act. GDPR. AMLD6. PSD3. DORA Article 17. The German Anti-Money Laundering Act. The new German AI Implementation Act, which assigns the BSI and the Federal Network Agency explicit central roles in the market surveillance of high-risk AI systems.
Every single one of these frameworks demands the same thing: technically verifiable proof that compliance occurred at the exact moment a regulated action was taken.
Not a report written three weeks later. Not a policy document. Not a screenshot. Technically verifiable, cryptographically immutable, time-anchored proof.
The probability that a European financial institution can produce this evidence for the past 36 months: conservatively below 20 percent.
The regulations are in force. Enforcement has begun. The infrastructure is missing.
Part II
The Illusion of Digital Sovereignty
Let us talk about something that remains consistently too vague in the political debate.
Digital sovereignty is not a promise. It is either mathematically enforced or it does not exist.
The US CLOUD Act of 2018 grants US law enforcement agencies the authority to compel US technology companies to produce data, regardless of where that data physically resides. Contractual commitments about data sovereignty are exactly that: contractual commitments. The CLOUD Act is a federal statute. When the two conflict, the statute wins.
This also applies to offerings like STACKIT, the cloud service of the Schwarz Group, which positions itself as a dedicated European alternative. STACKIT is a serious and meaningful step in the right direction. But even here the principle holds: sovereignty over data is only complete when the cryptographic keys reside exclusively with the customer and are not reconstructible by the provider.
This is Zero Key Custody. And it is the only principle that technically enforces digital sovereignty instead of contractually promising it.
In the immo.quick architecture, cryptographic signing keys never leave the customer's own infrastructure. They are split using 2-of-3 Shamir Secret Sharing across three geographically separated EU locations. There is nothing to hand over. The keys simply do not exist on infrastructure subject to CLOUD Act jurisdiction.
This is not a marketing statement. This is mathematics.
Part III
The New BSI Mandate and Why Our Architecture Delivers Exactly What Was Ordered
The AI Implementation Act assigns the BSI an explicit role in the market surveillance of high-risk AI systems.
Here is a direct opening, and we intend to address it head-on.
The immo.quick Sovereign Compliance Engine does not use AI for compliance decisions. It uses deterministic, purely mathematical functions. 67 legal rules encoded as immutable code. Zero probabilistic inference. Every outcome is fully explainable, fully reproducible, and fully auditable.
But the system creates precisely what the BSI's new oversight mandate structurally requires: the evidentiary substrate on which supervision can actually be technically grounded.
Part IV
What a Receipt Is — and Why It Still Holds Up in Court Thirty Years From Now
Since this concept forms the foundation of all our arguments, we want to explain it without technical jargon.
Every transaction passes through seven sequential verification gates: legal identity (GLEIF), sanctions (OFAC, EU, UN, OpenSanctions), legal rules (GwG, DORA, KWG, FINMA and more), risk scoring, dual-approval check, witness record, issuance and memory zeroing.
RECEIPT: SLE-2026-00003847
TIMESTAMP: 400000006849a1c3 (TAI64N)
ENTITY: Deutsche Industrieholding GmbH
LEI: 5299001XXXXXXXXXXXXXX (GLEIF verified)
GATE_1: PASS — LEI active, entity registered
GATE_2: PASS — no sanctions match (EU/OFAC/UN)
GATE_3: WARN — GwG §10 EDD triggered
GATE_4: RISK_SCORE: 0.62 / LEVEL: MEDIUM
GATE_5: DUAL_APPROVAL: not required (< 0.70)
GATE_6: WITNESS_HASH: a3f7c9d2...
GATE_7: ISSUED · PROCESSING_TIME: 41ms
HMAC_SHA256: c7f3a19b8e2d4061...
RULE_VERSION_HASH: 8b2d14f1...
This Receipt can be verified by anyone, anywhere, at any time, without access to our infrastructure, without an internet connection, without immo.quick existing as a company. A Receipt issued in 2026 is mathematically verifiable in 2036, 2046, 2056. Not because we promise to keep the servers running. Because the mathematics does not expire.
Parts V – X
Public Data Proof · Post-Quantum · Exculpation · Mittelstand · Geopolitics · Standardization
The threat model "harvest now, decrypt later" makes CRYSTALS-Kyber and CRYSTALS-Dilithium (NIST FIPS 203/204) a necessity today — not in seven years. We integrate both in parallel with the classical HMAC-SHA256 chain.
A Receipt is not documentation. It is exculpation. The compliance officer who presents this Receipt to a BaFin examiner is not arguing that their institution tried to comply. They are proving, mathematically, that it did.
A Mittelstand fund with 200 annual transactions spends EUR 24 per year on technically verifiable, court-admissible compliance documentation — instead of EUR 400,000 on an internal compliance function that fails its first serious regulatory examination 40 percent of the time.
Here we address a structural point that is rarely spoken openly: DORA enforcement began in January 2025. Institutions are being examined today, against standards that are not grounded in a reference technical infrastructure that actually exists.
What We Are Asking For
From the BSI
Examine our architecture as a reference implementation for the evidentiary requirements of the new AI oversight mandate. Establish Zero Key Custody and post-quantum hybrid signatures as mandatory requirements for regulated compliance infrastructure. Accelerate the standardization process using real production systems as the foundation.
From the BMDS
Recognize Institutional Trust Infrastructure as a distinct and strategically significant category in Germany's digital infrastructure strategy. Address the compliance cost asymmetry between large institutions and the Mittelstand as a market failure that regulation must correct, not deepen.
From the EU Commission
Declare CLOUD Act risk a formal compliance consideration under DORA and NIS2. Mandate Zero Key Custody for compliance data of critical infrastructure operators. Set a timeline for post-quantum readiness that creates urgency without creating panic.
The Alternative
The documentation vacuum will be filled by a new generation of AI-generated compliance reports that are sophisticated, plausible, and technically unverifiable. Regulators will not be able to distinguish them from genuine contemporaneous records. Enforcement will become theater. And European digital sovereignty will remain a phrase in policy documents while the actual infrastructure on which European regulated data depends sits in data centers subject to the legal jurisdiction of a foreign power. We have built the alternative. The Receipts are real and mathematically permanent.
immo.quick Global
Hattingen, Germany
Rami Cherri, Founder & CEO