Independence from non-European technology stacks, off-the-shelf solutions, and service models that leave clients exposed in the event of a failure. At LuxTrust, sovereignty is not a positioning statement, it is an architecture. Pierre Grasset, Chief Commercial Officer, reflects on a long-standing strategy and what it means in practical terms for its clients and for the financial centre.

When it comes to cybersecurity, which issues are currently in the spotlight?

PG: I would mention two issues: fraud and data breaches.

Fraud, first and foremost, as they are becoming increasingly sophisticated. AI enables fraudsters to become ever more inventive: deepfakes, voice spoofing, videos impersonating your CEO, fake websites, and forged documents. The scenarios are incredibly elaborate. And we need to move away from the stereotype of the elderly person falling into a trap: victims today come from all age groups, and some are perfectly well-informed. Fraud management is indeed a priority for the majority of executive committees in our financial centre.

Next, data breaches. We see this particularly in France, where a major data leak is revealed almost every day, affecting major organisations.

In both cases, we find that identity theft is often the gateway.

In the face of these threats, the quality of the technological solutions used is crucial. However, Luxembourg, relies heavily on non-European digital solutions. Is this dependence itself a risk factor?

PG: Absolutely. Luxembourg, like its European neighbours, is heavily reliant on digital solutions from countries outside the EU, where regulations allow access to the data they host. This reliance is not without security implications. Failing to control the components of your value chain means accepting exposure to risks that cannot be fully managed. It is precisely to address this that the issue of technological sovereignty becomes central, both for LuxTrust and for its clients.

In practical terms, what does sovereignty mean to you?

PG: For us, sovereignty means independence and control over our value chain. The fundamental question is simple: what is the risk exposure for each component of my value chain? What happens if a critical supplier cuts off service?

That is why, several years ago, we embarked on a strategy to develop our own components, rather than relying on existing solutions on the market. One example of this is our dedicated electronic signature server, which is now our own property and certified to the highest European standards. Not relying on non-European technology stacks is a first guarantee of independence. Owning our own intellectual property for our critical components is another. This long-standing strategy is now bearing fruit.

For us, sovereignty means independence and control over our value chain.
Pierre Grasset

Pierre GrassetChief Commercial OfficerLuxTrust

This strategy of independence was put to the test in December 2025. What lessons did you learn from that?

PG: First and foremost, the incident in December had nothing to do with a cyberattack. It occurred due to an application bug which, unfortunately, compromised our redundant infrastructure. But it led us to a fundamental question: how can we guarantee our clients’ operational independence, even in the event of a failure of our own services?

It was from this line of thinking that the concept of distributed autonomy emerged. In practical terms, our clients will be provided with “keys” granting them access to the LuxTrust value chain, thereby ensuring the continuity of their operations, even if our services become unavailable. This incident has therefore acted as a catalyst for innovation in the pursuit of resilience. Resilience was already a core value for LuxTrust; this incident gave us an opportunity to go further and take a significant step forward.

In practical terms, how do you help your clients gain greater sovereignty?

PG: There are several aspects to this.

As a qualified, audited and certified trust service provider, we provide our clients with services that meet European standards, notably electronic signatures and electronic archiving, enabling them to incorporate guarantees of data protection, document integrity and long-term preservation into their value chain. These services comply with the eIDAS, PSD2 and GDPR regulations, enabling clients to ensure their own compliance, representing a significant benefit in terms of sovereignty.

Our approach is firmly end-to-end. We cover the entire lifecycle of a digital transaction: user identification, authentication, document signing, archiving, consent management and data encryption. Solutions such as COSI, our electronic signature platform, and Pineappli, our PSDC-certified electronic archiving platform, are all hosted in Europe, and we hold full intellectual property rights over them.

Wherever possible, we also offer our solutions as on-premises deployments, so that our clients retain full control over their data. We also integrate AI to enhance security: by analysing behavioural indicators during transactions, we generate real-time risk scores and block fraud attempts.

Finally, we are working to build strategic partnerships to create value across the market. We are currently establishing a partnership with Incert, with the aim of creating a true Luxembourg champion of digital trust, whose services will benefit the country but can also be exported abroad.

Do European regulations support your vision of controlled digital sovereignty?

PG: Yes, our vision is supported by eIDAS 2.0 and the introduction of the EUDI wallet, which is undoubtedly the most significant regulatory development in the short term. The wallet will provide every European citizen with a strong digital identity, accessible via mobile, free of charge and certified to the highest European standards. Above all, it should help reduce identity theft scenarios, which we unfortunately see all too often in cases of fraud and data breaches, thereby closing the loop on the threats mentioned at the outset.

For our clients, this will become a regulatory requirement by December 2027: they will have to accept these wallets as part of their digital customer journeys. Our role is to make this easier for them. They will benefit from access to these wallets through the services they have already integrated today. What might appear to be a constraint is in fact an opportunity to significantly increase the security of their transactions.

For us, the digital wallet is not merely a regulatory requirement: it is the realisation, on a European scale, of what we have been building for several years. A sovereign, self-managed digital identity that serves both citizens and businesses.