Westover Labs UG is the consulting practice of James Westover — a former Staff/Principal engineer who built navigation infrastructure at that throughput at Uber and grew an autonomous-vehicle capture team from 2 to 14 engineers at HERE Technologies. The work here sits at that altitude: EU-sovereign infrastructure migrations, senior code audits on systems that carry real risk, and the architecture calls that decide whether something survives contact with scale — available as a fractional principal retainer, without a principal's full-time seat.
DORA has been in force for financial entities and their ICT providers since January 2025. The EU Data Act is pushing hard toward real cloud-switching rights. And underneath both sits a fact most vibe-coded stacks were built without knowing: "hosted in an EU region" is not the same thing as "under EU jurisdiction."
The US CLOUD Act is extraterritorial by design — it compels any provider subject to US jurisdiction to hand over data it controls, regardless of where the disks physically sit. A US-parented company running a Frankfurt region is still reachable by a US warrant. That is exactly the basis on which the CJEU's 2020 Schrems II ruling struck down the EU-US Privacy Shield: US surveillance law reaches EU personal data in ways the GDPR does not tolerate, and EU data subjects have no effective redress.
"Pick the EU region of a US hyperscaler" does not solve this. Sovereignty is a property of the corporate control chain and applicable law, not the data center's postcode — and a growing number of "sovereign cloud" offerings are European wrappers over US-controlled technology underneath. We build against the real test, not the marketing one.
You don't need a principal engineer sitting in your Slack forty hours a week — and if you did, most teams couldn't absorb that much senior-level throughput anyway. Hourly billing gets this backwards from both directions: an honest principal rate looks alarming on an invoice, and a discounted "consulting-friendly" rate insults the value of the judgment. So every engagement here is priced monthly or as a fixed scope, against a defined slice of deliverables and business outcomes — never against a timesheet.
In practice that means roughly a day a week of principal-level judgment, permanently slotted into your business, with a concrete return defined up front for every month.
None of these are an hourly rate. Each is scoped up front so you know exactly what you're getting.
A defined deliverable, scoped and priced up front, delivered once. The senior code audit + remediation and the EU-sovereign infrastructure migration both live here — see below.
Principal-level architecture ownership and judgment, permanently slotted into your business — without a principal's full-time compensation package. Roughly a day a week, or an equivalent monthly deliverable set: the calls your team can't fully own alone.
Once your infrastructure is EU-sovereign, we keep it patched, backed up, monitored, and right-sized — on the same Ansible pattern we run for our own fleet.
Principal-tier, not enterprise-only. Big-tech-scale judgment is usually locked behind a full-time principal's compensation package — out of reach for a funded startup or a growing small business long before it needs, or wants, a full-time engineering leader. This practice is built to change that: the fixed-scope and retainer models, plus the automation leverage behind them, make principal-caliber work available at a small-business price point. A Focused Review starts at €900; the retainer scopes down to founder-stage cadence as readily as it scales up to a regulated migration. Who it's for, both ends: large or regulated organizations that need sovereign migrations, security and code audits, and architecture de-risking — and small teams and founders that want a senior second opinion before they scale, without hiring one.
We move a vibe-coded US stack onto EU-owned, EU-jurisdiction infrastructure — Hetzner, Scaleway, OVHcloud — Ansible-driven and GitHub-Actions-deployed, the same conform pattern behind our own ~30-service fleet. The compute and data plane run under EU/EEA law with no US CLOUD Act exposure. (Edge/CDN can stay on Cloudflare for cost and performance; a fully EU-sovereign edge is available as an add-on where a client's threat model requires it.)
You own the Azure or AWS account, and the data. We operate under Azure Lighthouse or a scoped AWS cross-account role — the cloud bills you directly, we never touch the money, and you can revoke access at any time.
This isn't a stack we invented to sell. It's exactly how our own fleet runs today: one git push, one Ansible conform, health-gated deploys, secrets encrypted in git.
A typical small-app workload: roughly €30/month of EU-sovereign cloud, billed direct, plus a flat management fee — versus a platform bill that heads toward €400–800/month as you scale, add egress, and add seats.
We qualify for this honestly. The raw cloud saving alone rarely funds a management fee at tiny scale — the real case is the scaling bill (egress, per-seat, per-service cliffs), ownership and lock-in, and the DevOps function you'd otherwise have to hire. If you're low-traffic and happy, this is a trajectory-and-ownership conversation, not a save-money-today one — and we'll tell you that.
≤30 endpoints, ≤5 schemas, <10GB, standard auth, one environment.
50–100 endpoints, >5 schemas, custom/social auth, staging + prod, spot batch tier.
>100 endpoints, multi-service, HA / compliance / zero-downtime mandate.
Not every problem needs a migration or a retainer. If you — or an AI coding tool — shipped fast and something is now fragile, expensive, or you just want a principal-level second opinion before you scale, these are small, fixed-scope, fixed-price engagements. Every fix ships with characterization tests written first, so the change is provably behavior-preserving — the same tests pass before and after, not a rewrite you have to trust blindly.
A senior review of one thing — a codebase, an auth surface, a cloud setup, an architecture decision — with a prioritized findings register and concrete recommendations. No code changes.
A de-risked codebase, not a stack of advice: senior findings plus the fixes delivered as pull requests, with characterization tests written first so the refactor is provably behavior-preserving. Scoped to 2–3 named areas — modularization, database handling, auth/PII — with one clarification call, delivered within a week.
A one-page teardown of what you're paying now — agency retainer, hosting, booking SaaS, cloud — and what it could be, with a real before/after number. Then the migration, done.
A structured working session on a specific decision — should you self-host auth, is this ready to scale, where's the risk in this stack — with a written summary and recommendation.
A Focused Review credits 100% toward an Audit + Remediation if you proceed. Fixed means fixed — scope is frozen up front, and genuine unknowns become a short written change order, never silent creep. Prices ex-VAT.
For genuinely bespoke work that doesn't fit a fixed-scope product or the retainer, the ad-hoc day rate is €1,500/day. Engaging directly here rather than through a marketplace means no platform commission on either side — better economics for you, cleaner for us.
Managed EU-sovereign hosting follows a completed migration — OS and security patching, dependency bumps through CI to conform, monitoring, backups, and a monthly restore test that actually proves the backup works.
Business-hours support, next-business-day resolution.
1-hour acknowledgement, 4-hour resolution.
24/7, tighter SLA, quarterly architecture review.
Staff Software Engineer at Uber, building the navigation platform at 10M+ requests/second, managing GDPR-compliant data deletion across distributed databases on two clouds, and founding the Python Platform team that supported all of Uber's Python development. Full background at westover.dev.
One principal engineer, not a bench of juniors routed through account management — plus ~30 production services run on our own Ansible + GitHub Actions conform pattern, zero manual server operations. The migration and management offering isn't a pitch deck; it's how our own fleet already runs, and every hour on your problem is senior-level attention, whether that's a half-day advisory or a year-long retainer.
German national, a decade in US big tech, now back in Europe. That combination is unusual: understanding both Uber-scale engineering and GDPR, data residency, and DORA/CLOUD-Act exposure from the inside, not from a compliance checklist.
Refactors ship with characterization tests written first. Cost cuts are documented against real before/after invoices. Findings are source-of-truth — no confabulation, no "trust me."
Every engagement ends with you owning the result outright — code, infrastructure, credentials, and documentation. Nothing here is designed to depend on us sticking around, including the fixed-scope work and the retainer.
Portable infrastructure, your own cloud accounts, your own repos. You can end any engagement — retainer, managed hosting, migration — and keep everything that was built, with no migration tax charged on the way out.
You don't need a principal engineer in your Slack forty hours a week, and most teams couldn't absorb that much senior throughput even if they had it. Hourly billing misaligns incentives from both sides: an honest principal rate looks alarming on an invoice, and a discounted rate insults the value of the judgment.
So retainer and managed engagements are priced monthly against a defined slice of deliverables and outcomes — roughly a day a week of principal-level judgment, with a concrete return agreed up front for each month. Fixed-scope work (the audit, the migration) is priced once, against the deliverable, not the hours it takes.
It's a fractional principal retainer — principal-level architecture ownership and judgment, permanently slotted into your business at roughly a day a week, without the full-time compensation package or the misalignment of hourly billing.
It is not gig work, and it is not a junior-to-mid contractor filling a ticket queue. The engagements this site is built around — sovereign migrations, security/code audits, architecture de-risking — are the kind of problem that calls for that altitude specifically.
No — it's a specific, checkable claim. The US CLOUD Act compels any provider subject to US jurisdiction to hand over data it controls regardless of where the servers physically sit. That's the exact basis on which the CJEU struck down the EU-US Privacy Shield in Schrems II (2020). An "EU region" of a US-parented hyperscaler doesn't clear that bar.
We move the compute and data plane onto infrastructure owned and operated under EU/EEA law (Hetzner, Scaleway, OVHcloud) — genuinely outside CLOUD Act reach. We're honest about the one common exception: edge/CDN can stay on Cloudflare (US-owned) for cost and performance unless your threat model specifically requires a fully EU-sovereign edge too, which is available as an add-on.
Start with a Focused Review — a read-only senior review of your codebase, auth surface, or cloud setup, with a prioritized findings register. If you proceed to Audit + Remediation, we write characterization tests against the current behavior first, then ship the fixes as pull requests against 2–3 named areas. Same tests pass before and after — the refactor is provably behavior-preserving, not a rewrite you have to trust blindly.
No — and it's increasingly the norm, not the exception. AI-assisted code ships fast but tends to skip characterization tests, error handling, and architecture review. The audit treats it the same as any other codebase: read what's actually there, write the tests it skipped, then fix it provably.
The fixed-scope audit is a named, priced product starting at €2,000 ex-VAT — no reason to hide that. The EU-sovereign migration has published fixed-price tiers by app size. The retainer and managed-hosting tiers are scoped to your footprint and cadence, so those get quoted on a short call rather than a number that would be wrong for most people.
Send an email to [email protected] with a two-sentence description of the problem you're trying to solve. I respond within one business day and we schedule a 30-minute call. If there's a fit, you get a scope document within a week. The first call is free, and there's no discovery sprint that costs money before you've decided anything.
Send a two-sentence description of your problem to [email protected]. No formal brief required. I respond within one business day. Westover Labs UG is the contracting entity behind every engagement here — see the company at westoverlabs.eu, or James's full background at westover.dev.