Skip to content
Knowledge

Sovereignty trade-offs

Buzz offers real ownership: your domain, your relay, your data, your identity, an open protocol and an Apache 2.0 licence that lets you fork the whole thing. Nothing about the arrangement depends on a vendor's continued goodwill.

What you accept in exchange is stated plainly in the project's own material. You run infrastructure. You manage keys with no recovery path. You accept a young ecosystem where things change and some things do not work. The exit cost is operational rather than contractual — you can always leave, provided someone will run the destination.

Why it matters to you

For a team or organization, this is the frame in which the hosting decision, the backup question and the key-custody discipline all sit. They are not separate chores; they are the price of the property that makes Buzz attractive for confidential work in the first place.

It is also the clear-eyed counterweight to the sovereignty rhetoric. Owning your data means being responsible for it, and most organisations have never had to be.

How to apply it

Treat self-hosting as a commitment with an owner and a cost, not as a checkbox. Someone has to run Postgres, storage and backups, or Buzz is not a defensible home for confidential material.

Budget the operational work in plain terms when deciding whether Buzz fits a project.

Keep the exit real by testing it. Portability that has never been exercised is a claim, not a capability. See Back up and export the workspace.

Re-evaluate on a schedule rather than continuously — three to six months is a workable cadence — watching maturity and community momentum together.

Do not oversell the sovereignty story to clients or stakeholders. "We control the data" invites the follow-up question "and who backs it up", which should have an answer.

If you ignore this

The upside is durable: a workspace that cannot be shut off, repriced or discontinued out from under a project, and data that remains yours in an open format.

The downside is quiet and cumulative. An unrun backup, an unmanaged key, an unpatched relay — none of these fail on the day you skip them, and all of them fail eventually.

Examples

Owning the building rather than renting a desk. Nobody can evict you; nobody else fixes the roof.

A team self-hosts for a health-sector client, which is the only defensible option — and now owns uptime, backup verification and upgrades for the life of the project.

Choosing Buzz for the sovereignty argument and then running everything on a hosted relay, which reintroduces exactly the vendor dependency the argument was about.

Verified against Buzz v0.5.20 · Updated 2 Sep 2026