Aller au contenu
shadgramers

Illustrative scenarios

What ShadGramers delivers
in practice.

Illustrative scenarios — not real customers. These examples describe typical situations and the estimated results ShadGramers can produce. No real customer is identified. Real case studies will be published here once the first production deployments are validated.

Six representative scenarios covering the four ShadGramers divisions — sovereign open-source tools, security consulting, custom development and training — for SMBs, mid-caps, firms and public bodies. Each scenario indicates the divisions involved: distinct in scope, complementary in mission.

Industry / Manufacturing

Typical SMB — 80 to 100 employees

Open-source catalogueTrainingbouquet-souverain + backup-drIllustrative scenario

01. Migrating from Microsoft 365 to a sovereign suite for a subcontracting SMB

Problem

An industrial SMB using Microsoft 365 (Teams, SharePoint, OneDrive, Exchange) for ~€12,500/year. A NIS2 audit reveals a high risk linked to Cloud Act extraterritoriality. Goal: migration in under a month, with no production interruption.

Solution deployed

Deployment of bouquet-souverain (Nextcloud + Mattermost + OnlyOffice + Vaultwarden) on a dedicated EU server (2 vCPU, 16 GB). Mailbox migration to Mailcow. restic 3-2-1 backups to Scaleway Glacier FR. User training over 3 half-days.

Results

  • Migration estimated at ~18 days (30-day target)
  • Target annual cost: ~€4,800 vs €12,500 (estimated 62% savings)
  • Estimated NIS2 score gain after audit (e.g. 72 → 91)
  • Production continuity maintained during migration

Legal / Consulting

Typical firm — 10 to 25 people

Open-source catalogueConsultingpack-entreprise-360 + comms-vpn-onlyIllustrative scenario

02. Strengthened confidentiality and GDPR compliance for a law firm

Problem

A law firm using Dropbox, Slack and Gmail for Business to share case files. The Bar Association reiterates the obligation of absolute confidentiality. Client data cannot legally transit through non-European servers.

Solution deployed

Pack Entreprise 360 in VPN-only mode: tool access only via WireGuard (Headscale). Nextcloud for document management, Vaultwarden for shared credentials, Mattermost for internal messaging. Segmentation by Nextcloud folder with fine-grained ACLs.

Results

  • Professional secrecy and GDPR compliance contractually guaranteed
  • Estimated efficiency gain on file access (Nextcloud search vs. emails)
  • Segmented infrastructure, zero data outside the EU
  • Estimated return on investment in 8 to 12 months

Local government

Typical municipality — 2,000 to 6,000 residents

Open-source catalogueTrainingpdp-relay + bouquet-souverainIllustrative scenario

03. Preparing for PDP 2026 e-invoicing and sovereign office tools for a municipality

Problem

A municipality that must comply with the PDP / Factur-X obligation (September 2026) for all supplier invoices. In parallel, the municipal council wants to leave Google Workspace (GDPR, CNIL). Budget capped at ~€3,500/year excluding setup.

Solution deployed

Dolibarr with a Factur-X module connected to Chorus Pro (AIFE portal). Nextcloud for municipal document management. Deployment on an OVHcloud FR VPS managed by ShadGramers. Front-office staff training over 2 half-days.

Results

  • PDP 2026 compliance contractually guaranteed
  • Target annual budget: ~€2,800 all-inclusive vs €4,200 for Google
  • CNIL: GDPR compliance attested (DPA provided)
  • Estimated reduction in invoice processing times

B2B services / Trading

Typical SMB — 40 to 80 employees

DevelopmentConsultingservice-custom + service-monitoring-setupIllustrative scenario

04. Replacing an Excel-and-email process with a custom business tool

Problem

A trading SMB manages quotes, orders and follow-ups through shared Excel files and emails. Daily double entry, version errors, no consolidated tracking. Market SaaS products impose a per-user subscription, data outside the EU, and customization limited to the company's actual process.

Solution deployed

Custom development in batches (service-custom): immersion and a costed assessment of the process, a first 6-to-8-week batch on the most costly step, user acceptance testing after each batch before the next one. EU hosting (OVHcloud / Scaleway), code delivered in full. Production monitoring of the tool (service-monitoring-setup) and onboarding training included.

Results

  • First useful batch estimated at 6 to 8 weeks (immersion, acceptance testing and go-live included)
  • Typical estimated budget: €15,000 to €25,000 for the first batch (catalog range €12,000 – €150,000 depending on scope)
  • Estimated double-entry time cut in half from the first batch
  • Code and data owned by the client — no vendor dependency

Tech / SaaS vendor

Typical scale-up — 15 to 40 people

ConsultingOpen-source catalogueservice-pen-test + service-server-hardening + backup-drIllustrative scenario

05. Penetration testing and hardening ahead of an enterprise tender

Problem

A B2B SaaS vendor must answer a major prospect's security questionnaire: over 200 questions, with supporting evidence. No penetration test has ever been carried out, servers were configured piecemeal over time, and the team has no formal document to attach to the file.

Solution deployed

Scoped penetration test (written rules of engagement, controlled OWASP exploitation of the application and its API, CVSS report, debrief) followed by CIS server hardening with a lynis re-scan and regression tests. As a follow-on, encrypted 3-2-1 backups deployed via the open-source backup-dr stack. Retest of fixes included within 60 days.

Results

  • Typical estimated budget: €8,000 to €14,000 (7-day pentest + hardening of 3 servers)
  • Pentest report and lynis score ≥ 80 ready to include in the tender file
  • Critical vulnerabilities fixed then retested within 60 days
  • OSS bridge: encrypted backups externalized in the EU (backup-dr)

Industry / Mid-cap

Typical mid-cap — 100 to 250 employees

TrainingConsultingservice-formation-cybersecuriteIllustrative scenario

06. Cybersecurity awareness measured through simulated phishing campaigns

Problem

After a wire-transfer fraud at a peer company, the management of an industrial mid-cap wants an awareness program with measurable results — not an annual presentation quickly forgotten. Its cyber insurer also requires a documented program to maintain the policy's conditions.

Solution deployed

Initial simulated phishing campaign (GoPhish) to measure the real click-through rate, then one-day sessions in groups of 15: phishing, passwords and MFA, everyday reflexes, GDPR basics — concrete examples, no jargon. Quiz and handout given to each participant. Follow-up campaign 4 to 6 weeks later to measure progress.

Results

  • Click-through rate measured before/after — the gap between the two campaigns objectifies the progress
  • Typical estimated budget: €4,000 to €7,000 (4 session days + 2 phishing campaigns)
  • Documented awareness program, presentable to the cyber insurer
  • Possible Consulting follow-on: GDPR audit or penetration test on the same findings

Does your situation resemble one of these examples?

Try the demo for free. Quote within 48h.

ShadGramers is in its launch phase — no real customer to feature here yet. Become a pilot customer and get priority access and favorable pricing terms.