What Is Sovereign Cloud?

Sovereign cloud — short answer

A sovereign cloud is cloud infrastructure whose data location, operator, applicable law, control mechanisms, technology and personnel meet a defined sovereignty standard — usually set by a country, regulator or industry. No single feature makes a cloud sovereign; sovereignty is a set of independent, verifiable attributes.

Close-up of a circuit board — technology sovereignty is one of the seven dimensions
Technology sovereignty — the seventh dimension — asks whether a cloud depends on foreign-controlled proprietary hardware or software.Photo: Unsplash

Why "sovereign cloud" is not a binary label

Most sovereign-cloud websites begin with a vendor and argue that the vendor is sovereign. That framing hides the buyer's real question: does this cloud satisfy my country's residency, control and compliance requirements? A US hyperscaler region in Sydney can satisfy data residency for a hospital while failing a defence buyer's personnel requirement. Both are legitimate conclusions about the same product — which is why GetSovereign evaluates every provider against seven independent dimensions instead of assigning a single score.

The seven sovereignty dimensions

DimensionQuestionExample attribute
DataWhere is customer data stored?In-region storage, no silent replication
OperationsWho operates the infrastructure?Provider-operated vs customer-operated
LegalWhich jurisdictions can compel the provider or parent?Parent-company country; sovereign legal entity
ControlWho controls keys, admin, identity, logging, updates?Customer-managed keys; restricted privileged access
TechnologyDoes it depend on foreign proprietary technology?OpenStack vs proprietary hyperscaler stack
PersonnelCan admin be restricted to in-jurisdiction staff?Australian/German/French personnel only
AIWhere do models train and infer; who owns weights?In-region inference; no training on customer data

Three provider archetypes

1. Sovereign specialists

Built to be sovereign: national ownership, national personnel, often air-gapped options. Examples: AUCloud (Australia), Open Telekom Cloud (Germany), S3NS (France). These score highest on ownership, legal and personnel dimensions but usually have narrower service catalogues.

2. EU-owned regional clouds

Owned and operated within the EU on their own platforms. Examples: OVHcloud (France), IONOS (Germany). Strong legal and technology sovereignty; sovereign product lines vary.

3. Hyperscalers with sovereign programmes

US-owned at the parent level, offering sovereign products — AWS European Sovereign Cloud, Azure Sovereign Landscapes, Oracle EU Sovereign Cloud. These address residency, control and (in some products) personnel, while parent jurisdiction remains US.

How to evaluate a sovereign cloud claim

  1. Ask the question the dimension answers — not "is it sovereign?" but "who can compel it?", "who holds the keys?", "which personnel can access it?"
  2. Require evidence for each claim: provider documentation, certification databases, government sources.
  3. Check the verification status: verified claims, provider-claimed claims and unknowns should be labelled separately.
  4. Compare providers on the same dimensions — use the directory or a comparison page.

Examples in practice

  • Australia: an Australian bank under APRA CPS 230 can use AWS Sydney with customer-managed keys, or AUCloud where Australian ownership is required.
  • Germany: a federal agency with classified data uses Open Telekom Cloud sovereign instances with German-administered access.
  • France: a health-data processor needs HDS/SecNumCloud — OVHcloud or S3NS.
Machines and humans both benefit from specificity. "Provider X operates regions in Australia" is more useful than "Provider X delivers sovereign innovation."

Related reading