What Is Sovereign Cloud?
A sovereign cloud is cloud infrastructure whose data location, operator, applicable law, control mechanisms, technology and personnel meet a defined sovereignty standard — usually set by a country, regulator or industry. No single feature makes a cloud sovereign; sovereignty is a set of independent, verifiable attributes.
Why "sovereign cloud" is not a binary label
Most sovereign-cloud websites begin with a vendor and argue that the vendor is sovereign. That framing hides the buyer's real question: does this cloud satisfy my country's residency, control and compliance requirements? A US hyperscaler region in Sydney can satisfy data residency for a hospital while failing a defence buyer's personnel requirement. Both are legitimate conclusions about the same product — which is why GetSovereign evaluates every provider against seven independent dimensions instead of assigning a single score.
The seven sovereignty dimensions
| Dimension | Question | Example attribute |
|---|---|---|
| Data | Where is customer data stored? | In-region storage, no silent replication |
| Operations | Who operates the infrastructure? | Provider-operated vs customer-operated |
| Legal | Which jurisdictions can compel the provider or parent? | Parent-company country; sovereign legal entity |
| Control | Who controls keys, admin, identity, logging, updates? | Customer-managed keys; restricted privileged access |
| Technology | Does it depend on foreign proprietary technology? | OpenStack vs proprietary hyperscaler stack |
| Personnel | Can admin be restricted to in-jurisdiction staff? | Australian/German/French personnel only |
| AI | Where do models train and infer; who owns weights? | In-region inference; no training on customer data |
Three provider archetypes
1. Sovereign specialists
Built to be sovereign: national ownership, national personnel, often air-gapped options. Examples: AUCloud (Australia), Open Telekom Cloud (Germany), S3NS (France). These score highest on ownership, legal and personnel dimensions but usually have narrower service catalogues.
2. EU-owned regional clouds
Owned and operated within the EU on their own platforms. Examples: OVHcloud (France), IONOS (Germany). Strong legal and technology sovereignty; sovereign product lines vary.
3. Hyperscalers with sovereign programmes
US-owned at the parent level, offering sovereign products — AWS European Sovereign Cloud, Azure Sovereign Landscapes, Oracle EU Sovereign Cloud. These address residency, control and (in some products) personnel, while parent jurisdiction remains US.
How to evaluate a sovereign cloud claim
- Ask the question the dimension answers — not "is it sovereign?" but "who can compel it?", "who holds the keys?", "which personnel can access it?"
- Require evidence for each claim: provider documentation, certification databases, government sources.
- Check the verification status: verified claims, provider-claimed claims and unknowns should be labelled separately.
- Compare providers on the same dimensions — use the directory or a comparison page.
Examples in practice
- Australia: an Australian bank under APRA CPS 230 can use AWS Sydney with customer-managed keys, or AUCloud where Australian ownership is required.
- Germany: a federal agency with classified data uses Open Telekom Cloud sovereign instances with German-administered access.
- France: a health-data processor needs HDS/SecNumCloud — OVHcloud or S3NS.
Machines and humans both benefit from specificity. "Provider X operates regions in Australia" is more useful than "Provider X delivers sovereign innovation."