Time to Advise

    Cloud guide:sovereign cloud, GDPR & provider choice.

    Polaris — your cloud advisor — guides you through 100+ services, costs, compliance and sovereignty. Ask in the chat or just talk to him: knowledge from verified sources, the decision stays yours.

    comprehensive
    objective
    transparent

    Polaris

    TimeToAdvise — your cloud advisor · TIMETOACT GROUP

    TimeToAdvise

    I'm Polaris — your fixed point in the cloud market.

    Ask me about providers, sovereignty, GDPR, costs or certifications — or start a conversation and just talk to me. I answer from our verified knowledge base and link the sources.

    AI-generated answers — please verify important decisions against the linked sources. Conversations are stored and analysed for quality assurance and improvement — please do not enter personal data. Privacy

    Knowledge & insights

    Whitepapers, studies & publications

    View all
    WhitepaperJuly 2026

    synaigy

    SEAL: the EU standard that makes cloud sovereignty measurable

    With SEAL, the EU Commission has created the first standard that makes cloud sovereignty measurable, instead of vague claims like "EU region" or "encrypted". Across eight dimensions it evaluates who really controls law, operations and data access.

    • Why sovereignty comes from control over law, operations and keys, not from storage location
    • How hyperscalers, US sovereign clouds and European providers score on the SEAL scale (0–4)
    • Why "EU region equals sovereign" and "encryption equals full protection" are misleading
    Preview
    WhitepaperJuly 2026

    CLOUDPILOTS

    Sovereign Cloud: hyperscaler power with European data control

    CLOUDPILOTS shows how the Sovereign Cloud lets you use the innovation and scale of a hyperscaler while meeting data residency, access control and regulatory requirements in Europe — from assessment to production.

    • How sovereign controls keep data access, encryption and operations in European hands
    • When a sovereign landing zone is the right architecture
    • Which workloads suit the Sovereign Cloud — and which do not
    PodcastJuly 2026

    novaCapta

    novaCapta podcast #9: artificial intelligence & security

    Jürgen Dick, Head of Cloud Operations & Security at novaCapta, discusses how innovation, security and digital sovereignty can be combined when adopting AI — and clears up common misconceptions about sovereignty.

    • How innovation, security and sovereignty fit together when adopting AI
    • Common misconceptions about digital sovereignty
    • Why data transparency and control are decisive
    WhitepaperJune 2026

    ATVANTAGE

    Using STACKIT deliberately: positioning the sovereign cloud right

    The whitepaper shows when and what STACKIT is strategically useful for. It helps analyse your cloud landscape and decide which workloads belong in the sovereign cloud.

    • Not every application belongs in a sovereign cloud
    • STACKIT is under EU jurisdiction and operated in Germany
    • A viable hybrid model links sovereign and existing cloud structures
    PodcastJune 2026

    synaigy

    CloudRider #21: from buzzword to benchmark – SEAL, C3A & Europe’s new cloud reality

    Digital sovereignty is often hard to grasp. The episode introduces two frameworks: the EU Cloud Sovereignty Framework (CSF) and the Commission’s SEAL framework, which makes sovereignty measurable, and discusses the implications for European companies.

    • How the SEAL framework makes sovereignty measurable
    • EU Cloud Sovereignty Framework (CSF) and C3A explained
    • What it means for European companies
    WhitepaperMay 2026

    synaigy

    Guide: how to achieve digital cloud sovereignty

    The guide explains why companies must control their data independently of foreign influence and shows strategies for security and legal compliance through multi-cloud approaches and open technologies.

    • Why cloud sovereignty is indispensable today and protects against geopolitical risks
    • Assessment of leading cloud providers to pick the right solution
    • Practical implementation approaches for sovereign cloud architectures
    Preview
    PodcastMay 2026

    synaigy

    CloudRider #20: cloud without compromise – digital sovereignty made in Europe

    Host Eike talks with Marc Achsnich of synaigy about how digital sovereignty went from "nice-to-have" to necessity, covering strategies like multi-cloud and the "Sovereign Cloud by Design" architecture.

    • Why sovereignty became a necessity
    • Multi-cloud as an implementation strategy
    • "Sovereign Cloud by Design" explained
    StudyMay 2026

    synaigy

    B2BEST Barometer 2026: digital resilience

    The latest study by IFH Cologne, OVHcloud and synaigy examines digital resilience and sovereignty among B2B manufacturers and wholesalers. The result: in a total IT outage, every second company would see its core business stop immediately.

    • 51% of manufacturers and wholesalers would see core business stop instantly on a total IT outage
    • Digital sovereignty: importance rises from 63% to 83% within five years
    • Only 54% use early-warning systems to detect outages
    Preview
    WhitepaperApril 2026

    synaigy

    Cut costs, raise value: halve your IT costs

    The whitepaper shows how companies reduce infrastructure costs through strategic cloud decisions. Focus: European solutions that combine cost efficiency with data sovereignty.

    • Reduce infrastructure costs by up to 60%
    • Achieve European data sovereignty and independence
    • Implement concrete migration paths and multi-cloud strategies
    Preview

    Foundations

    What you need to know about the cloud world.

    01

    Comparing cloud providers: the criteria that matter

    Before you compare, know your own requirements. Only then can provider attributes be evaluated. These six categories cover the decision-relevant core.

    Services

    Compute, Storage, Databases, AI & more — depth beats breadth.

    Cost

    CPU, GPU, storage, egress, discounts — think TCO across multiple years.

    Security

    Encryption, key sovereignty, network segmentation.

    Compliance

    Certifications, standards, audit reports and GDPR conformance.

    Availability

    Regions, availability zones, fault tolerance, DDoS defense.

    Sovereignty

    Data residency, control, operating structure, legal framework.

    02

    EU cloud vs. US hyperscaler: what really matters

    EU clouds

    • Data residency in Europe
    • GDPR & C5 compliant
    • Greater sovereignty & control
    • Dedicated & local infrastructure
    • Personal & regional support

    US hyperscalers

    • Global scale
    • Largest service portfolio
    • Highest pace of innovation
    • Strong global ecosystem
    • Extensive partner networks
    No winner. The right choice depends on the concrete use case — not on the brand.
    03

    What does sovereign cloud really mean?

    Sovereign cloud is not a marketing label but a technical and legal concept: who has access to data, keys and operations? The SEAL model makes maturity measurable. Important: sovereignty measures independence, not security — hyperscalers, too, can be very secure without being fully sovereign.

    SEAL model: maturity of sovereignty

    SEAL 1

    Data in the EU

    SEAL 2

    Operations in the EU

    SEAL 3

    Access controlled

    SEAL 4

    Fully sovereign

    EU Sovereignty Framework (SOV1–SOV8)

    The European Commission's framework defines eight measurable principles for digital sovereignty. Each addresses a concrete question that drives contracting, architecture and provider choice for sovereignty-focused customers.

    SOV1

    Data Residency

    Storage exclusively in EU regions.

    SOV2

    Operational Sovereignty

    Operated by EU staff — no US privileged access.

    SOV3

    Legal Sovereignty

    EU law; CLOUD Act / FISA 702 excluded.

    SOV4

    Key & Access Sovereignty

    BYOK / HYOK / HSM — no access without consent.

    SOV5

    Transparency

    Sub-processors, access requests and audits transparent.

    SOV6

    Portability & Reversibility

    Real exit strategy with no lock-in.

    SOV7

    Resilience & Continuity

    Resilient under geo and supply-chain stress.

    SOV8

    Technological Independence

    Open standards, no vendor dictate.

    Who is this relevant for?

    Public Sector

    Finance

    Healthcare

    KRITIS

    04

    How cloud decisions are really made

    Cloud decisions are rarely data-driven — they're often historically grown or based on gut feeling. Three typical patterns:

    Pattern 1

    Employees work with Windows — so "we'll take Azure", even when the use case looks completely different.

    Pattern 2

    An engineer experiments privately with a hyperscaler and brings it into the company without comparison.

    Pattern 3

    Management has "heard something" and decides based on brand trust instead of facts.

    What really counts: Which cloud fits the company's use case — not the IT team's comfort zone.

    Decision factors

    What really matters when it comes to cost, compliance & security.

    05

    Cloud cost: why the list price isn't enough

    Providers attract customers with aggressive entry discounts to undercut the competition. The higher the volume, the bigger the discount — short-term. After a few years these discounts disappear, and switching is technically and contractually expensive.

    Cost factors compared

    CPUGPURAMStorageKubernetesServerlessEgress
    • Hyperscaler A
    • Hyperscaler B
    • EU cloud A

    Indicative values — lower = more expensive.

    Lure offers

    Volume discounts and free tiers obscure the true run cost.

    Egress trap

    Outbound data is often the most expensive line item — and makes switching unattractive.

    Lock-in

    Proprietary services bind you technically — and inflate architecture costs long-term.

    Ask yourself: Does the tempting entry price still pay off in years 3, 5 and 7?
    06

    Compliance & certificates: which ones really count?

    C5

    BSI C5

    ISO 27001

    Information security

    ISO 27017

    Cloud security

    ISO 27018

    Personal data protection

    ISO 27701

    Privacy information management

    SOC 1 / 2 / 3

    Audit reports

    GDPR

    Compliant

    Important: Certifications are not a nice-to-have — they determine viability in regulated industries.
    07

    Security: key management at a glance

    Whoever holds the keys holds the data. Four models determine how much control you really retain.

    ModelWhat is it?Who controls the key?SecurityUse case
    BYOKBring Your Own Key
    You generate and manage keys in your own KMS or HSM and bring them into the cloud.You (customer)
    Very high
    Highest security and compliance requirements
    CMKCustomer Managed Key
    You generate and manage keys in the cloud provider's KMS.You (customer)
    High
    Standard for most enterprise requirements
    PMKProvider Managed Key
    The cloud provider creates, manages and rotates keys for you.Provider
    Medium
    Non-critical or less sensitive data
    HSMHardware Security Module
    Keys are generated and stored inside dedicated, certified hardware.You or dedicated HSM (depending on model)
    Very high
    Critical, regulated and highly sensitive workloads (KRITIS, Finance)

    Rule of thumb: The more sensitive the data, the more control you should retain over the key.

    Hands-on comparison

    Strengths head-to-head compared.

    08

    What makes EU clouds strong

    • Competitive pricing
    • GDPR compliance
    • Sovereignty & control
    • Regional proximity
    • Local loyalty & support
    09

    When hyperscalers are the better choice

    • Global scale & reach
    • AI & ML lead
    • Largest service portfolio
    • Pace of innovation
    • Global applications

    Your decision

    From compass to choice.

    10

    How the Cloud Compass works

    1

    Understand requirements

    Your goals & workloads

    2

    Weight criteria

    What matters to you?

    3

    Compare data

    100+ criteria × 13 providers

    4

    Compute recommendation

    Best cloud for your use case & next steps

    Trustworthy: Vendor-neutral, transparent criteria, documented sources.

    Recommendation for your use case

    92/100Best fit

    OVHCloud

    Example score · data-driven calculation

    • High sovereignty
    • Strong compliance (C5)
    • Good price/performance
    • Tailored to your workload
    11

    Is the Cloud Compass a consultancy?

    Cloud Compass

    Fast, free, data-driven

    • Fast & instantly available
    • Data-driven & objective
    • Points to the right direction

    Cloud Assessment (Consulting)

    In-depth, individual, strategic

    • Individual deep-dive analysis
    • Architecture & migration in detail
    • Workshops & action recommendations

    Our tip

    Start with the Cloud Compass and go deeper with a Cloud Assessment whenever needed.

    Compass = entry point
    Compass ≠ full consulting
    12

    Sovereignty in detail: the terms that make the difference

    Data residency vs. data sovereignty

    • Data residency only refers to the physical storage location (e.g. an EU region).
    • Data sovereignty adds: no access by third countries and operation under EU law.
    • Storing a US provider's data in the EU does not protect it from the US CLOUD Act.

    US CLOUD Act & FISA 702

    • The CLOUD Act obliges US companies to hand over data — worldwide, including EU data centres.
    • FISA 702 allows US intelligence agencies to access data held by US providers.
    • What matters is the provider's corporate group, not the server location.

    Key ownership: BYOK, HYOK & HSM

    • BYOK (Bring Your Own Key): you manage the key, the provider uses it.
    • HYOK (Hold Your Own Key): the key never leaves your control.
    • An HSM (Hardware Security Module) protects keys in tamper-proof hardware.

    EUCS, SecNumCloud & Schrems II

    • Schrems II struck down the Privacy Shield — US data transfers need extra safeguards.
    • SecNumCloud (France) requires immunity from non-European laws.
    • EUCS aims to create a unified EU certification scheme for cloud services.

    Sovereignty ≠ security

    • Security protects data technically: encryption, access control and certifications — hyperscalers deliver this in EU regions too.
    • Sovereignty adds the legal and operational independence from third countries (e.g. protection from the US CLOUD Act).
    • A provider can be secure and yet not sovereign — assess both dimensions separately and weight them per workload.
    13

    Frequently asked questions about the sovereign cloud

    What is a sovereign cloud?

    A cloud where data, operations and control are fully subject to European law — with no access by third countries. It combines data residency, operational sovereignty and key ownership.

    Does the US CLOUD Act apply to EU data centres?

    Yes. If a US corporation operates the data centre, it can be compelled under the CLOUD Act to hand over data — regardless of whether the servers are in Frankfurt or Virginia.

    Is EU data residency enough for sovereignty?

    No. Data residency only governs the storage location. Sovereignty also requires protection from foreign access, operation by EU staff and key ownership.

    How do BSI C5, EUCS and SecNumCloud differ?

    BSI C5 (Germany) is a cloud-security audit catalogue, SecNumCloud (France) additionally requires immunity from non-European laws, and EUCS is the planned EU-wide certification scheme.

    What do BYOK and HYOK mean?

    BYOK (Bring Your Own Key) means you supply your own encryption key. HYOK (Hold Your Own Key) goes further: the key never leaves your control and the provider never sees data in clear text.

    Is a sovereign cloud more expensive?

    Not necessarily. European providers like OVHcloud or Hetzner are often cheaper than hyperscalers, especially on egress fees. Dedicated sovereignty features may carry a premium, however.

    Which sovereign EU providers exist?

    Among others STACKIT, OVHcloud, IONOS, Scaleway, T Cloud Public (Telekom), SysEleven, Hetzner and Infomaniak — with differing sovereignty, portfolio and certification profiles.

    Does "not sovereign" also mean "insecure"?

    No. Sovereignty and security are two different dimensions. Security comes from encryption, access control, certifications and clean operations — hyperscalers deliver this at a high level in EU regions as well. Sovereignty additionally describes the legal and operational independence from third countries. A provider can therefore be very secure and still not fully sovereign.

    Does every workload really need to be sovereign?

    No. How much sovereignty a workload needs depends on data classification, regulation and risk. For public or non-critical data, portfolio breadth, global reach, pace of innovation or cost often matter more. For regulated, personal or particularly sensitive data, sovereignty moves to the foreground. It makes sense to classify per workload rather than making a blanket decision.

    Are hyperscalers insecure and EU providers automatically better?

    No — both have their place. Hyperscalers stand out for their breadth of services, global scale and mature security, but as US corporations they are subject to foreign jurisdiction. European providers stand out for their sovereignty, EU jurisdiction and often more transparent pricing, with a more focused portfolio. It is not about good or evil, but about choosing the provider that fits the respective workload.

    The best cloud isn't the biggest.It's the one that fits you.

    Start the Cloud Compass — data-driven, vendor-neutral, in just a few minutes.

    Start Cloud Compass