Skip to main content

EU operator • EU infrastructure • EU jurisdiction

EU Sovereign Cloud

Run your Docker apps and managed databases on bare metal in Falkenstein, Germany, operated by a German company under German law. No transfer to a third country. No US parent that could be served a warrant.

850+apps deployed
320+developers building
200+services running now
Oct 2025in production since

Data sovereignty is three things, not one

Most “European cloud” claims cover only the first. Cloud sovereignty needs all three, so ask about all three.

1. Where the data sits

Bare-metal servers in Falkenstein, Saxony. Your app, your managed PostgreSQL, MySQL or Redis, your persistent volumes, your backups and your logs — all in that one region. No replicas outside Germany.

2. Who operates the platform

HOSTIM.DEV UG (haftungsbeschränkt), registered in Germany. No US parent, no US subsidiary, no US infrastructure. Verifiable in the German commercial register and in our Impressum.

3. Which law applies

German and EU law. Engineering and support are inside the EU. There is no foreign legal path to your data, because there is no foreign legal entity in the chain.

EU region is not the same as EU sovereign

The distinction procurement teams keep running into.

QuestionUS platform, EU regionHostim.dev
Data physically in the EU✅ Usually✅ Falkenstein, Germany
Operator incorporated in the EU❌ US parent✅ German UG
Outside US Cloud Act reach❌ No✅ Yes
SCCs / Transfer Impact Assessment needed✅ Yes, per Schrems II❌ No transfer to assess
DPA under GDPR Art. 28✅ Usually✅ On request, EN or DE
Support and engineering in the EU❌ Often not✅ Yes

The four questions auditors actually ask

GDPR — where is the data and who can reach it?

Hosting in the EU keeps personal data inside the EU territorial scope. No transfer to a third country means no Standard Contractual Clauses, no Transfer Impact Assessment and no supplementary measures. The compliance work shrinks from a project to a checkbox. What is left — consent UI, privacy policy, data subject requests, retention in your own tables — is application-level and stays your responsibility. We provide the substrate; you handle the surface.

Schrems II — is there a transfer at all?

The 2020 Schrems II decision invalidated Privacy Shield and put strict limits on sending personal data to US providers, even with SCCs in place. The simplest answer is not to transfer. Your containers, your queue workers, your databases and your volumes are all inside the EU, so the transfer analysis never starts.

US Cloud Act — can a foreign authority compel access?

The Cloud Act lets US authorities demand data held by US companies anywhere in the world, which conflicts with GDPR Article 48 in many cases. It applies to the company, not to the building. A German UG with no US presence is outside its reach.

Data residency — is it one region or many?

Today Hostim runs a single EU region in Falkenstein. That is good for residency and simple to attest. It also means we do not yet offer a second EU region for disaster recovery, or per-country localisation such as keeping a Polish customer’s data only in Poland. Both are on the roadmap, not shipped. If your DR plan depends on either, talk to us first.

What we do not claim

The honest list is shorter to read than the marketing one, and it is the part a buyer checks.

No formal certifications

We are not ISO 27001, SOC 2, BSI C5, TISAX or HIPAA certified. Those are audits we have not completed. If one is mandatory for your buyer, ask us before you build on us.

No sovereign cloud programme

We are not part of Gaia-X or SecNumCloud. The structural facts — EU operator, EU disks, EU jurisdiction — are what most commercial buyers actually ask about, but they are not a certification.

One payment sub-processor

Stripe handles payments under its own sub-processor chain. Standard for EU SaaS, but name it in your privacy policy. Application data has no non-EU sub-processor.

Digital sovereignty, without a migration project

The policy argument is about dependence. The engineering question is what it costs you to stop depending.

The dependency, stated plainly

Most European software runs on three American platforms. That is fine until a price change, an export rule or a court decision is made somewhere you have no vote. Digital sovereignty is the work of not being in that position.

Your container does not care

Hostim runs standard Docker images on Kubernetes. If your app builds into a container today, it runs here today, and it runs somewhere else tomorrow. Sovereignty you cannot reverse is just a different lock-in.

What it costs

From €2.50 per month per app, with managed PostgreSQL, MySQL and Redis on the same bill. A European cloud provider is not a premium product here. It is usually the cheaper line item.

EU sovereign cloud FAQ

What is an EU sovereign cloud?

An EU sovereign cloud means three things at once: the data is stored in the EU, the operator is an EU-incorporated company, and the governing jurisdiction is EU law. Residency alone is weaker — a US-owned platform with a Frankfurt region has EU residency but is not sovereign, because its parent company remains subject to US law.

How is data sovereignty different from data residency?

Residency is about the disk. Data sovereignty is about the disk, the company and the courts. A US provider can give you an EU region and still be compelled under the US Cloud Act. An EU operator with no US entity cannot be.

What is the difference between data sovereignty and digital sovereignty?

Data sovereignty is a question about one dataset: where it lives, who holds it, which law reaches it. Digital sovereignty is the wider question of whether your organisation depends on infrastructure it has no influence over. Hostim.dev answers the first directly, and helps with the second by running standard Docker images, so moving in or out is a deployment change rather than a rewrite.

Is Hostim subject to the US Cloud Act?

No. Hostim is operated by HOSTIM.DEV UG (haftungsbeschränkt), a German company with no US parent, no US subsidiary and no US infrastructure. There is no US legal entity in the chain for a US authority to serve.

Do I need Standard Contractual Clauses to use Hostim?

No. Both Hostim and your data are inside the EU, so there is no transfer to a third country. Schrems II obligations — SCCs, a Transfer Impact Assessment, supplementary measures — apply to transfers, and there is no transfer to assess.

Where exactly is the data stored?

On bare-metal servers in Falkenstein, Saxony, Germany. Application data, managed database data, backups and logs all stay in that one region. There are no replicas outside Germany.

Are there non-EU sub-processors?

Stripe processes payment data under its own contracts, which is standard for EU SaaS and worth naming in your privacy policy. For application data — your users, your database, your storage volumes — there is no non-EU sub-processor.

How do I get a Data Processing Agreement?

Email support@hostim.dev. We send a signed DPA as a PDF in English or German. The substance meets GDPR Article 28.

Are you ISO 27001, SOC 2, BSI C5 or TISAX certified?

No. We have not undergone those audits and we do not claim them. We are also not part of Gaia-X or SecNumCloud. If your buyer requires a specific certification, ask us first — we will tell you honestly whether we can meet it.

Can a German court compel access to my data?

Yes, under German law, like with any German company. That is the trade-off of EU sovereignty: EU legal access instead of foreign legal access. It is a narrower and more predictable exposure, not zero exposure.

Start now

Put something live today.

Open the dashboard and deploy a Docker image, a Git repo or a template. The 5-day trial project needs no card.