Comment by DarrenDev
10 hours ago
EU sovereign clouds are taking off right now - especially when it comes to sensitive data (government, healthcare, etc.). Lots of players moving into the space. The common denominator - nothing touches the US.
AWS, Azure, GCP, Oracle, Schwarz Digits, SAP
Requiring that you believe those companies that they won’t hand the keys over to the US at the first ask.
Like, the critical problem with the AWS sovereign pitch is that you must believe that they won’t give the keys to the US, and they also won’t give the source code that’s hosted in the US to the government either for them to find vulnerabilities in. I don’t know if that’s good enough unless you just need the data to stay in the EU and you don’t care if another country sees it.
I know they probably did some work on it (what if primary AWS goes rogue and the EU entity must work without it) but I don’t know if they explained how they’re safe to the public.
The harder problem here is that any real EU sovereign platform would have to come with ironclad guarantees that it isn't going to be directly or indirectly sold to a US party. And when enough customers move that marketshare is affected the bags with money tempting shareholders will get larger and larger.
Isn’t that counterbalanced by the fact that the reason they exist in the first place is to be a sovereign platform?
I am assuming the reason companies switch to them is not price or tech. US cloud providers have the advantage on both.
Selling EU companies data would mean destroying trust over their main selling point, not to mention incur on EU wrath.
Feels like living one whistleblower away from doom.
I refer to fully EU clouds, parent list includes US clouds that do not need bags of money, Clouds Act in enough.
You can strike at least four of those.
> AWS, Azure, GCP, Oracle
What? Those are US companies, they will have to give out your data under the Cloud Act. Only Schwarz and SAP are free from that by being German companies.
> Only Schwarz and SAP are free from that by being German companies.
Not true. You also have to be sure that the company directors will never travel to the US even for a holiday or any third party country that would uphold an extradition request from the US.
It's just email. Nobody is going to jail to protect your email.
If you care that much run your own email server.