AWS European Sovereign Cloud alternative: sovereignty without a US parent

AWS and Microsoft now sell a "sovereign" cloud built for Europe, with EU staff and local governance. The operator is still a US company, so the US Cloud Act still applies. Bunker is run by a European entity with no US parent, hosted in France, on a fully open-source stack.

The AWS European Sovereign Cloud is a real engineering effort. A dedicated region in Brandenburg, Germany, staffed by EU residents, with operations and support kept inside the European Union. Microsoft has gone the same way with its EU Data Boundary and a Sovereign Cloud line. Both genuinely solve data residency and local operations.

They do not change who owns the operator. Amazon and Microsoft are US companies, and a US parent stays within the reach of the Cloud Act and FISA Section 702 regardless of where the data sits. That gap is exactly what European data protection authorities debated during the EUCS sovereignty discussions and what Schrems II put on the table. Bunker closes it differently: a European operator, no US ownership, code you can read and run yourself.

Where a European operator changes the legal picture

Jurisdiction follows the operator

A US company must comply with a Cloud Act order even for data held in its German region. Bunker has no US parent and no US presence, so a US warrant has no entity to serve. Your data stays governed by EU law by structure, not by contract clause.

Open source you can audit

Bunker runs on Kubernetes, PostgreSQL, Ceph S3 and open LLM stacks. Your security team can read the code that holds your data, line by line. The hyperscaler sovereign offers keep their control plane proprietary, so the audit stops at the documentation.

Managed or on your own racks

Run Bunker as a managed sovereign cloud, or install the same stack on hardware you own. The AWS and Microsoft sovereign regions stay tied to their own datacenters and operating model, with no path to bring the platform in-house.

No egress tax on leaving

Bunker charges no egress fees and uses open formats, so moving data out costs nothing extra. On the hyperscalers, data transfer pricing and proprietary services raise the cost of an exit the longer you stay.

Bunker against the hyperscaler sovereign offers

Criterion Bunker AWS European Sovereign Cloud Microsoft EU Data Boundary
Operator nationality European Amazon, a US company Microsoft, a US company
US parent company None Amazon.com Inc. (US) Microsoft Corp. (US)
Within scope of the Cloud Act / FISA 702 Outside US extraterritorial law by jurisdiction Yes, the US parent remains bound Yes, the US parent remains bound
Data residency in the EU France Yes, region in Brandenburg, Germany Yes, EU Data Boundary
EU staff and local governance Yes Yes, EU residents and local control Yes, EU operations
Open source and auditable Full stack, public code No, proprietary control plane No, proprietary control plane
Reversibility / on-premise Re-internalisable on your hardware No, tied to AWS No, tied to Azure
Egress fees None Charged Charged

Why data residency is not the same as legal sovereignty

AWS EUSovereign CloudEU operatorData residencyLegal sovereignty

Data residency answers one question: where do the bytes physically live? The AWS European Sovereign Cloud answers it well, with a region in Germany, EU staff and a governance structure designed to keep operations inside the Union. Microsoft does the same with its EU Data Boundary. For many GDPR concerns, that is a meaningful step, and it removes the simplest objections about transatlantic transfers.

Legal sovereignty answers a harder question: which law can compel the operator? The Cloud Act lets US authorities order a US company to produce data it controls, including data stored by a foreign subsidiary. FISA Section 702 adds surveillance powers over non-US targets. As long as the operating entity has a US parent, those obligations follow the company, not the datacenter. Local governance and EU personnel reduce the practical likelihood of a request reaching your data, yet they do not extinguish the parent company's duty to comply. Bunker sits outside that perimeter because the operator is European and has no US owner to be served. The distinction is the one regulators raised throughout the EUCS debate and the one Schrems II forced organisations to take seriously.

Frequently asked questions

Isn't AWS European Sovereign Cloud already sovereign?

It is sovereign on data residency and operations. The region sits in Germany, staff are EU residents, and governance is local. The limit is legal: Amazon is a US company, so the Cloud Act and FISA 702 still bind the parent. Sovereignty over the physical and operational layer does not remove that obligation over the corporate layer.

Does Microsoft EU Data Boundary keep my data away from US authorities?

The EU Data Boundary keeps storage and most processing inside the European Union, which addresses data residency. It does not change Microsoft's status as a US company. A Cloud Act order can still be directed at the parent, and Microsoft has acknowledged it cannot guarantee it would never have to comply. Residency and legal reach are two separate questions.

How is Bunker actually outside US jurisdiction?

Bunker is operated by a European entity with no US parent and no US presence, on servers in France. US extraterritorial law works by compelling a company under US jurisdiction. With no such company in the chain, a US order has no party to enforce against. We state this as a structural position, by jurisdiction, rather than a claim of absolute immunity.

What do I give up by choosing a European operator over a hyperscaler?

You give up the very long catalogue of proprietary managed services that AWS and Azure offer. Bunker covers the infrastructure most SMEs and mid-market companies need: compute on Kubernetes, PostgreSQL, Ceph S3 storage, private LLMs, monitoring. In exchange you get auditable open source, no egress fees, and the option to run the same stack on your own hardware. An audit of your workloads shows what maps over cleanly and what needs work.

Get sovereignty that holds up legally

We map your workloads, compare the real exposure, and build a path to a European operator you can audit.