Sovereign cloud
Sovereign cloud is infrastructure where data location, the legal jurisdiction governing that data, and the entity operating the systems are all controlled by a single defined authority — typically a country or economic bloc — rather than left to a foreign provider's terms of service. It addresses who can be compelled to hand data over, not just where servers sit.
Three separate things get bundled under "sovereign cloud," and most of the confusion comes from conflating them: data residency (which country the bytes physically sit in), legal jurisdiction (which country's courts and agencies can compel access to that data, regardless of where it sits), and operational sovereignty (who — which company, under which corporate structure — actually runs the infrastructure and can be pressured, acquired, or sanctioned). A hyperscaler opening an EU-based data center satisfies the first criterion alone. It does not resolve the second: a US-headquartered company remains subject to US law — including statutes with extraterritorial reach — no matter where its servers are physically located. This is why "sovereign cloud" offerings from US hyperscalers, however genuinely EU-operated their local subsidiaries are structured to be, get scrutinized differently than infrastructure run end-to-end by a company incorporated and headquartered in the jurisdiction in question.
In practice, sovereignty is a spectrum of choices, not a certification you either hold or don't. A regulated organization might keep its most sensitive workloads on-premise or with a bare-metal provider physically located in-country, run less sensitive workloads with an EU-headquartered cloud provider (Hetzner, OVHcloud, Scaleway, and UpCloud are commonly cited examples), and accept a US hyperscaler for workloads where residency matters less than feature parity. What matters for a genuine sovereignty claim is that the customer can name, concretely, which entity holds the encryption keys, which court has jurisdiction over a subpoena, and who can revoke access unilaterally. "Sovereign" used as a feature label without answering those three questions is usually marketing language borrowed from a term that originally described a specific, auditable arrangement.
Why it matters
For regulated industries and government bodies operating under GDPR, NIS2, or sector-specific rules, sovereignty isn't an abstract preference — it determines which legal system will actually hear a dispute, which authority can compel data disclosure, and whether a foreign statute can reach data that never physically left the EU. It also shapes contract enforceability: a data processing agreement governed by EU law and litigated in an EU court is a materially different guarantee than the same document sitting inside a global provider's US-governed master agreement. NIS2 specifically raises the bar on evidence — incident records, access logs, and sub-processor disclosures all need to hold up under regulatory review, which is easier to guarantee when the operator itself sits inside the same jurisdiction as the regulation.
How Sencai fits in
Sencai is built and run by Sencai Tech s.r.o. in Prague, under EU law — not a regional subsidiary of a non-EU parent. Its bring-your-own-cloud model keeps the account, contract, and billing for each connected provider — including EU-headquartered options like Hetzner, OVHcloud, Scaleway, and UpCloud — with the customer; nothing migrates, and access stays revocable at the provider anytime. Where Sencai provisions and bills capacity directly, that contract sits under Czech and EU law. Sencai doesn't hold ISO 27001 or SOC 2, and says so directly; instead it hands over the evidence a sovereignty review asks for — an exportable, hash-chained audit log, records of processing, a sub-processor register, a data-residency statement, and a published Data Processing Agreement.
See the platform's security and compliance model →