Digital sovereignty is control, not geography
A data center inside the EU doesn't decide who can read your data — keys, access paths and exit options do. enclaive gives you all three, on whatever infrastructure you run.
ENCLAIVE PROVIDES THE CONFIDENTIAL COMPUTING LAYER OF GERMANY'S GOVTECH-PLATFORM. BUILT AND OPERATED IN GERMANY.
Sovereignty has become a label on region names. Under procurement scrutiny three gaps keep surfacing, and a residency clause closes none of them.
The jurisdiction gap
If your provider can decrypt your data, the provider can be compelled to produce it — under foreign legal access obligations that don't stop at an EU region's border. Residency answers where data sits, not who can be forced to hand it over readable.
The operator gap
Contracts promise that provider staff won't access your workloads. Technically, admins, support engineers and hypervisor operators still can. A promise backed by policy is an audit finding waiting for its moment; oversight bodies increasingly ask for technical enforcement.
The exit gap
Sovereignty you can't leave isn't sovereignty — it's a different dependency. When keys live in one provider's KMS and workloads only run on one stack, jurisdiction risk is replaced by concentration risk, and procurement knows it.
enclaive closes all three gaps with the same mechanism: workloads are always encrypted — now also while they run — and decryption keys are solely held by you, released only to environments that cryptographically prove they're untampered. Control stops being a contract clause and becomes a property of how the system runs.
Bring your own key or hold your own key in a virtual HSM under your control — independent from any cloud provider's KMS. Key release is gated on workload attestation, and the custodian role stays separate from platform administration.
Data stays encrypted even while it's processed, inside sealed environments the infrastructure operator cannot open. A provider cannot hand over what it cannot decrypt — and neither can a coerced or compromised insider.
The same protections deploy to AWS, Azure, Google Cloud, European providers and on-prem hardware. Because keys and baseline travel with you, changing providers — or leaving us — stays a project, not a crisis.
Attestation records, key custody coverage and access-path evidence are generated from live operations. When a regulator, auditor or parliamentary committee asks who can access the data, the answer comes with artifacts, not assurances.
A sovereignty mandate shouldn't dictate your platform choice. With control enforced at the workload level, every deployment route becomes defensible — and switching between them stays possible.
Keep AWS, Azure or Google Cloud economics and services while your keys and workload access stay outside the provider's reach. Often the fastest defensible path when a full provider change isn't realistic.
Run on IONOS, STACKIT or other EU providers with the same baseline — combining EU jurisdiction with technical operator exclusion, so the sovereignty case doesn't rest on the provider's nationality alone.
Keep the most sensitive workloads on your own hardware, burst or migrate the rest, and operate everything under one control plane, one key model and one evidence trail.
Built to survive a tender
Public and regulated procurement doesn't buy narratives; it scores criteria. This is how the platform answers the questions that appear, in some form, in every sovereignty-sensitive RFP.
Who holds the keys? You do — BYOK/HYOK in a customer-controlled virtual HSM, with documented separation of duties between key custody and platform operations
Can the operator access data? No — enforced by hardware-based encryption in use, verifiable through remote attestation, not by contractual assurance
What is the exit path? Documented and rehearsable — cloud-agnostic baseline, customer-held keys, and deployment into your own accounts
What evidence exists? Continuous attestation and access-path artifacts, mapped to GDPR, NIS2 and sector control frameworks
Where is the vendor? Germany — enclaive GmbH is owned and operated in the EU, under EU jurisdiction
What sovereignty owners ask
Isn't an EU region from a hyperscaler already sovereign?
An EU region answers data residency. It doesn't change who can technically decrypt the data or which legal obligations bind the provider's parent company. Sovereignty holds when the provider cannot produce readable data regardless of where the request comes from — which is a key custody and encryption-in-use question, not a geography question.
Does this protect against foreign legal access, like the US CLOUD Act?
We'll state it precisely rather than absolutely: a provider can only be compelled to hand over what it holds. With keys in your custody and data encrypted in use, what the provider holds is ciphertext it cannot decrypt. Your legal team should assess your specific exposure — we'll gladly join that conversation with the technical facts.
Do we have to leave the hyperscalers to be sovereign?
No — that's the point of enforcing control at the workload level. Many organizations keep hyperscaler infrastructure and add customer-held keys and operator exclusion on top. Others choose a European provider or hybrid setup. All three routes use the same baseline, so the decision stays reversible.
How is this different from the hyperscalers' own sovereign cloud offerings?
Those offerings change who operates the infrastructure and where; the operator still runs the stack you depend on. enclaive changes what any operator can see: nothing readable. It's also provider-neutral, so your sovereignty posture doesn't dissolve if you change infrastructure later.
We're subject to formal accreditation. What can you show an assessor?
Attestation records, key custody documentation, separation-of-duties models and access-path evidence, mapped to the relevant control frameworks. For certification specifics and our own security posture, see the Trust & security center.
What does the migration path look like for existing workloads?
Most workloads move without code changes — into confidential VMs, Kubernetes or databases. Programs usually start with key custody (the fastest sovereignty win), then move the most sensitive workloads into sealed environments, then standardize. Exiting VMware at the same time? The two programs share one landing zone.
Sovereignty is not one product — it is what these enforce together.
BYOK and HYOK in a virtual HSM you control, independent of any provider's KMS.
Workloads encrypted in use on hyperscalers, EU clouds or your own hardware.
Portable confidential Kubernetes — the same baseline wherever the estate moves.
Operate every route from one place, with the evidence trail oversight bodies ask for.
Put your sovereignty case on technical ground
Bring your requirement — a tender criterion, an audit finding, a board mandate. We'll show you which controls answer it, what the evidence looks like, and where your current setup stands.
Visit the Trust & security center.
.png)
