- ISO 27001 certified + PCI DSS Level 2 + VMware Cloud Verified
- BSI C5 in preparation (Q3 2026)
- GDPR Art. 28 compliant
- Schrems II safe
- NIS2-ready
- No US CLOUD Act
Why data sovereignty matters
The reality: your data is at risk
If you run workloads with US hyperscalers, your data is subject to the US CLOUD Act (Clarifying Lawful Overseas Use of Data Act). That means US authorities can access your data — without your knowledge and without a German court order. Even when the servers are physically located in Europe.
The consequences:
- Schrems II (2020): The European Court of Justice invalidated the Privacy Shield. Transferring personal data to US providers has been legally problematic ever since.
- GDPR Art. 44–49: Transfers to third countries are only permitted under strict conditions. Standard Contractual Clauses (SCCs) do not provide sufficient protection against government access.
- NIS2 Directive (2024/2025): The new EU cybersecurity directive significantly tightens the requirements for critical infrastructure and its supply chains.
The US CLOUD Act — what you need to know
CLOUD Act: why US providers are a risk
The US CLOUD Act (2018) obligates all US companies — including AWS, Microsoft Azure, and Google Cloud — to hand over data to US authorities. This applies regardless of where the data is physically stored.
What this means for you:
| Aspect | US hyperscalers | focusnet |
|---|---|---|
| Access by US authorities | Yes, possible at any time | No, ruled out |
| Legal basis | US CLOUD Act | German/EU law |
| Data location | Worldwide, including EU | Germany exclusively |
| Transparency about requests | No obligation to inform | Not applicable |
| Schrems II compliant | Legally contested | Fully compliant |
| Data processing | Complex SCCs required | DPA pursuant to GDPR Art. 28 |
Bottom line: Only when both the provider and the infrastructure are fully subject to European law is genuine data sovereignty guaranteed.
Our sovereign product portfolio
A sovereign cloud is more than a compliance promise — it is a complete stack that covers every workload without data ever having to leave Germany. The focusnet portfolio spans six product areas that can be combined or used individually.
Managed Kubernetes — container workloads, fully managed
Fully managed Kubernetes clusters based on SUSE Rancher Prime and RKE2. Four tiers, from the Free tier for PoCs through Flex and Business (vCluster) up to Dedicated with its own control plane and worker nodes on a dedicated VLAN. KubeOVN as the CNI with native network policies and VPC isolation, Harbor registry included, Gateway API starting with the Business tier.
Sovereignty advantages: European distribution (SUSE), open source CNI without US dependencies, German operations and 24/7 support. Full GDPR compliance, including for multi-tenant SaaS platforms.
Managed SUSE Virtualization — VM workloads without VMware lock-in
Our HCI platform for traditional VM workloads, based on SUSE Virtualization — an open source hyperconverged infrastructure that we offer fully managed. Storage, compute, and networking in one platform, with the same Rancher UI as our Kubernetes clusters. Three tiers (S/M/L), cancelable monthly.
Sovereignty advantages: an open source stack without Broadcom/VMware licensing costs or politics, a European vendor (SUSE), and a seamless mix with Kubernetes through a unified management interface. Ideal for companies looking to diversify their VMware investments over the long term.
OpenStack & VMware IaaS — traditional virtualization in German hands
For workloads that expect a proven IaaS stack, we operate VMware Cloud Director and OpenStack in our data center locations. Full API compatibility for existing tooling landscapes, dedicated public IPs, dedicated org networks, Windows vCPU options. Proxmox in preparation as an additional option.
Sovereignty advantages: standards-compliant APIs without vendor lock-in, a German operator, and a German contractual relationship — even though the virtualization software comes from VMware or OpenStack, operational control rests entirely in Germany.
S3-compatible object storage — data that does not migrate
S3-compatible object storage with data held in Germany. Flat-rate tiers: €15/TB (up to 50 TB), €12/TB (50–500 TB), €7/TB (from 500 TB). No egress traffic within the focusnet network — internal workloads communicate with S3 free of charge.
Sovereignty advantages: S3 API compatibility without AWS, three locations for geographic redundancy, no hidden transfer costs when leaving the platform. Ideal for backup archives, log storage, data lakes, and application uploads.
Backup-as-a-Service & DRaaS — business continuity on German infrastructure
A complete backup portfolio based on Veeam: server BaaS for VMs and physical systems, Microsoft 365 BaaS for Exchange, OneDrive, SharePoint, and Teams, plus Disaster-Recovery-as-a-Service with replicated locations. Encrypted transmission and at-rest encryption with customer-owned keys.
Sovereignty advantages: even your M365 data — which normally lives with Microsoft — is copied into a German backup that is independent of Microsoft. This is the only layer Microsoft cannot take away from you in a crisis (licensing dispute, account lock, Schrems III).
GDPR compliance in detail
GDPR: not just a checkbox, but an architecture decision
Art. 5 — Principles of processing focusnet processes data exclusively for defined purposes, with data minimization and transparency. All processing operations are documented and auditable.
Art. 25 — Data protection by design (privacy by design) The focusnet platform is designed to be privacy-friendly from the ground up: network isolation at every layer (KubeOVN for Kubernetes, VLAN separation for virtualization, isolated tenant networks in OpenStack/VCD), encryption in transit and at rest, granular access control through RBAC and MFA.
Art. 28 — Data processing focusnet provides a complete data processing agreement (DPA) that fulfills all requirements of Art. 28 GDPR. Subprocessors are transparently listed and are likewise subject to German law.
Art. 32 — Security of processing Technical and organizational measures (TOMs) include: ISO 27001 certified data centers, encrypted communication, regular security audits, access controls, incident response processes.
Art. 33/34 — Notification duties focusnet has established processes for reporting data protection incidents — on time and in line with the GDPR. Affected customers are informed without delay.
Art. 44–49 — International data transfers Not applicable. focusnet does not transfer any data to third countries. All data remains in Germany. No Privacy Shield, no SCCs, no transfer impact assessments required.
NIS2 — ready for the new cybersecurity directive
NIS2: new obligations, new risks — focusnet is prepared
The NIS2 Directive (EU 2022/2555) massively expands the range of affected companies and tightens cybersecurity requirements. From 2025, strict obligations apply to:
- Critical infrastructure (KRITIS)
- Important entities (energy, transport, health, finance)
- Digital infrastructure and IT service providers
- Their entire supply chain
How focusnet meets NIS2 requirements:
| NIS2 requirement | focusnet measure |
|---|---|
| Risk management | ISO 27001 ISMS + PCI DSS Level 2 certified |
| Incident handling | 24/7 monitoring, defined escalation processes |
| Business continuity | Redundant infrastructure, BaaS + DRaaS based on Veeam |
| Supply chain security | No US dependencies, German supply chain |
| Encryption | TLS everywhere, encryption at rest |
| Access control | RBAC, MFA, audit logs across all platforms |
| Reporting obligations | Automated detection, fast communication |
Compliance checklist
Your compliance checklist for the sovereign cloud
- Data location Germany: all data in ISO 27001 certified data center locations in Germany (Berlin 01, Berlin 02, Hannover 01)
- No US CLOUD Act: the provider is a German company, no US parent, no US ownership
- GDPR Art. 28 DPA: complete data processing agreement available
- Schrems II compliant: no data transfers to third countries
- ISO 27001: certified information security management system
- Encryption: TLS in transit, encryption at rest, KMS options
- Access control: RBAC, MFA, audit logging across all platforms
- Network isolation: KubeOVN for Kubernetes, VLAN separation in virtualization, tenant networks in VCD/OpenStack
- Backup & recovery: Veeam-based BaaS for VMs, M365, and disaster recovery
- Incident response: defined processes
- NIS2-ready: measures for the EU cybersecurity directive implemented
- Transparency: regular security reports and audit options
Industry-specific advantages
Financial services Banks, insurers, and fintech companies are subject to strict regulatory requirements (BaFin, MaRisk, BAIT/VAIT). focusnet provides the necessary infrastructure sovereignty: dedicated clusters for Kubernetes, isolated virtualization clusters, full network isolation, audit trails across all platforms, ISO 27001 and PCI DSS L2 certification. No data leaves Germany, no US authority has access.
Healthcare Hospitals, clinics, and health-tech companies process particularly sensitive data (Art. 9 GDPR). focusnet provides the technical and organizational measures required for processing health data: encryption, access control, dedicated infrastructure, and full GDPR compliance — whether your application runs containerized on Kubernetes or as a classic VM on SUSE Virtualization or VMware.
Public sector Government agencies and public institutions must keep data within their own jurisdiction. focusnet meets the requirements of BSI IT-Grundschutz and offers a sovereign alternative to US hyperscalers — from object storage through IaaS to Kubernetes. No CLOUD Act risks, full control over the infrastructure.
Industry and manufacturing Production data, IoT telemetry, and digital twins demand secure, high-performance infrastructure. focusnet offers both Kubernetes with a dedicated VLAN for cloud-native workloads and Managed SUSE Virtualization for classic OT and MES systems — all in Germany, with guaranteed latency and without dependence on US providers.
Legal and tax advisory Law firms and tax advisors process highly confidential client data. focusnet provides the infrastructure needed to reconcile professional confidentiality obligations with modern cloud applications — including German Microsoft 365 backups that cannot be withdrawn by Microsoft in a crisis.
Schrems II and its consequences
Schrems II: why an "EU region" at AWS is not enough
In July 2020, the European Court of Justice invalidated the Privacy Shield with its Schrems II ruling. The consequence: transferring personal data to US companies is now only possible under very strict conditions.
The core problem: even when AWS, Azure, or Google Cloud operate servers in Frankfurt, the US parent company remains subject to the CLOUD Act. The physical location of the data is irrelevant — the legal access path remains.
What data protection authorities are saying:
- The Austrian DSB declared the use of Google Analytics unlawful (January 2022)
- The French CNIL reached a similar conclusion
- German state data protection authorities increasingly warn against US cloud services
The solution: only a provider that is fully subject to European law and has no US parent company offers genuine Schrems II compliance. focusnet is a German company with data center locations in Germany — without any US connection. All data remains at one of the three German data center locations (Berlin 01, Berlin 02, Hannover 01).
Technical sovereignty
More than location: technical sovereignty in detail
Infrastructure sovereignty:
- Data center locations in Germany with physical access control (Berlin 01, Berlin 02, Hannover 01)
- Dedicated VLAN per dedicated cluster and per virtualization tenant
- Dedicated public IPs on all relevant tiers
- Own public AS and own backbone — no shared infrastructure with US providers
Software sovereignty:
- Kubernetes stack: SUSE RKE2 (European distribution), KubeOVN CNI (open source, OVN/OVS-based), Harbor registry (open source)
- Virtualization stack: SUSE Virtualization as open source HCI, VMware Cloud Director, OpenStack
- Storage stack: S3-compatible object storage with an open API, Veeam for backup and disaster recovery
- No dependence on proprietary US cloud services
Operational sovereignty:
- German operations team
- German support, German language, German escalation paths
- German contracting parties — no indirect US contractual relationship
- No access by foreign authorities
Service levels:
- SLA: 99.9% availability for all managed tiers (Kubernetes Flex/Business/Dedicated, SUSE Virtualization, IaaS)
- Cancellation: 30 days to the end of the month, no minimum term
- Term discounts: −15 / −25 / −35% for 12 / 24 / 36-month commitments
FAQ
1. Is focusnet a German company?
Yes. focusnet is a German company headquartered in Germany. There is no US parent company and no US ownership that could enable CLOUD Act access.
2. Is focusnet subject to the US CLOUD Act?
No. The US CLOUD Act applies exclusively to US companies and their subsidiaries. focusnet is not a US company and has no US ownership. Access under the CLOUD Act is therefore legally ruled out.
3. Which products does the sovereign platform include?
Six areas: Managed Kubernetes (RKE2/Rancher), Managed SUSE Virtualization (HCI for VM workloads), IaaS based on VMware Cloud Director and OpenStack, S3-compatible object storage, Backup-as-a-Service including Microsoft 365, and DRaaS based on Veeam.
4. How does focusnet protect my data from government access?
focusnet is subject exclusively to German and European law. Requests from foreign authorities are not answered without a German legal basis (e.g., a mutual legal assistance treaty or court order). German authorities only receive access when a court order is presented.
5. Does focusnet provide a data processing agreement (DPA)?
Yes. focusnet provides all customers with a complete DPA pursuant to Art. 28 GDPR. The agreement covers all technical and organizational measures, subprocessor registers, and provisions for data deletion — valid across all product areas.
6. Is focusnet suitable for companies classified as critical infrastructure (KRITIS)?
Yes. With ISO 27001 and PCI DSS L2 certification, dedicated infrastructure, NIS2 readiness, SOC-as-a-Service, and complete data sovereignty, focusnet is suitable for companies that fall under KRITIS regulations. Our BSI C5 is expected by the end of Q3 2026. For specific requirements, we offer individual consulting.
7. Can I avoid a transfer impact assessment (TIA)?
Yes. Since focusnet does not transfer any data to third countries and is subject exclusively to German law, a transfer impact assessment as recommended by the EDPB is not required.
8. What SLA does focusnet offer?
All paid managed tiers come with an SLA of 99.9% availability — Kubernetes (Flex, Business, Dedicated), Managed SUSE Virtualization, IaaS. The Free tier has no SLA (best effort).
9. What are the cancellation terms?
The cancellation period is 30 days to the end of the month. There is no minimum contract term. For voluntary commitments of 12 / 24 / 36 months, we grant term discounts of −15 / −25 / −35%.
Data sovereignty starts with the right platform
Switch to a cloud that keeps your data where it belongs — in Germany. Under German law. With a product portfolio that covers every workload. Without compromise.