00 Sovereignty

What sovereign cloud really means

Most "sovereign cloud" offerings are US platforms with an EU label. Sovereignty by contract is not sovereignty.

"Sovereign cloud" has become a label that US hyperscalers apply to EU-region deployments — AWS, Azure, Google and Oracle all sell one. But the parent company remains subject to US law, so under the CLOUD Act the data can be compelled regardless of where it sits. That is sovereignty by contract and promise. UltimaOS takes the other route: sovereignty by architecture. If you are comparing EU cloud provider options, or weighing cloud computing Europe against a US hyperscaler's local region, that distinction is the one that decides the answer. It is built and operated in the EU, under EU jurisdiction, and encrypts everything end-to-end so that even the operating system cannot read your data — there is nothing readable to compel.

01 Overview

Two kinds of sovereignty.

01

Sovereignty by contract

A US hyperscaler runs your workload in an EU region and promises, contractually and operationally, to keep it there. The infrastructure is genuinely local — but the parent company is a US entity, so US law still reaches it. The promise is only as strong as the law behind the vendor.

02

Sovereignty by architecture

The provider is an EU entity operating on EU infrastructure under EU jurisdiction, and the data is encrypted end-to-end so the provider holds only ciphertext. There is no readable data to hand over and no foreign parent to compel. Sovereignty is a property of how the system is built, not a clause you have to trust.

03

Why the distinction is not academic

The US CLOUD Act lets US authorities compel data held by US companies wherever it is stored. A sovereign-region deployment of a US platform does not remove that exposure; end-to-end encryption under EU control does.

02 Details

How UltimaOS delivers it.

Data sovereignty on UltimaOS is not a tier or a region setting — it is the default state of the operating system.

01

EU-built, EU-hosted, EU jurisdiction

UltimaOS runs entirely on EU infrastructure under EU law, with no transatlantic transfer. GDPR alignment is a property of the architecture rather than a configuration you enable.

02

Nothing readable to compel

Every file, message and document is encrypted end-to-end on your device. The server holds only ciphertext and has no key, and there is no password database — so there is no plaintext for any authority to demand.

03

Post-quantum boundary

The operating system uses NIST post-quantum algorithms — ML-KEM-768 for key encapsulation and ML-DSA-65 for signatures — so the sovereign boundary holds against harvest-now-decrypt-later as well as today's threats.

04

No foreign parent, no ad model

There is no US parent company to bring the workload back under foreign law, and no advertising business that would profile what it cannot read.

03 Key points

Choosing a sovereign cloud.

  1. 01

    Ask who the European cloud provider ultimately answers to

    If the parent company is subject to US law, the deployment is exposed under the CLOUD Act regardless of the region. Sovereignty follows the entity, not just the datacenter — which is why an EU-headquartered provider and a US hyperscaler's EU region are not the same purchase.

  2. 02

    Ask whether the provider can read the data

    If the provider holds the keys, it can be compelled to use them. End-to-end encryption with no server-side key removes the provider as a party that can hand over plaintext.

  3. 03

    Prefer sovereignty you can verify in the architecture

    EU entity, EU hosting, EU jurisdiction and end-to-end encryption are structural facts, not promises. That is the sovereignty UltimaOS is built on.

04b References

Standards and references.

05 Frequently asked

Sovereign cloud — common questions

What does sovereign cloud mean?

Short answer

It means your data is subject only to the laws of your own jurisdiction and beyond the reach of foreign authorities. In practice, many 'sovereign cloud' offerings are US platforms deployed in EU regions, which still fall under US law via the CLOUD Act. Genuine sovereignty requires either an EU-controlled provider or end-to-end encryption so there is nothing readable to compel.

Is an AWS/Azure/Google sovereign cloud actually sovereign?

Short answer

The infrastructure is local, but the parent company is a US entity subject to US law, so data can be compelled under the CLOUD Act regardless of region. That is sovereignty by contract, not by architecture.

How is UltimaOS different?

Short answer

UltimaOS is an EU entity operating on EU infrastructure under EU jurisdiction, and it encrypts everything end-to-end so the provider holds only ciphertext. There is no US parent to compel and no readable data to hand over.

Does end-to-end encryption make sovereignty stronger?

Short answer

Yes. If the provider cannot read your data, there is no plaintext to demand — so sovereignty no longer depends on jurisdiction alone. UltimaOS combines both: EU jurisdiction and end-to-end encryption.

Is this GDPR compliant?

Short answer

UltimaOS is built and hosted in the EU under EU jurisdiction, encrypts data end-to-end, and keeps no password database, so GDPR alignment is a property of the architecture rather than a setting.

Free forever

Free for individuals and families. Forever.

No ads, no data mining, no trial clock. Individual and family accounts are free — permanently. Organisations pay per seat, and that is what funds it.

Request your account Invite-only while we scale