Sovereign by design, not by certificate.
It runs on local servers. The only keys stay local. A US-owned provider can't hand over data it never had.

A cloud provider can hand over the data, without ever telling anyone.
Here's the part nobody likes to say out loud. A US-owned cloud must obey US court orders, even for data kept in Europe. That is the CLOUD Act. A contract can't beat a law. So the real question isn't whether a provider would hand data over. It's whether they can be forced to. They can.
See the timeline
What does US-jurisdictional exposure cost?
Drag the sliders to match the environment. See the real cost of sovereignty gaps.
Three steps. One sovereign stack.
Host
Run it on local servers, an EU cloud, or both. Rediacc is an Estonian company. No US parent. No US control panel. Nothing for a US court order to reach.
Hold keys
Keys never leave the customer side. They are made there, not here. We never see data unscrambled. One command shows who holds each key.
Prove it
Run one command for a signed report on who holds every key. It satisfies the main EU rules: SecNumCloud 3.2, BSI C5:2026, the ANSSI-BSI joint declaration, and EDPB Recommendations 01/2020 Use Case 2.
Why data residency is not data sovereignty
A US-owned provider can keep data in Frankfurt and still be forced by US courts to give it up. Our setup removes that risk at the root. There are no keys for us to hand over. There is no phone-home channel to tap.
Why data residency is not data sovereignty
| US-owned provider | Rediacc (no keys to hand over) |
|---|---|
| Provider answers to US courts no matter where the data sits | Estonian operator. No US parent. Nothing for the CLOUD Act to reach. |
| Vendor holds the keys. It can unscramble the data on legal demand. | Keys made on the customer side. The vendor never holds them, so there's nothing to seize. |
| Data requests logged by the vendor, never disclosed | SHA-256 signed audit log. Every key access is recorded and readable. |
| Locked backup format. Leaving means a vendor-run migration. | Open format (btrfs send, tar). The exit is just a working copy. Data Act compliant. |
| Recovery testing grows with data size. Days for large repos. | Instant copy via btrfs. 100 GB and 100 TB copy in the same seconds. |
What it includes
CLOUD Act immunity, built in
No US parent company. No keys parked with a vendor. The design itself is the defense. The Carniaux testimony to the French Senate (18 June 2025) ended the idea that a contract can replace real immunity.
EU Data Act 2027 ready
Open data format. No fees to leave, ever. Every backup is a working copy, ready to pick up and move. That meets Data Act Articles 23-31 well before the 12 January 2027 deadline that bans switching charges. The whole Kubernetes cluster moves too, data and all. The switch takes about 16 seconds.
SecNumCloud and C5:2026 aligned
All four parts of the ANSSI-BSI joint declaration (17 November 2025) are covered. Data stays in the EU. Only EU law applies. No outside power can reach it. And operations continue without any non-EU tools.
Short on time?
Skip the deep-dive. Grab the five-minute version, short enough to read at a stand-up.
Download short brief (PDF)Sovereignty compared
Most vendors offer data residency. That just means where the data sits. None deliver what we do by design: customer-held keys, an EU-only operator, and real CLOUD Act immunity.
Sovereignty compared
| Capability | Veeam | Rubrik | AWS Sovereign | Microsoft Bleu | Keepit | Rediacc |
|---|---|---|---|---|---|---|
| CLOUD Act immunity (no US parent company) | ✗ | ✗ | ✗ | ✓ | ✓ | ✓ |
| Customer holds the keys (provider can't read the data) | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |
| EU-only operator (no US parent company) | ✗ | ✗ | ✗ | ✓ | ✓ | ✓ |
| SecNumCloud / C5:2026 certification path | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |
| Open exit format (Data Act Art. 30) | ✗ | ✗ | ✗ | ✗ | ✗ | ✓ |
| Self-hosted on owned servers | ✓ | ✗ | ✗ | ✗ | ✗ | ✓ |
| EU data residency by default | ✗ | ✗ | ✓ | ✓ | ✓ | ✓ |
Sources(13)
- Microsoft France Director of Public and Legal Affairs Anton Carniaux, French Senate inquiry on public procurement and digital sovereignty, 18 June 2025: "No, I cannot guarantee that, but, again, it has never happened before." Reported by The Register, 25 July 2025.
- Gartner, February 2026: European sovereign cloud IaaS spending forecast at $12.6B in 2026 and $23.1B in 2027, surpassing North America by 2027.
- European Commission, "Commission Advances Cloud Sovereignty Through Strategic Procurement," 17 April 2026. Cloud III €180M tender awarded to Post Telecom + OVHcloud + CleverCloud, STACKIT, Scaleway, and Proximus + S3NS + Clarence + Mistral AI. Zero US-headquartered primary contractors.
- CLOUD Act (Clarifying Lawful Overseas Use of Data Act), 18 U.S.C. 2713, 2018. Authorises US authorities to compel US-jurisdictional providers to disclose customer data stored anywhere in the world.
- EDPB Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data, Version 2.0, June 2021. Use Case 2: encryption as supplementary measure requires customer-exclusive key custody and technical unintelligibility at the importer.
- Keepit A/S, Copenhagen. SaaS-only backup for Microsoft 365, Salesforce, and Google Workspace. EU-incorporated, no US parent. Does not back up self-hosted or on-prem workloads.
- ANSSI SecNumCloud 3.2 qualification requirements. Providers must be majority EU-owned, EU-headquartered, and immune to extraterritorial law. Non-EU shareholders capped at 25% individually and 39% collectively. AWS Sovereign Cloud and Microsoft Bleu do not qualify.
- EU Data Act (Regulation (EU) 2023/2854), Articles 23-31. Operative since 12 September 2025. Full prohibition on switching charges from 12 January 2027. Providers must ensure functional equivalence after switching.
- Veeam Backup and Replication supports on-premises self-hosted deployment. Veeam does not hold direct sovereignty certifications; EU sovereignty story depends on partner IaaS (notably OVHcloud).
- AWS European Sovereign Cloud, GA 15 January 2026. Operates under four German GmbHs. US-headquartered parent (Amazon.com Inc.) remains subject to CLOUD Act.
- ANSSI-BSI joint statement on cloud sovereignty criteria, 17 November 2025. Four disqualifying criteria: strict data and support localisation, exclusive application of European law, absence of unauthorised access by extra-European third parties, and capacity to maintain business continuity without non-EU technologies.
- European Supervisory Authorities, "Designation of Critical ICT Third-Party Providers under DORA," 18 November 2025. First 19 CTPPs designated include AWS, Microsoft Azure, Google Cloud, IBM, Oracle, SAP, Salesforce.
- Keepit data residency policy: customer data stored exclusively in EU datacentres (Frankfurt, Amsterdam, Copenhagen). SaaS-only model with EU-only operator and EU-only storage.
Explore Other Solutions
Stop renting data back from a US-owned provider.
Run the first key-custody check in under a minute. Start the 14-day free trial.
Start free trial