Sovereign & hybrid cloud

Which data may live where, and who enforces it

Hosted in Europe says nothing until you say which jurisdiction the provider answers to. Sovereignty is a placement rule, written per class of data and enforced by the infrastructure rather than by a policy document.

The jurisdiction follows the provider, not the datacentre.

Since 2018, data held by a provider subject to US law can be reached wherever it physically sits. A European region is therefore an answer to the wrong question, and it is the answer most contracts still give.

We start from the data instead. Each class gets a written rule saying where it may live, who holds the keys, and what happens to its backups. The rule then lives in the infrastructure, where a wrongly placed workload is refused at creation rather than discovered in an audit.

What we do

Four workstreams so where the data lives becomes a decision rather than a consequence.

WORKSTREAM 01Per class, not per platform

Classification and placement rule

Each class of data gets a written rule: allowed hosting, forbidden hosting, who holds the encryption keys and which framework applies. The rule is negotiated once, then applied everywhere.

an exception is named, dated and reviewed, never implicit

  • Allowed and forbidden hosting per class
  • Keys held by you where sensitivity demands it
  • Exceptions dated and reviewed twice a year
WORKSTREAM 02Three zones, one rule

Qualified and private hosting

Public European cloud, private infrastructure or SecNumCloud-qualified hosting, chosen by class rather than for the whole estate. Most estates need all three.

the choice follows the data, not a preference for one provider

  • Qualified hosting where the framework requires it
  • Private infrastructure for what must not leave
  • Public European cloud for the rest
WORKSTREAM 03What crosses is listed

Interconnection

Hybrid does not mean two platforms side by side. The two halves talk over a private link, with a latency budget and an explicit list of what is allowed to cross.

everything not listed is refused by default, and the refusal is logged

  • Private link, end-to-end encryption
  • One directory of record, short-lived tokens
  • A latency budget, beyond which sync calls are barred
WORKSTREAM 04Backups included

Residency control

Placement is audited against the rule, backups included. A backup inherits the sensitivity of its source, and this is where sovereignty most often leaks without anyone deciding it.

a default option can move a copy out of the perimeter on its own

  • Placement audited against the written rule
  • Backups and cross-region replication inspected
  • Refusals and exceptions readable in the log

What you get

One project runs through the four deliverables below: the hybrid foundation of a public-service operator, forty-seven workloads across three zones. Each line states what is actually handed over, in the order it is handed over.

01

The classification, and its placement rule

Per class of data: allowed hosting, forbidden hosting, applicable framework and who holds the keys. This is the file the whole rest depends on, and the only one the business has to arbitrate.

02

The rule inside the infrastructure

Zones declared with the jurisdiction each answers to, and a wrongly placed workload refused at creation. Backups inherit the sensitivity of their source, which is what most rules forget to say.

03

The interconnection between the two halves

A private link, end-to-end encryption, one directory of record, and an explicit list of what may cross in each direction. Everything else is refused by default and appears in the log.

04

The residency audit

Workloads, volumes and backups inspected against the rule. What the audit finds is rarely a decision someone made: it is usually a provider default that nobody turned off.

How we deliver

PHASE 012 to 6 weeks

Inventory

depending on the number of workloads, dependencies and residency constraints

  • Inventory and dependencies per workload
  • One strategy per workload, retirement included
  • Costed trajectory with hidden costs modelled
PHASE 024 to 10 weeks

First wave

depending on the landing zone to lay down and the workloads selected

  • Landing zone described as code
  • Cutover rehearsed, fallback proven
  • Fourteen days of comparison before switch-off
PHASE 033 to 6 months

Following waves

depending on the workloads left and how coupled they are

  • Following waves on the same template
  • Workloads rewritten where moving is not enough
  • Team upskilling
PHASE 04continuous

Operate

service commitment defined with you

  • Cost attached to the workload and tracked
  • Guardrails enforced at creation
  • Reversibility proven, not declared

Where the European market stands

15%
of the European cloud market was held by regional providers in 2025, against more than 70% for the three US hyperscalers
2018
the year of the Cloud Act: data held by a provider under US law can be reached wherever it physically sits
March 2026
the ANSSI and the German BSI publish joint criteria for cloud sovereignty, the first basis for a shared Franco-German doctrine

Enterprise-grade AI: sovereign and compliant

Adservio runs your AI platforms on sovereign cloud, with European models and native compliance: the security and control large organisations need

Learn more

Sovereign cloud

OVHcloud, Scaleway, HDS hosting and SecNumCloud: your data and your models stay under European jurisdiction.

European models

Self-hosted models (Mistral, Llama), with no dependency on US hyperscalers, operated right next to your systems.

ConformitéAI ActEUSouverainetéRGPDNIS2 · DORA
European public cloudSecNumCloud-qualifiedInternal infrastructure

Native compliance

A stack compliant by default: AI Act, DORA, NIS2 and GDPR, with model traceability and governance.

24/7 cyber-resilience

SOC and SIEM monitored around the clock, AI red teaming and tested continuity plans for your critical systems.

Sovereignty under real constraint

An augmented IT department on a critical public-service network
GRDFEnergy & public services
Public service
Case(01)

An augmented IT department on a critical public-service network

12,000 employees covered · Critical systems kept in service

The challenge

A gas distribution network operator whose systems fall under essential-service obligations, where an interruption is not an incident report but a service outage, and where data residency is a constraint rather than a preference.

Our answer

An augmented IT department built around the existing teams, with the engineering standards and the governance that let critical systems evolve without the availability commitment being renegotiated each time.

Read the case study
Fraud caught in real time, under compliance and sovereignty constraints
BNP ParibasBanking & finance
Regulated
Case(02)

Fraud caught in real time, under compliance and sovereignty constraints

+40% fraud detection · −60% KYC time

The challenge

Detecting fraud on massive volumes in real time and making regulatory data reliable, under compliance and sovereignty constraints that rule out sending the data anywhere convenient.

Our answer

A governed data foundation with detection models wired into the flows and a copilot whose every answer carries its sources, hosted according to what each dataset allows rather than according to what is easiest.

Read the case study
TALK TO AN EXPERT

Decide where your data lives

A classification, a placement rule enforced at creation, and a residency audit that inspects the backups too.

By submitting this form, you agree to our privacy policy.

Frequently asked questions

No. Since the Cloud Act, data held by a provider subject to US law can be reached wherever it physically sits. The question is not where the datacentre is but which jurisdiction the provider answers to, and who holds the encryption keys.

That a provider meets the security and immunity-to-extraterritorial-law requirements set by the French ANSSI. It applies to an offer, not to a company, so a provider can hold it on one service and not on another. It is checked per service, not per logo.

No, and treating the whole estate the same way is what makes sovereignty unaffordable. Public data does not need qualified hosting. The cost comes from the classes that do, so the value of the exercise is in drawing the line precisely.

In the backups. The database sits in the right zone, and its automatic backup replicates to a second region outside it, because the provider enables cross-region replication by default. Nobody decided it, and an audit that only inspects workloads will not see it.

Not if the placement is arbitrated per class. What costs is running two full platforms in parallel out of caution. What works is one rule, three zones, and each workload in exactly one of them, with an explicit list of what may cross between them.

You do, on anything the framework or the sensitivity requires, with the keys managed on your own hardware module. A provider that can decrypt on request has not removed the risk, it has moved it into a contract clause.

Framing takes 2 to 6 weeks depending on the number of workloads, dependencies and residency constraints, and produces the classification and the placement rule. The rule is then enforced by the infrastructure within 4 to 10 weeks, along with the first residency audit, backups included.