The hyperscaler problem
AWS, Azure, and GCP are US companies. Even when they offer EU regions, they remain subject to the US CLOUD Act. For a zero-knowledge encryption product, using a US-controlled infrastructure provider undermines the security model.
Why EU-owned infrastructure
Our servers run in Falkenstein, Germany, operated by a European company with no US parent, no US investors, and no US operational presence. Key factors:
- No US jurisdiction: European company, European ownership — cannot be compelled under the CLOUD Act
- Own hardware: Dedicated servers in EU-operated data centres. No abstraction layers, no shared hyperscaler fabric.
- Cost efficiency: Dedicated servers at a fraction of hyperscaler pricing. We pass these savings to customers.
- Renewable energy: Our primary data centre runs on renewable energy.
What about redundancy?
We use Falkenstein, Germany as our primary location. For geographic redundancy, we plan to add a secondary location in the Netherlands. Both EU-owned and operated.
The trade-off
EU infrastructure providers do not offer the managed services ecosystem of AWS. We build more infrastructure ourselves: load balancing, backup rotation, monitoring. This is a trade-off we accept because the alternative — putting encrypted data on US-controlled infrastructure — would undermine the entire product.