Skip to content
Independently verified · Quarterly re-audit
EU VETTED

Aruba Cloud

VERIFIED
Cloud & hosting · Italy
Founded 1994 · arubacloud.com ↗

Italian sovereign cloud (Aruba S.p.A.), 4 Italian DCs (Arezzo/Bergamo/Rome), ACN-qualified up to AI3/QC3 for public administration.

Why this score?

Aruba Cloud is the cloud division of Aruba S.p.A. (Ponte San Pietro, BG, Italy; P.IVA 01573850516), Italy''s largest privately-held cloud and hosting provider — proprietary infrastructure with four Italian data centres in Arezzo (IT1 + IT2), Bergamo (IT3), and Rome (IT4), Rating 4 ANSI/TIA-942-C at IT1 (the highest tier), ISO/IEC 27001 + 27017 + 27018 + 27035 certifications, qualified by Italy''s ACN (National Cybersecurity Agency) up to AI3 / QC3 levels for IaaS / PaaS / SaaS, CISPE Code of Conduct, DORA and NIS 2 compliant — rated 3/5: an exceptionally strong infrastructure and certification profile, but Aruba does not publish a standalone DPA; data-processing terms are buried in the general T&Cs and a separate data-processing agreement is only obtainable by contacting dpo@aruba.it, which under EU Vetted''s rubric caps the score at 3/5 despite zero CLOUD Act exposure.

SCORE
3.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
not disclosed
JUMP TO
OVERVIEW

About Aruba Cloud

Aruba Cloud is the cloud division of Aruba S.p.A. — Italy's largest privately-held cloud and web-services group, founded in 1994 and headquartered in Ponte San Pietro (BG), Italy (P.IVA 01573850516, C.F. 04552920482). The company operates proprietary infrastructure across four Italian data centres: IT1 and IT2 in Arezzo (the unique twin-DC configuration only a few kilometres apart that enables low-latency redundancy), IT3 in Bergamo (the flagship Global Cloud Data Centre campus), and IT4 in Rome. IT1 carries the highest Rating 4 ANSI/TIA-942-C-2024 data-centre certification. Compliance posture is among the strongest in Europe for Italian public-sector procurement. Aruba Cloud is qualified by Italy's **ACN** (Agenzia per la Cybersicurezza Nazionale / National Cybersecurity Agency) at the **AI3** level for infrastructure and **QC3** level for services — the qualifications required by the Italian Public Administration (PA) to host critical and strategic data. Certifications include ISO/IEC 27001, ISO 27017, ISO 27018, ISO 27035, and ISO 9001 at the management-system level. The company is a **CISPE** Code of Conduct signatory (the European cloud-infrastructure association founded explicitly around GDPR alignment), **DORA**-compliant for EU financial-services operational resilience, and **NIS 2**-compliant. The product is a VMware **Pinnacle Partner** (the highest VMware partnership tier) and offers data-sovereignty positioning under the explicit promise that "your data stays in Italy." Aruba S.p.A. also operates the .it domain registry, giving it deep ties to Italian internet infrastructure. The product surface covers bare metal, VPS, public cloud compute, VMware cloud, object storage, and managed services. Pricing is highly competitive: Cloud Server Pro starts from roughly €1/month for the smallest entry tier (the headline "Cloud Server PRO from €1/month" offer is a long-running positioning). Best fit: Italian SMBs, agencies, the entire Italian public-sector procurement chain (ACN-qualified workloads), VMware shops in Italy and Southern Europe, regulated industries (financial services post-DORA), and any EU buyer needing geographic diversity from DACH-clustered alternatives. Together with Hetzner (DE), OVHcloud (FR), Scaleway (FR), IONOS (DE), UpCloud (FI), STACKIT (DE), Cleura (SE), Exoscale (CH), T Cloud Public (DE), and Stackscale (ES), Aruba Cloud completes the 11-vendor procurement-grade EU hyperscaler-alternative shortlist.
SUB-PROCESSORS

Sub-processor map · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
CERTIFICATIONS

Frameworks & certifications

ISO/IEC 27001
ACTIVE
ISO/IEC 27017
ACTIVE
ISO/IEC 27018
ACTIVE
FEATURES

Capability matrix

INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) Yes
COMPLIANCE & GOVERNANCE
Audit log Yes
Self-host / on-prem option No
PRICING

Pricing & tiers

PAID
from €1/mo
View pricing page ↗
PUBLIC DOCUMENTS

Public documents

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement — this caps the compliance score (see How we score).
Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    — missing
    missing
ALTERNATIVES

Alternatives in this category