Exoscale
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based This listing EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Swiss public cloud (Akenes SA, A1 Digital member), 6 EU/CH zones, ISO 27001 + FINMA + TISAX, Swiss-data-residency guarantee.
Exoscale is a European service hosted in Switzerland, with at most minor, transient US exposure under the CLOUD Act. It is listed under Cloud & hosting.
Assessment notes
Lausanne-based Swiss public cloud (Akenes SA, member of Austrian Telekom A1 Group's A1 Digital), founded 2011, with ISO/IEC 27001:2022 + ISO 27017 + ISO 27018 + FINMA Circular 2018/3 + TISAX + DORA-ready, six EU/EEA + CH data-centre zones in Geneva, Zurich, Vienna ×2, Frankfurt, and Zagreb, and a Swiss-data-residency guarantee for workloads placed in Swiss zones; AWS appears as an archival sub-processor on the customer-data path, which is the sole reason a minor CLOUD Act flag applies. Compute, object storage and SKS workloads stay on the EU/CH stack with no US dependency.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
European This listing Swiss/EEA-owned, with no significant US ownership; treated as European.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
- Sub-processors
- 9 · 2 US
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: Not assessed
-
Public DPA: Yes
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: Yes
Jump to
About Exoscale
Exoscale is a Swiss public cloud operated by Akenes SA (Boulevard de Grancy 19A, 1006 Lausanne; CHE-423.524.322), founded in 2011 and a member of A1 Digital, the digital subsidiary of A1 Telekom Austria Group, the largest telecoms group in Central and Eastern Europe. The product covers compute, storage, AI/GPU instances, Kubernetes (SKS), DBaaS (PostgreSQL, MySQL, Redis, OpenSearch, Kafka, Valkey), and object storage across six European data-centre zones: Switzerland (Geneva CH-GVA-2 and Zurich CH-DK-2), Austria (Vienna AT-VIE-1 and AT-VIE-2), Germany (Frankfurt DE-FRA-1), and Croatia (Zagreb HR-ZAG-1). Pricing is billed by the second at a flat rate across all zones, with no upfront commitment.
Compliance is enterprise-grade and built specifically for regulated workloads. Exoscale carries ISO/IEC 27001:2022, ISO 27017, ISO 27018, BSI C5, SOC 2, HDS (French healthcare data hosting), the Swiss FINMA Circular 2018/3 outsourcing framework (essential for Swiss financial-services customers), TISAX (German automotive supply-chain security), DORA-readiness for EU financial-services operational resilience, and the full Cloud Security Alliance 100-control-point framework. Operating under Swiss law and the Swiss Federal Data Protection Act, the company explicitly guarantees that "data uploaded in one of our Swiss zones is stored in Switzerland only": no cross-border transfers. The Swiss zones are housed in Equinix-managed facilities with strict physical-access controls; decommissioned drives are destroyed or cryptographically locked. Switzerland's EU adequacy decision (Art. 45 GDPR) keeps transfers between CH and EU jurisdictions legally clean without SCCs.
Sub-processors are deliberately minimal: Aiven Oy (Helsinki, FI) handles DBaaS orchestration; Adyen (NL) and PayPal cover payments; Bexio (CH) accounting, Brevo (FR) newsletters, Formbricks (DE) surveys, A1 Digital International (AT) business intelligence and MoocIt (FR) online learning make up the rest of the published list; AWS appears solely as an archival sub-processor and is the only US-owned entry on the customer-data path, which is what holds the CLOUD Act flag at Minor. Compute, Storage, and SKS currently have no third-party processors listed. The EU GDPR representative is A1 Digital International GmbH (Lassallestrasse 9, Vienna, AT). Best fit: Swiss financial-services (FINMA-regulated), DACH automotive supply-chain (TISAX), regulated public-sector buyers, and EU companies that want Swiss data residency with EU/CH adequacy clarity.
Sub-processor map · 9
-
Amazon Web Services, Inc. USUnited States
Archival sub-processor; customer-data backups/archives at rest (US-owned); sole reason for the minor CLOUD Act flag, kept off the live customer workloads
-
PayPal USUnited States
Payment processing; ancillary, off the customer-data path
-
A1 Digital International GmbH EUAustria
Business intelligence; parent-group entity, ancillary, off the customer-data path
-
Adyen N.V. EUNetherlands
Payment processing; ancillary, off the customer-data path
-
Aiven Oy EUFinland
Orchestration of data infrastructure services instances (DBaaS) running on Exoscale Compute
-
Bexio AG EUSwitzerland
Accounting; ancillary, off the customer-data path
-
Brevo EUFrance
Newsletters and marketing campaigns; ancillary, off the customer-data path (replaced Mailchimp)
-
Formbricks GmbH EUGermany
Surveys; ancillary, off the customer-data path
-
MoocIt EUFrance
Online learning platform; ancillary, off the customer-data path
| Vendor | Country | Purpose | Owner |
|---|---|---|---|
| Amazon Web Services, Inc. | United States | Archival sub-processor; customer-data backups/archives at rest (US-owned); sole reason for the minor CLOUD Act flag, kept off the live customer workloads | US |
| PayPal | United States | Payment processing; ancillary, off the customer-data path | US |
| A1 Digital International GmbH | Austria | Business intelligence; parent-group entity, ancillary, off the customer-data path | EU |
| Adyen N.V. | Netherlands | Payment processing; ancillary, off the customer-data path | EU |
| Aiven Oy | Finland | Orchestration of data infrastructure services instances (DBaaS) running on Exoscale Compute | EU |
| Bexio AG | Switzerland | Accounting; ancillary, off the customer-data path | EU |
| Brevo | France | Newsletters and marketing campaigns; ancillary, off the customer-data path (replaced Mailchimp) | EU |
| Formbricks GmbH | Germany | Surveys; ancillary, off the customer-data path | EU |
| MoocIt | France | Online learning platform; ancillary, off the customer-data path | EU |
Source: the vendor’s published sub-processor list, read 26 Aug 2026.
Frameworks & certifications
Capability matrix
Table 2Capabilities of Exoscale
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
Finland · $5/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
Italy · €1.99/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: No Open source: No -
-
SwedenEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
$5/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: No
Open source: No
|
€1.99/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |