Wake Up EuropeOne of seven

We're on a sovereign cloud with a European operating entity

EU-resident staff, customer-held keys, an EU legal entity

That genuinely helps. Now ask who holds the keys, and who can walk up to the machines.

Sovereign cloud offerings place a European company between the customer and an American owner, usually with staff based in Europe and sometimes with encryption keys held by the customer. They are the strongest answer on this page and they narrow the problem genuinely. On their own they do not remove it. What matters is not where the European company is registered but whether any American company keeps a way into the equipment: in April 2024 the United States widened its wording to cover a supplier with access to the equipment used to carry or store messages. Keys held by the customer change the answer most, because material nobody can read is of little use to anybody. So the questions that separate one arrangement from another are narrow ones: who holds the keys, whose staff can reach the hardware, and whether the European company could keep running without its owner.

What this does not settle. No particular sovereign-cloud product is assessed here. Whether one specific arrangement puts the operator out of reach depends on that contract and that setup.

50 U.S.C. §1881(b)(4), as amended by RISAA §504 · checked 2026-09-04 · 18 U.S.C. §2713 · checked 2026-09-04

What to ask instead

Who holds the keys, and whose staff can walk up to the machines?

This is the strongest of the seven, so the question is a narrow one. These arrangements differ enormously, and those two details are what separate one that moves the problem from one that only moves the address.

If the answer is a European company you can name, that settles it.

The other six

Or run the whole test on your own company — about four minutes, nothing kept.