Sovereign Cloud Compass
Operator access exclusion (workload scope)

Operator access exclusion (workload scope)

Why important?

Technical reduction of operator access (e.g. TEEs, attestation, customer-held keys), relevant for highly regulated data and workloads.

How measured?

Scale 0–5 + N/A:
  • 0 = Operator can access workloads/OS (no protection)
  • 1 = Access restricted but possible (break-glass without strong controls)
  • 2 = Controls in place (just-in-time, logging), but access not excluded
  • 3 = Access to workloads largely excluded or strongly reduced (limited scope)
  • 4 = Strong technically enforced controls (e.g. Nitro/confidential computing) + processes
  • 5 = Zero/no operator access (workload scope) + verifiably evidenced (attestation/evidence)
  • N/A = no reliable evidence

Validation questions (RFP)

  • Which TEE/confidential computing options are GA? Is remote attestation available? Who owns/manages the keys (BYOK/HYOK)? Which debug/break-glass paths exist? Are there production references?

Scores comparison

Providers Score
AWS European Sovereign Cloud 4.0
STACKIT 4.0
Oracle EU Sovereign Cloud 4.0
OVHcloud Public Cloud (inkl. SecNumCloud) 3.0
T Cloud Public 3.0
pluscloud open 3.0
UpCloud 3.0
Microsoft Sovereign Cloud 3.0
IONOS Cloud 2.0
Delos Cloud 2.0
noris Sovereign Cloud 1.0
SysEleven OpenStack Cloud 1.0
Cloud Temple Trusted Cloud 1.0 SecNumCloud limits operator access by design. No explicit confidential computing offering (Intel SGX/AMD SEV) documented. Physical isolation via dedicated infrastructure.
Exoscale 0.0
Hetzner Cloud 0.0
Scaleway 0.0
Infomaniak Public Cloud 0.0 No confidential computing offering (Intel SGX/AMD SEV) documented.