Sovereign Cloud Compass
Provider profile Oracle EU Sovereign Cloud

Oracle EU Sovereign Cloud

Provider-specific sources from the current dataset. Use the Compass for scoring, weighting, and A/B comparison.

Compare in the Compass

Provider Snapshot

Sources / Evidence

Customer content in the EU

EU Sovereign Cloud: Regionen in Frankfurt & Madrid; Daten/Processing in EU (stated).

Customer-created metadata in the EU

Separater Realm (Frankfurt, Madrid). Physisch/logisch/kryptographisch isoliert. Keine Verbindungen zu anderen OCI-Realms. Metadaten verbleiben in EU.

Physically & logically separated

EU Sovereign Cloud als eigener OCI Realm: physisch/logisch/cryptographisch getrennt (stated).

EU-based operations & support

Operators EU residents, employed by EU legal entity; support/ops in EU (stated).

No critical non-EU dependencies

EU Sovereign Cloud Realm: keine expliziten/impliziten Verbindungen zu anderen Realms (stated).

Ownership / ultimate parent (EU-owned?)

Oracle (US) – EU Sovereign Cloud wird ueber EU legal entities betrieben, aber ultimate parent non-EU (stated).

Controlling interest & FISA 702 risk (jurisdiction ≠ residency)

Ultimate Parent: Oracle Corporation (US). Auch bei EU-Residency/Realm bleibt US-Jurisdiktion als Risiko-Faktor (FISA 702 / CLOUD Act) grundsätzlich relevant.

Local contracting entity & EU governance (operational model)

EU Sovereign Cloud realm: Operators EU residents, employed by EU legal entity; EU governance committee (stated).

Independent advisory board

EU Governance Committee fuer EU Sovereign Cloud (stated).

EU root CA / trust services

Separater kryptographischer Realm. Aber: Root CA / Trust Services nicht explizit als EU-basiert dokumentiert.

BSI C5

EU Sovereign Cloud: Einbindung in Audit-Programme inkl. BSI C5 (stated; nach Abschluss der Audits).

ISO 27001 / ISMS

Oracle Cloud Compliance Programme (ISO 27001 u.a.) – EU SC: align/extend je Scope (stated).

IT-Grundschutz (BSI)

US-Unternehmen (Oracle Corp.). IT-Grundschutz (BSI/deutscher Standard) nicht adressiert.

Open standards / API portability

OCI APIs/Services primaer proprietaer; Portabilitaet v.a. ueber Architektur/Container (partial).

Service portfolio depth

Aehnliche Services/Experience wie OCI Commercial (stated) – grosse Breite.

Geographic footprint & redundancy (regions/AZ/DCs in EU/DE)

EU Sovereign Cloud: 2 Regionen (Frankfurt & Madrid) mit gegenseitiger HA/DR (stated).

Audit reports / evidence pack

Compliance-/Audit-Programme (SOC/ISO etc) kommuniziert; EU SC spezifische Evidence auf Anfrage (partial).

Policy enforcement (guardrails)

OCI: Security Zones/Cloud Guard erzwingen Security-Policies (Guardrails) dokumentiert.

Default deny / secure by default

Default Security List enthält initiale Regeln (nicht strikt 'deny-by-default'); Härtung erforderlich.

Independent verification (continuous)

EU Sovereign Cloud in Audit-Programmen (SOC/ISO etc.) genannt (periodisch); keine Continuous/maschinenlesbare Verification öffentlich belegt.

Blackbox exposure (ops/control plane)

EU Governance Committee. 150+ OCI Services transparent. Separate Realm-Architektur. EU-only Operations (EU-Bewohner, EU-Rechtseinheiten).

Operator access exclusion (workload scope)

OCI Confidential Computing (Confidential VMs) dokumentiert (Workload-Scope; TEE/verschlüsselter Memory) – geeignet zur Operator-Access-Reduktion.

IaC & automation (Terraform/OpenTofu, SDKs, APIs)

OCI hat IaC/SDK/CLI; EU SC nutzt gleiche Tools/Change Mgmt (stated).

Everyday SDLC/DevOps (CI/CD, registry, secrets, K8s)

OCI DevOps/Services: EU SC aligned mit OCI Change Mgmt (stated).

Observability (logs/metrics/traces, alerting)

OCI Monitoring/Logging typischerweise verfuegbar; EU SC aehnliche Experience (stated).

Limits/quotas (transparency & increase)

Quotas/Limits in OCI dokumentiert; EU SC vermutlich analog (partial).

Reference architectures / landing zones

Referenzarchitekturen/Best Practices in OCI Docs (partial).

Energieeffizienz / PUE & Zielwerte

Sustainability-Programm/Commitments veröffentlicht, aber keine PUE-KPIs/Targets für OCI in Quelle ausgewiesen. (Quelle: Oracle Cloud Sustainability)

CO₂-/Wasser-Reporting + erneuerbare Energiequellen

Renewable-Energy Commitments/Programme beschrieben; kein konsistentes Carbon/Wasser-Reporting (Scopes/WUE) in Quelle. (Quelle: Oracle Cloud Sustainability)

Service catalog (core/security)
Expand to load the service catalog …