Sovereign infrastructure without becoming Bare Metalsson
Data residence has become a much debated topic over the past couple of years with the largest public cloud providers. Geopolitical precedence, legal requirements and the technological confidential compute bring higher focus on the topic for European companies in particular.
This talk will cover the current state of sovereignty and data ownership, the existing technical measures to implement confidential computing on the largest hyperscalers, as well as the caveats for those who consider choosing a true EU-based public cloud provider.
Cloud sovereignty is often reduced to a checkbox mandated by your compliance department: choose an EU region, bring your own encryption keys, and call it a day. The reality, however, is a lot more nuanced.
As European companies revisit their cloud choices, data residency, sovereignty, ownership, encryption, and jurisdiction are often mixed into one vague compliance conversation. This talk separates those concerns and looks at what control customers really have when running workloads on major hyperscalers.
We will cover cloud encryption models, the limitations of BYOK, the promise and caveats of confidential computing, and the difference between legal assurances and technical guarantees. We will also discuss what cloud providers could technically or legally be compelled to do with customer data under US government pressure.
Finally, we will walk through a practical migration of small-scale projects from a hyperscaler to a European cloud provider, including PaaS gaps, migration options, operational compromises, and the surprising usefulness of AI during the process.
Dovydas Rimeisis