Our Commitment to Data Sovereignty
OptiCloud operates exclusively on infrastructure hosted within the European Union. This means all customer data — including billing records, resource metadata, audit logs, and user information — is processed and stored in EU-based data centers.
We believe data sovereignty is not optional. By keeping all infrastructure within the EU, we ensure compliance with GDPR, local data protection laws, and the highest standards of data governance expected by European enterprises.
Hosting Architecture
Our infrastructure is distributed across multiple EU regions for resilience and performance:
Primary Region
Frankfurt, Germany (EU-Central) — Main application cluster, databases, and API gateways
Disaster Recovery
Amsterdam, Netherlands (EU-West) — Real-time replicated standby environment
Edge / CDN
EU-only CDN nodes in Prague, Vienna, and Warsaw for low-latency static asset delivery
Data Flow & Cloud Providers
When connecting to external cloud providers (OCI, Azure, AWS, GCP), OptiCloud only transmits:
- API credentials (encrypted, stored in EU-hosted vault)
- Billing and cost metadata queries
- Resource inventory identifiers
- Usage metrics for cost analysis
No personal user data is transferred outside the EU. All cloud provider API calls are made from EU-based infrastructure, and responses are processed and stored within the EU.
Infrastructure Security
- TLS 1.2+ for all data in transit — no exceptions
- AES-256 encryption for all data at rest
- Dedicated VPC isolation per tenant
- EU-based key management (no keys leave the EU)
- 24/7 monitoring with EU-based SOC team
- Regular penetration testing by EU-certified auditors
Certifications & Compliance
ISO/IEC 27001
Information Security Management System aligned with international standards
GDPR Compliant
Full compliance with EU General Data Protection Regulation
SOC 2 Type II
Independent audit of security, availability, and confidentiality controls
EU Data Residency
Guaranteed data residency within EU member states
Audit & Retention
All system actions are logged in tamper-proof audit trails stored in EU data centers. Standard retention is 2 years. Extended retention up to 5 years is available as an additional service for organizations with stricter regulatory requirements.
2
Years Standard
5
Years Extended
Questions about our infrastructure?
For detailed technical questions about our EU hosting setup, security architecture, or data processing practices, please contact our infrastructure team.
Email: infrastructure@solutia.cz
Last updated: March 2026