Everyone is sovereign. Allegedly.
The word appears on every vendor slide. The substance behind it is rarer. This walkthrough moves through the layers where sovereignty is actually decided.
The word appears on every vendor slide. The substance behind it is rarer. This walkthrough moves through the layers where sovereignty is actually decided.
German data centers answer the data residency question. They do not answer who controls the systems when it matters.
Operational control is decided here, not in the brochure: admin access, key management, support paths.
The CLOUD Act and FISA 702 travel with the vendor, not with the hardware. The decisive clauses live in contracts, not in datasheets.
Technology does not decide. The question is who can act under pressure, and that responsibility cannot be outsourced.
It is verifiable control under pressure.
Look for it in marketing and you will find stickers.
Look for it in contracts, architectures and tests and you will find answers.
Toolkit
Which law governs the operator, the control plane and the support paths in a conflict?
What counts is the emergency, not normal operations.
Who can force admin access, and who could refuse it?
The answer is rarely in the press release.
Is key management verifiably outside the vendor's sphere?
Verifiable means auditable, not promised.
Has the exit been tested for real, not just documented?
An unrehearsed exit strategy is an assumption.
Does this contract increase your depth of control, or only your feature set?
More features are not sovereignty.
Who decides in an emergency, and how fast?
Unclear responsibility is the most expensive dependency.

The book
436 pages on digital sovereignty: deployment models, architecture, regulation, migration and the executive perspective, with conversations from the leadership of Microsoft, AWS, SAP, Delos, StackIT, Red Hat and IBM.
Published by Rheinwerk Computing, in German. The foundation of every analysis on this site.
Get the book