Cyso Cloud vs Exoscale

Compare Cyso Cloud and Exoscale on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Amazon Web Services (AWS), Google Cloud Platform, Microsoft Azure

Logo: Cyso Cloud

Cyso Cloud

Netherlands· Cloud Computing

Needs review

Shortlist Cyso Cloud when you want Dutch-operated OpenStack IaaS and KCSP managed Kubernetes with AMS/FRA residency and engineer-to-engineer support. Skip when you need global hyperscaler regions or default encryption-at-rest object storage—consider OVHcloud or Scaleway for broader European multi-region IaaS, or keep a hyperscaler for worldwide PaaS depth.

EU-operated (NL)OpenStack IaaSManaged Kubernetes (KCSP)AMS + FRA regionsISO 27001 (claimed)NEN 7510 (claimed)
Logo: Exoscale

Exoscale

Switzerland· Cloud Computing

Needs review

Shortlist Exoscale when you need multi-country European IaaS (CH/DE/AT/BG/HR zones), managed Kubernetes and open-source DBaaS under a Swiss operator in the A1 Telekom Austria group. Skip when you need hyperscaler global PaaS depth or bare-metal-first catalogs—consider OVHcloud or Scaleway instead, or AWS/Azure/GCP for worldwide regions.

EU/CH zones onlySwiss operator (Akenes SA)Managed Kubernetes (SKS)Managed DBaaSISO 27001/27017/27018 (claimed)Per-second pay-as-you-go
Cyso Cloud vs Exoscale: Snapshot
FeatureLogo: Cyso CloudCyso CloudLogo: ExoscaleExoscale
Country of originNetherlandsSwitzerland
CategoryCloud ComputingCloud Computing
Open sourceYesNo
Self-hostedNoNo
HeadquartersNetherlandsSwitzerland
Legal entityCyso B.V. (part of Cyso Group B.V.), Wognumsebuurt 3, 1817 BH Alkmaar; KVK 37133395Akenes SA, Boulevard de Grancy 19A, 1006 Lausanne, Switzerland (CHE-423.524.322); member of A1 Digital International GmbH & Co KG / A1 Telekom Austria Group
Governing lawNot listedSwiss law (DPA: canton of Vaud jurisdiction language)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencyPrimary public IaaS on Cyso-operated hardware in Tier 3 facilities in Amsterdam and Frankfurt (3 AZs per region); vendor states storage replicas/backups stay in the selected EU region. Not marketed as AWS/Azure/GCP-hosted IaaS. Ancillary tools disclosed at group level include website analytics (PostHog) and third parties for payments/support; status tooling has referenced Atlassian Statuspage. Full public customer-workload subprocessor list not found.Customer compute/storage/SKS on Exoscale European zones (CH-GVA-2, CH-DK-2, DE-FRA-1, DE-MUC-1, AT-VIE-1/2, BG-SOF-1, HR-ZAG-1); DBaaS orchestrated by Aiven Oy (Finland) on Exoscale compute. Client ops third parties include AWS (US) data archival, Twilio (US) auth, PayPal (US) payments—privacy policy states customer-uploaded service data is not sent to those ops providers.
Summary

Dutch OpenStack IaaS from Cyso B.V. with AMS/FRA regions, managed Kubernetes (KCSP), S3-compatible object storage, and EU data residency for teams avoiding hyperscaler lock-in.

European public cloud (IaaS) from Swiss operator Akenes SA (A1 Digital): multi-zone compute, managed Kubernetes (SKS), DBaaS, object and block storage, and GPUs across CH, DE, AT, BG, and HR.

Tags
At a glance: Cyso Cloud vs Exoscale
At a glanceLogo: Cyso CloudCyso CloudLogo: ExoscaleExoscale
HQAlkmaar, NetherlandsLausanne, Switzerland
Legal entityCyso B.V. (Cyso Group)Akenes SA (CHE-423.524.322)
Founded1997 (group); public OpenStack cloud since 2016 (Fuga); Cyso Cloud brand 2025Not listed
RegionsAmsterdam, Frankfurt (more under investigation)Not listed
StackOpenStack + managed Kubernetes (KCSP)Not listed
Commercial modelPay-as-you-go / hourly; optional trial via salesNot listed
GroupNot listedA1 Digital / A1 Telekom Austria Group
HostingNot listedEuropean zones only (CH, DE, AT, BG, HR)
ModelNot listedPublic cloud IaaS + managed K8s/DBaaS
Self-hostNot listedNo (managed public cloud)
Key capabilities: Cyso Cloud vs Exoscale
Key capabilitiesLogo: Cyso CloudCyso CloudLogo: ExoscaleExoscale
EU-operated (NL)YesNot listed
OpenStack IaaSYesNot listed
Managed Kubernetes (KCSP)YesNot listed
AMS + FRA regionsYesNot listed
ISO 27001 (claimed)YesNot listed
NEN 7510 (claimed)YesNot listed
EU/CH zones onlyNot listedYes
Swiss operator (Akenes SA)Not listedYes
Managed Kubernetes (SKS)Not listedYes
Managed DBaaSNot listedYes
ISO 27001/27017/27018 (claimed)Not listedYes
Per-second pay-as-you-goNot listedYes

Cyso Cloud

  • OpenStack public IaaS on EU hardware

    Vanilla OpenStack compute (roughly 2–64 vCPUs and up to 512 GB RAM flavors), NVMe-backed ephemeral and block volumes, dashboard plus OpenStack APIs/CLI. Deployed on Cyso-managed hardware in Amsterdam and Frankfurt with three availability zones per region so multi-AZ designs are first-class.

  • S3-compatible NVMe object storage

    Region-scoped object storage with triple-disk redundancy, versioning, lifecycle rules, object lock, pre-signed URLs, and standard S3 clients (AWS CLI, Rclone, MinIO mc, SDKs). Data and replicas stay in the selected AMS or FRA region; default server-side encryption at rest is not applied—plan client-side or customer-key approaches for sensitive objects.

  • Enterprise Managed Kubernetes (KCSP)

    CNCF Kubernetes Certified Service Provider managed control planes with multi-version support, automated upgrades, worker groups (including GPU/high-memory options), HPA/VPA/node autoscaling, Garden Linux workers, Terraform/kubectl/k9s workflows, and cluster hibernation to scale workers to zero on a schedule.

  • European networking and multi-AZ design

    VPC-style private networks, security groups as virtual firewalls, load balancers with health checks, floating/reserved IPs, Anycast DNS, IPv6 dual-stack, native edge DDoS mitigation, and Direct Connect-style private links. SLA text targets 99.99% monthly uptime for listed compute, volume, object, and networking services when multi-AZ conditions are met.

  • Private cloud and wholesale options

    Same OpenStack-based stack can be deployed as a private cloud on customer data-centre hardware (including VMware-alternative messaging) or white-label/wholesale models for partners—useful when public multi-tenant regions are not enough for isolation or residency policy.

Exoscale

  • Multi-zone European KVM compute

    Launch KVM instances in published zones across Switzerland, Germany, Austria, Bulgaria, and Croatia. Families cover standard, CPU-, memory-, and storage-optimized profiles plus NVIDIA GPU shapes; anti-affinity groups, instance pools, snapshots, custom templates, security groups, and live migration support production patterns. Billed per second with powered-off storage semantics as documented.

  • SKS managed Kubernetes (CNCF certified)

    Scalable Kubernetes Service deploys a managed control plane quickly (vendor claims under about a minute to two minutes). Starter is free without SLA; Pro adds HA control plane, etcd backups, and SLA language. Node pools use Exoscale instance types including GPUs; NLB, CSI storage, autoscaling/Karpenter (Pro), and vanilla CNCF-conformance positioning keep the stack portable.

  • Managed DBaaS on Exoscale compute (Aiven orchestration)

    Managed PostgreSQL, MySQL, Kafka, OpenSearch, Valkey, Grafana, and related engines run as DBaaS with automated backups, plan scaling, and high-availability options. Orchestration subprocessor is Aiven Oy (Finland); database instances run on Exoscale infrastructure in the zone you choose—confirm geo-replication and plan limits in docs before multi-region designs.

  • S3-compatible object storage and block volumes

    Simple Object Storage provides S3-compatible APIs for backups, media, and app assets integrated with Exoscale IAM and zones. Block storage attaches persistent NVMe-class volumes to instances and Kubernetes via CSI for stateful workloads without tying data solely to local disks.

  • IAM, private networks, and automation APIs

    Fine-grained IAM on API keys, private networks, and network load balancers support multi-tier designs. Portal, CLI, API, and Terraform-friendly workflows match common European DevOps practice without requiring a proprietary control language.

Assurance & compliance: Cyso Cloud vs Exoscale
Assurance & complianceLogo: Cyso CloudCyso CloudLogo: ExoscaleExoscale
Independent security / no-logs audit
Not found

Security measures and pen-testing philosophy are described; no public independent no-logs or IaaS audit report found beyond ISMS certs.

Partial

Vendor states regular independent audits and publishes multi-framework certs via Compliance Center; not a VPN-style no-logs audit. Download current reports under account/NDA for verification.

ISO 27001
Vendor claimed

Vendor publishes ISO/IEC 27001 certificate PDF via Trust Centre / certifications (listed expiry into 2028). Not re-checked on an independent registry for this draft.

Vendor claimed

Vendor asserts ISO/IEC 27001:2022 ISMS certification since 2018; certificates via Compliance Center.

SOC 2 / SOC 3
Not found

Certifications page explains SOC 2 Type II generally; no clear statement that Cyso currently holds a published SOC 2 report.

Vendor claimed

SOC 2 listed on compliance marketing; obtain report via Compliance Center / NDA.

GDPR / EU data protection
Vendor claimed

EU legal entity; AMS/FRA residency claims; Trust Centre GDPR section. Obtain DPA and TOMs for controller/processor mapping.

Vendor claimed

Swiss entity; GDPR + Swiss FADP claims; EU zones; public DPA. Not legal advice.

US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: EU entity, no known US parent, primary IaaS claimed on self-operated NL/DE hardware (not AWS/GCP/Azure). Partial because no full public subprocessor schedule and ancillary SaaS (e.g. PostHog analytics, Atlassian-linked status) may involve non-EU providers. Not legal advice.

Partial

Swiss operator, no known US parent, European workload zones, and no third-party processor for compute/storage/SKS customer data. Medium residual path via US ops providers (AWS archival, Twilio auth, PayPal) listed for client data. DBaaS uses Aiven (Finland). Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Marketing (e.g. Azure alternative pages) states Cyso signs a DPA under Dutch law; confirm current template and subprocessor annex in contracting.

Vendor claimed

Public DPA for Akenes SA as processor; Swiss law; Aiven listed for DBaaS.

NEN 7510 (Dutch healthcare information security)
Vendor claimed

Vendor publishes NEN 7510 certificate PDF on certifications/Trust Centre pages.

Not listed
EU AI Act
Not applicable

IaaS/infrastructure platform, not an AI system product.

Not applicable

Primary product is IaaS/managed infrastructure; customer AI workloads remain customer-controlled. Concrete AI offerings may need separate review if used as an AI system.

ISO 27017 (cloud security)Not listed
Vendor claimed

Listed on compliance site as certified cloud security controls.

ISO 27018 (cloud PII)Not listed
Vendor claimed

Listed on compliance site for personal data protection in public cloud.

BSI C5Not listed
Vendor claimed

BSI C5 listed among national/international standards on compliance page.

HDS (French health data hosting)Not listed
Vendor claimed

HDS listed on compliance page; confirm scope and zones for health workloads.

CSA STARNot listed
Vendor claimed

CSA STAR listed on compliance page.

Considerations & known limitations: Cyso Cloud vs Exoscale
Considerations & known limitationsLogo: Cyso CloudCyso CloudLogo: ExoscaleExoscale
Only two live public regions
Medium

Production public cloud is AMS and FRA today. Multi-continent latency, in-country residency outside NL/DE, or extensive multi-region DR across Europe may require another provider or private cloud.

Not listed
No default object storage encryption at rest
Medium

Official FAQs state no standard server-side encryption at rest; TLS in transit and client-side/SSE-C patterns are recommended. Regulated designs must implement key management outside default storage behaviour.

Not listed
Incomplete public subprocessor inventory
Medium

Primary hosting path is vendor-operated EU hardware, but privacy materials list third parties without a dedicated live subprocessor register for all ancillary processing. Request the schedule under NDA or DPA annex.

Not listed
Certifications are vendor-published PDFs
Low

ISO 27001 and NEN 7510 are claimed with certificate PDFs on Cyso sites; this draft did not independently verify registry entries. Treat as claimed until audit pack is reviewed.

Not listed
Smaller ecosystem than hyperscalers
Low

Fewer managed PaaS services and marketplace options than AWS/Azure/GCP. Expect to run more of the stack yourself on OpenStack/Kubernetes.

Not listed
US third parties on client/ops pathNot listed
Medium

Privacy policy lists AWS (US) data archival, Twilio (US) authentication, and PayPal (US) among client operations providers. Vendor states customer-uploaded service data is not transferred to these providers, but account/ops data paths still matter for CLOUD Act and transfer diligence.

DBaaS subprocessor (Aiven)Not listed
Low

Managed databases depend on Aiven Oy (Finland) for orchestration while instances run on Exoscale. Confirm contractual chain, access model, and zone placement for sensitive data.

Cert evidence mostly in customer portal / NDANot listed
Low

ISO/SOC/C5/HDS claims are strong marketing signals, but full certificates and SOC reports typically require Compliance Center access or NDA—not fully public PDFs for all frameworks.

Narrower PaaS than hyperscalersNot listed
Medium

Expect solid IaaS, SKS, DBaaS, storage, and GPU—not the global proprietary service catalog of AWS/Azure/GCP. Validate feature gaps early for serverless, global edge, and specialized managed services.

Zone catalog evolvesNot listed
Low

Public materials discuss further European expansion (e.g. Spain via A1 Digital messaging). Treat the live datacenters page as source of truth for residency commitments.

Fit

Cyso Cloud

Best fit when

  • European product/SaaS teams that need VMs, volumes, and S3-compatible storage with explicit Amsterdam or Frankfurt residency
  • Organisations standardising on OpenStack APIs/CLI to reduce hyperscaler lock-in and support multi-cloud portability
  • Teams wanting CNCF KCSP managed Kubernetes with hibernation and pay-as-you-go worker nodes on EU infrastructure
  • Dutch healthcare-adjacent or regulated buyers who need NEN 7510 alongside ISO 27001 claims from a NL operator
  • Buyers evaluating a private OpenStack cloud or VMware alternative on their own data-centre hardware

Poor fit when

  • Workloads that require many global regions, edge PoPs, or a large marketplace of managed PaaS services
  • Storage designs that assume default server-side encryption at rest without customer-managed keys
  • Procurement that must rely only on a fully published subprocessor schedule without vendor engagement
  • Teams that need fully self-serve free tiers or only automated chat support with no human engineering contact

Consider instead when

  • When: You need many European (or global) regions and a broader product catalogue than two live IaaS regions

    Consider: OVHcloud or Scaleway

    Larger EU multi-region footprints; different APIs and commercial models.

  • When: You want Swiss multi-zone simplicity with strong managed Kubernetes emphasis

    Consider: Exoscale

    Swiss operator profile; fewer regions than hyperscalers but clear sovereignty messaging.

  • When: You need maximum global PaaS depth, AI services, and worldwide edge

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Trade EU ownership for ecosystem breadth; apply your own residency and CLOUD Act analysis.

  • When: You prioritise high-performance European VMs across more city locations than AMS/FRA only

    Consider: UpCloud

    Different stack; compare residency guarantees and support model side by side.

Exoscale

Best fit when

  • Teams that must pin VMs, Kubernetes, and object storage to named European zones (including Swiss options)
  • SaaS and product orgs wanting SKS plus managed PostgreSQL/MySQL/Kafka/OpenSearch without running the control planes
  • Buyers who need a published DPA, zone list, and multi-framework compliance pack from a non-US legal entity
  • Workloads that fit IaaS plus managed open-source data services rather than proprietary global PaaS catalogs
  • Organizations evaluating A1 Digital / A1 Telekom Austria group cloud as a European alternative to AWS/Azure/GCP

Poor fit when

  • Products that depend on dozens of proprietary hyperscaler services or multi-continent active-active regions
  • Buyers who require zero US-group SaaS anywhere on the account path (privacy lists AWS archival, Twilio, PayPal for ops)
  • Teams seeking a fully self-hosted OpenStack/Kubernetes distribution rather than a managed public cloud
  • Bare-metal-heavy designs better served by large European bare-metal catalogs (e.g. OVHcloud)

Consider instead when

  • When: You need extensive bare-metal or a different pan-EU hosting footprint

    Consider: OVHcloud

    Often stronger metal catalog and broader hosting packaging; different sovereignty and product mix.

  • When: You want a developer-centric alternative with a different regional product mix

    Consider: Scaleway

    Common EU shortlist peer; compare zones, K8s, and storage packaging side by side.

  • When: You need global regions and deep proprietary PaaS/AI catalogs

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Trade European-operator simplicity for worldwide service breadth and US CLOUD Act parent risk.

Open questions for due diligence

Cyso Cloud

  • Can Cyso provide the current DPA, technical and organisational measures, and a dated subprocessor list covering payments, support, analytics, and status tooling?
  • What is the exact OpenStack release, upgrade cadence, and any divergences from upstream APIs that affect Terraform/automation?
  • For object storage and volumes, what encryption-at-rest or KMS options can be contractually committed for regulated data?
  • What are contractual 24/7 escalation SLAs for severity-1 incidents beyond office-hours tech-to-tech support?
  • Which additional EU regions (if any) have committed go-live dates versus community voting only?

Exoscale

  • Download current ISO/SOC/C5/HDS certificates from the Compliance Center and verify auditor, scope, and expiry for your zones.
  • Confirm whether your use case can accept AWS/Twilio/PayPal on the account/ops path even if workload data stays on European Exoscale zones.
  • For DBaaS, document Aiven access boundaries, encryption, backup locations, and multi-zone replication behavior in writing.
  • If Spanish or other new zones are required, get contractual residency language rather than relying on roadmap announcements.
  • Clarify support plan SLAs and enterprise contracting terms beyond self-serve pay-as-you-go.