Cyso Cloud vs gridscale

Compare Cyso Cloud and gridscale on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Amazon Web Services (AWS), Microsoft Azure

Logo: Cyso Cloud

Cyso Cloud

Netherlands· Cloud Computing

Needs review

Shortlist Cyso Cloud when you want Dutch-operated OpenStack IaaS and KCSP managed Kubernetes with AMS/FRA residency and engineer-to-engineer support. Skip when you need global hyperscaler regions or default encryption-at-rest object storage—consider OVHcloud or Scaleway for broader European multi-region IaaS, or keep a hyperscaler for worldwide PaaS depth.

EU-operated (NL)OpenStack IaaSManaged Kubernetes (KCSP)AMS + FRA regionsISO 27001 (claimed)NEN 7510 (claimed)
Logo: gridscale

gridscale

Germany· Cloud Computing

Needs review

Shortlist when you need a German GmbH cloud with EU/CH/AT location choice, managed Kubernetes/databases, and Hybrid Core white-label HCI. Skip when you need global hyperscaler coverage or pure lowest-cost VMs—consider Hetzner for cost-sensitive compute or AWS/Azure for worldwide breadth; use OVHcloud parent portfolio when scale across more European regions is the priority.

EU-operated (DE entity)Multi-country EU/CH locationsManaged KubernetesHybrid Core HCIBSI C5 (claimed)OVHcloud group
Cyso Cloud vs gridscale: Snapshot
FeatureLogo: Cyso CloudCyso CloudLogo: gridscalegridscale
Country of originNetherlandsGermany
CategoryCloud ComputingCloud Computing
Open sourceYesNo
Self-hostedNoNo
HeadquartersNetherlandsGermany
Legal entityCyso B.V. (part of Cyso Group B.V.), Wognumsebuurt 3, 1817 BH Alkmaar; KVK 37133395gridscale GmbH, Oskar-Jäger-Straße 173, 50825 Köln (HRB 97235, Amtsgericht Cologne)
Governing lawNot listedGerman law (GTC; English GTC for information only—German prevails)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencyPrimary public IaaS on Cyso-operated hardware in Tier 3 facilities in Amsterdam and Frankfurt (3 AZs per region); vendor states storage replicas/backups stay in the selected EU region. Not marketed as AWS/Azure/GCP-hosted IaaS. Ancillary tools disclosed at group level include website analytics (PostHog) and third parties for payments/support; status tooling has referenced Atlassian Statuspage. Full public customer-workload subprocessor list not found.Customer infrastructure marketed on European Tier 3 locations (Frankfurt multi-AZ, Eichenzell, Hannover, Paderborn, Amsterdam, Gais, Lucerne, Vienna); some Hybrid Core sites partner-operated (hosttech, rhöncloud, BAIONITY, windCORES). Privacy policy also lists US-group ancillary processors: Stripe (payments), Google Analytics/GTM, Microsoft Bing Ads, Meta, LinkedIn; Mautic on-prem DE; Recruitee NL. No public claim that primary VM storage runs on AWS/GCP/Azure.
Summary

Dutch OpenStack IaaS from Cyso B.V. with AMS/FRA regions, managed Kubernetes (KCSP), S3-compatible object storage, and EU data residency for teams avoiding hyperscaler lock-in.

Cologne-based German IaaS/PaaS and Hybrid Core HCI cloud (OVHcloud group) with European locations, managed Kubernetes, and white-label private cloud options for DACH teams.

Tags
At a glance: Cyso Cloud vs gridscale
At a glanceLogo: Cyso CloudCyso CloudLogo: gridscalegridscale
HQAlkmaar, NetherlandsCologne, Germany
Legal entityCyso B.V. (Cyso Group)gridscale GmbH (HRB 97235)
Founded1997 (group); public OpenStack cloud since 2016 (Fuga); Cyso Cloud brand 2025Not listed
RegionsAmsterdam, Frankfurt (more under investigation)Not listed
StackOpenStack + managed Kubernetes (KCSP)Not listed
Commercial modelPay-as-you-go / hourly; optional trial via salesB2B; trial then per-minute usage metering
ParentNot listedOVHcloud (100% since Sept 2023)
HostingNot listedEuropean Tier 3 sites DE/NL/CH/AT (+ partners)
Open sourceNot listedNo (API/IaC clients only)
Key capabilities: Cyso Cloud vs gridscale
Key capabilitiesLogo: Cyso CloudCyso CloudLogo: gridscalegridscale
EU-operated (NL)YesYes
OpenStack IaaSYesNot listed
Managed Kubernetes (KCSP)YesYes
AMS + FRA regionsYesNot listed
ISO 27001 (claimed)YesNot listed
NEN 7510 (claimed)YesNot listed
Multi-country EU/CH locationsNot listedYes
Hybrid Core HCINot listedYes
BSI C5 (claimed)Not listedYes
OVHcloud groupNot listedYes

Cyso Cloud

  • OpenStack public IaaS on EU hardware

    Vanilla OpenStack compute (roughly 2–64 vCPUs and up to 512 GB RAM flavors), NVMe-backed ephemeral and block volumes, dashboard plus OpenStack APIs/CLI. Deployed on Cyso-managed hardware in Amsterdam and Frankfurt with three availability zones per region so multi-AZ designs are first-class.

  • S3-compatible NVMe object storage

    Region-scoped object storage with triple-disk redundancy, versioning, lifecycle rules, object lock, pre-signed URLs, and standard S3 clients (AWS CLI, Rclone, MinIO mc, SDKs). Data and replicas stay in the selected AMS or FRA region; default server-side encryption at rest is not applied—plan client-side or customer-key approaches for sensitive objects.

  • Enterprise Managed Kubernetes (KCSP)

    CNCF Kubernetes Certified Service Provider managed control planes with multi-version support, automated upgrades, worker groups (including GPU/high-memory options), HPA/VPA/node autoscaling, Garden Linux workers, Terraform/kubectl/k9s workflows, and cluster hibernation to scale workers to zero on a schedule.

  • European networking and multi-AZ design

    VPC-style private networks, security groups as virtual firewalls, load balancers with health checks, floating/reserved IPs, Anycast DNS, IPv6 dual-stack, native edge DDoS mitigation, and Direct Connect-style private links. SLA text targets 99.99% monthly uptime for listed compute, volume, object, and networking services when multi-AZ conditions are met.

  • Private cloud and wholesale options

    Same OpenStack-based stack can be deployed as a private cloud on customer data-centre hardware (including VMware-alternative messaging) or white-label/wholesale models for partners—useful when public multi-tenant regions are not enough for isolation or residency policy.

gridscale

  • Panel + API + Terraform provisioning

    Deploy VMs with attached storage in seconds via the control panel or automate with the REST API and common IaC clients (Terraform, Packer). Built for teams that want both click-ops and git-ops without a hyperscaler control-plane learning curve.

  • Managed Kubernetes, databases, and load balancers

    PaaS layers cover managed Kubernetes orchestration plus fully managed databases with audit logs and automatic backups, and managed load balancers for traffic distribution—so app teams avoid running the full stack themselves.

  • S3-compatible object storage and Rocket NVMe storage

    Object storage follows S3-style APIs for backups, archives, and unstructured data, with region choice called out for GDPR-oriented placement. Rocket Storage targets high-IOPS NVMe workloads; not every Hybrid Core location exposes object storage—check the data-center matrix.

  • Per-minute GPU bare-metal for AI/ML

    GPU instances are marketed as dedicated bare-metal performance for AI/ML and data science, with CPU, RAM, and storage included and usage billed by the minute rather than only long-term reserved shapes.

  • Hybrid Core Concierge HCI and white-label cloud

    Fully managed hyperconverged packages combine hardware delivery, installation, remote operations, white-label branding/SAML options, and access to the wider gridscale location ecosystem—aimed at enterprises and hosters building private or partner clouds.

Assurance & compliance: Cyso Cloud vs gridscale
Assurance & complianceLogo: Cyso CloudCyso CloudLogo: gridscalegridscale
Independent security / no-logs audit
Not found

Security measures and pen-testing philosophy are described; no public independent no-logs or IaaS audit report found beyond ISMS certs.

Not applicable

IaaS/PaaS provider—not a no-logs VPN product. Request penetration-test or SOC-style reports under NDA if required.

ISO 27001
Vendor claimed

Vendor publishes ISO/IEC 27001 certificate PDF via Trust Centre / certifications (listed expiry into 2028). Not re-checked on an independent registry for this draft.

Vendor claimed

Vendor compliance pages and chronology claim ISO/IEC 27001; obtain current certificate for verification.

SOC 2 / SOC 3
Not found

Certifications page explains SOC 2 Type II generally; no clear statement that Cyso currently holds a published SOC 2 report.

Not found

No public SOC 2 found; vendor promotes ISAE 3402 SOC 1 Type 2 instead (different standard).

GDPR / EU data protection
Vendor claimed

EU legal entity; AMS/FRA residency claims; Trust Centre GDPR section. Obtain DPA and TOMs for controller/processor mapping.

Vendor claimed

German controller (gridscale GmbH); European location marketing; privacy policy under DS-GVO. Confirm DPA and location selection for your processing.

US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: EU entity, no known US parent, primary IaaS claimed on self-operated NL/DE hardware (not AWS/GCP/Azure). Partial because no full public subprocessor schedule and ancillary SaaS (e.g. PostHog analytics, Atlassian-linked status) may involve non-EU providers. Not legal advice.

Partial

EU entity, no known US parent (OVHcloud France owns group). Customer hosting marketed in EU/CH/AT. Partial because privacy recipient list includes US-group Stripe, Google Analytics/GTM, Microsoft, Meta, LinkedIn for payments/marketing. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Marketing (e.g. Azure alternative pages) states Cyso signs a DPA under Dutch law; confirm current template and subprocessor annex in contracting.

Vendor claimed

GTC §14.2 requires a separate order-processing contract when gridscale processes personal data for the customer, finalised at latest on contract conclusion. Execute AV/DPA—do not rely on website privacy alone.

NEN 7510 (Dutch healthcare information security)
Vendor claimed

Vendor publishes NEN 7510 certificate PDF on certifications/Trust Centre pages.

Not listed
EU AI Act
Not applicable

IaaS/infrastructure platform, not an AI system product.

Not applicable

Infrastructure cloud; not an AI system product. GPU capacity may host customer AI workloads under shared-responsibility model.

ISO 27017 (cloud security)Not listed
Vendor claimed

Compliance page links a certificate PDF download; treat as vendor-published evidence until auditor validates.

ISO 27018 (cloud PII)Not listed
Vendor claimed

Claimed on compliance/about materials; request current scope.

ISAE 3402 SOC 1 Type 2Not listed
Vendor claimed

About chronology highlights successful ISAE 3402 SOC 1 Type 2 (incl. January 2025 call-out). Request full report.

BSI C5Not listed
Vendor claimed

Prominently listed on compliance pages; About chronology pairs C5 with January 2025 certification success. Request current attestation.

Trusted Cloud (DE)Not listed
Vendor claimed

Compliance page links Trusted Cloud service listing; verify current entry on trusted-cloud.de.

Considerations & known limitations: Cyso Cloud vs gridscale
Considerations & known limitationsLogo: Cyso CloudCyso CloudLogo: gridscalegridscale
Only two live public regions
Medium

Production public cloud is AMS and FRA today. Multi-continent latency, in-country residency outside NL/DE, or extensive multi-region DR across Europe may require another provider or private cloud.

Not listed
No default object storage encryption at rest
Medium

Official FAQs state no standard server-side encryption at rest; TLS in transit and client-side/SSE-C patterns are recommended. Regulated designs must implement key management outside default storage behaviour.

Not listed
Incomplete public subprocessor inventory
Medium

Primary hosting path is vendor-operated EU hardware, but privacy materials list third parties without a dedicated live subprocessor register for all ancillary processing. Request the schedule under NDA or DPA annex.

Not listed
Certifications are vendor-published PDFs
Low

ISO 27001 and NEN 7510 are claimed with certificate PDFs on Cyso sites; this draft did not independently verify registry entries. Treat as claimed until audit pack is reviewed.

Not listed
Smaller ecosystem than hyperscalers
Low

Fewer managed PaaS services and marketplace options than AWS/Azure/GCP. Expect to run more of the stack yourself on OpenStack/Kubernetes.

Low

Location set is European-weighted. Unsuitable as a drop-in for multi-continent latency or hyperscaler-only services (global CDN marketplaces, specialized managed services).

Parent-group integration after OVHcloud acquisitionNot listed
Medium

100% OVHcloud ownership since 2023 may change roadmap, tooling, support model, or cross-entity data flows over time. Confirm entity, subcontractors, and exit terms for your contract generation.

Partner-operated Hybrid Core locationsNot listed
Medium

Some sites are operated with partners (hosttech, rhöncloud, BAIONITY, windCORES, etc.). Capability matrices differ (for example object storage not everywhere). Map exact location codes to SLA and subprocessor wording.

US-group ancillary processors (account/marketing)Not listed
Medium

Privacy policy lists Stripe, Google Analytics/GTM, Microsoft Bing Ads, Meta, and LinkedIn. Material for DPIAs even when VM disks stay in EU halls. Ask which tools touch production account identities versus marketing only.

Certifications need current attestation packsNot listed
Low

BSI C5, ISAE 3402, and ISO claims are vendor-published. Production security reviews should obtain dated reports rather than relying on marketing badges alone.

Fit

Cyso Cloud

Best fit when

  • European product/SaaS teams that need VMs, volumes, and S3-compatible storage with explicit Amsterdam or Frankfurt residency
  • Organisations standardising on OpenStack APIs/CLI to reduce hyperscaler lock-in and support multi-cloud portability
  • Teams wanting CNCF KCSP managed Kubernetes with hibernation and pay-as-you-go worker nodes on EU infrastructure
  • Dutch healthcare-adjacent or regulated buyers who need NEN 7510 alongside ISO 27001 claims from a NL operator
  • Buyers evaluating a private OpenStack cloud or VMware alternative on their own data-centre hardware

Poor fit when

  • Workloads that require many global regions, edge PoPs, or a large marketplace of managed PaaS services
  • Storage designs that assume default server-side encryption at rest without customer-managed keys
  • Procurement that must rely only on a fully published subprocessor schedule without vendor engagement
  • Teams that need fully self-serve free tiers or only automated chat support with no human engineering contact

Consider instead when

  • When: You need many European (or global) regions and a broader product catalogue than two live IaaS regions

    Consider: OVHcloud or Scaleway

    Larger EU multi-region footprints; different APIs and commercial models.

  • When: You want Swiss multi-zone simplicity with strong managed Kubernetes emphasis

    Consider: Exoscale

    Swiss operator profile; fewer regions than hyperscalers but clear sovereignty messaging.

  • When: You need maximum global PaaS depth, AI services, and worldwide edge

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Trade EU ownership for ecosystem breadth; apply your own residency and CLOUD Act analysis.

  • When: You prioritise high-performance European VMs across more city locations than AMS/FRA only

    Consider: UpCloud

    Different stack; compare residency guarantees and support model side by side.

gridscale

Best fit when

  • DACH mid-market teams wanting German contracting plus managed PaaS (Kubernetes, databases, load balancers)
  • MSPs and hosters needing white-label branding, multi-tenant accounts, and optional Hybrid Core hardware
  • Workloads that must pick DE/NL/CH/AT regions with Tier 3 marketing claims and green-energy positioning
  • AI/ML or data-science jobs that need GPU bare-metal with per-minute metering
  • Buyers who value panel + API/Terraform over hyperscaler IAM sprawl

Poor fit when

  • Global multi-region applications that need hyperscaler edge, marketplace services, or non-European regions
  • Teams optimising only for lowest bare VM or dedicated-server unit cost (evaluate Hetzner first)
  • Buyers requiring public SOC 2 Type II specifically rather than ISAE 3402 SOC 1 Type 2 / BSI C5 packs
  • Organisations that forbid any US-group ancillary processors (Stripe/Google marketing tools appear in the privacy recipient list)

Consider instead when

  • When: You need the broader European hyperscale portfolio and more regions under one group brand

    Consider: OVHcloud

    OVHcloud is the parent group; gridscale stays the HCI/panel-focused product line

  • When: Cost-sensitive VMs or dedicated servers dominate and you do not need Hybrid Core white-label

    Consider: Hetzner

    Hetzner typically wins raw price/performance for simple compute

  • When: France-centric developer cloud with different location and product skew

    Consider: Scaleway

    Compare ARM options and FR footprint versus gridscale DACH Hybrid Core

  • When: Swiss-rooted EU cloud positioning is the primary evaluation criterion

    Consider: Exoscale

    Still compare DE/CH site maps and managed service depth side by side

  • When: You need worldwide regions, marketplace depth, or US-public-sector cloud programmes

    Consider: Amazon Web Services (AWS) or Microsoft Azure

    Trade EU-entity simplicity for hyperscaler breadth and US ownership path

Open questions for due diligence

Cyso Cloud

  • Can Cyso provide the current DPA, technical and organisational measures, and a dated subprocessor list covering payments, support, analytics, and status tooling?
  • What is the exact OpenStack release, upgrade cadence, and any divergences from upstream APIs that affect Terraform/automation?
  • For object storage and volumes, what encryption-at-rest or KMS options can be contractually committed for regulated data?
  • What are contractual 24/7 escalation SLAs for severity-1 incidents beyond office-hours tech-to-tech support?
  • Which additional EU regions (if any) have committed go-live dates versus community voting only?

gridscale

  • Will gridscale execute your template AV/DPA and attach a location-specific subprocessor list for the regions you enable?
  • What is the current scope and report date for BSI C5 and ISAE 3402 SOC 1 Type 2 covering the services you will buy?
  • Which privacy-policy third parties process production account/identity data versus website marketing only?
  • How are OVHcloud group affiliates involved in support, billing, or platform operations for gridscale customers post-acquisition?
  • For Hybrid Core partner sites, who is the data-center operator of record and what audit rights apply?