Cyso Cloud vs Hetzner

Compare Cyso Cloud and Hetzner on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Amazon Web Services (AWS), Google Cloud Platform, Microsoft Azure

Logo: Cyso Cloud

Cyso Cloud

Netherlands· Cloud Computing

Needs review

Shortlist Cyso Cloud when you want Dutch-operated OpenStack IaaS and KCSP managed Kubernetes with AMS/FRA residency and engineer-to-engineer support. Skip when you need global hyperscaler regions or default encryption-at-rest object storage—consider OVHcloud or Scaleway for broader European multi-region IaaS, or keep a hyperscaler for worldwide PaaS depth.

EU-operated (NL)OpenStack IaaSManaged Kubernetes (KCSP)AMS + FRA regionsISO 27001 (claimed)NEN 7510 (claimed)
Logo: Hetzner

Hetzner

Germany· Cloud Computing

Needs review

Shortlist for German-owned IaaS/bare metal in DE/FI parks, API cloud VMs, inclusive-traffic EU economics, ISO 27001 + BSI C5 Type 2. Skip for hyperscaler PaaS depth, SOC 2-first audits, or zero US-group footprint (optional US Ashburn/Hillsboro + Singapore via subsidiaries/colocation). Prefer OVHcloud/Scaleway for broader EU portfolios; STACKIT for DE public-sector framing.

EU-operated (DE HQ)Owned DE/FI parksISO 27001:2022BSI C5 Type 2Bare metal + auctionOptional US/SG cloud
Cyso Cloud vs Hetzner: Snapshot
FeatureLogo: Cyso CloudCyso CloudLogo: HetznerHetzner
Country of originNetherlandsGermany
CategoryCloud ComputingCloud Computing
Open sourceYesNo
Self-hostedNoNo
HeadquartersNetherlandsGermany
Legal entityCyso B.V. (part of Cyso Group B.V.), Wognumsebuurt 3, 1817 BH Alkmaar; KVK 37133395Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen (HRB 6089 Ansbach)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencyPrimary public IaaS on Cyso-operated hardware in Tier 3 facilities in Amsterdam and Frankfurt (3 AZs per region); vendor states storage replicas/backups stay in the selected EU region. Not marketed as AWS/Azure/GCP-hosted IaaS. Ancillary tools disclosed at group level include website analytics (PostHog) and third parties for payments/support; status tooling has referenced Atlassian Statuspage. Full public customer-workload subprocessor list not found.Owned parks: Nuremberg, Falkenstein (DE), Helsinki (FI). Non-cloud EU-only. Cloud optional US (Ashburn, Hillsboro) and Singapore on 3rd-party colocation. AV subprocessors: Hetzner Finland Oy; US: Hetzner US LLC, NTT Americas, QTS Hillsboro; SG: Hetzner Singapore, NTT SG1. Master data stays EU.
Summary

Dutch OpenStack IaaS from Cyso B.V. with AMS/FRA regions, managed Kubernetes (KCSP), S3-compatible object storage, and EU data residency for teams avoiding hyperscaler lock-in.

German data center operator (Gunzenhausen): dedicated servers, Hetzner Cloud VPS, storage, and owned parks in Germany and Finland, with optional US and Singapore cloud locations.

Tags
At a glance: Cyso Cloud vs Hetzner
At a glanceLogo: Cyso CloudCyso CloudLogo: HetznerHetzner
HQAlkmaar, NetherlandsGunzenhausen, Germany
Legal entityCyso B.V. (Cyso Group)Hetzner Online GmbH (HRB 6089 Ansbach)
Founded1997 (group); public OpenStack cloud since 2016 (Fuga); Cyso Cloud brand 2025Not listed
RegionsAmsterdam, Frankfurt (more under investigation)Not listed
StackOpenStack + managed Kubernetes (KCSP)Not listed
Commercial modelPay-as-you-go / hourly; optional trial via salesNot listed
EU parksNot listedNuremberg, Falkenstein (DE); Helsinki (FI)
Optional cloud regionsNot listedAshburn and Hillsboro (US); Singapore
ModelNot listedIaaS / dedicated / hosting (unmanaged cloud and root)
Open sourceNot listedNo (commercial infrastructure)
Key capabilities: Cyso Cloud vs Hetzner
Key capabilitiesLogo: Cyso CloudCyso CloudLogo: HetznerHetzner
EU-operated (NL)YesYes
OpenStack IaaSYesNot listed
Managed Kubernetes (KCSP)YesNot listed
AMS + FRA regionsYesNot listed
ISO 27001 (claimed)YesYes
NEN 7510 (claimed)YesNot listed
Owned DE/FI parksNot listedYes
BSI C5 Type 2Not listedYes
Bare metal + auctionNot listedYes
Optional US/SG cloudNot listedYes

Cyso Cloud

  • OpenStack public IaaS on EU hardware

    Vanilla OpenStack compute (roughly 2–64 vCPUs and up to 512 GB RAM flavors), NVMe-backed ephemeral and block volumes, dashboard plus OpenStack APIs/CLI. Deployed on Cyso-managed hardware in Amsterdam and Frankfurt with three availability zones per region so multi-AZ designs are first-class.

  • S3-compatible NVMe object storage

    Region-scoped object storage with triple-disk redundancy, versioning, lifecycle rules, object lock, pre-signed URLs, and standard S3 clients (AWS CLI, Rclone, MinIO mc, SDKs). Data and replicas stay in the selected AMS or FRA region; default server-side encryption at rest is not applied—plan client-side or customer-key approaches for sensitive objects.

  • Enterprise Managed Kubernetes (KCSP)

    CNCF Kubernetes Certified Service Provider managed control planes with multi-version support, automated upgrades, worker groups (including GPU/high-memory options), HPA/VPA/node autoscaling, Garden Linux workers, Terraform/kubectl/k9s workflows, and cluster hibernation to scale workers to zero on a schedule.

  • European networking and multi-AZ design

    VPC-style private networks, security groups as virtual firewalls, load balancers with health checks, floating/reserved IPs, Anycast DNS, IPv6 dual-stack, native edge DDoS mitigation, and Direct Connect-style private links. SLA text targets 99.99% monthly uptime for listed compute, volume, object, and networking services when multi-AZ conditions are met.

  • Private cloud and wholesale options

    Same OpenStack-based stack can be deployed as a private cloud on customer data-centre hardware (including VMware-alternative messaging) or white-label/wholesale models for partners—useful when public multi-tenant regions are not enough for isolation or residency policy.

Hetzner

  • Dedicated root servers and Server Auction

    Bare-metal root servers with full hardware isolation for predictable I/O and custom OS installs. The Server Auction lists surplus or end-of-primary-use machines at declining prices for labs, secondary environments, and cost-sensitive dedicated capacity.

  • Hetzner Cloud with API, networks, and apps

    VMs with shared or dedicated vCPU classes, managed via Console, REST API, and CLI. Private networks, stateful firewalls, load balancers, Linux images, Terraform/Ansible/Kubernetes integrations, and one-click apps (Docker, Nextcloud, GitLab CE, WireGuard, and more) for self-hosted stacks.

  • Owned EU data center parks plus optional US/Singapore cloud

    Company-operated parks in Nuremberg, Falkenstein (Germany), and Helsinki (Finland). Cloud also in Ashburn, Hillsboro (USA), and Singapore on third-party colocation. Non-cloud products and EU-selected cloud locations keep server data in the EU per Hetzner docs; master data stays in the EU.

  • ISO 27001, BSI C5 Type 2, and console DPA

    Public ISO/IEC 27001:2022 certificate for DE/FI park scope; BSI C5 Type 2 for cloud; Art. 28 DPA accept-in-console with published TOMs and annual external TOM review available to DPA customers. Not a SOC 2-first vendor.

  • Inclusive traffic-oriented European cloud pricing model

    Pay-as-you-go cloud (hourly or monthly) and list-based dedicated servers, with marketing emphasis on high inclusive traffic on European plans versus hyperscaler egress bills. Confirm current allowances and rates only on the official calculator—figures change by region and over time.

Assurance & compliance: Cyso Cloud vs Hetzner
Assurance & complianceLogo: Cyso CloudCyso CloudLogo: HetznerHetzner
Independent security / no-logs audit
Not found

Security measures and pen-testing philosophy are described; no public independent no-logs or IaaS audit report found beyond ISMS certs.

Not applicable

Hosting/IaaS, not a no-logs VPN. Public ISO 27001, BSI C5 Type 2, and annual TOM review (TUV Rheinland) instead.

ISO 27001
Vendor claimed

Vendor publishes ISO/IEC 27001 certificate PDF via Trust Centre / certifications (listed expiry into 2028). Not re-checked on an independent registry for this draft.

Verified

ISO/IEC 27001:2022; public SOCOTEC certificate. Scope: infrastructure, operation, support of Nuremberg, Falkenstein, Helsinki parks.

SOC 2 / SOC 3
Not found

Certifications page explains SOC 2 Type II generally; no clear statement that Cyso currently holds a published SOC 2 report.

Not found

Hetzner states focus on ISO 27001 rather than SOC 2 for international market.

GDPR / EU data protection
Vendor claimed

EU legal entity; AMS/FRA residency claims; Trust Centre GDPR section. Obtain DPA and TOMs for controller/processor mapping.

Vendor claimed

German entity; public privacy policy, Art. 28 DPA, TOMs, subprocessor list. Customer remains controller for data on rented systems.

US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: EU entity, no known US parent, primary IaaS claimed on self-operated NL/DE hardware (not AWS/GCP/Azure). Partial because no full public subprocessor schedule and ancillary SaaS (e.g. PostHog analytics, Atlassian-linked status) may involve non-EU providers. Not legal advice.

Partial

EU entity / no known US parent, but optional US cloud uses Hetzner US LLC and US colocation (NTT, QTS); Singapore similarly. EU placements keep server data in EU per docs. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Marketing (e.g. Azure alternative pages) states Cyso signs a DPA under Dutch law; confirm current template and subprocessor annex in contracting.

Vendor claimed

Standard DPA accept-in-console; sample PDF published; no custom wet-ink DPAs per vendor docs.

NEN 7510 (Dutch healthcare information security)
Vendor claimed

Vendor publishes NEN 7510 certificate PDF on certifications/Trust Centre pages.

Not listed
EU AI Act
Not applicable

IaaS/infrastructure platform, not an AI system product.

Not applicable

Infrastructure hosting, not an AI system product.

BSI C5 (cloud)Not listed
Verified

Vendor publishes BSI C5 Type 2 attestation PDF for cloud services (German BSI catalogue).

KRITIS / section 8a BSIGNot listed
Vendor claimed

Hetzner states BSI classification as operator of critical services and certification under section 8a BSIG.

Considerations & known limitations: Cyso Cloud vs Hetzner
Considerations & known limitationsLogo: Cyso CloudCyso CloudLogo: HetznerHetzner
Only two live public regions
Medium

Production public cloud is AMS and FRA today. Multi-continent latency, in-country residency outside NL/DE, or extensive multi-region DR across Europe may require another provider or private cloud.

Not listed
No default object storage encryption at rest
Medium

Official FAQs state no standard server-side encryption at rest; TLS in transit and client-side/SSE-C patterns are recommended. Regulated designs must implement key management outside default storage behaviour.

Not listed
Incomplete public subprocessor inventory
Medium

Primary hosting path is vendor-operated EU hardware, but privacy materials list third parties without a dedicated live subprocessor register for all ancillary processing. Request the schedule under NDA or DPA annex.

Not listed
Certifications are vendor-published PDFs
Low

ISO 27001 and NEN 7510 are claimed with certificate PDFs on Cyso sites; this draft did not independently verify registry entries. Treat as claimed until audit pack is reviewed.

Not listed
Smaller ecosystem than hyperscalers
Low

Fewer managed PaaS services and marketplace options than AWS/Azure/GCP. Expect to run more of the stack yourself on OpenStack/Kubernetes.

Not listed
Optional US and Singapore cloud regionsNot listed
Medium

Ashburn, Hillsboro, and Singapore use third-party colocation and local subsidiaries; server content placed there leaves the EU. Zero-US-footprint policies may still reject the vendor even for EU-only workloads.

Unmanaged cloud and dedicated serversNot listed
Medium

You own OS patching, app security, and backups. Platform firewalls help but do not replace customer ops. Poor fit if you need managed DBaaS and full-stack ops.

Narrower managed-service catalog vs hyperscalersNot listed
Low

Strong IaaS and bare metal; weak match if procurement assumes AWS-parity managed services. Plan hybrid architecture early.

ISO scope is DE/FI parksNot listed
Low

Published ISO 27001 scope centers on German and Finnish parks. Do not assume identical coverage for every US/Singapore deployment without reading current certificates.

Fit

Cyso Cloud

Best fit when

  • European product/SaaS teams that need VMs, volumes, and S3-compatible storage with explicit Amsterdam or Frankfurt residency
  • Organisations standardising on OpenStack APIs/CLI to reduce hyperscaler lock-in and support multi-cloud portability
  • Teams wanting CNCF KCSP managed Kubernetes with hibernation and pay-as-you-go worker nodes on EU infrastructure
  • Dutch healthcare-adjacent or regulated buyers who need NEN 7510 alongside ISO 27001 claims from a NL operator
  • Buyers evaluating a private OpenStack cloud or VMware alternative on their own data-centre hardware

Poor fit when

  • Workloads that require many global regions, edge PoPs, or a large marketplace of managed PaaS services
  • Storage designs that assume default server-side encryption at rest without customer-managed keys
  • Procurement that must rely only on a fully published subprocessor schedule without vendor engagement
  • Teams that need fully self-serve free tiers or only automated chat support with no human engineering contact

Consider instead when

  • When: You need many European (or global) regions and a broader product catalogue than two live IaaS regions

    Consider: OVHcloud or Scaleway

    Larger EU multi-region footprints; different APIs and commercial models.

  • When: You want Swiss multi-zone simplicity with strong managed Kubernetes emphasis

    Consider: Exoscale

    Swiss operator profile; fewer regions than hyperscalers but clear sovereignty messaging.

  • When: You need maximum global PaaS depth, AI services, and worldwide edge

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Trade EU ownership for ecosystem breadth; apply your own residency and CLOUD Act analysis.

  • When: You prioritise high-performance European VMs across more city locations than AMS/FRA only

    Consider: UpCloud

    Different stack; compare residency guarantees and support model side by side.

Hetzner

Best fit when

  • Teams that want German-jurisdiction hosting with owned parks in Germany and Finland
  • Workloads that need bare-metal root servers or cost-effective dedicated via Server Auction
  • Ops-heavy orgs comfortable with unmanaged IaaS (Console/API/CLI, Terraform, apps)
  • Buyers optimizing for EU residency plus inclusive traffic economics versus hyperscaler egress
  • German/EU checklists asking for ISO 27001, BSI C5, and an Art. 28 DPA in-console

Poor fit when

  • Orgs that need a full AWS/Azure-style managed services catalog (PaaS, serverless, AI)
  • Policies that forbid any US subsidiary, US colocation, or optional US region at group level
  • Buyers requiring SOC 2 as the primary assurance artifact (Hetzner focuses on ISO/C5)
  • Teams expecting fully managed OS patching, databases, and DR without operating the stack

Consider instead when

  • When: You need a broader European cloud portfolio or more managed service surface

    Consider: OVHcloud or Scaleway

    Still European operators; compare regions, bare-metal depth, and support models.

  • When: German public-sector sovereign cloud framing is the primary procurement driver

    Consider: STACKIT

    Different product and governance story; verify current certifications and residency.

  • When: You need hyperscaler managed depth more than EU-owned IaaS

    Consider: AWS, Azure, or Google Cloud (accept US-group CLOUD Act posture)

    Trade EU operator control for catalog breadth.

  • When: You want a smaller EU regional cloud with a different feature/region mix

    Consider: Exoscale or UpCloud

    Compare locations, SLAs, and managed options against Hetzner's park scale.

Open questions for due diligence

Cyso Cloud

  • Can Cyso provide the current DPA, technical and organisational measures, and a dated subprocessor list covering payments, support, analytics, and status tooling?
  • What is the exact OpenStack release, upgrade cadence, and any divergences from upstream APIs that affect Terraform/automation?
  • For object storage and volumes, what encryption-at-rest or KMS options can be contractually committed for regulated data?
  • What are contractual 24/7 escalation SLAs for severity-1 incidents beyond office-hours tech-to-tech support?
  • Which additional EU regions (if any) have committed go-live dates versus community voting only?

Hetzner

  • Does your policy allow a German provider that also offers US/Singapore regions if you only deploy in DE/FI?
  • Is BSI C5 Type 2 + ISO 27001 sufficient, or is SOC 2 mandatory for your auditors?
  • Which SKUs (cloud vs dedicated vs managed web hosting) match your backup and support needs?
  • Will you need regions or managed services Hetzner does not offer natively (CDN, managed DB, AI APIs)?