Cyso Cloud vs Seeweb

Compare Cyso Cloud and Seeweb on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Amazon Web Services (AWS), Microsoft Azure

Logo: Cyso Cloud

Cyso Cloud

Netherlands· Cloud Computing

Needs review

Shortlist Cyso Cloud when you want Dutch-operated OpenStack IaaS and KCSP managed Kubernetes with AMS/FRA residency and engineer-to-engineer support. Skip when you need global hyperscaler regions or default encryption-at-rest object storage—consider OVHcloud or Scaleway for broader European multi-region IaaS, or keep a hyperscaler for worldwide PaaS depth.

EU-operated (NL)OpenStack IaaSManaged Kubernetes (KCSP)AMS + FRA regionsISO 27001 (claimed)NEN 7510 (claimed)
Logo: Seeweb

Seeweb

Italy· Cloud Computing

Needs review

Shortlist Seeweb when you want Italian-operated IaaS with KVM cloud servers, NVIDIA/AMD GPU capacity, managed Kubernetes, and ACN-qualified product scope—plus European data-center choices under DHH Group ownership. Skip when you need global hyperscaler PaaS breadth or many continents of regions; consider OVHcloud, Scaleway, or Aruba Cloud instead for scale or alternate Italian sovereign stacks.

Italian operator (DHH)NVIDIA + AMD GPU cloudManaged Kubernetes (SKS)ACN QI2/QC2 (claimed)ISO 27001 (claimed)CISPE registered
Cyso Cloud vs Seeweb: Snapshot
FeatureLogo: Cyso CloudCyso CloudLogo: SeewebSeeweb
Country of originNetherlandsItaly
CategoryCloud ComputingCloud Computing
Open sourceYesNo
Self-hostedNoNo
HeadquartersNetherlandsItaly
Legal entityCyso B.V. (part of Cyso Group B.V.), Wognumsebuurt 3, 1817 BH Alkmaar; KVK 37133395Seeweb S.r.l. (p.IVA/C.F. 02043220603); fully owned by DHH S.p.A.
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowLow
Hosting / residencyPrimary public IaaS on Cyso-operated hardware in Tier 3 facilities in Amsterdam and Frankfurt (3 AZs per region); vendor states storage replicas/backups stay in the selected EU region. Not marketed as AWS/Azure/GCP-hosted IaaS. Ancillary tools disclosed at group level include website analytics (PostHog) and third parties for payments/support; status tooling has referenced Atlassian Statuspage. Full public customer-workload subprocessor list not found.Primary: Seeweb proprietary data centers in Milan and Frosinone (Italy). Additional cloud sites: Lugano (Swisscom facility), Zurich (Global Data Centers Switzerland AG), Sofia (Evolink). DR/backup marketed within Europe. No AWS/GCP/Azure as primary cloud host found on public pages. Network transit via multi-carrier mix (including Cogent, GTT, NTT) for connectivity.
Summary

Dutch OpenStack IaaS from Cyso B.V. with AMS/FRA regions, managed Kubernetes (KCSP), S3-compatible object storage, and EU data residency for teams avoiding hyperscaler lock-in.

Italian cloud and data-center provider (DHH Group): KVM cloud servers, NVIDIA/AMD GPU for AI, managed Kubernetes, VPC, and storage on European sites including proprietary Milan and Frosinone facilities.

Tags
At a glance: Cyso Cloud vs Seeweb
At a glanceLogo: Cyso CloudCyso CloudLogo: SeewebSeeweb
HQAlkmaar, NetherlandsNot listed
Legal entityCyso B.V. (Cyso Group)Not listed
Founded1997 (group); public OpenStack cloud since 2016 (Fuga); Cyso Cloud brand 20251998
RegionsAmsterdam, Frankfurt (more under investigation)Not listed
StackOpenStack + managed Kubernetes (KCSP)Not listed
Commercial modelPay-as-you-go / hourly; optional trial via salesPay-as-you-go / consumption (SPU & hourly GPU); no public free tier
HQ / legal entityNot listedSeeweb S.r.l. — Frosinone & Milan, Italy
OwnershipNot listed100% DHH S.p.A. (Euronext Growth Milan) since 2020
Hosting regionsNot listedIT (Milan, Frosinone), CH (Lugano, Zurich), BG (Sofia)
Core productsNot listedCloud Server, GPU, SKS Kubernetes, VPC, storage, colocation
Self-host productNot listedNo — managed IaaS / DC services
Key capabilities: Cyso Cloud vs Seeweb
Key capabilitiesLogo: Cyso CloudCyso CloudLogo: SeewebSeeweb
EU-operated (NL)YesYes
OpenStack IaaSYesNot listed
Managed Kubernetes (KCSP)YesYes
AMS + FRA regionsYesNot listed
ISO 27001 (claimed)YesYes
NEN 7510 (claimed)YesNot listed
NVIDIA + AMD GPU cloudNot listedYes
ACN QI2/QC2 (claimed)Not listedYes
CISPE registeredNot listedYes

Cyso Cloud

  • OpenStack public IaaS on EU hardware

    Vanilla OpenStack compute (roughly 2–64 vCPUs and up to 512 GB RAM flavors), NVMe-backed ephemeral and block volumes, dashboard plus OpenStack APIs/CLI. Deployed on Cyso-managed hardware in Amsterdam and Frankfurt with three availability zones per region so multi-AZ designs are first-class.

  • S3-compatible NVMe object storage

    Region-scoped object storage with triple-disk redundancy, versioning, lifecycle rules, object lock, pre-signed URLs, and standard S3 clients (AWS CLI, Rclone, MinIO mc, SDKs). Data and replicas stay in the selected AMS or FRA region; default server-side encryption at rest is not applied—plan client-side or customer-key approaches for sensitive objects.

  • Enterprise Managed Kubernetes (KCSP)

    CNCF Kubernetes Certified Service Provider managed control planes with multi-version support, automated upgrades, worker groups (including GPU/high-memory options), HPA/VPA/node autoscaling, Garden Linux workers, Terraform/kubectl/k9s workflows, and cluster hibernation to scale workers to zero on a schedule.

  • European networking and multi-AZ design

    VPC-style private networks, security groups as virtual firewalls, load balancers with health checks, floating/reserved IPs, Anycast DNS, IPv6 dual-stack, native edge DDoS mitigation, and Direct Connect-style private links. SLA text targets 99.99% monthly uptime for listed compute, volume, object, and networking services when multi-AZ conditions are met.

  • Private cloud and wholesale options

    Same OpenStack-based stack can be deployed as a private cloud on customer data-centre hardware (including VMware-alternative messaging) or white-label/wholesale models for partners—useful when public multi-tenant regions are not enough for isolation or residency policy.

Seeweb

  • KVM Cloud Servers with dedicated resources

    Cloud Server is a KVM virtual machine with dedicated CPU, RAM, and SAN-backed storage, N+1 style redundancy messaging, and guaranteed 1 Gbps bandwidth class. Scale vertically (add CPU/RAM/disk) or horizontally by composing multi-tier stacks. Unmanaged or fully managed by Seeweb engineers—fit for production web, DB, and agency workloads that need predictable isolation rather than noisy shared hosts.

  • GPU cloud for AI/ML (NVIDIA + AMD)

    Cloud Server GPU instances target training, inference, and HPC-style jobs with NVIDIA cards (H100, H200, A100, L40S, RTX A6000, L4 and related) and AMD options including MI300X. Ready-to-use drivers, Terraform support, hourly usage billing, and Spot Instances with a short preemption notice suit bursty or interruptible jobs. Data stays on European sites per vendor GDPR messaging—confirm region per SKU at order time.

  • Managed Kubernetes Service (SKS)

    SKS is Kubernetes-as-a-Service with a HA control plane, worker sizing you design with Seeweb, CSI storage (Vast Data driver on the product page), optional S3-compatible object storage, load balancing, and GPU workers (including MI300X and NVIDIA H-class cards). Aimed at teams that want orchestration without running etcd themselves; Proactive Support tiers add predictive monitoring for production clusters.

  • VPC, Foundation Server, and hybrid DC footprint

    Virtual Private Cloud builds private infrastructures on VMware or Proxmox; Foundation Server targets dedicated bare-metal-style capacity for business-critical virtualization. Combine with housing/colocation in Milan and Frosinone plus European partner sites for DR. Useful when you need private networking and dedicated hosts under the same Italian operator rather than public multi-tenant only.

  • ACN-qualified IaaS and CISPE EU residency claims

    Seeweb publishes ACN CSP qualification (QI2 infrastructure; QC2 for Foundation Server Pro, VPC, Shared CPU/High Memory cloud, and AI/supercomputing infrastructures) for Italian public administration procurement. CISPE Code of Conduct registration is used to assert customer data stored exclusively in European territories. Pair these claims with your own DPIA—they are procurement signals, not a substitute for a signed DPA.

Assurance & compliance: Cyso Cloud vs Seeweb
Assurance & complianceLogo: Cyso CloudCyso CloudLogo: SeewebSeeweb
Independent security / no-logs audit
Not found

Security measures and pen-testing philosophy are described; no public independent no-logs or IaaS audit report found beyond ISMS certs.

Not applicable

IaaS/data-center provider—not a consumer no-logs VPN. Assurance is via ISO/ISMS and sector qualifications rather than a no-logs report.

ISO 27001
Vendor claimed

Vendor publishes ISO/IEC 27001 certificate PDF via Trust Centre / certifications (listed expiry into 2028). Not re-checked on an independent registry for this draft.

Vendor claimed

Vendor certifications page: ISO/IEC 27001:2022, AXE REGISTER cert IT18-27702D, valid until 28 Nov 2027; locations Milan & Frosinone. Re-verify serial in procurement.

SOC 2 / SOC 3
Not found

Certifications page explains SOC 2 Type II generally; no clear statement that Cyso currently holds a published SOC 2 report.

Not found

No SOC 2/3 report advertised on the official certifications page at research time.

GDPR / EU data protection
Vendor claimed

EU legal entity; AMS/FRA residency claims; Trust Centre GDPR section. Obtain DPA and TOMs for controller/processor mapping.

Vendor claimed

Italian controller/processor entity, European hosting messaging, privacy policy, ISO 27018 claim, CISPE; confirm DPA for your processing roles.

US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: EU entity, no known US parent, primary IaaS claimed on self-operated NL/DE hardware (not AWS/GCP/Azure). Partial because no full public subprocessor schedule and ancillary SaaS (e.g. PostHog analytics, Atlassian-linked status) may involve non-EU providers. Not legal advice.

Partial

Italian Seeweb S.r.l., Italian DHH parent, no known US parent; primary hosting on European DCs (not AWS/GCP/Azure). Third-party Swiss/BG facilities and global transit carriers exist. Indicative only—not legal advice.

Data processing agreement (B2B)
Vendor claimed

Marketing (e.g. Azure alternative pages) states Cyso signs a DPA under Dutch law; confirm current template and subprocessor annex in contracting.

Vendor claimed

Art. 28 DPA language used for Seeweb-operated services (e.g. published for Regolo); request current signed DPA + TOMs + subprocessors for core cloud/IaaS contracts.

NEN 7510 (Dutch healthcare information security)
Vendor claimed

Vendor publishes NEN 7510 certificate PDF on certifications/Trust Centre pages.

Not listed
EU AI Act
Not applicable

IaaS/infrastructure platform, not an AI system product.

Partial

Infrastructure/GPU provider and Rethic.AI partnership messaging; AI Act duties mainly fall on customer AI systems. Not a full provider high-risk AI assessment by EuropeanStack.

ISO/IEC 27017 (cloud security)Not listed
Vendor claimed

Appendix to ISO 27001 certificate on certifications page; same validity window stated.

ISO/IEC 27018 (cloud PII)Not listed
Vendor claimed

Appendix to ISO 27001 certificate on certifications page; same validity window stated.

CISPE Data Protection Code of ConductNot listed
Vendor claimed

Vendor states CISPE registry presence and European data storage under the Code (since 31 May 2017 on certifications page).

ACN Qualified CSP (QI2/QC2)Not listed
Vendor claimed

IaaS qualification for Italian PA; QI2 infrastructure and QC2 for listed products including AI/supercomputing infrastructures (19 Jan 2023 on certifications page).

CSA STAR Level 1Not listed
Vendor claimed

Stated for Virtual Private Cloud and Foundation Server PRO (6 July 2022 on certifications page).

Considerations & known limitations: Cyso Cloud vs Seeweb
Considerations & known limitationsLogo: Cyso CloudCyso CloudLogo: SeewebSeeweb
Only two live public regions
Medium

Production public cloud is AMS and FRA today. Multi-continent latency, in-country residency outside NL/DE, or extensive multi-region DR across Europe may require another provider or private cloud.

Not listed
No default object storage encryption at rest
Medium

Official FAQs state no standard server-side encryption at rest; TLS in transit and client-side/SSE-C patterns are recommended. Regulated designs must implement key management outside default storage behaviour.

Not listed
Incomplete public subprocessor inventory
Medium

Primary hosting path is vendor-operated EU hardware, but privacy materials list third parties without a dedicated live subprocessor register for all ancillary processing. Request the schedule under NDA or DPA annex.

Medium

Facility partners and network carriers are described on DC pages, but a consolidated customer-content subprocessor list was not found as one public document. Request annex under NDA for regulated workloads.

Certifications are vendor-published PDFs
Low

ISO 27001 and NEN 7510 are claimed with certificate PDFs on Cyso sites; this draft did not independently verify registry entries. Treat as claimed until audit pack is reviewed.

Not listed
Smaller ecosystem than hyperscalers
Low

Fewer managed PaaS services and marketplace options than AWS/Azure/GCP. Expect to run more of the stack yourself on OpenStack/Kubernetes.

Medium

Region set is European (IT/CH/BG) with a mid-size operator catalog. Multi-continent apps or niche managed PaaS may force multi-cloud or a larger EU peer.

Certifications are vendor-publishedNot listed
Low

ISO and ACN claims include certificate numbers and dates on seeweb.it, but EuropeanStack did not re-download every registry PDF. Re-verify serials and scope statements in formal assurance reviews.

GPU Spot Instances can be interruptedNot listed
Low

Vendor documents ~2-minute notice before Spot termination when On-Demand needs capacity. Architect batch/checkpointing; do not run sole critical control planes only on Spot.

Some sites use third-party data centersNot listed
Low

Lugano, Zurich, and Sofia are presented via partner facilities (Swisscom, Global Data Centers Switzerland AG, Evolink). Italy-only residency must be contracted explicitly if required.

Fit

Cyso Cloud

Best fit when

  • European product/SaaS teams that need VMs, volumes, and S3-compatible storage with explicit Amsterdam or Frankfurt residency
  • Organisations standardising on OpenStack APIs/CLI to reduce hyperscaler lock-in and support multi-cloud portability
  • Teams wanting CNCF KCSP managed Kubernetes with hibernation and pay-as-you-go worker nodes on EU infrastructure
  • Dutch healthcare-adjacent or regulated buyers who need NEN 7510 alongside ISO 27001 claims from a NL operator
  • Buyers evaluating a private OpenStack cloud or VMware alternative on their own data-centre hardware

Poor fit when

  • Workloads that require many global regions, edge PoPs, or a large marketplace of managed PaaS services
  • Storage designs that assume default server-side encryption at rest without customer-managed keys
  • Procurement that must rely only on a fully published subprocessor schedule without vendor engagement
  • Teams that need fully self-serve free tiers or only automated chat support with no human engineering contact

Consider instead when

  • When: You need many European (or global) regions and a broader product catalogue than two live IaaS regions

    Consider: OVHcloud or Scaleway

    Larger EU multi-region footprints; different APIs and commercial models.

  • When: You want Swiss multi-zone simplicity with strong managed Kubernetes emphasis

    Consider: Exoscale

    Swiss operator profile; fewer regions than hyperscalers but clear sovereignty messaging.

  • When: You need maximum global PaaS depth, AI services, and worldwide edge

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Trade EU ownership for ecosystem breadth; apply your own residency and CLOUD Act analysis.

  • When: You prioritise high-performance European VMs across more city locations than AMS/FRA only

    Consider: UpCloud

    Different stack; compare residency guarantees and support model side by side.

Seeweb

Best fit when

  • Italian PA and public-sector projects that need ACN-qualified IaaS (verify QI2/QC2 scope against the tender)
  • AI/ML teams wanting European GPU hours (NVIDIA H-class / L-class and AMD MI300X) with usage-based or Spot billing
  • System integrators and SaaS vendors that prefer managed Kubernetes (SKS) plus Italian engineering support over pure DIY clusters
  • Workloads that must stay under Italian/EU legal entities with CISPE-style European data-location claims
  • Hybrid designs combining Cloud Servers or VPC with colocation in Milan/Frosinone and European DR sites

Poor fit when

  • Applications that depend on dozens of global regions or proprietary hyperscaler PaaS (Lambda-style, global managed DB fleets)
  • Buyers seeking a free tier or purely self-hosted open-source cloud distribution without a commercial operator
  • Teams that need a published SOC 2 Type II report as a hard gate (not found on Seeweb certifications page)
  • Organizations that refuse any third-party facility (Swiss/Bulgarian partner DCs) without Italy-only contractual pins

Consider instead when

  • When: You need a large multi-country European cloud with denser product catalog and strong self-service DX

    Consider: OVHcloud or Scaleway

    Broader regions and developer tooling; less Italian ACN-specific packaging than Seeweb.

  • When: You want another Italian sovereign cloud with mass-market public-cloud SKUs

    Consider: Aruba Cloud

    Closest national peer; compare GPU/K8s maturity and PA qualification details side by side.

  • When: You mainly need simple self-service VMs/storage at aggressive commercial terms without Italian PA focus

    Consider: Hetzner

    Strong for general-purpose EU VMs; different compliance and support model.

  • When: You require global enterprise PaaS and marketplace ecosystems

    Consider: AWS or Microsoft Azure

    Accept US-group cloud and CLOUD Act exposure tradeoffs for breadth.

Open questions for due diligence

Cyso Cloud

  • Can Cyso provide the current DPA, technical and organisational measures, and a dated subprocessor list covering payments, support, analytics, and status tooling?
  • What is the exact OpenStack release, upgrade cadence, and any divergences from upstream APIs that affect Terraform/automation?
  • For object storage and volumes, what encryption-at-rest or KMS options can be contractually committed for regulated data?
  • What are contractual 24/7 escalation SLAs for severity-1 incidents beyond office-hours tech-to-tech support?
  • Which additional EU regions (if any) have committed go-live dates versus community voting only?

Seeweb

  • Will Seeweb provide a current signed DPA, TOMs, and full subprocessor list scoped to our SKUs and regions?
  • Can every required product (GPU, SKS, VPC) be pinned exclusively to Milan/Frosinone under contract?
  • What is the exact SLA and support tier mapping for our architecture (marketing cites up to 99.99%)?
  • Are current ISO certificate serials and ACN register entries still valid for the products we will buy?
  • Is IBM Spectrum Protect operated entirely on Seeweb infrastructure, or does any backup path leave European facilities?