Cyso Cloud vs UpCloud

Compare Cyso Cloud and UpCloud on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Amazon Web Services (AWS), Google Cloud Platform, Microsoft Azure

Logo: Cyso Cloud

Cyso Cloud

Netherlands· Cloud Computing

Needs review

Shortlist Cyso Cloud when you want Dutch-operated OpenStack IaaS and KCSP managed Kubernetes with AMS/FRA residency and engineer-to-engineer support. Skip when you need global hyperscaler regions or default encryption-at-rest object storage—consider OVHcloud or Scaleway for broader European multi-region IaaS, or keep a hyperscaler for worldwide PaaS depth.

EU-operated (NL)OpenStack IaaSManaged Kubernetes (KCSP)AMS + FRA regionsISO 27001 (claimed)NEN 7510 (claimed)
Logo: UpCloud

UpCloud

Finland· Cloud Computing

Needs review

Shortlist UpCloud when you want Finnish-contracted IaaS with MaxIOPS storage, CNCF Managed Kubernetes, managed open-source databases, and customer-pinned EU regions—plus optional global PoPs. Skip when you need hyperscaler-only PaaS depth or the absolute lowest bare-metal VPS pricing; consider Hetzner, Scaleway, or AWS/Azure/GCP depending on that gap.

Finnish-operated IaaSMaxIOPS block storageCNCF Managed KubernetesISO 27001 (claimed)Selectable EU regionsZero-cost egress policy
Cyso Cloud vs UpCloud: Snapshot
FeatureLogo: Cyso CloudCyso CloudLogo: UpCloudUpCloud
Country of originNetherlandsFinland
CategoryCloud ComputingCloud Computing
Open sourceYesNo
Self-hostedNoNo
HeadquartersNetherlandsFinland
Legal entityCyso B.V. (part of Cyso Group B.V.), Wognumsebuurt 3, 1817 BH Alkmaar; KVK 37133395UpCloud Oy (Business ID 2431560-5), Aleksanterinkatu 15 B, 00100 Helsinki
Governing lawNot listedFinland (Terms of Service; arbitration Helsinki)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencyPrimary public IaaS on Cyso-operated hardware in Tier 3 facilities in Amsterdam and Frankfurt (3 AZs per region); vendor states storage replicas/backups stay in the selected EU region. Not marketed as AWS/Azure/GCP-hosted IaaS. Ancillary tools disclosed at group level include website analytics (PostHog) and third parties for payments/support; status tooling has referenced Atlassian Statuspage. Full public customer-workload subprocessor list not found.Customer-selected regions across 15 DCs (EU majority: FI, SE, NO, DK, DE, NL, ES, PL, UK; plus US-CHI/NYC/SJO, SG, AU) in colocations (Equinix, Digital Realty, CoreSite, Telia, Verne, Green Mountain, etc.). Customer Data stays in chosen DC. Vendor: EU VMs have no customer-data subprocessors; group subsidiaries only otherwise. Account data in Finland with global support access (incl. US/SG). Payments/hCaptcha are separate third parties.
Summary

Dutch OpenStack IaaS from Cyso B.V. with AMS/FRA regions, managed Kubernetes (KCSP), S3-compatible object storage, and EU data residency for teams avoiding hyperscaler lock-in.

Finnish IaaS from UpCloud Oy (Helsinki): MaxIOPS block storage, Cloud Servers, managed Kubernetes and databases across 15 global regions with customer-selected residency.

Tags
At a glance: Cyso Cloud vs UpCloud
At a glanceLogo: Cyso CloudCyso CloudLogo: UpCloudUpCloud
HQAlkmaar, NetherlandsHelsinki, Finland
Legal entityCyso B.V. (Cyso Group)UpCloud Oy (2431560-5)
Founded1997 (group); public OpenStack cloud since 2016 (Fuga); Cyso Cloud brand 20252011
RegionsAmsterdam, Frankfurt (more under investigation)15 DCs / 12 countries (EU-heavy + US/APAC)
StackOpenStack + managed Kubernetes (KCSP)Not listed
Commercial modelPay-as-you-go / hourly; optional trial via salesHourly pay-as-you-go; trial credits; zero-cost egress policy
Open sourceNot listedNo (platform proprietary)
Self-hostedNot listedNo (public/private cloud IaaS)
Key capabilities: Cyso Cloud vs UpCloud
Key capabilitiesLogo: Cyso CloudCyso CloudLogo: UpCloudUpCloud
EU-operated (NL)YesNot listed
OpenStack IaaSYesNot listed
Managed Kubernetes (KCSP)YesYes
AMS + FRA regionsYesNot listed
ISO 27001 (claimed)YesYes
NEN 7510 (claimed)YesNot listed
Finnish-operated IaaSNot listedYes
MaxIOPS block storageNot listedYes
Selectable EU regionsNot listedYes
Zero-cost egress policyNot listedYes

Cyso Cloud

  • OpenStack public IaaS on EU hardware

    Vanilla OpenStack compute (roughly 2–64 vCPUs and up to 512 GB RAM flavors), NVMe-backed ephemeral and block volumes, dashboard plus OpenStack APIs/CLI. Deployed on Cyso-managed hardware in Amsterdam and Frankfurt with three availability zones per region so multi-AZ designs are first-class.

  • S3-compatible NVMe object storage

    Region-scoped object storage with triple-disk redundancy, versioning, lifecycle rules, object lock, pre-signed URLs, and standard S3 clients (AWS CLI, Rclone, MinIO mc, SDKs). Data and replicas stay in the selected AMS or FRA region; default server-side encryption at rest is not applied—plan client-side or customer-key approaches for sensitive objects.

  • Enterprise Managed Kubernetes (KCSP)

    CNCF Kubernetes Certified Service Provider managed control planes with multi-version support, automated upgrades, worker groups (including GPU/high-memory options), HPA/VPA/node autoscaling, Garden Linux workers, Terraform/kubectl/k9s workflows, and cluster hibernation to scale workers to zero on a schedule.

  • European networking and multi-AZ design

    VPC-style private networks, security groups as virtual firewalls, load balancers with health checks, floating/reserved IPs, Anycast DNS, IPv6 dual-stack, native edge DDoS mitigation, and Direct Connect-style private links. SLA text targets 99.99% monthly uptime for listed compute, volume, object, and networking services when multi-AZ conditions are met.

  • Private cloud and wholesale options

    Same OpenStack-based stack can be deployed as a private cloud on customer data-centre hardware (including VMware-alternative messaging) or white-label/wholesale models for partners—useful when public multi-tenant regions are not enough for isolation or residency policy.

UpCloud

  • MaxIOPS clustered block storage

    In-house all-flash block tier rated up to ~100,000 read IOPS at 4K, separate from compute hosts, with Standard and Archive tiers for capacity. Attach up to 16 devices per server (up to 64 TB total); encryption at rest optional. Suits databases and I/O-heavy apps that outgrow commodity cloud disks.

  • Cloud Servers on AMD EPYC with automation

    Linux/Windows VMs with Starter, Premium, and Cloud Native plan families, hot resize options, firewall, utility and SDN private networking. Full lifecycle via control panel, REST API, CLI, Terraform/OpenTofu, Pulumi, and Crossplane—for teams automating fleets rather than clicking one-off VPS.

  • CNCF Managed Kubernetes (UKS)

    Managed control planes with CNCF-certified Kubernetes versions, autoscaler integration, CSI block volumes, load-balancer integration, and private-only clusters. Worker nodes use ordinary Cloud Server plans including Private Cloud hosts—good fit when you want K8s without running etcd yourself.

  • Managed PostgreSQL, MySQL, Valkey, OpenSearch

    Turnkey databases with automated backups, multi-node HA options, private utility/SDN connectivity, and point-in-time recovery on relational plans. Reduces ops load for product teams that still want open engines rather than proprietary hyperscaler databases.

  • Customer-selected global regions (EU-first footprint)

    Fifteen data centers across twelve countries: dense Northern/Central Europe (Helsinki x2, Stockholm, Stavanger, Copenhagen, Amsterdam, Frankfurt, Madrid, Warsaw, London) plus US, Singapore, and Sydney. Customer Data stays in the chosen zone unless you request a move—use EU zones for residency programmes.

  • Zero-cost egress packaging and 99.999% SLA line

    Public pricing emphasises no per-GB internet egress charges under a Fair Transfer Policy, plus Premium-class 99.999% SLA with service credits for unscheduled downtime. Simplifies bills for chatty APIs and multi-service architectures compared with classic egress meters—confirm fair-use limits for extreme transfer cases.

Assurance & compliance: Cyso Cloud vs UpCloud
Assurance & complianceLogo: Cyso CloudCyso CloudLogo: UpCloudUpCloud
Independent security / no-logs audit
Not found

Security measures and pen-testing philosophy are described; no public independent no-logs or IaaS audit report found beyond ISMS certs.

Vendor claimed

Vendor states cloud services audited against Finnish PiTuKri criteria by an independent firm; ISO 27001 ISMS regularly audited. Public PiTuKri report not fully reproduced on marketing pages—request artefacts.

ISO 27001
Vendor claimed

Vendor publishes ISO/IEC 27001 certificate PDF via Trust Centre / certifications (listed expiry into 2028). Not re-checked on an independent registry for this draft.

Vendor claimed

Vendor asserts ISO 27001 certified ISMS and publishes certificate PDF; independent registry re-check not completed in this draft.

SOC 2 / SOC 3
Not found

Certifications page explains SOC 2 Type II generally; no clear statement that Cyso currently holds a published SOC 2 report.

Not found

Facility providers list SOC reports; no clear first-party UpCloud SOC 2 Type II product claim found on compliance pages reviewed.

GDPR / EU data protection
Vendor claimed

EU legal entity; AMS/FRA residency claims; Trust Centre GDPR section. Obtain DPA and TOMs for controller/processor mapping.

Vendor claimed

Finnish controller/processor under GDPR; customer chooses region; DPA in ToS; CISPE Code of Conduct adherence claimed.

US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: EU entity, no known US parent, primary IaaS claimed on self-operated NL/DE hardware (not AWS/GCP/Azure). Partial because no full public subprocessor schedule and ancillary SaaS (e.g. PostHog analytics, Atlassian-linked status) may involve non-EU providers. Not legal advice.

Partial

Finnish entity / no known US parent; EU-region VMs can avoid US storage. Material exceptions: optional US DCs, US/SG support affiliates for account ops, US colocations if selected. Assessment not a vendor safety claim. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Marketing (e.g. Azure alternative pages) states Cyso signs a DPA under Dutch law; confirm current template and subprocessor annex in contracting.

Vendor claimed

DPA incorporated into Terms of Service; binding on acceptance without separate signature per vendor.

NEN 7510 (Dutch healthcare information security)
Vendor claimed

Vendor publishes NEN 7510 certificate PDF on certifications/Trust Centre pages.

Not listed
EU AI Act
Not applicable

IaaS/infrastructure platform, not an AI system product.

Not applicable

General-purpose IaaS/platform; not an AI system provider by primary product.

CISPE Code of ConductNot listed
Vendor claimed

Vendor states adherence to CISPE data protection code for cloud infrastructure providers.

Considerations & known limitations: Cyso Cloud vs UpCloud
Considerations & known limitationsLogo: Cyso CloudCyso CloudLogo: UpCloudUpCloud
Only two live public regions
Medium

Production public cloud is AMS and FRA today. Multi-continent latency, in-country residency outside NL/DE, or extensive multi-region DR across Europe may require another provider or private cloud.

Not listed
No default object storage encryption at rest
Medium

Official FAQs state no standard server-side encryption at rest; TLS in transit and client-side/SSE-C patterns are recommended. Regulated designs must implement key management outside default storage behaviour.

Not listed
Incomplete public subprocessor inventory
Medium

Primary hosting path is vendor-operated EU hardware, but privacy materials list third parties without a dedicated live subprocessor register for all ancillary processing. Request the schedule under NDA or DPA annex.

Not listed
Certifications are vendor-published PDFs
Low

ISO 27001 and NEN 7510 are claimed with certificate PDFs on Cyso sites; this draft did not independently verify registry entries. Treat as claimed until audit pack is reviewed.

Not listed
Smaller ecosystem than hyperscalers
Low

Fewer managed PaaS services and marketplace options than AWS/Azure/GCP. Expect to run more of the stack yourself on OpenStack/Kubernetes.

Not listed
Optional non-EU regions and support accessNot listed
Medium

US, Singapore, and Sydney zones are first-class options. Mis-pinned workloads or defaults can place Customer Data outside the EU. Account information is accessible to non-EEA support staff even when VMs stay in Europe.

Narrower catalogue than hyperscalersNot listed
Low

Strong IaaS and focused managed services; missing many proprietary AWS/Azure/GCP PaaS and AI products. Multi-cloud or dual-vendor designs may still be required.

Limited public SOC 2 for UpCloud entityNot listed
Medium

ISO 27001 and PiTuKri claims are published; a customer-facing SOC 2 Type II for UpCloud itself was not found. Enterprise questionnaires may need NDA artefacts or reliance on ISO plus facility reports.

Colocation facility dependencyNot listed
Low

Platform runs in third-party data centres. Facility certifications differ by site; treat them as complementary to UpCloud’s own ISMS, not a substitute for vendor due diligence.

Fair Transfer Policy on zero egressNot listed
Low

Zero-cost egress is a commercial differentiator but is governed by a Fair Transfer Policy—extreme or abusive transfer patterns may fall outside the marketing promise. Validate for CDN-scale or bulk egress designs.

Fit

Cyso Cloud

Best fit when

  • European product/SaaS teams that need VMs, volumes, and S3-compatible storage with explicit Amsterdam or Frankfurt residency
  • Organisations standardising on OpenStack APIs/CLI to reduce hyperscaler lock-in and support multi-cloud portability
  • Teams wanting CNCF KCSP managed Kubernetes with hibernation and pay-as-you-go worker nodes on EU infrastructure
  • Dutch healthcare-adjacent or regulated buyers who need NEN 7510 alongside ISO 27001 claims from a NL operator
  • Buyers evaluating a private OpenStack cloud or VMware alternative on their own data-centre hardware

Poor fit when

  • Workloads that require many global regions, edge PoPs, or a large marketplace of managed PaaS services
  • Storage designs that assume default server-side encryption at rest without customer-managed keys
  • Procurement that must rely only on a fully published subprocessor schedule without vendor engagement
  • Teams that need fully self-serve free tiers or only automated chat support with no human engineering contact

Consider instead when

  • When: You need many European (or global) regions and a broader product catalogue than two live IaaS regions

    Consider: OVHcloud or Scaleway

    Larger EU multi-region footprints; different APIs and commercial models.

  • When: You want Swiss multi-zone simplicity with strong managed Kubernetes emphasis

    Consider: Exoscale

    Swiss operator profile; fewer regions than hyperscalers but clear sovereignty messaging.

  • When: You need maximum global PaaS depth, AI services, and worldwide edge

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Trade EU ownership for ecosystem breadth; apply your own residency and CLOUD Act analysis.

  • When: You prioritise high-performance European VMs across more city locations than AMS/FRA only

    Consider: UpCloud

    Different stack; compare residency guarantees and support model side by side.

UpCloud

Best fit when

  • EU product teams needing IaaS with Finnish legal entity and pin-to-zone residency
  • Workloads sensitive to block I/O that benefit from MaxIOPS-class SSDs
  • Cloud-native stacks on managed Kubernetes plus managed PostgreSQL/MySQL/Valkey
  • Multi-service apps where predictable outbound transfer packaging matters
  • Agencies and SaaS operators standardising on API/Terraform automation

Poor fit when

  • Organisations that require a full hyperscaler catalogue (proprietary AI/PaaS breadth)
  • Buyers optimising solely for the lowest-cost bare metal or unlimited-traffic VPS
  • Programmes that forbid any non-EU group support access to account metadata without extra controls
  • Teams that will deploy only to US regions yet still market the stack as EU-sovereign

Consider instead when

  • When: You need cheaper raw compute or dedicated servers more than managed K8s packaging

    Consider: Hetzner

    Often stronger on price for VPS/dedicated; compare managed service depth separately.

  • When: You want a broader French/EU public-cloud portfolio or different regional SKUs

    Consider: OVHcloud or Scaleway

    Different product breadth and commercial culture; still European-operated peers.

  • When: You need hyperscaler-managed platforms, global enterprise contracts, or deep marketplace ecosystems

    Consider: AWS, Google Cloud, or Microsoft Azure

    Trade European HQ simplicity for catalogue depth and global account teams.

  • When: You want a compact European cloud with Swiss roots and a tighter region set

    Consider: Exoscale

    Compare region map and managed feature parity to UpCloud’s 15-DC footprint.

Open questions for due diligence

Cyso Cloud

  • Can Cyso provide the current DPA, technical and organisational measures, and a dated subprocessor list covering payments, support, analytics, and status tooling?
  • What is the exact OpenStack release, upgrade cadence, and any divergences from upstream APIs that affect Terraform/automation?
  • For object storage and volumes, what encryption-at-rest or KMS options can be contractually committed for regulated data?
  • What are contractual 24/7 escalation SLAs for severity-1 incidents beyond office-hours tech-to-tech support?
  • Which additional EU regions (if any) have committed go-live dates versus community voting only?

UpCloud

  • Obtain current ISO 27001 certificate scope/dates and any PiTuKri or other audit reports under NDA if required.
  • Confirm DPA Appendix 1 legal names and countries of all group-company subprocessors for your service mix.
  • Document which regions and backup/object-storage endpoints will be allow-listed for EU-only programmes.
  • Ask whether a SOC 2 or equivalent report for UpCloud Oy is available for enterprise review.
  • Validate Fair Transfer Policy thresholds for your expected egress profile.