Exoscale vs Hetzner

Compare Exoscale and Hetzner on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Amazon Web Services (AWS), Google Cloud Platform, Microsoft Azure

Logo: Exoscale

Exoscale

Switzerland· Cloud Computing

Needs review

Shortlist Exoscale when you need multi-country European IaaS (CH/DE/AT/BG/HR zones), managed Kubernetes and open-source DBaaS under a Swiss operator in the A1 Telekom Austria group. Skip when you need hyperscaler global PaaS depth or bare-metal-first catalogs—consider OVHcloud or Scaleway instead, or AWS/Azure/GCP for worldwide regions.

EU/CH zones onlySwiss operator (Akenes SA)Managed Kubernetes (SKS)Managed DBaaSISO 27001/27017/27018 (claimed)Per-second pay-as-you-go
Logo: Hetzner

Hetzner

Germany· Cloud Computing

Needs review

Shortlist for German-owned IaaS/bare metal in DE/FI parks, API cloud VMs, inclusive-traffic EU economics, ISO 27001 + BSI C5 Type 2. Skip for hyperscaler PaaS depth, SOC 2-first audits, or zero US-group footprint (optional US Ashburn/Hillsboro + Singapore via subsidiaries/colocation). Prefer OVHcloud/Scaleway for broader EU portfolios; STACKIT for DE public-sector framing.

EU-operated (DE HQ)Owned DE/FI parksISO 27001:2022BSI C5 Type 2Bare metal + auctionOptional US/SG cloud
Exoscale vs Hetzner: Snapshot
FeatureLogo: ExoscaleExoscaleLogo: HetznerHetzner
Country of originSwitzerlandGermany
CategoryCloud ComputingCloud Computing
Open sourceNoNo
Self-hostedNoNo
HeadquartersSwitzerlandGermany
Legal entityAkenes SA, Boulevard de Grancy 19A, 1006 Lausanne, Switzerland (CHE-423.524.322); member of A1 Digital International GmbH & Co KG / A1 Telekom Austria GroupHetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen (HRB 6089 Ansbach)
Governing lawSwiss law (DPA: canton of Vaud jurisdiction language)Not listed
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyCustomer compute/storage/SKS on Exoscale European zones (CH-GVA-2, CH-DK-2, DE-FRA-1, DE-MUC-1, AT-VIE-1/2, BG-SOF-1, HR-ZAG-1); DBaaS orchestrated by Aiven Oy (Finland) on Exoscale compute. Client ops third parties include AWS (US) data archival, Twilio (US) auth, PayPal (US) payments—privacy policy states customer-uploaded service data is not sent to those ops providers.Owned parks: Nuremberg, Falkenstein (DE), Helsinki (FI). Non-cloud EU-only. Cloud optional US (Ashburn, Hillsboro) and Singapore on 3rd-party colocation. AV subprocessors: Hetzner Finland Oy; US: Hetzner US LLC, NTT Americas, QTS Hillsboro; SG: Hetzner Singapore, NTT SG1. Master data stays EU.
Summary

European public cloud (IaaS) from Swiss operator Akenes SA (A1 Digital): multi-zone compute, managed Kubernetes (SKS), DBaaS, object and block storage, and GPUs across CH, DE, AT, BG, and HR.

German data center operator (Gunzenhausen): dedicated servers, Hetzner Cloud VPS, storage, and owned parks in Germany and Finland, with optional US and Singapore cloud locations.

Tags
At a glance: Exoscale vs Hetzner
At a glanceLogo: ExoscaleExoscaleLogo: HetznerHetzner
HQLausanne, SwitzerlandGunzenhausen, Germany
Legal entityAkenes SA (CHE-423.524.322)Hetzner Online GmbH (HRB 6089 Ansbach)
GroupA1 Digital / A1 Telekom Austria GroupNot listed
HostingEuropean zones only (CH, DE, AT, BG, HR)Not listed
ModelPublic cloud IaaS + managed K8s/DBaaSIaaS / dedicated / hosting (unmanaged cloud and root)
Self-hostNo (managed public cloud)Not listed
EU parksNot listedNuremberg, Falkenstein (DE); Helsinki (FI)
Optional cloud regionsNot listedAshburn and Hillsboro (US); Singapore
Open sourceNot listedNo (commercial infrastructure)
Key capabilities: Exoscale vs Hetzner
Key capabilitiesLogo: ExoscaleExoscaleLogo: HetznerHetzner
EU/CH zones onlyYesNot listed
Swiss operator (Akenes SA)YesNot listed
Managed Kubernetes (SKS)YesNot listed
Managed DBaaSYesNot listed
ISO 27001/27017/27018 (claimed)YesNot listed
Per-second pay-as-you-goYesNot listed
EU-operated (DE HQ)Not listedYes
Owned DE/FI parksNot listedYes
ISO 27001:2022Not listedYes
BSI C5 Type 2Not listedYes
Bare metal + auctionNot listedYes
Optional US/SG cloudNot listedYes

Exoscale

  • Multi-zone European KVM compute

    Launch KVM instances in published zones across Switzerland, Germany, Austria, Bulgaria, and Croatia. Families cover standard, CPU-, memory-, and storage-optimized profiles plus NVIDIA GPU shapes; anti-affinity groups, instance pools, snapshots, custom templates, security groups, and live migration support production patterns. Billed per second with powered-off storage semantics as documented.

  • SKS managed Kubernetes (CNCF certified)

    Scalable Kubernetes Service deploys a managed control plane quickly (vendor claims under about a minute to two minutes). Starter is free without SLA; Pro adds HA control plane, etcd backups, and SLA language. Node pools use Exoscale instance types including GPUs; NLB, CSI storage, autoscaling/Karpenter (Pro), and vanilla CNCF-conformance positioning keep the stack portable.

  • Managed DBaaS on Exoscale compute (Aiven orchestration)

    Managed PostgreSQL, MySQL, Kafka, OpenSearch, Valkey, Grafana, and related engines run as DBaaS with automated backups, plan scaling, and high-availability options. Orchestration subprocessor is Aiven Oy (Finland); database instances run on Exoscale infrastructure in the zone you choose—confirm geo-replication and plan limits in docs before multi-region designs.

  • S3-compatible object storage and block volumes

    Simple Object Storage provides S3-compatible APIs for backups, media, and app assets integrated with Exoscale IAM and zones. Block storage attaches persistent NVMe-class volumes to instances and Kubernetes via CSI for stateful workloads without tying data solely to local disks.

  • IAM, private networks, and automation APIs

    Fine-grained IAM on API keys, private networks, and network load balancers support multi-tier designs. Portal, CLI, API, and Terraform-friendly workflows match common European DevOps practice without requiring a proprietary control language.

Hetzner

  • Dedicated root servers and Server Auction

    Bare-metal root servers with full hardware isolation for predictable I/O and custom OS installs. The Server Auction lists surplus or end-of-primary-use machines at declining prices for labs, secondary environments, and cost-sensitive dedicated capacity.

  • Hetzner Cloud with API, networks, and apps

    VMs with shared or dedicated vCPU classes, managed via Console, REST API, and CLI. Private networks, stateful firewalls, load balancers, Linux images, Terraform/Ansible/Kubernetes integrations, and one-click apps (Docker, Nextcloud, GitLab CE, WireGuard, and more) for self-hosted stacks.

  • Owned EU data center parks plus optional US/Singapore cloud

    Company-operated parks in Nuremberg, Falkenstein (Germany), and Helsinki (Finland). Cloud also in Ashburn, Hillsboro (USA), and Singapore on third-party colocation. Non-cloud products and EU-selected cloud locations keep server data in the EU per Hetzner docs; master data stays in the EU.

  • ISO 27001, BSI C5 Type 2, and console DPA

    Public ISO/IEC 27001:2022 certificate for DE/FI park scope; BSI C5 Type 2 for cloud; Art. 28 DPA accept-in-console with published TOMs and annual external TOM review available to DPA customers. Not a SOC 2-first vendor.

  • Inclusive traffic-oriented European cloud pricing model

    Pay-as-you-go cloud (hourly or monthly) and list-based dedicated servers, with marketing emphasis on high inclusive traffic on European plans versus hyperscaler egress bills. Confirm current allowances and rates only on the official calculator—figures change by region and over time.

Assurance & compliance: Exoscale vs Hetzner
Assurance & complianceLogo: ExoscaleExoscaleLogo: HetznerHetzner
Independent security / control audit
Partial

Vendor states regular independent audits and publishes multi-framework certs via Compliance Center; not a VPN-style no-logs audit. Download current reports under account/NDA for verification.

Not applicable

Hosting/IaaS, not a no-logs VPN. Public ISO 27001, BSI C5 Type 2, and annual TOM review (TUV Rheinland) instead.

ISO 27001
Vendor claimed

Vendor asserts ISO/IEC 27001:2022 ISMS certification since 2018; certificates via Compliance Center.

Verified

ISO/IEC 27001:2022; public SOCOTEC certificate. Scope: infrastructure, operation, support of Nuremberg, Falkenstein, Helsinki parks.

ISO 27017 (cloud security)
Vendor claimed

Listed on compliance site as certified cloud security controls.

Not listed
ISO 27018 (cloud PII)
Vendor claimed

Listed on compliance site for personal data protection in public cloud.

Not listed
SOC 2 / SOC 3
Vendor claimed

SOC 2 listed on compliance marketing; obtain report via Compliance Center / NDA.

Not found

Hetzner states focus on ISO 27001 rather than SOC 2 for international market.

BSI C5
Vendor claimed

BSI C5 listed among national/international standards on compliance page.

Not listed
HDS (French health data hosting)
Vendor claimed

HDS listed on compliance page; confirm scope and zones for health workloads.

Not listed
CSA STAR
Vendor claimed

CSA STAR listed on compliance page.

Not listed
GDPR / EU data protection
Vendor claimed

Swiss entity; GDPR + Swiss FADP claims; EU zones; public DPA. Not legal advice.

Vendor claimed

German entity; public privacy policy, Art. 28 DPA, TOMs, subprocessor list. Customer remains controller for data on rented systems.

US CLOUD Act exposure (indicative)
Partial

Swiss operator, no known US parent, European workload zones, and no third-party processor for compute/storage/SKS customer data. Medium residual path via US ops providers (AWS archival, Twilio auth, PayPal) listed for client data. DBaaS uses Aiven (Finland). Not legal advice.

Partial

EU entity / no known US parent, but optional US cloud uses Hetzner US LLC and US colocation (NTT, QTS); Singapore similarly. EU placements keep server data in EU per docs. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Public DPA for Akenes SA as processor; Swiss law; Aiven listed for DBaaS.

Vendor claimed

Standard DPA accept-in-console; sample PDF published; no custom wet-ink DPAs per vendor docs.

EU AI Act
Not applicable

Primary product is IaaS/managed infrastructure; customer AI workloads remain customer-controlled. Concrete AI offerings may need separate review if used as an AI system.

Not applicable

Infrastructure hosting, not an AI system product.

BSI C5 (cloud)Not listed
Verified

Vendor publishes BSI C5 Type 2 attestation PDF for cloud services (German BSI catalogue).

KRITIS / section 8a BSIGNot listed
Vendor claimed

Hetzner states BSI classification as operator of critical services and certification under section 8a BSIG.

Considerations & known limitations: Exoscale vs Hetzner
Considerations & known limitationsLogo: ExoscaleExoscaleLogo: HetznerHetzner
US third parties on client/ops path
Medium

Privacy policy lists AWS (US) data archival, Twilio (US) authentication, and PayPal (US) among client operations providers. Vendor states customer-uploaded service data is not transferred to these providers, but account/ops data paths still matter for CLOUD Act and transfer diligence.

Not listed
DBaaS subprocessor (Aiven)
Low

Managed databases depend on Aiven Oy (Finland) for orchestration while instances run on Exoscale. Confirm contractual chain, access model, and zone placement for sensitive data.

Not listed
Cert evidence mostly in customer portal / NDA
Low

ISO/SOC/C5/HDS claims are strong marketing signals, but full certificates and SOC reports typically require Compliance Center access or NDA—not fully public PDFs for all frameworks.

Not listed
Narrower PaaS than hyperscalers
Medium

Expect solid IaaS, SKS, DBaaS, storage, and GPU—not the global proprietary service catalog of AWS/Azure/GCP. Validate feature gaps early for serverless, global edge, and specialized managed services.

Not listed
Zone catalog evolves
Low

Public materials discuss further European expansion (e.g. Spain via A1 Digital messaging). Treat the live datacenters page as source of truth for residency commitments.

Not listed
Optional US and Singapore cloud regionsNot listed
Medium

Ashburn, Hillsboro, and Singapore use third-party colocation and local subsidiaries; server content placed there leaves the EU. Zero-US-footprint policies may still reject the vendor even for EU-only workloads.

Unmanaged cloud and dedicated serversNot listed
Medium

You own OS patching, app security, and backups. Platform firewalls help but do not replace customer ops. Poor fit if you need managed DBaaS and full-stack ops.

Narrower managed-service catalog vs hyperscalersNot listed
Low

Strong IaaS and bare metal; weak match if procurement assumes AWS-parity managed services. Plan hybrid architecture early.

ISO scope is DE/FI parksNot listed
Low

Published ISO 27001 scope centers on German and Finnish parks. Do not assume identical coverage for every US/Singapore deployment without reading current certificates.

Fit

Exoscale

Best fit when

  • Teams that must pin VMs, Kubernetes, and object storage to named European zones (including Swiss options)
  • SaaS and product orgs wanting SKS plus managed PostgreSQL/MySQL/Kafka/OpenSearch without running the control planes
  • Buyers who need a published DPA, zone list, and multi-framework compliance pack from a non-US legal entity
  • Workloads that fit IaaS plus managed open-source data services rather than proprietary global PaaS catalogs
  • Organizations evaluating A1 Digital / A1 Telekom Austria group cloud as a European alternative to AWS/Azure/GCP

Poor fit when

  • Products that depend on dozens of proprietary hyperscaler services or multi-continent active-active regions
  • Buyers who require zero US-group SaaS anywhere on the account path (privacy lists AWS archival, Twilio, PayPal for ops)
  • Teams seeking a fully self-hosted OpenStack/Kubernetes distribution rather than a managed public cloud
  • Bare-metal-heavy designs better served by large European bare-metal catalogs (e.g. OVHcloud)

Consider instead when

  • When: You need extensive bare-metal or a different pan-EU hosting footprint

    Consider: OVHcloud

    Often stronger metal catalog and broader hosting packaging; different sovereignty and product mix.

  • When: You want a developer-centric alternative with a different regional product mix

    Consider: Scaleway

    Common EU shortlist peer; compare zones, K8s, and storage packaging side by side.

  • When: You need global regions and deep proprietary PaaS/AI catalogs

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Trade European-operator simplicity for worldwide service breadth and US CLOUD Act parent risk.

Hetzner

Best fit when

  • Teams that want German-jurisdiction hosting with owned parks in Germany and Finland
  • Workloads that need bare-metal root servers or cost-effective dedicated via Server Auction
  • Ops-heavy orgs comfortable with unmanaged IaaS (Console/API/CLI, Terraform, apps)
  • Buyers optimizing for EU residency plus inclusive traffic economics versus hyperscaler egress
  • German/EU checklists asking for ISO 27001, BSI C5, and an Art. 28 DPA in-console

Poor fit when

  • Orgs that need a full AWS/Azure-style managed services catalog (PaaS, serverless, AI)
  • Policies that forbid any US subsidiary, US colocation, or optional US region at group level
  • Buyers requiring SOC 2 as the primary assurance artifact (Hetzner focuses on ISO/C5)
  • Teams expecting fully managed OS patching, databases, and DR without operating the stack

Consider instead when

  • When: You need a broader European cloud portfolio or more managed service surface

    Consider: OVHcloud or Scaleway

    Still European operators; compare regions, bare-metal depth, and support models.

  • When: German public-sector sovereign cloud framing is the primary procurement driver

    Consider: STACKIT

    Different product and governance story; verify current certifications and residency.

  • When: You need hyperscaler managed depth more than EU-owned IaaS

    Consider: AWS, Azure, or Google Cloud (accept US-group CLOUD Act posture)

    Trade EU operator control for catalog breadth.

  • When: You want a smaller EU regional cloud with a different feature/region mix

    Consider: Exoscale or UpCloud

    Compare locations, SLAs, and managed options against Hetzner's park scale.

Open questions for due diligence

Exoscale

  • Download current ISO/SOC/C5/HDS certificates from the Compliance Center and verify auditor, scope, and expiry for your zones.
  • Confirm whether your use case can accept AWS/Twilio/PayPal on the account/ops path even if workload data stays on European Exoscale zones.
  • For DBaaS, document Aiven access boundaries, encryption, backup locations, and multi-zone replication behavior in writing.
  • If Spanish or other new zones are required, get contractual residency language rather than relying on roadmap announcements.
  • Clarify support plan SLAs and enterprise contracting terms beyond self-serve pay-as-you-go.

Hetzner

  • Does your policy allow a German provider that also offers US/Singapore regions if you only deploy in DE/FI?
  • Is BSI C5 Type 2 + ISO 27001 sufficient, or is SOC 2 mandatory for your auditors?
  • Which SKUs (cloud vs dedicated vs managed web hosting) match your backup and support needs?
  • Will you need regions or managed services Hetzner does not offer natively (CDN, managed DB, AI APIs)?