Exoscale vs STACKIT

Compare Exoscale and STACKIT on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Amazon Web Services (AWS), Google Cloud Platform, Microsoft Azure

Logo: Exoscale

Exoscale

Switzerland· Cloud Computing

Needs review

Shortlist Exoscale when you need multi-country European IaaS (CH/DE/AT/BG/HR zones), managed Kubernetes and open-source DBaaS under a Swiss operator in the A1 Telekom Austria group. Skip when you need hyperscaler global PaaS depth or bare-metal-first catalogs—consider OVHcloud or Scaleway instead, or AWS/Azure/GCP for worldwide regions.

EU/CH zones onlySwiss operator (Akenes SA)Managed Kubernetes (SKS)Managed DBaaSISO 27001/27017/27018 (claimed)Per-second pay-as-you-go
Logo: STACKIT

STACKIT

Germany· Cloud Computing

Needs review

Shortlist STACKIT when you want German-entity IaaS/PaaS on Schwarz Group–owned DE/AT infrastructure with managed Kubernetes, scoped BSI C5 Type 2 claims, and optional same-campus colocation. Skip when you need global multi-region hyperscaler breadth or a fully self-hosted control plane—consider OVHcloud or Scaleway for multi-country EU clouds, or AWS/Azure when worldwide services dominate the architecture.

EU-operatedGerman legal entityGroup-owned DE/AT DCsBSI C5 Type 2 (claimed)Managed Kubernetes (SKE)EU colocation + hybrid
Exoscale vs STACKIT: Snapshot
FeatureLogo: ExoscaleExoscaleLogo: STACKITSTACKIT
Country of originSwitzerlandGermany
CategoryCloud ComputingCloud Computing
Open sourceNoNo
Self-hostedNoNo
HeadquartersSwitzerlandGermany
Legal entityAkenes SA, Boulevard de Grancy 19A, 1006 Lausanne, Switzerland (CHE-423.524.322); member of A1 Digital International GmbH & Co KG / A1 Telekom Austria GroupSchwarz Digits Cloud GmbH & Co. KG (Am Campus 1, 74177 Bad Friedrichshall; imprint lists STACKIT Beteiligungs-GmbH as general partner vehicle in Neckarsulm)
Governing lawSwiss law (DPA: canton of Vaud jurisdiction language)Germany (imprint also notes ICT infrastructure jurisdiction Germany and Austria)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyCustomer compute/storage/SKS on Exoscale European zones (CH-GVA-2, CH-DK-2, DE-FRA-1, DE-MUC-1, AT-VIE-1/2, BG-SOF-1, HR-ZAG-1); DBaaS orchestrated by Aiven Oy (Finland) on Exoscale compute. Client ops third parties include AWS (US) data archival, Twilio (US) auth, PayPal (US) payments—privacy policy states customer-uploaded service data is not sent to those ops providers.Vendor claims STACKIT Cloud runs in group-owned ISO 27001 data centers in Germany and Austria (sites publicly named include Neckarsulm DC01, Ellhofen DC08, Ostermiething DC10; additional EU sites claimed). Cloud regions include EU01 (Germany) and EU02 (Austria). No public evidence found that customer data-plane hosting is on AWS/GCP/Azure. A detailed third-party subprocessor list for all support/analytics tooling was not found on marketing pages—confirm in the AVV.
Summary

European public cloud (IaaS) from Swiss operator Akenes SA (A1 Digital): multi-zone compute, managed Kubernetes (SKS), DBaaS, object and block storage, and GPUs across CH, DE, AT, BG, and HR.

German sovereign cloud from Schwarz Digits (Schwarz Group): IaaS, managed Kubernetes, databases, and colocation on group-owned data centers in Germany and Austria.

Tags
At a glance: Exoscale vs STACKIT
At a glanceLogo: ExoscaleExoscaleLogo: STACKITSTACKIT
HQLausanne, SwitzerlandNot listed
Legal entityAkenes SA (CHE-423.524.322)Not listed
GroupA1 Digital / A1 Telekom Austria GroupNot listed
HostingEuropean zones only (CH, DE, AT, BG, HR)Group-owned data centers in Germany & Austria (e.g. EU01/EU02); not marketed as AWS/Azure reseller
ModelPublic cloud IaaS + managed K8s/DBaaSConsumption-based public cloud + quote-based colocation
Self-hostNo (managed public cloud)Not listed
HQ / legal entityNot listedBad Friedrichshall / Neckarsulm area, Germany — Schwarz Digits Cloud GmbH & Co. KG
ParentNot listedSchwarz Digits (Schwarz Group — Lidl/Kaufland)
Open sourceNot listedUses open-source components; platform itself is managed, not self-hosted
External marketNot listedPublic offering from 2022 (internal roots from 2018)
Key capabilities: Exoscale vs STACKIT
Key capabilitiesLogo: ExoscaleExoscaleLogo: STACKITSTACKIT
EU/CH zones onlyYesNot listed
Swiss operator (Akenes SA)YesNot listed
Managed Kubernetes (SKS)YesNot listed
Managed DBaaSYesNot listed
ISO 27001/27017/27018 (claimed)YesNot listed
Per-second pay-as-you-goYesNot listed
EU-operatedNot listedYes
German legal entityNot listedYes
Group-owned DE/AT DCsNot listedYes
BSI C5 Type 2 (claimed)Not listedYes
Managed Kubernetes (SKE)Not listedYes
EU colocation + hybridNot listedYes

Exoscale

  • Multi-zone European KVM compute

    Launch KVM instances in published zones across Switzerland, Germany, Austria, Bulgaria, and Croatia. Families cover standard, CPU-, memory-, and storage-optimized profiles plus NVIDIA GPU shapes; anti-affinity groups, instance pools, snapshots, custom templates, security groups, and live migration support production patterns. Billed per second with powered-off storage semantics as documented.

  • SKS managed Kubernetes (CNCF certified)

    Scalable Kubernetes Service deploys a managed control plane quickly (vendor claims under about a minute to two minutes). Starter is free without SLA; Pro adds HA control plane, etcd backups, and SLA language. Node pools use Exoscale instance types including GPUs; NLB, CSI storage, autoscaling/Karpenter (Pro), and vanilla CNCF-conformance positioning keep the stack portable.

  • Managed DBaaS on Exoscale compute (Aiven orchestration)

    Managed PostgreSQL, MySQL, Kafka, OpenSearch, Valkey, Grafana, and related engines run as DBaaS with automated backups, plan scaling, and high-availability options. Orchestration subprocessor is Aiven Oy (Finland); database instances run on Exoscale infrastructure in the zone you choose—confirm geo-replication and plan limits in docs before multi-region designs.

  • S3-compatible object storage and block volumes

    Simple Object Storage provides S3-compatible APIs for backups, media, and app assets integrated with Exoscale IAM and zones. Block storage attaches persistent NVMe-class volumes to instances and Kubernetes via CSI for stateful workloads without tying data solely to local disks.

  • IAM, private networks, and automation APIs

    Fine-grained IAM on API keys, private networks, and network load balancers support multi-tier designs. Portal, CLI, API, and Terraform-friendly workflows match common European DevOps practice without requiring a proprietary control language.

STACKIT

  • Compute Engine VMs and GPUs in group-owned EU regions

    Provision Linux and Windows virtual machines, GPU-backed instances, automated server backup and OS update management from the STACKIT portal, CLI, API, or Terraform. Workloads land in European cloud regions such as EU01 (Germany) and EU02 (Austria) on Schwarz Group–operated infrastructure rather than rented hyperscaler bare metal. Best for teams that need predictable EU residency for general compute and AI/ML training or inference on GPU shapes—confirm available instance families per region before migration.

  • STACKIT Kubernetes Engine (SKE)

    Managed, CNCF-compliant Kubernetes with a highly available control plane, automated Kubernetes/OS upgrades, repair functions, pod and node autoscaling, optional temporary cluster shutdown, and automation via Terraform, SKE API, and CLI. Suited to cloud-native apps, stateful workloads on block storage, and ML pipelines that must stay in European regions. Not a self-hosted kubeadm replacement—you consume a managed service with STACKIT-controlled plane components.

  • Managed databases, messaging, and observability

    Fully managed PostgreSQL Flex, MongoDB Flex, SQL Server Flex, MariaDB, Redis, OpenSearch, and RabbitMQ plus LogMe, Logs, and Observability stacks reduce ops load for application teams. Flex models emphasize automated maintenance, backups, and scaling inside the STACKIT cloud. Ideal when you want PaaS data services under the same German operator as your VMs/K8s—validate HA topology, backup retention, and region pairing for each service.

  • Confidential computing and key/secrets control

    Confidential Server and Confidential Kubernetes options aim to protect data in use with hardware-backed isolation; Secrets Manager and Key Management Service handle secret storage/rotation and cryptographic operations. Useful for regulated or multi-tenant sensitive workloads beyond disk encryption alone. Confirm attestation models, supported node types, and which compliance reports cover these products.

  • EU colocation with hybrid path to public cloud

    Racks, cages, and private rooms in Neckarsulm, Ellhofen, and Ostermiething facilities—with remote hands, carrier connectivity, and hybrid designs that keep non-migratable hardware next to STACKIT public cloud. Positions STACKIT for gradual cloud adoption without a pure forklift. Colocation is quote-driven and site certifications can vary by facility; request site data sheets early.

  • Object, block, file, backup, and archiving storage

    S3-compatible object storage, high-performance block volumes, NFS file storage, backup storage, and audit-oriented archiving for retention workloads. Supports application data, VM disks, and compliance archives inside the same European footprint as compute. Check durability/replication claims and cross-region options against your RPO/RTO rather than assuming hyperscaler multi-region defaults.

Assurance & compliance: Exoscale vs STACKIT
Assurance & complianceLogo: ExoscaleExoscaleLogo: STACKITSTACKIT
Independent security / control audit
Partial

Vendor states regular independent audits and publishes multi-framework certs via Compliance Center; not a VPN-style no-logs audit. Download current reports under account/NDA for verification.

Vendor claimed

Vendor claims BSI C5 Type 2 for a listed IaaS/storage product set; reports available on request (iso@digits.schwarz). Not a VPN-style no-logs audit.

ISO 27001
Vendor claimed

Vendor asserts ISO/IEC 27001:2022 ISMS certification since 2018; certificates via Compliance Center.

Vendor claimed

Certificates page claims ISO/IEC 27001 ISMS (with downloadable cert links) plus ISO 27017 and ISO 27018; also ISO 27001 based on IT baseline protection for named IaaS components.

ISO 27017 (cloud security)
Vendor claimed

Listed on compliance site as certified cloud security controls.

Not listed
ISO 27018 (cloud PII)
Vendor claimed

Listed on compliance site for personal data protection in public cloud.

Not listed
SOC 2 / SOC 3
Vendor claimed

SOC 2 listed on compliance marketing; obtain report via Compliance Center / NDA.

Vendor claimed

Vendor states ISAE 3000 (SOC 2) and ISAE 3402 in addition to C5 Type 2; obtain current reports under NDA/request.

BSI C5
Vendor claimed

BSI C5 listed among national/international standards on compliance page.

Vendor claimed

C5 Type 2 claimed for Compute Engine (incl. GPU), Windows/RHEL, server backup/update management, block/object/backup/file storage, archiving—not automatically every PaaS product.

HDS (French health data hosting)
Vendor claimed

HDS listed on compliance page; confirm scope and zones for health workloads.

Not listed
CSA STAR
Vendor claimed

CSA STAR listed on compliance page.

Not listed
GDPR / EU data protection
Vendor claimed

Swiss entity; GDPR + Swiss FADP claims; EU zones; public DPA. Not legal advice.

Vendor claimed

EU legal entity; vendor claims GDPR-aligned operation with processing in own DE/AT data centers and ISO 27018 claims for PII in the cloud.

US CLOUD Act exposure (indicative)
Partial

Swiss operator, no known US parent, European workload zones, and no third-party processor for compute/storage/SKS customer data. Medium residual path via US ops providers (AWS archival, Twilio auth, PayPal) listed for client data. DBaaS uses Aiven (Finland). Not legal advice.

Partial

German operator under Schwarz Digits / Schwarz Group; no known US parent; customer cloud claimed on group-owned EU DCs without named AWS/GCP/Azure data-plane hosts. Partial (not a clean bill): confirm AVV subprocessors and any non-EU support tools. Indicative only—not legal advice.

Data processing agreement (B2B)
Vendor claimed

Public DPA for Akenes SA as processor; Swiss law; Aiven listed for DBaaS.

Not found

No self-serve public AVV/DPA URL confirmed during research; expect contract packaging—request AVV, TOMs, and subprocessor list in procurement.

EU AI Act
Not applicable

Primary product is IaaS/managed infrastructure; customer AI workloads remain customer-controlled. Concrete AI offerings may need separate review if used as an AI system.

Not applicable

Primary offering is IaaS/PaaS infrastructure; optional AI Model Serving and related data/AI products may need separate AI Act analysis if you deploy high-risk AI systems.

TISAX Level 3Not listed
Vendor claimed

Vendor claims TISAX Level 3; verification via ENX portal (assessment ID ATA163-1 / scope ID SH938N per certificates page).

Considerations & known limitations: Exoscale vs STACKIT
Considerations & known limitationsLogo: ExoscaleExoscaleLogo: STACKITSTACKIT
US third parties on client/ops path
Medium

Privacy policy lists AWS (US) data archival, Twilio (US) authentication, and PayPal (US) among client operations providers. Vendor states customer-uploaded service data is not transferred to these providers, but account/ops data paths still matter for CLOUD Act and transfer diligence.

Not listed
DBaaS subprocessor (Aiven)
Low

Managed databases depend on Aiven Oy (Finland) for orchestration while instances run on Exoscale. Confirm contractual chain, access model, and zone placement for sensitive data.

Not listed
Cert evidence mostly in customer portal / NDA
Low

ISO/SOC/C5/HDS claims are strong marketing signals, but full certificates and SOC reports typically require Compliance Center access or NDA—not fully public PDFs for all frameworks.

Not listed
Narrower PaaS than hyperscalers
Medium

Expect solid IaaS, SKS, DBaaS, storage, and GPU—not the global proprietary service catalog of AWS/Azure/GCP. Validate feature gaps early for serverless, global edge, and specialized managed services.

Not listed
Zone catalog evolves
Low

Public materials discuss further European expansion (e.g. Spain via A1 Digital messaging). Treat the live datacenters page as source of truth for residency commitments.

Not listed
Narrower service map than US hyperscalersNot listed
Medium

STACKIT covers core compute, K8s, databases, and storage, but global specialty services and third-party marketplace depth lag AWS/Azure/GCP. Practical impact: multi-cloud or lift-and-shift of complex hyperscaler architectures may need redesign.

C5 Type 2 is product-scopedNot listed
Medium

Attestation tables list specific IaaS/storage products. Teams assuming every managed database or PaaS SKU is C5 Type 2 covered without reading the scope can mis-state compliance. Practical impact: map each in-scope service before audits.

Limited public subprocessor inventoryNot listed
Low

Marketing asserts own data centers and EU processing; a complete public subprocessor/support-tool list was not found on the pages reviewed. Practical impact: force AVV + subprocessor exhibits before production personal data.

Retail-group operator concentrationNot listed
Low

Economic stability is a stated strength of Schwarz Group ownership, but roadmap and commercial leverage differ from pure-play clouds. Practical impact: negotiate exit, data export, and roadmap commitments explicitly.

Fit

Exoscale

Best fit when

  • Teams that must pin VMs, Kubernetes, and object storage to named European zones (including Swiss options)
  • SaaS and product orgs wanting SKS plus managed PostgreSQL/MySQL/Kafka/OpenSearch without running the control planes
  • Buyers who need a published DPA, zone list, and multi-framework compliance pack from a non-US legal entity
  • Workloads that fit IaaS plus managed open-source data services rather than proprietary global PaaS catalogs
  • Organizations evaluating A1 Digital / A1 Telekom Austria group cloud as a European alternative to AWS/Azure/GCP

Poor fit when

  • Products that depend on dozens of proprietary hyperscaler services or multi-continent active-active regions
  • Buyers who require zero US-group SaaS anywhere on the account path (privacy lists AWS archival, Twilio, PayPal for ops)
  • Teams seeking a fully self-hosted OpenStack/Kubernetes distribution rather than a managed public cloud
  • Bare-metal-heavy designs better served by large European bare-metal catalogs (e.g. OVHcloud)

Consider instead when

  • When: You need extensive bare-metal or a different pan-EU hosting footprint

    Consider: OVHcloud

    Often stronger metal catalog and broader hosting packaging; different sovereignty and product mix.

  • When: You want a developer-centric alternative with a different regional product mix

    Consider: Scaleway

    Common EU shortlist peer; compare zones, K8s, and storage packaging side by side.

  • When: You need global regions and deep proprietary PaaS/AI catalogs

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Trade European-operator simplicity for worldwide service breadth and US CLOUD Act parent risk.

STACKIT

Best fit when

  • Public-sector, healthcare, finance, or retail teams that require EU residency under a German operator with dual DE/AT regions
  • Platform teams standardizing on managed Kubernetes (SKE) plus VMs and managed databases in one European cloud
  • Organizations migrating gradually via colocation racks/cages in STACKIT facilities next to public cloud projects
  • Buyers that prioritize BSI C5 Type 2 and ISO 27001 family claims on core compute/storage over hyperscaler marketplace depth
  • Workloads that benefit from GPU compute, confidential computing options, or AI model serving inside the same sovereign stack

Poor fit when

  • Architectures that depend on many specialized AWS/Azure/GCP managed services or global multi-continent regions
  • Teams that must self-host the full cloud control plane rather than consume a managed public cloud
  • Simple single-VM or low-ops hobby hosting where a basic VPS provider is enough
  • Procurement that needs every PaaS product under the same C5 Type 2 table without reviewing scope gaps
  • Use cases requiring non-European data residency as a primary requirement

Consider instead when

  • When: You need a wider multi-country European region map and a large independent cloud portfolio

    Consider: OVHcloud or Scaleway

    Different ownership and product cultures; still not US hyperscaler breadth

  • When: Your workload is mainly simple German VMs/web hosting without managed K8s/PaaS depth

    Consider: IONOS (or similar DE hosts)

    Often simpler packaging for commodity compute

  • When: You require global regions, the largest third-party marketplace, or existing multi-cloud tooling locked to hyperscaler APIs

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Trade EU ownership of the operator for ecosystem scale; apply your own CLOUD Act / transfer analysis

  • When: Swiss or other non-DE sovereignty framing matters more than Schwarz Group scale

    Consider: Exoscale

    Smaller portfolio; different jurisdiction story

Open questions for due diligence

Exoscale

  • Download current ISO/SOC/C5/HDS certificates from the Compliance Center and verify auditor, scope, and expiry for your zones.
  • Confirm whether your use case can accept AWS/Twilio/PayPal on the account/ops path even if workload data stays on European Exoscale zones.
  • For DBaaS, document Aiven access boundaries, encryption, backup locations, and multi-zone replication behavior in writing.
  • If Spanish or other new zones are required, get contractual residency language rather than relying on roadmap announcements.
  • Clarify support plan SLAs and enterprise contracting terms beyond self-serve pay-as-you-go.

STACKIT

  • Will STACKIT provide a signed AVV/DPA, current TOMs, and a full subprocessor list covering support, monitoring, and marketplace components?
  • Which of our target services (SKE, PostgreSQL Flex, Confidential Kubernetes, etc.) fall inside the latest C5 Type 2 and ISO reports?
  • What are the exact region availability, geo-redundancy options, and SLA credits for our workloads across EU01/EU02 (and any additional regions)?
  • What are exit, data export, and termination assistance terms for large object stores and managed databases?
  • For public-sector or KRITIS use cases: which additional attestations, clearance processes, or reference architectures are required?