Hetzner vs STACKIT

Compare Hetzner and STACKIT on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Amazon Web Services (AWS), DigitalOcean, Google Cloud Platform, Microsoft Azure

Logo: Hetzner

Hetzner

Germany· Cloud Computing

Needs review

Shortlist for German-owned IaaS/bare metal in DE/FI parks, API cloud VMs, inclusive-traffic EU economics, ISO 27001 + BSI C5 Type 2. Skip for hyperscaler PaaS depth, SOC 2-first audits, or zero US-group footprint (optional US Ashburn/Hillsboro + Singapore via subsidiaries/colocation). Prefer OVHcloud/Scaleway for broader EU portfolios; STACKIT for DE public-sector framing.

EU-operated (DE HQ)Owned DE/FI parksISO 27001:2022BSI C5 Type 2Bare metal + auctionOptional US/SG cloud
Logo: STACKIT

STACKIT

Germany· Cloud Computing

Needs review

Shortlist STACKIT when you want German-entity IaaS/PaaS on Schwarz Group–owned DE/AT infrastructure with managed Kubernetes, scoped BSI C5 Type 2 claims, and optional same-campus colocation. Skip when you need global multi-region hyperscaler breadth or a fully self-hosted control plane—consider OVHcloud or Scaleway for multi-country EU clouds, or AWS/Azure when worldwide services dominate the architecture.

EU-operatedGerman legal entityGroup-owned DE/AT DCsBSI C5 Type 2 (claimed)Managed Kubernetes (SKE)EU colocation + hybrid
Hetzner vs STACKIT: Snapshot
FeatureLogo: HetznerHetznerLogo: STACKITSTACKIT
Country of originGermanyGermany
CategoryCloud ComputingCloud Computing
Open sourceNoNo
Self-hostedNoNo
HeadquartersGermanyGermany
Legal entityHetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen (HRB 6089 Ansbach)Schwarz Digits Cloud GmbH & Co. KG (Am Campus 1, 74177 Bad Friedrichshall; imprint lists STACKIT Beteiligungs-GmbH as general partner vehicle in Neckarsulm)
Governing lawNot listedGermany (imprint also notes ICT infrastructure jurisdiction Germany and Austria)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyOwned parks: Nuremberg, Falkenstein (DE), Helsinki (FI). Non-cloud EU-only. Cloud optional US (Ashburn, Hillsboro) and Singapore on 3rd-party colocation. AV subprocessors: Hetzner Finland Oy; US: Hetzner US LLC, NTT Americas, QTS Hillsboro; SG: Hetzner Singapore, NTT SG1. Master data stays EU.Vendor claims STACKIT Cloud runs in group-owned ISO 27001 data centers in Germany and Austria (sites publicly named include Neckarsulm DC01, Ellhofen DC08, Ostermiething DC10; additional EU sites claimed). Cloud regions include EU01 (Germany) and EU02 (Austria). No public evidence found that customer data-plane hosting is on AWS/GCP/Azure. A detailed third-party subprocessor list for all support/analytics tooling was not found on marketing pages—confirm in the AVV.
Summary

German data center operator (Gunzenhausen): dedicated servers, Hetzner Cloud VPS, storage, and owned parks in Germany and Finland, with optional US and Singapore cloud locations.

German sovereign cloud from Schwarz Digits (Schwarz Group): IaaS, managed Kubernetes, databases, and colocation on group-owned data centers in Germany and Austria.

Tags
At a glance: Hetzner vs STACKIT
At a glanceLogo: HetznerHetznerLogo: STACKITSTACKIT
HQGunzenhausen, GermanyNot listed
Legal entityHetzner Online GmbH (HRB 6089 Ansbach)Not listed
EU parksNuremberg, Falkenstein (DE); Helsinki (FI)Not listed
Optional cloud regionsAshburn and Hillsboro (US); SingaporeNot listed
ModelIaaS / dedicated / hosting (unmanaged cloud and root)Consumption-based public cloud + quote-based colocation
Open sourceNo (commercial infrastructure)Uses open-source components; platform itself is managed, not self-hosted
HQ / legal entityNot listedBad Friedrichshall / Neckarsulm area, Germany — Schwarz Digits Cloud GmbH & Co. KG
ParentNot listedSchwarz Digits (Schwarz Group — Lidl/Kaufland)
HostingNot listedGroup-owned data centers in Germany & Austria (e.g. EU01/EU02); not marketed as AWS/Azure reseller
External marketNot listedPublic offering from 2022 (internal roots from 2018)
Key capabilities: Hetzner vs STACKIT
Key capabilitiesLogo: HetznerHetznerLogo: STACKITSTACKIT
EU-operated (DE HQ)YesYes
Owned DE/FI parksYesNot listed
ISO 27001:2022YesNot listed
BSI C5 Type 2YesNot listed
Bare metal + auctionYesNot listed
Optional US/SG cloudYesNot listed
German legal entityNot listedYes
Group-owned DE/AT DCsNot listedYes
BSI C5 Type 2 (claimed)Not listedYes
Managed Kubernetes (SKE)Not listedYes
EU colocation + hybridNot listedYes

Hetzner

  • Dedicated root servers and Server Auction

    Bare-metal root servers with full hardware isolation for predictable I/O and custom OS installs. The Server Auction lists surplus or end-of-primary-use machines at declining prices for labs, secondary environments, and cost-sensitive dedicated capacity.

  • Hetzner Cloud with API, networks, and apps

    VMs with shared or dedicated vCPU classes, managed via Console, REST API, and CLI. Private networks, stateful firewalls, load balancers, Linux images, Terraform/Ansible/Kubernetes integrations, and one-click apps (Docker, Nextcloud, GitLab CE, WireGuard, and more) for self-hosted stacks.

  • Owned EU data center parks plus optional US/Singapore cloud

    Company-operated parks in Nuremberg, Falkenstein (Germany), and Helsinki (Finland). Cloud also in Ashburn, Hillsboro (USA), and Singapore on third-party colocation. Non-cloud products and EU-selected cloud locations keep server data in the EU per Hetzner docs; master data stays in the EU.

  • ISO 27001, BSI C5 Type 2, and console DPA

    Public ISO/IEC 27001:2022 certificate for DE/FI park scope; BSI C5 Type 2 for cloud; Art. 28 DPA accept-in-console with published TOMs and annual external TOM review available to DPA customers. Not a SOC 2-first vendor.

  • Inclusive traffic-oriented European cloud pricing model

    Pay-as-you-go cloud (hourly or monthly) and list-based dedicated servers, with marketing emphasis on high inclusive traffic on European plans versus hyperscaler egress bills. Confirm current allowances and rates only on the official calculator—figures change by region and over time.

STACKIT

  • Compute Engine VMs and GPUs in group-owned EU regions

    Provision Linux and Windows virtual machines, GPU-backed instances, automated server backup and OS update management from the STACKIT portal, CLI, API, or Terraform. Workloads land in European cloud regions such as EU01 (Germany) and EU02 (Austria) on Schwarz Group–operated infrastructure rather than rented hyperscaler bare metal. Best for teams that need predictable EU residency for general compute and AI/ML training or inference on GPU shapes—confirm available instance families per region before migration.

  • STACKIT Kubernetes Engine (SKE)

    Managed, CNCF-compliant Kubernetes with a highly available control plane, automated Kubernetes/OS upgrades, repair functions, pod and node autoscaling, optional temporary cluster shutdown, and automation via Terraform, SKE API, and CLI. Suited to cloud-native apps, stateful workloads on block storage, and ML pipelines that must stay in European regions. Not a self-hosted kubeadm replacement—you consume a managed service with STACKIT-controlled plane components.

  • Managed databases, messaging, and observability

    Fully managed PostgreSQL Flex, MongoDB Flex, SQL Server Flex, MariaDB, Redis, OpenSearch, and RabbitMQ plus LogMe, Logs, and Observability stacks reduce ops load for application teams. Flex models emphasize automated maintenance, backups, and scaling inside the STACKIT cloud. Ideal when you want PaaS data services under the same German operator as your VMs/K8s—validate HA topology, backup retention, and region pairing for each service.

  • Confidential computing and key/secrets control

    Confidential Server and Confidential Kubernetes options aim to protect data in use with hardware-backed isolation; Secrets Manager and Key Management Service handle secret storage/rotation and cryptographic operations. Useful for regulated or multi-tenant sensitive workloads beyond disk encryption alone. Confirm attestation models, supported node types, and which compliance reports cover these products.

  • EU colocation with hybrid path to public cloud

    Racks, cages, and private rooms in Neckarsulm, Ellhofen, and Ostermiething facilities—with remote hands, carrier connectivity, and hybrid designs that keep non-migratable hardware next to STACKIT public cloud. Positions STACKIT for gradual cloud adoption without a pure forklift. Colocation is quote-driven and site certifications can vary by facility; request site data sheets early.

  • Object, block, file, backup, and archiving storage

    S3-compatible object storage, high-performance block volumes, NFS file storage, backup storage, and audit-oriented archiving for retention workloads. Supports application data, VM disks, and compliance archives inside the same European footprint as compute. Check durability/replication claims and cross-region options against your RPO/RTO rather than assuming hyperscaler multi-region defaults.

Assurance & compliance: Hetzner vs STACKIT
Assurance & complianceLogo: HetznerHetznerLogo: STACKITSTACKIT
Independent security / no-logs audit
Not applicable

Hosting/IaaS, not a no-logs VPN. Public ISO 27001, BSI C5 Type 2, and annual TOM review (TUV Rheinland) instead.

Vendor claimed

Vendor claims BSI C5 Type 2 for a listed IaaS/storage product set; reports available on request (iso@digits.schwarz). Not a VPN-style no-logs audit.

ISO 27001
Verified

ISO/IEC 27001:2022; public SOCOTEC certificate. Scope: infrastructure, operation, support of Nuremberg, Falkenstein, Helsinki parks.

Vendor claimed

Certificates page claims ISO/IEC 27001 ISMS (with downloadable cert links) plus ISO 27017 and ISO 27018; also ISO 27001 based on IT baseline protection for named IaaS components.

SOC 2 / SOC 3
Not found

Hetzner states focus on ISO 27001 rather than SOC 2 for international market.

Vendor claimed

Vendor states ISAE 3000 (SOC 2) and ISAE 3402 in addition to C5 Type 2; obtain current reports under NDA/request.

GDPR / EU data protection
Vendor claimed

German entity; public privacy policy, Art. 28 DPA, TOMs, subprocessor list. Customer remains controller for data on rented systems.

Vendor claimed

EU legal entity; vendor claims GDPR-aligned operation with processing in own DE/AT data centers and ISO 27018 claims for PII in the cloud.

US CLOUD Act exposure (indicative)
Partial

EU entity / no known US parent, but optional US cloud uses Hetzner US LLC and US colocation (NTT, QTS); Singapore similarly. EU placements keep server data in EU per docs. Not legal advice.

Partial

German operator under Schwarz Digits / Schwarz Group; no known US parent; customer cloud claimed on group-owned EU DCs without named AWS/GCP/Azure data-plane hosts. Partial (not a clean bill): confirm AVV subprocessors and any non-EU support tools. Indicative only—not legal advice.

Data processing agreement (B2B)
Vendor claimed

Standard DPA accept-in-console; sample PDF published; no custom wet-ink DPAs per vendor docs.

Not found

No self-serve public AVV/DPA URL confirmed during research; expect contract packaging—request AVV, TOMs, and subprocessor list in procurement.

EU AI Act
Not applicable

Infrastructure hosting, not an AI system product.

Not applicable

Primary offering is IaaS/PaaS infrastructure; optional AI Model Serving and related data/AI products may need separate AI Act analysis if you deploy high-risk AI systems.

BSI C5 (cloud)
Verified

Vendor publishes BSI C5 Type 2 attestation PDF for cloud services (German BSI catalogue).

Not listed
KRITIS / section 8a BSIG
Vendor claimed

Hetzner states BSI classification as operator of critical services and certification under section 8a BSIG.

Not listed
BSI C5 Type 2Not listed
Vendor claimed

C5 Type 2 claimed for Compute Engine (incl. GPU), Windows/RHEL, server backup/update management, block/object/backup/file storage, archiving—not automatically every PaaS product.

TISAX Level 3Not listed
Vendor claimed

Vendor claims TISAX Level 3; verification via ENX portal (assessment ID ATA163-1 / scope ID SH938N per certificates page).

Considerations & known limitations: Hetzner vs STACKIT
Considerations & known limitationsLogo: HetznerHetznerLogo: STACKITSTACKIT
Optional US and Singapore cloud regions
Medium

Ashburn, Hillsboro, and Singapore use third-party colocation and local subsidiaries; server content placed there leaves the EU. Zero-US-footprint policies may still reject the vendor even for EU-only workloads.

Not listed
Unmanaged cloud and dedicated servers
Medium

You own OS patching, app security, and backups. Platform firewalls help but do not replace customer ops. Poor fit if you need managed DBaaS and full-stack ops.

Not listed
Narrower managed-service catalog vs hyperscalers
Low

Strong IaaS and bare metal; weak match if procurement assumes AWS-parity managed services. Plan hybrid architecture early.

Not listed
ISO scope is DE/FI parks
Low

Published ISO 27001 scope centers on German and Finnish parks. Do not assume identical coverage for every US/Singapore deployment without reading current certificates.

Not listed
Narrower service map than US hyperscalersNot listed
Medium

STACKIT covers core compute, K8s, databases, and storage, but global specialty services and third-party marketplace depth lag AWS/Azure/GCP. Practical impact: multi-cloud or lift-and-shift of complex hyperscaler architectures may need redesign.

C5 Type 2 is product-scopedNot listed
Medium

Attestation tables list specific IaaS/storage products. Teams assuming every managed database or PaaS SKU is C5 Type 2 covered without reading the scope can mis-state compliance. Practical impact: map each in-scope service before audits.

Limited public subprocessor inventoryNot listed
Low

Marketing asserts own data centers and EU processing; a complete public subprocessor/support-tool list was not found on the pages reviewed. Practical impact: force AVV + subprocessor exhibits before production personal data.

Retail-group operator concentrationNot listed
Low

Economic stability is a stated strength of Schwarz Group ownership, but roadmap and commercial leverage differ from pure-play clouds. Practical impact: negotiate exit, data export, and roadmap commitments explicitly.

Fit

Hetzner

Best fit when

  • Teams that want German-jurisdiction hosting with owned parks in Germany and Finland
  • Workloads that need bare-metal root servers or cost-effective dedicated via Server Auction
  • Ops-heavy orgs comfortable with unmanaged IaaS (Console/API/CLI, Terraform, apps)
  • Buyers optimizing for EU residency plus inclusive traffic economics versus hyperscaler egress
  • German/EU checklists asking for ISO 27001, BSI C5, and an Art. 28 DPA in-console

Poor fit when

  • Orgs that need a full AWS/Azure-style managed services catalog (PaaS, serverless, AI)
  • Policies that forbid any US subsidiary, US colocation, or optional US region at group level
  • Buyers requiring SOC 2 as the primary assurance artifact (Hetzner focuses on ISO/C5)
  • Teams expecting fully managed OS patching, databases, and DR without operating the stack

Consider instead when

  • When: You need a broader European cloud portfolio or more managed service surface

    Consider: OVHcloud or Scaleway

    Still European operators; compare regions, bare-metal depth, and support models.

  • When: German public-sector sovereign cloud framing is the primary procurement driver

    Consider: STACKIT

    Different product and governance story; verify current certifications and residency.

  • When: You need hyperscaler managed depth more than EU-owned IaaS

    Consider: AWS, Azure, or Google Cloud (accept US-group CLOUD Act posture)

    Trade EU operator control for catalog breadth.

  • When: You want a smaller EU regional cloud with a different feature/region mix

    Consider: Exoscale or UpCloud

    Compare locations, SLAs, and managed options against Hetzner's park scale.

STACKIT

Best fit when

  • Public-sector, healthcare, finance, or retail teams that require EU residency under a German operator with dual DE/AT regions
  • Platform teams standardizing on managed Kubernetes (SKE) plus VMs and managed databases in one European cloud
  • Organizations migrating gradually via colocation racks/cages in STACKIT facilities next to public cloud projects
  • Buyers that prioritize BSI C5 Type 2 and ISO 27001 family claims on core compute/storage over hyperscaler marketplace depth
  • Workloads that benefit from GPU compute, confidential computing options, or AI model serving inside the same sovereign stack

Poor fit when

  • Architectures that depend on many specialized AWS/Azure/GCP managed services or global multi-continent regions
  • Teams that must self-host the full cloud control plane rather than consume a managed public cloud
  • Simple single-VM or low-ops hobby hosting where a basic VPS provider is enough
  • Procurement that needs every PaaS product under the same C5 Type 2 table without reviewing scope gaps
  • Use cases requiring non-European data residency as a primary requirement

Consider instead when

  • When: You need a wider multi-country European region map and a large independent cloud portfolio

    Consider: OVHcloud or Scaleway

    Different ownership and product cultures; still not US hyperscaler breadth

  • When: Your workload is mainly simple German VMs/web hosting without managed K8s/PaaS depth

    Consider: IONOS (or similar DE hosts)

    Often simpler packaging for commodity compute

  • When: You require global regions, the largest third-party marketplace, or existing multi-cloud tooling locked to hyperscaler APIs

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Trade EU ownership of the operator for ecosystem scale; apply your own CLOUD Act / transfer analysis

  • When: Swiss or other non-DE sovereignty framing matters more than Schwarz Group scale

    Consider: Exoscale

    Smaller portfolio; different jurisdiction story

Open questions for due diligence

Hetzner

  • Does your policy allow a German provider that also offers US/Singapore regions if you only deploy in DE/FI?
  • Is BSI C5 Type 2 + ISO 27001 sufficient, or is SOC 2 mandatory for your auditors?
  • Which SKUs (cloud vs dedicated vs managed web hosting) match your backup and support needs?
  • Will you need regions or managed services Hetzner does not offer natively (CDN, managed DB, AI APIs)?

STACKIT

  • Will STACKIT provide a signed AVV/DPA, current TOMs, and a full subprocessor list covering support, monitoring, and marketplace components?
  • Which of our target services (SKE, PostgreSQL Flex, Confidential Kubernetes, etc.) fall inside the latest C5 Type 2 and ISO reports?
  • What are the exact region availability, geo-redundancy options, and SLA credits for our workloads across EU01/EU02 (and any additional regions)?
  • What are exit, data export, and termination assistance terms for large object stores and managed databases?
  • For public-sector or KRITIS use cases: which additional attestations, clearance processes, or reference architectures are required?