Hostinger vs STACKIT

Compare Hostinger and STACKIT on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: DigitalOcean

Logo: Hostinger

Hostinger

Lithuania· Cloud Computing

Needs review

Shortlist Hostinger when you want managed WordPress or a simple KVM VPS with an EU data-center option and a published DPA. Skip it when you need HIPAA or PCI, an EU-only data path, or a custom enterprise SLA. Consider Hetzner or OVHcloud instead for more operator-centric European infrastructure.

EU-operated (Cyprus contract)ISO 27001 (claimed)Managed WordPressKVM VPS + public APIPublic DPASelectable EU data centers
Logo: STACKIT

STACKIT

Germany· Cloud Computing

Needs review

Shortlist STACKIT when you want German-entity IaaS/PaaS on Schwarz Group–owned DE/AT infrastructure with managed Kubernetes, scoped BSI C5 Type 2 claims, and optional same-campus colocation. Skip when you need global multi-region hyperscaler breadth or a fully self-hosted control plane—consider OVHcloud or Scaleway for multi-country EU clouds, or AWS/Azure when worldwide services dominate the architecture.

EU-operatedGerman legal entityGroup-owned DE/AT DCsBSI C5 Type 2 (claimed)Managed Kubernetes (SKE)EU colocation + hybrid
Hostinger vs STACKIT: Snapshot
FeatureLogo: HostingerHostingerLogo: STACKITSTACKIT
Country of originLithuaniaGermany
CategoryCloud ComputingCloud Computing
Open sourceNoNo
Self-hostedNoNo
HeadquartersLithuaniaGermany
Legal entityEU customers: Hostinger International Ltd (Cyprus). Affiliates: HOSTINGER, UAB and HOSTINGER operations, UAB (Vilnius). Also Hostinger UK Limited and Hostinger Global S.a r.l. (Luxembourg).Schwarz Digits Cloud GmbH & Co. KG (Am Campus 1, 74177 Bad Friedrichshall; imprint lists STACKIT Beteiligungs-GmbH as general partner vehicle in Neckarsulm)
Governing lawNot listedGermany (imprint also notes ICT infrastructure jurisdiction Germany and Austria)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyCustomer-chosen DCs: FR, DE, LT, NL, UK plus US (Phoenix, Boston, Asheville), Brazil, India, Indonesia, Malaysia (plan-dependent). DPA subprocessors include AWS EMEA SARL, Google Cloud EMEA Limited, Cloudflare, Inc., MailChannels, Proofpoint, Inc., Anthropic Ireland, and spectra tech UAB. Privacy policy also names Google Analytics, Meta ads, Ravelin, and iDenfy.Vendor claims STACKIT Cloud runs in group-owned ISO 27001 data centers in Germany and Austria (sites publicly named include Neckarsulm DC01, Ellhofen DC08, Ostermiething DC10; additional EU sites claimed). Cloud regions include EU01 (Germany) and EU02 (Austria). No public evidence found that customer data-plane hosting is on AWS/GCP/Azure. A detailed third-party subprocessor list for all support/analytics tooling was not found on marketing pages—confirm in the AVV.
Summary

Lithuania-founded web hosting for WordPress, managed cloud, and KVM VPS, with selectable European data centers and Cyprus contracting for EU customers.

German sovereign cloud from Schwarz Digits (Schwarz Group): IaaS, managed Kubernetes, databases, and colocation on group-owned data centers in Germany and Austria.

Tags
At a glance: Hostinger vs STACKIT
At a glanceLogo: HostingerHostingerLogo: STACKITSTACKIT
HQ / operationsVilnius, Lithuania (also Kaunas; Yogyakarta office)Not listed
EU contracting entityHostinger International Ltd (Larnaca, Cyprus)Not listed
Founded2004 as Hosting Media; Hostinger brand in 2011Not listed
Product shapeManaged web/WordPress, managed cloud, KVM VPS, domains, emailNot listed
Open source / self-hostNeither. Proprietary platform; VPS guests are customer-managedNot listed
Commercial modelPrepaid subscription with auto-renew; 30-day money-back on eligible hostingNot listed
HQ / legal entityNot listedBad Friedrichshall / Neckarsulm area, Germany — Schwarz Digits Cloud GmbH & Co. KG
ParentNot listedSchwarz Digits (Schwarz Group — Lidl/Kaufland)
HostingNot listedGroup-owned data centers in Germany & Austria (e.g. EU01/EU02); not marketed as AWS/Azure reseller
ModelNot listedConsumption-based public cloud + quote-based colocation
Open sourceNot listedUses open-source components; platform itself is managed, not self-hosted
External marketNot listedPublic offering from 2022 (internal roots from 2018)
Key capabilities: Hostinger vs STACKIT
Key capabilitiesLogo: HostingerHostingerLogo: STACKITSTACKIT
EU-operated (Cyprus contract)YesYes
ISO 27001 (claimed)YesNot listed
Managed WordPressYesNot listed
KVM VPS + public APIYesNot listed
Public DPAYesNot listed
Selectable EU data centersYesNot listed
German legal entityNot listedYes
Group-owned DE/AT DCsNot listedYes
BSI C5 Type 2 (claimed)Not listedYes
Managed Kubernetes (SKE)Not listedYes
EU colocation + hybridNot listedYes

Hostinger

  • Selectable European and global data centers

    Web and cloud plans can be placed in France, Germany, Lithuania, the Netherlands, or the United Kingdom, or in the United States, Brazil, India, Indonesia, or Malaysia. VPS omits the Netherlands. Location is chosen at setup and can be moved later on web and cloud, but not on VPS without rebuild.

  • Managed WordPress on LiteSpeed and hPanel

    Plans include one-click install, staging, automatic updates, malware scanning, WAF, Let's Encrypt, WP-CLI, SSH, and Git. WordPress.org lists Hostinger as a recommended host. Shared plans isolate accounts with CloudLinux LVE. Not a self-hosted WordPress appliance you run elsewhere.

  • KVM VPS with root, templates, and a public API

    KVM guests use AMD EPYC and NVMe, weekly backups, snapshots, a managed firewall, Wanguard DDoS filtering, and one-click OS or app templates (Docker, n8n, Ubuntu, and others). A documented public API and MCP server support automation. The guest is unmanaged: you patch the OS.

  • Managed cloud with dedicated IP and NVMe

    Cloud plans keep hPanel and add more CPU, RAM, NVMe, PHP workers, inode headroom, a dedicated IP, CDN, and daily or on-demand backups. Aimed at agencies and busier WordPress or Node.js sites that do not want root. Upgrade path from shared hosting is in-panel.

  • In-house hPanel, Access Manager, and migrations

    hPanel is Hostinger's control plane for sites, DNS, mail, backups, and collaborators. Access Manager shares scoped access without handing over the account password. Website migration is a supported request flow for common CMS stacks. Developer tools (SSH, Git, PHP versions) live in the same panel.

  • Public DPA with a named sub-processor list

    A click-through DPA covers hosting, VPS, email, domains, Website Builder, Horizons, and Reach. Appendix 3 lists AWS EMEA, Google Cloud EMEA, Cloudflare, MailChannels, Proofpoint, Anthropic Ireland, and spectra tech UAB. New sub-processors can be added with a 10-day objection window.

STACKIT

  • Compute Engine VMs and GPUs in group-owned EU regions

    Provision Linux and Windows virtual machines, GPU-backed instances, automated server backup and OS update management from the STACKIT portal, CLI, API, or Terraform. Workloads land in European cloud regions such as EU01 (Germany) and EU02 (Austria) on Schwarz Group–operated infrastructure rather than rented hyperscaler bare metal. Best for teams that need predictable EU residency for general compute and AI/ML training or inference on GPU shapes—confirm available instance families per region before migration.

  • STACKIT Kubernetes Engine (SKE)

    Managed, CNCF-compliant Kubernetes with a highly available control plane, automated Kubernetes/OS upgrades, repair functions, pod and node autoscaling, optional temporary cluster shutdown, and automation via Terraform, SKE API, and CLI. Suited to cloud-native apps, stateful workloads on block storage, and ML pipelines that must stay in European regions. Not a self-hosted kubeadm replacement—you consume a managed service with STACKIT-controlled plane components.

  • Managed databases, messaging, and observability

    Fully managed PostgreSQL Flex, MongoDB Flex, SQL Server Flex, MariaDB, Redis, OpenSearch, and RabbitMQ plus LogMe, Logs, and Observability stacks reduce ops load for application teams. Flex models emphasize automated maintenance, backups, and scaling inside the STACKIT cloud. Ideal when you want PaaS data services under the same German operator as your VMs/K8s—validate HA topology, backup retention, and region pairing for each service.

  • Confidential computing and key/secrets control

    Confidential Server and Confidential Kubernetes options aim to protect data in use with hardware-backed isolation; Secrets Manager and Key Management Service handle secret storage/rotation and cryptographic operations. Useful for regulated or multi-tenant sensitive workloads beyond disk encryption alone. Confirm attestation models, supported node types, and which compliance reports cover these products.

  • EU colocation with hybrid path to public cloud

    Racks, cages, and private rooms in Neckarsulm, Ellhofen, and Ostermiething facilities—with remote hands, carrier connectivity, and hybrid designs that keep non-migratable hardware next to STACKIT public cloud. Positions STACKIT for gradual cloud adoption without a pure forklift. Colocation is quote-driven and site certifications can vary by facility; request site data sheets early.

  • Object, block, file, backup, and archiving storage

    S3-compatible object storage, high-performance block volumes, NFS file storage, backup storage, and audit-oriented archiving for retention workloads. Supports application data, VM disks, and compliance archives inside the same European footprint as compute. Check durability/replication claims and cross-region options against your RPO/RTO rather than assuming hyperscaler multi-region defaults.

Assurance & compliance: Hostinger vs STACKIT
Assurance & complianceLogo: HostingerHostingerLogo: STACKITSTACKIT
Independent security / no-logs audit
Not found

Vendor describes internal pentests and a HackerOne-style responsible disclosure programme. No public independent audit PDF found.

Vendor claimed

Vendor claims BSI C5 Type 2 for a listed IaaS/storage product set; reports available on request (iso@digits.schwarz). Not a VPN-style no-logs audit.

ISO 27001
Vendor claimed

Trust Center and security article claim ISO/IEC 27001:2022. Certificate download requires Trust Center access. Not independently verified here.

Vendor claimed

Certificates page claims ISO/IEC 27001 ISMS (with downloadable cert links) plus ISO 27017 and ISO 27018; also ISO 27001 based on IT baseline protection for named IaaS components.

SOC 2 / SOC 3
Not found

No public SOC 2 or SOC 3 report found on Trust Center overview or legal pages.

Vendor claimed

Vendor states ISAE 3000 (SOC 2) and ISAE 3402 in addition to C5 Type 2; obtain current reports under NDA/request.

GDPR / EU data protection
Vendor claimed

EU/UK/Luxembourg contracting entities; privacy policy cites GDPR; DPA includes EU SCCs and UK addendum. Confirm entity on the invoice.

Vendor claimed

EU legal entity; vendor claims GDPR-aligned operation with processing in own DE/AT data centers and ISO 27018 claims for PII in the cloud.

US CLOUD Act exposure (indicative)
Partial

European group, no known US parent. Exposure is medium because customers may select US data centers and the DPA names US-group processors (AWS EMEA, Google Cloud EMEA, Cloudflare, Proofpoint). Not legal advice.

Partial

German operator under Schwarz Digits / Schwarz Group; no known US parent; customer cloud claimed on group-owned EU DCs without named AWS/GCP/Azure data-plane hosts. Partial (not a clean bill): confirm AVV subprocessors and any non-EU support tools. Indicative only—not legal advice.

Data processing agreement (B2B)
Vendor claimed

Public DPA incorporated into the Terms of Service. Parties: Hostinger International Ltd, Hostinger UK Limited, or Hostinger Global S.a r.l.

Not found

No self-serve public AVV/DPA URL confirmed during research; expect contract packaging—request AVV, TOMs, and subprocessor list in procurement.

EU AI Act
Not applicable

Core product is hosting. Horizons, Kodee, and Reach are AI features inside that product, not an AI-centric system of record.

Not applicable

Primary offering is IaaS/PaaS infrastructure; optional AI Model Serving and related data/AI products may need separate AI Act analysis if you deploy high-risk AI systems.

HIPAA / PCI environment
Not applicable

Hosting agreement: services are not intended to provide a PCI or HIPAA compliant environment.

Not listed
BSI C5 Type 2Not listed
Vendor claimed

C5 Type 2 claimed for Compute Engine (incl. GPU), Windows/RHEL, server backup/update management, block/object/backup/file storage, archiving—not automatically every PaaS product.

TISAX Level 3Not listed
Vendor claimed

Vendor claims TISAX Level 3; verification via ENX portal (assessment ID ATA163-1 / scope ID SH938N per certificates page).

Considerations & known limitations: Hostinger vs STACKIT
Considerations & known limitationsLogo: HostingerHostingerLogo: STACKITSTACKIT
Optional non-EU hosting regions
Medium

US, Brazil, and Asia data centers are first-class options. An operator can place production outside the EEA at checkout. Lock region in procurement if residency is required.

Not listed
US-group cloud, CDN, email, and security vendors
Medium

Even an EU VM still depends on AWS EMEA, Google Cloud EMEA, Cloudflare, Proofpoint, MailChannels, plus Google/Meta marketing tools. This is why CLOUD Act exposure is not low.

Not listed
Cyprus contract vs Lithuanian operations
Low

HQ and affiliates are Lithuanian; EU paper is usually Hostinger International Ltd (Cyprus). Invoices may also be charged by other group entities. Confirm the contracting party before security review.

Not listed
ISO 27001 certificate not independently verified here
Low

The cert is claimed on the Trust Center but gated. Download it before treating ISO as verified.

Not listed
Customer still owns CMS, guest OS, and backups
Medium

VPS is unmanaged. Terms require you to keep your own backups even when Hostinger offers weekly copies. Shared and cloud plans are not HIPAA/PCI environments.

Not listed
Narrower service map than US hyperscalersNot listed
Medium

STACKIT covers core compute, K8s, databases, and storage, but global specialty services and third-party marketplace depth lag AWS/Azure/GCP. Practical impact: multi-cloud or lift-and-shift of complex hyperscaler architectures may need redesign.

C5 Type 2 is product-scopedNot listed
Medium

Attestation tables list specific IaaS/storage products. Teams assuming every managed database or PaaS SKU is C5 Type 2 covered without reading the scope can mis-state compliance. Practical impact: map each in-scope service before audits.

Limited public subprocessor inventoryNot listed
Low

Marketing asserts own data centers and EU processing; a complete public subprocessor/support-tool list was not found on the pages reviewed. Practical impact: force AVV + subprocessor exhibits before production personal data.

Retail-group operator concentrationNot listed
Low

Economic stability is a stated strength of Schwarz Group ownership, but roadmap and commercial leverage differ from pure-play clouds. Practical impact: negotiate exit, data export, and roadmap commitments explicitly.

Fit

Hostinger

Best fit when

  • SMBs and creators who want domain, SSL, mail, and a WordPress or builder site in one hPanel
  • Teams that can pick an EU data center (FR, DE, LT, NL, or UK) and still accept named US-group subprocessors
  • Agencies managing multiple client WordPress sites on Hostinger Pro or cloud plans
  • Developers who want a straightforward KVM VPS with templates, weekly backups, and a public API
  • Buyers who need a click-through DPA and published sub-processor list before legal review

Poor fit when

  • Workloads that require a HIPAA or PCI environment (explicitly excluded in the hosting agreement)
  • Organisations that mandate EU-only processing with no US-group cloud, CDN, email, or analytics vendors
  • Buyers who need a custom enterprise SLA, dedicated account team, or AWS/GCP-scale IaaS catalog
  • Operators who need to relocate a VPS between regions without a backup-and-reinstall

Consider instead when

  • When: You want German-operated dedicated servers, object storage, or more operator-centric VPS without a consumer website-builder overlay

    Consider: Hetzner

    Hetzner is in the catalog as German web hosting and cloud.

  • When: You need a large European public cloud with many regions and a stronger IaaS and public-sector posture

    Consider: OVHcloud or IONOS

    Both are catalog EU clouds; IONOS also covers consumer-style web hosting.

  • When: You need US-centric SMB WordPress hosting already familiar to North American agencies

    Consider: GoDaddy or Bluehost

    Different jurisdiction. Useful only if European contracting is not a filter.

STACKIT

Best fit when

  • Public-sector, healthcare, finance, or retail teams that require EU residency under a German operator with dual DE/AT regions
  • Platform teams standardizing on managed Kubernetes (SKE) plus VMs and managed databases in one European cloud
  • Organizations migrating gradually via colocation racks/cages in STACKIT facilities next to public cloud projects
  • Buyers that prioritize BSI C5 Type 2 and ISO 27001 family claims on core compute/storage over hyperscaler marketplace depth
  • Workloads that benefit from GPU compute, confidential computing options, or AI model serving inside the same sovereign stack

Poor fit when

  • Architectures that depend on many specialized AWS/Azure/GCP managed services or global multi-continent regions
  • Teams that must self-host the full cloud control plane rather than consume a managed public cloud
  • Simple single-VM or low-ops hobby hosting where a basic VPS provider is enough
  • Procurement that needs every PaaS product under the same C5 Type 2 table without reviewing scope gaps
  • Use cases requiring non-European data residency as a primary requirement

Consider instead when

  • When: You need a wider multi-country European region map and a large independent cloud portfolio

    Consider: OVHcloud or Scaleway

    Different ownership and product cultures; still not US hyperscaler breadth

  • When: Your workload is mainly simple German VMs/web hosting without managed K8s/PaaS depth

    Consider: IONOS (or similar DE hosts)

    Often simpler packaging for commodity compute

  • When: You require global regions, the largest third-party marketplace, or existing multi-cloud tooling locked to hyperscaler APIs

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Trade EU ownership of the operator for ecosystem scale; apply your own CLOUD Act / transfer analysis

  • When: Swiss or other non-DE sovereignty framing matters more than Schwarz Group scale

    Consider: Exoscale

    Smaller portfolio; different jurisdiction story

Open questions for due diligence

Hostinger

  • Which Hostinger group entity will appear on our invoice and DPA counterparty line?
  • Can we obtain the ISO/IEC 27001:2022 certificate and statement of applicability without NDA friction?
  • Which subprocessors and regions actually touch our account if we pin web hosting to Lithuania or Germany and disable AI, Reach, and Dark Web Monitor?
  • Is a SOC 2 or equivalent report available under NDA?
  • What is the exact SLA credit process and exclusion list for our plan versus the 99.9% marketing figure?

STACKIT

  • Will STACKIT provide a signed AVV/DPA, current TOMs, and a full subprocessor list covering support, monitoring, and marketplace components?
  • Which of our target services (SKE, PostgreSQL Flex, Confidential Kubernetes, etc.) fall inside the latest C5 Type 2 and ISO reports?
  • What are the exact region availability, geo-redundancy options, and SLA credits for our workloads across EU01/EU02 (and any additional regions)?
  • What are exit, data export, and termination assistance terms for large object stores and managed databases?
  • For public-sector or KRITIS use cases: which additional attestations, clearance processes, or reference architectures are required?