Open Telekom Cloud vs Scaleway

Compare Open Telekom Cloud and Scaleway on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Amazon Web Services (AWS), Google Cloud Platform, Microsoft Azure

Logo: Open Telekom Cloud

Open Telekom Cloud

Germany· Cloud Computing

Needs review

Shortlist when you need a German Telekom/T-Systems OpenStack public cloud with DE/NL/CH regions and a strong BSI C5/ISO/TISAX package for regulated or public-sector workloads. Skip when you need hyperscaler global PaaS breadth or pure self-hosted OpenStack—consider OVHcloud, Scaleway, or AWS/Azure for those cases.

EU-operated (T-Systems)OpenStack public IaaSBSI C5 Type II (claimed)DE / NL / CH regionsGPU + ModelArts AIPay-as-you-go
Logo: Scaleway

Scaleway

France· Cloud Computing

Needs review

Shortlist Scaleway for French-owned multi-AZ IaaS (Paris/Amsterdam/Warsaw) with bare metal, EU-resident GPUs and Kapsule Kubernetes—especially HDS/sovereignty-sensitive stacks. Skip if you need completed SecNumCloud today or hyperscaler global depth; consider OVHcloud, Exoscale/UpCloud, or AWS/Azure/GCP instead.

EU-operated regionsBare metal + Elastic MetalEU GPU for AIKapsule KubernetesISO 27001 (certified)HDS (claimed)
Open Telekom Cloud vs Scaleway: Snapshot
FeatureLogo: Open Telekom CloudOpen Telekom CloudLogo: ScalewayScaleway
Country of originGermanyFrance
CategoryCloud ComputingCloud Computing
Open sourceNoNo
Self-hostedNoNo
HeadquartersGermanyFrance
Legal entityT-Systems International GmbH (Deutsche Telekom group); product marketed as T Cloud Public / Open Telekom CloudSCALEWAY SAS (R.C.S. Paris 433 115 904), 8 rue de la Ville l'Évêque, 75008 Paris
Governing lawGerman / EU law for the cloud service (confirm contract)French law (General Terms of Services)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowLow
Hosting / residencyPrimary: Telekom/T-Systems twin-core data centers in Germany (Biere/Magdeburg), Netherlands (Amsterdam region), and Switzerland (Bern/Zollikofen). No public indication that AWS, Azure, or GCP is the primary IaaS host. Backups/DR via platform multi-AZ services. Full public subprocessor table not found—request DPA annex. Historical Huawei technology partnership is supply-chain diligence, not US-cloud hosting.Customer cloud workloads on Scaleway-operated European multi-AZ infrastructure (Paris, Amsterdam, Warsaw; Milan listed in availability docs)—not primary hosting on AWS/GCP/Azure. Account/controller activities use processors; privacy policy allows some non-EU transfers under SCCs. Full named subprocessor table is via Trust Center/contracts rather than a fully public marketing page.
Summary

Deutsche Telekom / T-Systems sovereign European public cloud (now marketed as T Cloud Public): OpenStack-based IaaS and platform services in Germany, Netherlands, and Swiss regions with BSI C5, ISO, and SOC attestations.

French iliad-group cloud platform: bare metal, virtual instances, EU-resident GPU for AI, managed Kubernetes, serverless, storage and databases on Scaleway-operated multi-AZ regions in Europe.

Tags
At a glance: Open Telekom Cloud vs Scaleway
At a glanceLogo: Open Telekom CloudOpen Telekom CloudLogo: ScalewayScaleway
HQ / operatorGermany — T-Systems / Deutsche TelekomNot listed
Current brandT Cloud Public (formerly Open Telekom Cloud)Not listed
PlatformOpenStack-based public cloudNot listed
RegionsGermany (Biere/Magdeburg), Netherlands, SwitzerlandParis, Amsterdam, Warsaw multi-AZ (+ Milan listed)
Commercial modelPay-as-you-go (+ optional discounts/reservations)Pay-as-you-go; compute Savings Plans (GPU rules differ)
Self-hostNo — managed public cloudNot listed
HQNot listedParis, France (SCALEWAY SAS)
GroupNot listediliad Group subsidiary
ModelNot listedPublic cloud IaaS/PaaS (not self-hosted)
Open sourceNot listedPlatform proprietary; open standards (K8s, S3 API, Terraform)
Key capabilities: Open Telekom Cloud vs Scaleway
Key capabilitiesLogo: Open Telekom CloudOpen Telekom CloudLogo: ScalewayScaleway
EU-operated (T-Systems)YesYes
OpenStack public IaaSYesNot listed
BSI C5 Type II (claimed)YesNot listed
DE / NL / CH regionsYesNot listed
GPU + ModelArts AIYesYes
Pay-as-you-goYesNot listed
Bare metal + Elastic MetalNot listedYes
Kapsule KubernetesNot listedYes
ISO 27001 (certified)Not listedYes
HDS (claimed)Not listedYes

Open Telekom Cloud

  • OpenStack public cloud with Elastic Cloud Server and GPUs

    Self-service IaaS on OpenStack: Elastic Cloud Server flavors from general-purpose to GPU shapes for AI/ML and graphics, plus Dedicated Host and Bare Metal where the region supports them. Provision via console, API, or automation; Auto Scaling for metric-driven capacity. Suited to production VMs and hybrid patterns that need European operator control rather than a thin VPS plan.

  • Multi-AZ object, block, and file storage in EU regions

    Object Storage Service provides S3-compatible multi-AZ object storage; Elastic Volume Service attaches block disks with snapshots; Scalable File Service offers NFS shared filesystems. Cloud Backup and Recovery and related services back up VMs and volumes into platform object storage. Pin workloads to DE, NL, or Swiss regions according to residency policy.

  • VPC networking, Direct Connect, and security services

    Virtual Private Cloud isolation, Elastic Load Balancer, VPN, NAT, Enterprise Router, and Direct Connect for high-bandwidth hybrid links. Security stack includes Anti-DDoS, WAF, Cloud Firewall, Host Security Service, and Key Management Service with bring-your-own-key options—useful for regulated network architectures without leaving Telekom-operated regions.

  • Cloud Container Engine and managed data services

    Cloud Container Engine runs Kubernetes-managed clusters and images; companion services cover container instances and registries. Relational Database Service supports MySQL, PostgreSQL, and Microsoft SQL with HA and backup patterns; document, cache (Redis-class), MapReduce, and search services extend the data plane. Service availability differs between DE and NL—check the regional matrix before design freezes.

  • ModelArts and sovereign AI positioning

    ModelArts provides an end-to-end AI development path (data prep, training, deployment) on European infrastructure, with GPU-backed instances for training and inference. Aimed at teams that want model and training-data residency under the same European operator as their IaaS—confirm which AI services exist in your chosen region (several AI offerings are DE-focused).

  • Twin-core European data centers (DE, NL, CH)

    Published regions: twin-core Germany (Biere/Magdeburg), Netherlands (Amsterdam area), and Switzerland (Bern/Zollikofen) for Swiss data residency. Vendor claims geo-redundant twin-core design, high availability targets, and renewable-powered German facilities. Not a global multi-continent footprint—by design for European sovereignty shortlists.

Scaleway

  • Elastic Metal, Dedibox and Apple Silicon bare metal

    Single-tenant physical servers without a shared hypervisor layer: Dedibox for a wide dedicated catalogue, Elastic Metal for bare metal integrated with Scaleway VPC, load balancing, storage and Kubernetes, plus Apple Silicon Mac mini hosts for native macOS/iOS CI. Best when you need hardware isolation, custom kernels, or GPU bare metal without VM overhead—product lines are still converging, so compare availability zone coverage per SKU.

  • EU-resident GPU instances for AI training and inference

    On-demand GPU VMs with recent NVIDIA options (including L4, L40S, H100 PCIe/SXM and B300-SXM) aimed at LLM fine-tuning, inference and graphics/media acceleration, with data residency in European regions. Integrates with Kapsule via the NVIDIA GPU Operator; pay-as-you-go by the minute. GPU capacity and Savings Plan eligibility differ from general instances—validate stock and zone before committing multi-node jobs.

  • Kubernetes Kapsule and multi-cloud Kosmos

    Managed Kubernetes control planes on Scaleway nodes (Kapsule) with autoscaling-oriented operations, plus Kosmos for hybrid/multi-cloud worker pools including non-Scaleway infrastructure. Suits teams standardising on portable Kubernetes rather than proprietary orchestrators; external Kosmos pools remain your responsibility to patch and size.

  • Multi-AZ European regions with VPC networking

    Place compute and storage in Paris, Amsterdam and Warsaw multi-AZ regions (docs also reference Milan), using regional private networking, load balancers and related network services. Useful for EU latency and residency designs without a US region on the primary map—confirm each product’s AZ matrix in the product-availability guide before multi-region DR planning.

  • Managed storage and databases on open-ish APIs

    S3-compatible Object Storage (including multi-AZ class options), block volumes, and managed database engines (PostgreSQL, MySQL, Redis, MongoDB, ClickHouse-oriented analytics) plus serverless containers/functions/jobs. Reduces day-2 ops for common stack pieces while keeping export paths closer to open standards than pure proprietary PaaS—always check engine versions, HA options and backup retention for production.

  • API, CLI and Terraform-first operations

    Full console plus documented APIs, CLI and Infrastructure-as-Code workflows for provisioning instances, networks and managed services. Fits platform teams automating environments; IAM permissions and account Owner roles still need deliberate design for production orgs.

Assurance & compliance: Open Telekom Cloud vs Scaleway
Assurance & complianceLogo: Open Telekom CloudOpen Telekom CloudLogo: ScalewayScaleway
Independent security / no-logs audit
Not applicable

IaaS platform—not a no-logs consumer VPN. Independent assurance is via ISO/SOC/C5-style audits rather than a no-logs report.

Not applicable

IaaS provider (not a no-logs VPN). Trust Center references penetration testing and security reports available on request; not a public no-logs audit product claim.

ISO 27001
Vendor claimed

Vendor certifications page links ISO/IEC 27001 umbrella certificate PDF for download; re-verify serial/date in procurement.

Verified

ISO/IEC 27001:2022 certificate documentation published (e.g. certificate IS 787020 for SCALEWAY, Paris). Confirm scope covers the services you buy.

ISO/IEC 27017 (cloud security)
Vendor claimed

Claimed with downloadable attestation PDF on certifications page.

Not listed
ISO/IEC 27018 (cloud PII)
Vendor claimed

Claimed with downloadable attestation PDF on certifications page.

Not listed
SOC 2 / SOC 3
Vendor claimed

SOC 2 Type II (request report); SOC 3 public PDF linked on certifications page. SOC 1 Type II also claimed.

Not found

Not listed among public Trust Center compliance badges reviewed (GDPR, HDS, ISO 27001, CSA STAR L1).

BSI C5 Type II
Vendor claimed

Vendor claims BSI C5:2020 Type II (ISAE 3000); detailed report typically on request via audit-reports download flow.

Not listed
TISAX Level 3
Vendor claimed

Vendor states TISAX Level 3 for Germany and Netherlands regions.

Not listed
GDPR / EU data protection
Vendor claimed

EU operator, EU/CH regions, ISO 27018/27701 claims, DPA language on marketing pages—confirm signed DPA for your entity.

Vendor claimed

EU controller/processor with published privacy policy and DPA; French entity. Not legal advice.

US CLOUD Act exposure (indicative)
Partial

German Telekom/T-Systems operator, no known US parent of the cloud business, primary hosting on Telekom EU/CH data centers (not AWS/GCP/Azure). Not a legal clearance of zero extraterritorial risk. Historical Huawei tech partnership is separate supply-chain diligence. Not legal advice.

Partial

French SAS / iliad Group; customer IaaS on self-operated EU regions; no US parent found. Controller-side processors and possible third-country transfers per privacy policy; SecNumCloud not complete. Assessment only—not a vendor “safe” claim.

Data processing agreement (B2B)
Vendor claimed

Vendor GDPR pages state DPA, TOMs, and audit reports available for B2B; obtain current signed pack—not fully self-serve public template verified here.

Vendor claimed

DPA PDF downloadable on https://www.scaleway.com/en/contracts/ alongside TOMs.

EU AI Act
Partial

Platform offers AI services (ModelArts) that may fall under customer AI Act obligations; OTC itself is infrastructure—not an automated high-risk AI system assessment by EuropeanStack.

Not applicable

Infrastructure/GPU host; customer models and apps drive AI Act roles. Not an AI Act conformity product claim.

HDS (French health data hosting)Not listed
Vendor claimed

Vendor security and healthcare pages claim HDS certification; Trust Center lists HDS. Confirm certified service scope for your architecture.

CSA STAR Level 1Not listed
Vendor claimed

Trust Center announces CSA STAR Level 1 (CCM self-assessment / CAIQ).

ANSSI SecNumCloudNot listed
Partial

Qualification process started (public news); security pages mark SecNumCloud as ongoing—not obtained as a finished qualification in sources reviewed.

Considerations & known limitations: Open Telekom Cloud vs Scaleway
Considerations & known limitationsLogo: Open Telekom CloudOpen Telekom CloudLogo: ScalewayScaleway
Historical Huawei technology partnership
Medium

Platform launched with Huawei hardware/software partnership; residual stack components may still matter for sensitive public-sector RFPs. T-Systems states independent operation. Review supply-chain docs under NDA.

Not listed
Service catalog differs by region
Medium

Several services (e.g. ModelArts, bare metal, some database/analytics SKUs) are unavailable in NL or limited to DE. Design against the live regional matrix, not the full marketing list.

Not listed
Limited public subprocessor table
Low

Unlike some SaaS vendors, a complete public subprocessor inventory was not found on marketing pages. Request DPA annex and subcontractor list before high-assurance processing.

Not listed
Smaller global ecosystem than AWS/Azure/GCP
Low

Expect fewer regions, fewer proprietary PaaS services, and a smaller marketplace than US hyperscalers. Migration tools and partner ecosystem exist but differ in depth.

Not listed
Brand transition OTC → T Cloud Public
Low

Documentation, console URLs, and community still mix Open Telekom Cloud and T Cloud Public names. Factor rebrand into runbooks and vendor risk registers.

Not listed
SecNumCloud not yet obtainedNot listed
Medium

ANSSI SecNumCloud is in progress on public materials. Regulated French public-sector tenders that hard-require a qualified cloud today may need another SKU/provider or a delayed migration plan.

Smaller service catalogue than US hyperscalersNot listed
Medium

Expect fewer proprietary managed services and less global region density than AWS/Azure/GCP. Multi-cloud or complementary SaaS may still be required for parts of the estate.

Account-plane processors and possible non-EU transfersNot listed
Low

Even with EU workload regions, privacy policy allows processor use and SCC-backed transfers for some controller purposes (support, payments, marketing, etc.). Pull the live subprocessor list for DPIAs.

Shared responsibility for guest securityNot listed
Medium

Scaleway secures the platform; you own OS hardening, IAM, application security, encryption keys and backups. Recent Trust Center advisories on kernel issues illustrate customer patching duties on instances and Kapsule nodes.

Dedibox vs Elastic Metal product splitNot listed
Low

Two bare-metal experiences still coexist while Scaleway documents convergence. Mis-choosing the line can affect API integration, networking features and migration effort.

Fit

Open Telekom Cloud

Best fit when

  • German public sector and regulated buyers needing Telekom-group operator plus BSI C5 / ISO package
  • Enterprises pinning workloads to DE, NL, or Swiss twin-core regions under GDPR (and Swiss DSG where relevant)
  • Teams wanting OpenStack-based IaaS with ECS, object/block storage, VPC, and Kubernetes (CCE) without US hyperscaler residency defaults
  • AI/ML projects that require GPU capacity and ModelArts-class tooling with European data residency messaging
  • Hybrid architectures using Direct Connect / VPN into Telekom data centers with 24/7 European support expectations

Poor fit when

  • Workloads that require dozens of global regions or deep proprietary hyperscaler PaaS catalogs
  • Buyers seeking a free self-hosted OpenStack distribution rather than a commercial public cloud
  • Teams that need every service in every region—several AI, bare-metal, and data services are DE-only or limited
  • Organisations that reject any non-European technology supply chain without further review (historical Huawei partnership)

Consider instead when

  • When: You need extensive bare-metal catalogs and a very large multi-country EU footprint

    Consider: OVHcloud

    Different operator (France) and product packaging; compare bare-metal and region maps.

  • When: You prefer developer-centric European cloud packaging outside the Telekom stack

    Consider: Scaleway or Exoscale

    Scaleway for FR/NL-oriented developer UX; Exoscale for Swiss multi-zone IaaS + managed K8s.

  • When: You need global regions, marketplace depth, or proprietary PaaS only hyperscalers provide

    Consider: AWS, Microsoft Azure, or Google Cloud Platform

    Accept US-parent CLOUD Act exposure and multi-region complexity in exchange for breadth.

  • When: You want German-market hosting adjacency with a different commercial/product mix

    Consider: IONOS

    Often compared for German buyers; validate IaaS depth vs OTC enterprise cloud features.

Scaleway

Best fit when

  • Teams that need compute, storage, networking and managed Kubernetes in documented EU multi-AZ regions under a French legal entity
  • AI/ML workloads that require NVIDIA GPUs with European data residency rather than US-region training defaults
  • Workloads that benefit from single-tenant bare metal (Elastic Metal or Dedibox) alongside cloud APIs
  • Healthtech or French-market buyers that need HDS-oriented hosting signals plus a published B2B DPA
  • Platform engineers standardising on Terraform/API-driven provisioning with S3-compatible storage and managed Postgres/MySQL

Poor fit when

  • Organisations that require a finished ANSSI SecNumCloud qualification on day one (process is ongoing, not completed on public pages)
  • Architectures that must run primary production in US or APAC regions on the same cloud account
  • Buyers that need the full hyperscaler catalogue (global edge, proprietary PaaS density, enterprise marketplace breadth)
  • Teams expecting a self-hosted “install Scaleway on your own DC” product rather than a managed cloud
  • Procurement processes that accept only SOC 2 Type II as the primary assurance artefact (not surfaced as a public Trust Center badge here)

Consider instead when

  • When: You need completed SecNumCloud-qualified private cloud or a larger non-EU region footprint under one European operator

    Consider: OVHcloud

    Compare exact qualified product SKUs and region maps; OVH and Scaleway are both French industrial clouds with different strengths.

  • When: You want simpler EU VPS/dedicated economics with a smaller product surface

    Consider: UpCloud, Exoscale, or Cyso Cloud

    Leaner catalogues; validate GPU, HDS and multi-AZ needs separately.

  • When: You need maximum global managed-service depth and partner ecosystem

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Accept US-parent CLOUD Act exposure and design residency/controls explicitly.

  • When: German SMB hosting plus EU cloud under a DE-centric brand is the priority

    Consider: IONOS

    Different product mix and market focus than Scaleway’s developer/AI-oriented public cloud.

Open questions for due diligence

Open Telekom Cloud

  • Will T-Systems provide the current full subprocessor/subcontractor list and signed DPA annex for our legal entity and region?
  • What is the residual Huawei (or other non-EU) component inventory for the regions we will use, and is it acceptable under our procurement policy?
  • Which services in our target architecture are available in DE vs NL vs Swiss regions with which SLAs?
  • Can we obtain current C5 Type II and SOC 2 reports (not only marketing claims and SOC 3 summary) under NDA?
  • For AI workloads, which ModelArts/GPU SKUs and data paths apply, and how do they map to our EU AI Act role?

Scaleway

  • What is the exact HDS certificate scope (services, regions, shared responsibility) for our architecture?
  • What is the current ANSSI SecNumCloud milestone and target date for the SKUs we would buy?
  • Which named subprocessors (including any non-EU) process account, billing, support or security telemetry data?
  • For multi-region DR, which products are GA in each AZ (including Milan) at contract time?
  • Are independent SOC 2 / C5 or other reports available under NDA if our assurance programme requires them?