OVHcloud vs STACKIT

Compare OVHcloud and STACKIT on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Amazon Web Services (AWS), DigitalOcean, Google Cloud Platform, Microsoft Azure

Logo: OVHcloud

OVHcloud

France· Cloud Computing

Needs review

Shortlist OVHcloud when you need a European-owned IaaS/bare-metal stack with SecNumCloud/HDS options and multi-continent regions you control per project. Skip when you need hyperscaler platform depth, or when even optional US subsidiaries/regions are a procurement red line—consider Scaleway for leaner French cloud or Hetzner for simpler dedicated/VPS estates.

EU-operated (global regions)Bare Metal + Public CloudOpenStack Public CloudSecNumCloud Private CloudAnti-DDoS includedEU / US / CA / APAC
Logo: STACKIT

STACKIT

Germany· Cloud Computing

Needs review

Shortlist STACKIT when you want German-entity IaaS/PaaS on Schwarz Group–owned DE/AT infrastructure with managed Kubernetes, scoped BSI C5 Type 2 claims, and optional same-campus colocation. Skip when you need global multi-region hyperscaler breadth or a fully self-hosted control plane—consider OVHcloud or Scaleway for multi-country EU clouds, or AWS/Azure when worldwide services dominate the architecture.

EU-operatedGerman legal entityGroup-owned DE/AT DCsBSI C5 Type 2 (claimed)Managed Kubernetes (SKE)EU colocation + hybrid
OVHcloud vs STACKIT: Snapshot
FeatureLogo: OVHcloudOVHcloudLogo: STACKITSTACKIT
Country of originFranceGermany
CategoryCloud ComputingCloud Computing
Open sourceNoNo
Self-hostedNoNo
HeadquartersFranceGermany
Legal entityOVH SAS / OVH Groupe (Roubaix); regional entities include OVH US LLC for US servicesSchwarz Digits Cloud GmbH & Co. KG (Am Campus 1, 74177 Bad Friedrichshall; imprint lists STACKIT Beteiligungs-GmbH as general partner vehicle in Neckarsulm)
Governing lawFrench/EU law for EU contracts; US terms apply for OVH US LLC-contracted servicesGermany (imprint also notes ICT infrastructure jurisdiction Germany and Austria)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyOwn global infrastructure: EU regions (FR including Paris 3-AZ, DE Limburg, PL Warsaw, UK Erith, IT Milan 3-AZ, many Local Zones); US (Vint Hill VA, Hillsboro OR); Canada (Beauharnois, Toronto); APAC (Singapore, Sydney, Mumbai). Primary hosting is OVH-operated, not AWS/GCP resale. Optional non-EU regions are first-class products.Vendor claims STACKIT Cloud runs in group-owned ISO 27001 data centers in Germany and Austria (sites publicly named include Neckarsulm DC01, Ellhofen DC08, Ostermiething DC10; additional EU sites claimed). Cloud regions include EU01 (Germany) and EU02 (Austria). No public evidence found that customer data-plane hosting is on AWS/GCP/Azure. A detailed third-party subprocessor list for all support/analytics tooling was not found on marketing pages—confirm in the AVV.
Summary

French cloud and infrastructure group (Roubaix): Bare Metal dedicated servers, OpenStack Public Cloud, Hosted Private Cloud (incl. SecNumCloud), and Web Cloud on OVH-operated datacentres across Europe, North America, and Asia-Pacific.

German sovereign cloud from Schwarz Digits (Schwarz Group): IaaS, managed Kubernetes, databases, and colocation on group-owned data centers in Germany and Austria.

Tags
At a glance: OVHcloud vs STACKIT
At a glanceLogo: OVHcloudOVHcloudLogo: STACKITSTACKIT
HQRoubaix, France (OVH SAS / OVH Groupe)Not listed
Founded1999 (Octave Klaba)Not listed
Hosting modelOwn datacentres and network; multi-region IaaS/bare metalNot listed
Open source product?No (OpenStack-based public cloud uses open APIs)Not listed
Commercial modelHourly/monthly public cloud; dedicated server subscriptions; free public cloud trial credits (vendor)Not listed
Notable certs (claimed)ISO 27001 family, SOC 1/2/3, HDS, SecNumCloud (Private Cloud), PCI DSSNot listed
HQ / legal entityNot listedBad Friedrichshall / Neckarsulm area, Germany — Schwarz Digits Cloud GmbH & Co. KG
ParentNot listedSchwarz Digits (Schwarz Group — Lidl/Kaufland)
HostingNot listedGroup-owned data centers in Germany & Austria (e.g. EU01/EU02); not marketed as AWS/Azure reseller
ModelNot listedConsumption-based public cloud + quote-based colocation
Open sourceNot listedUses open-source components; platform itself is managed, not self-hosted
External marketNot listedPublic offering from 2022 (internal roots from 2018)
Key capabilities: OVHcloud vs STACKIT
Key capabilitiesLogo: OVHcloudOVHcloudLogo: STACKITSTACKIT
EU-operated (global regions)YesYes
Bare Metal + Public CloudYesNot listed
OpenStack Public CloudYesNot listed
SecNumCloud Private CloudYesNot listed
Anti-DDoS includedYesNot listed
EU / US / CA / APACYesNot listed
German legal entityNot listedYes
Group-owned DE/AT DCsNot listedYes
BSI C5 Type 2 (claimed)Not listedYes
Managed Kubernetes (SKE)Not listedYes
EU colocation + hybridNot listedYes

OVHcloud

  • Bare Metal dedicated servers (in-house hardware)

    Physical servers assembled and operated by OVHcloud across ranges such as Advance, Scale, High Grade, and Game—full CPU/RAM/storage without a hypervisor layer. Water cooling and hardware lifecycle are part of the industrial model. Best for performance-sensitive, virtualisation, gaming, or large single-tenant workloads where you administer the OS.

  • OpenStack Public Cloud and managed PaaS

    On-demand compute, multi-class object storage (S3-compatible API), block/file storage, managed databases, Kubernetes/container services, networking, and data/AI platforms. Deploy via Control Panel or OpenStack APIs with 1-AZ or 3-AZ region options (for example Paris and Milan). Suited to cloud-native and hybrid automation without US hyperscaler lock-in.

  • Hosted Private Cloud with SecNumCloud path

    VMware-based Hosted Private Cloud (and related stacks) for dedicated virtualisation estates. Selected Private Cloud offerings hold French ANSSI SecNumCloud qualification, with customer data under European regulation and hosting in French sites (Roubaix, Gravelines, Strasbourg)—relevant for French public sector and sensitive workloads under Cloud at the Center doctrine.

  • Global multi-region footprint (EU, US, CA, APAC)

    Own datacentres and regions spanning Europe (France, Germany, Poland, UK, Italy, many Local Zones), North America (Vint Hill VA, Hillsboro OR, Beauharnois and Toronto in Canada), and Asia-Pacific (Singapore, Sydney, Mumbai and related offerings). Choose residency for latency and law; do not assume EU-only by default.

  • Anti-DDoS and vRack private networking included

    Network-integrated anti-DDoS mitigation is standard across services. vRack provides private L2 networking across eligible OVHcloud locations so bare metal, public, and private cloud can interconnect without public exposure. Public bandwidth is typically unmetered in Europe and North America with fair-use rules; Asia-Pacific often uses lower default bandwidth and monthly traffic caps—verify per SKU.

STACKIT

  • Compute Engine VMs and GPUs in group-owned EU regions

    Provision Linux and Windows virtual machines, GPU-backed instances, automated server backup and OS update management from the STACKIT portal, CLI, API, or Terraform. Workloads land in European cloud regions such as EU01 (Germany) and EU02 (Austria) on Schwarz Group–operated infrastructure rather than rented hyperscaler bare metal. Best for teams that need predictable EU residency for general compute and AI/ML training or inference on GPU shapes—confirm available instance families per region before migration.

  • STACKIT Kubernetes Engine (SKE)

    Managed, CNCF-compliant Kubernetes with a highly available control plane, automated Kubernetes/OS upgrades, repair functions, pod and node autoscaling, optional temporary cluster shutdown, and automation via Terraform, SKE API, and CLI. Suited to cloud-native apps, stateful workloads on block storage, and ML pipelines that must stay in European regions. Not a self-hosted kubeadm replacement—you consume a managed service with STACKIT-controlled plane components.

  • Managed databases, messaging, and observability

    Fully managed PostgreSQL Flex, MongoDB Flex, SQL Server Flex, MariaDB, Redis, OpenSearch, and RabbitMQ plus LogMe, Logs, and Observability stacks reduce ops load for application teams. Flex models emphasize automated maintenance, backups, and scaling inside the STACKIT cloud. Ideal when you want PaaS data services under the same German operator as your VMs/K8s—validate HA topology, backup retention, and region pairing for each service.

  • Confidential computing and key/secrets control

    Confidential Server and Confidential Kubernetes options aim to protect data in use with hardware-backed isolation; Secrets Manager and Key Management Service handle secret storage/rotation and cryptographic operations. Useful for regulated or multi-tenant sensitive workloads beyond disk encryption alone. Confirm attestation models, supported node types, and which compliance reports cover these products.

  • EU colocation with hybrid path to public cloud

    Racks, cages, and private rooms in Neckarsulm, Ellhofen, and Ostermiething facilities—with remote hands, carrier connectivity, and hybrid designs that keep non-migratable hardware next to STACKIT public cloud. Positions STACKIT for gradual cloud adoption without a pure forklift. Colocation is quote-driven and site certifications can vary by facility; request site data sheets early.

  • Object, block, file, backup, and archiving storage

    S3-compatible object storage, high-performance block volumes, NFS file storage, backup storage, and audit-oriented archiving for retention workloads. Supports application data, VM disks, and compliance archives inside the same European footprint as compute. Check durability/replication claims and cross-region options against your RPO/RTO rather than assuming hyperscaler multi-region defaults.

Assurance & compliance: OVHcloud vs STACKIT
Assurance & complianceLogo: OVHcloudOVHcloudLogo: STACKITSTACKIT
Independent security / no-logs audit
Not applicable

IaaS/hosting provider, not a no-logs VPN product. Security is covered via ISO/SOC programme rather than a public no-logs audit.

Vendor claimed

Vendor claims BSI C5 Type 2 for a listed IaaS/storage product set; reports available on request (iso@digits.schwarz). Not a VPN-style no-logs audit.

ISO 27001
Vendor claimed

Vendor compliance pages assert ISO/IEC 27001 (with 27017/27018) for cloud services and datacentres; US pages reference Schellman certificate directory. Confirm current scope per product and region.

Vendor claimed

Certificates page claims ISO/IEC 27001 ISMS (with downloadable cert links) plus ISO 27017 and ISO 27018; also ISO 27001 based on IT baseline protection for named IaaS components.

SOC 2 / SOC 3
Vendor claimed

Vendor asserts SSAE 18 Type 2 SOC 1, SOC 2 (+NIST), and SOC 3 attestations; reports available to prospective customers under vendor process.

Vendor claimed

Vendor states ISAE 3000 (SOC 2) and ISAE 3402 in addition to C5 Type 2; obtain current reports under NDA/request.

GDPR / EU data protection
Vendor claimed

EU headquartered; GDPR compliance asserted; DPA documents published for relevant subsidiaries. Residency depends on chosen region.

Vendor claimed

EU legal entity; vendor claims GDPR-aligned operation with processing in own DE/AT data centers and ISO 27018 claims for PII in the cloud.

US CLOUD Act exposure (indicative)
Partial

French group with no known US parent, but operates US datacentres (Vint Hill, Hillsboro) and OVH US LLC. Medium indicative exposure: EU-region workloads on EU contracts differ from US-region workloads. Not legal advice.

Partial

German operator under Schwarz Digits / Schwarz Group; no known US parent; customer cloud claimed on group-owned EU DCs without named AWS/GCP/Azure data-plane hosts. Partial (not a clean bill): confirm AVV subprocessors and any non-EU support tools. Indicative only—not legal advice.

Data processing agreement (B2B)
Vendor claimed

Published DPAs form part of terms (e.g. OVH SAS Europe paths; separate US DPA for OVH US LLC). Obtain the DPA matching your contracting entity.

Not found

No self-serve public AVV/DPA URL confirmed during research; expect contract packaging—request AVV, TOMs, and subprocessor list in procurement.

EU AI Act
Not applicable

Core product is IaaS/bare metal/hosting; AI/ML platforms are optional infrastructure offerings, not a single AI system product under typical procurement framing.

Not applicable

Primary offering is IaaS/PaaS infrastructure; optional AI Model Serving and related data/AI products may need separate AI Act analysis if you deploy high-risk AI systems.

ANSSI SecNumCloud
Vendor claimed

Hosted Private Cloud (VMware on OVHcloud and related) holds SecNumCloud qualification; hosted in French sites (Roubaix, Gravelines, Strasbourg). Not all products are SecNumCloud-qualified.

Not listed
HDS (French health data hosting)
Vendor claimed

Vendor lists HDS certification for healthcare data hosting options; confirm which products and locations are in scope.

Not listed
PCI DSS
Vendor claimed

Vendor asserts PCI DSS Level 1 certification for payment data hosting—confirm applicability to your architecture.

Not listed
BSI C5 Type 2Not listed
Vendor claimed

C5 Type 2 claimed for Compute Engine (incl. GPU), Windows/RHEL, server backup/update management, block/object/backup/file storage, archiving—not automatically every PaaS product.

TISAX Level 3Not listed
Vendor claimed

Vendor claims TISAX Level 3; verification via ENX portal (assessment ID ATA163-1 / scope ID SH938N per certificates page).

Considerations & known limitations: OVHcloud vs STACKIT
Considerations & known limitationsLogo: OVHcloudOVHcloudLogo: STACKITSTACKIT
US regions and US subsidiary
Medium

US East/West datacentres and OVH US LLC mean CLOUD Act and US process risk apply to US-placed data and some contracts. EU-only deployment reduces this but buyers must enforce region and contracting path.

Not listed
2021 Strasbourg datacentre fire (resilience history)
Medium

A major fire at SBG caused widespread customer outages. Treat multi-AZ/multi-region backup design as mandatory for critical data; do not rely on single-site assumptions.

Not listed
Certification scope is product- and region-specific
Medium

ISO, SOC, HDS, SecNumCloud, and PCI claims do not automatically cover every SKU and location. Procurement should request the exact report for the services ordered.

Not listed
APAC bandwidth and traffic rules differ
Low

Vendor documents unmetered traffic exceptions for Asia-Pacific (lower default bandwidth and monthly volume caps vs Europe/North America). Model egress and bandwidth options for APAC workloads.

Not listed
Broad catalogue complexity
Low

Bare Metal, Public Cloud, Private Cloud, and Web Cloud under one brand can confuse account structure, IAM, and billing. Define landing-zone standards early.

Not listed
Narrower service map than US hyperscalersNot listed
Medium

STACKIT covers core compute, K8s, databases, and storage, but global specialty services and third-party marketplace depth lag AWS/Azure/GCP. Practical impact: multi-cloud or lift-and-shift of complex hyperscaler architectures may need redesign.

C5 Type 2 is product-scopedNot listed
Medium

Attestation tables list specific IaaS/storage products. Teams assuming every managed database or PaaS SKU is C5 Type 2 covered without reading the scope can mis-state compliance. Practical impact: map each in-scope service before audits.

Limited public subprocessor inventoryNot listed
Low

Marketing asserts own data centers and EU processing; a complete public subprocessor/support-tool list was not found on the pages reviewed. Practical impact: force AVV + subprocessor exhibits before production personal data.

Retail-group operator concentrationNot listed
Low

Economic stability is a stated strength of Schwarz Group ownership, but roadmap and commercial leverage differ from pure-play clouds. Practical impact: negotiate exit, data export, and roadmap commitments explicitly.

Fit

OVHcloud

Best fit when

  • Teams wanting European ownership with optional global regions (EU, US, Canada, APAC) under one operator
  • Workloads that need exclusive Bare Metal performance or hybrid bare metal + OpenStack/vRack designs
  • French public sector or sensitive estates needing ANSSI SecNumCloud-qualified Hosted Private Cloud paths
  • Organisations standardising on OpenStack APIs and S3-compatible object storage for reversibility
  • Sites that benefit from network-integrated anti-DDoS and private multi-site networking as defaults

Poor fit when

  • Buyers who require the deepest managed AI/marketplace/IAM ecosystems of AWS, Azure, or GCP
  • Policies that forbid any provider with US legal entities or US datacentre options regardless of region selection
  • Teams seeking the simplest low-SKU VPS experience—Hetzner or similar may fit better
  • Anyone assuming EU-only residency without selecting and enforcing EU regions in architecture

Consider instead when

  • When: You want a leaner French public cloud with a strong developer product surface and less enterprise sovereign packaging

    Consider: Scaleway

    Often simpler for cloud-native teams; confirm region and compliance fit.

  • When: You primarily need price-performance VPS or dedicated servers with a smaller catalogue

    Consider: Hetzner

    Strong for lean estates; different sovereign/cert posture and global region set.

  • When: You need maximum managed-service breadth, global account tooling, and partner marketplace density

    Consider: Amazon Web Services (AWS), Microsoft Azure, or Google Cloud Platform

    Hyperscalers win platform depth; accept US ownership and CLOUD Act parent exposure.

  • When: You want German SMB hosting plus cloud IaaS with EU and some non-EU options

    Consider: IONOS

    Different product mix and compliance packaging than OVHcloud's bare-metal industrial model.

STACKIT

Best fit when

  • Public-sector, healthcare, finance, or retail teams that require EU residency under a German operator with dual DE/AT regions
  • Platform teams standardizing on managed Kubernetes (SKE) plus VMs and managed databases in one European cloud
  • Organizations migrating gradually via colocation racks/cages in STACKIT facilities next to public cloud projects
  • Buyers that prioritize BSI C5 Type 2 and ISO 27001 family claims on core compute/storage over hyperscaler marketplace depth
  • Workloads that benefit from GPU compute, confidential computing options, or AI model serving inside the same sovereign stack

Poor fit when

  • Architectures that depend on many specialized AWS/Azure/GCP managed services or global multi-continent regions
  • Teams that must self-host the full cloud control plane rather than consume a managed public cloud
  • Simple single-VM or low-ops hobby hosting where a basic VPS provider is enough
  • Procurement that needs every PaaS product under the same C5 Type 2 table without reviewing scope gaps
  • Use cases requiring non-European data residency as a primary requirement

Consider instead when

  • When: You need a wider multi-country European region map and a large independent cloud portfolio

    Consider: OVHcloud or Scaleway

    Different ownership and product cultures; still not US hyperscaler breadth

  • When: Your workload is mainly simple German VMs/web hosting without managed K8s/PaaS depth

    Consider: IONOS (or similar DE hosts)

    Often simpler packaging for commodity compute

  • When: You require global regions, the largest third-party marketplace, or existing multi-cloud tooling locked to hyperscaler APIs

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Trade EU ownership of the operator for ecosystem scale; apply your own CLOUD Act / transfer analysis

  • When: Swiss or other non-DE sovereignty framing matters more than Schwarz Group scale

    Consider: Exoscale

    Smaller portfolio; different jurisdiction story

Open questions for due diligence

OVHcloud

  • Which contracting entity and DPA (EU OVH SAS path vs OVH US LLC) will apply to our account?
  • Which exact products/regions are in scope for the ISO/SOC/HDS/SecNumCloud certificates we need?
  • What is our multi-region DR design given historical single-site fire risk?
  • Are any non-OVH subprocessors used for our specific managed services (support, monitoring, payments) beyond OVH-operated infrastructure?
  • Do APAC or Local Zone bandwidth/SLA terms meet our traffic profile?

STACKIT

  • Will STACKIT provide a signed AVV/DPA, current TOMs, and a full subprocessor list covering support, monitoring, and marketplace components?
  • Which of our target services (SKE, PostgreSQL Flex, Confidential Kubernetes, etc.) fall inside the latest C5 Type 2 and ISO reports?
  • What are the exact region availability, geo-redundancy options, and SLA credits for our workloads across EU01/EU02 (and any additional regions)?
  • What are exit, data export, and termination assistance terms for large object stores and managed databases?
  • For public-sector or KRITIS use cases: which additional attestations, clearance processes, or reference architectures are required?