Scaleway vs STACKIT

Compare Scaleway and STACKIT on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Amazon Web Services (AWS), DigitalOcean, Google Cloud Platform, Microsoft Azure

Logo: Scaleway

Scaleway

France· Cloud Computing

Needs review

Shortlist Scaleway for French-owned multi-AZ IaaS (Paris/Amsterdam/Warsaw) with bare metal, EU-resident GPUs and Kapsule Kubernetes—especially HDS/sovereignty-sensitive stacks. Skip if you need completed SecNumCloud today or hyperscaler global depth; consider OVHcloud, Exoscale/UpCloud, or AWS/Azure/GCP instead.

EU-operated regionsBare metal + Elastic MetalEU GPU for AIKapsule KubernetesISO 27001 (certified)HDS (claimed)
Logo: STACKIT

STACKIT

Germany· Cloud Computing

Needs review

Shortlist STACKIT when you want German-entity IaaS/PaaS on Schwarz Group–owned DE/AT infrastructure with managed Kubernetes, scoped BSI C5 Type 2 claims, and optional same-campus colocation. Skip when you need global multi-region hyperscaler breadth or a fully self-hosted control plane—consider OVHcloud or Scaleway for multi-country EU clouds, or AWS/Azure when worldwide services dominate the architecture.

EU-operatedGerman legal entityGroup-owned DE/AT DCsBSI C5 Type 2 (claimed)Managed Kubernetes (SKE)EU colocation + hybrid
Scaleway vs STACKIT: Snapshot
FeatureLogo: ScalewayScalewayLogo: STACKITSTACKIT
Country of originFranceGermany
CategoryCloud ComputingCloud Computing
Open sourceNoNo
Self-hostedNoNo
HeadquartersFranceGermany
Legal entitySCALEWAY SAS (R.C.S. Paris 433 115 904), 8 rue de la Ville l'Évêque, 75008 ParisSchwarz Digits Cloud GmbH & Co. KG (Am Campus 1, 74177 Bad Friedrichshall; imprint lists STACKIT Beteiligungs-GmbH as general partner vehicle in Neckarsulm)
Governing lawFrench law (General Terms of Services)Germany (imprint also notes ICT infrastructure jurisdiction Germany and Austria)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowLow
Hosting / residencyCustomer cloud workloads on Scaleway-operated European multi-AZ infrastructure (Paris, Amsterdam, Warsaw; Milan listed in availability docs)—not primary hosting on AWS/GCP/Azure. Account/controller activities use processors; privacy policy allows some non-EU transfers under SCCs. Full named subprocessor table is via Trust Center/contracts rather than a fully public marketing page.Vendor claims STACKIT Cloud runs in group-owned ISO 27001 data centers in Germany and Austria (sites publicly named include Neckarsulm DC01, Ellhofen DC08, Ostermiething DC10; additional EU sites claimed). Cloud regions include EU01 (Germany) and EU02 (Austria). No public evidence found that customer data-plane hosting is on AWS/GCP/Azure. A detailed third-party subprocessor list for all support/analytics tooling was not found on marketing pages—confirm in the AVV.
Summary

French iliad-group cloud platform: bare metal, virtual instances, EU-resident GPU for AI, managed Kubernetes, serverless, storage and databases on Scaleway-operated multi-AZ regions in Europe.

German sovereign cloud from Schwarz Digits (Schwarz Group): IaaS, managed Kubernetes, databases, and colocation on group-owned data centers in Germany and Austria.

Tags
At a glance: Scaleway vs STACKIT
At a glanceLogo: ScalewayScalewayLogo: STACKITSTACKIT
HQParis, France (SCALEWAY SAS)Not listed
Groupiliad Group subsidiaryNot listed
RegionsParis, Amsterdam, Warsaw multi-AZ (+ Milan listed)Not listed
ModelPublic cloud IaaS/PaaS (not self-hosted)Consumption-based public cloud + quote-based colocation
Commercial modelPay-as-you-go; compute Savings Plans (GPU rules differ)Not listed
Open sourcePlatform proprietary; open standards (K8s, S3 API, Terraform)Uses open-source components; platform itself is managed, not self-hosted
HQ / legal entityNot listedBad Friedrichshall / Neckarsulm area, Germany — Schwarz Digits Cloud GmbH & Co. KG
ParentNot listedSchwarz Digits (Schwarz Group — Lidl/Kaufland)
HostingNot listedGroup-owned data centers in Germany & Austria (e.g. EU01/EU02); not marketed as AWS/Azure reseller
External marketNot listedPublic offering from 2022 (internal roots from 2018)
Key capabilities: Scaleway vs STACKIT
Key capabilitiesLogo: ScalewayScalewayLogo: STACKITSTACKIT
EU-operated regionsYesYes
Bare metal + Elastic MetalYesNot listed
EU GPU for AIYesNot listed
Kapsule KubernetesYesNot listed
ISO 27001 (certified)YesNot listed
HDS (claimed)YesNot listed
German legal entityNot listedYes
Group-owned DE/AT DCsNot listedYes
BSI C5 Type 2 (claimed)Not listedYes
Managed Kubernetes (SKE)Not listedYes
EU colocation + hybridNot listedYes

Scaleway

  • Elastic Metal, Dedibox and Apple Silicon bare metal

    Single-tenant physical servers without a shared hypervisor layer: Dedibox for a wide dedicated catalogue, Elastic Metal for bare metal integrated with Scaleway VPC, load balancing, storage and Kubernetes, plus Apple Silicon Mac mini hosts for native macOS/iOS CI. Best when you need hardware isolation, custom kernels, or GPU bare metal without VM overhead—product lines are still converging, so compare availability zone coverage per SKU.

  • EU-resident GPU instances for AI training and inference

    On-demand GPU VMs with recent NVIDIA options (including L4, L40S, H100 PCIe/SXM and B300-SXM) aimed at LLM fine-tuning, inference and graphics/media acceleration, with data residency in European regions. Integrates with Kapsule via the NVIDIA GPU Operator; pay-as-you-go by the minute. GPU capacity and Savings Plan eligibility differ from general instances—validate stock and zone before committing multi-node jobs.

  • Kubernetes Kapsule and multi-cloud Kosmos

    Managed Kubernetes control planes on Scaleway nodes (Kapsule) with autoscaling-oriented operations, plus Kosmos for hybrid/multi-cloud worker pools including non-Scaleway infrastructure. Suits teams standardising on portable Kubernetes rather than proprietary orchestrators; external Kosmos pools remain your responsibility to patch and size.

  • Multi-AZ European regions with VPC networking

    Place compute and storage in Paris, Amsterdam and Warsaw multi-AZ regions (docs also reference Milan), using regional private networking, load balancers and related network services. Useful for EU latency and residency designs without a US region on the primary map—confirm each product’s AZ matrix in the product-availability guide before multi-region DR planning.

  • Managed storage and databases on open-ish APIs

    S3-compatible Object Storage (including multi-AZ class options), block volumes, and managed database engines (PostgreSQL, MySQL, Redis, MongoDB, ClickHouse-oriented analytics) plus serverless containers/functions/jobs. Reduces day-2 ops for common stack pieces while keeping export paths closer to open standards than pure proprietary PaaS—always check engine versions, HA options and backup retention for production.

  • API, CLI and Terraform-first operations

    Full console plus documented APIs, CLI and Infrastructure-as-Code workflows for provisioning instances, networks and managed services. Fits platform teams automating environments; IAM permissions and account Owner roles still need deliberate design for production orgs.

STACKIT

  • Compute Engine VMs and GPUs in group-owned EU regions

    Provision Linux and Windows virtual machines, GPU-backed instances, automated server backup and OS update management from the STACKIT portal, CLI, API, or Terraform. Workloads land in European cloud regions such as EU01 (Germany) and EU02 (Austria) on Schwarz Group–operated infrastructure rather than rented hyperscaler bare metal. Best for teams that need predictable EU residency for general compute and AI/ML training or inference on GPU shapes—confirm available instance families per region before migration.

  • STACKIT Kubernetes Engine (SKE)

    Managed, CNCF-compliant Kubernetes with a highly available control plane, automated Kubernetes/OS upgrades, repair functions, pod and node autoscaling, optional temporary cluster shutdown, and automation via Terraform, SKE API, and CLI. Suited to cloud-native apps, stateful workloads on block storage, and ML pipelines that must stay in European regions. Not a self-hosted kubeadm replacement—you consume a managed service with STACKIT-controlled plane components.

  • Managed databases, messaging, and observability

    Fully managed PostgreSQL Flex, MongoDB Flex, SQL Server Flex, MariaDB, Redis, OpenSearch, and RabbitMQ plus LogMe, Logs, and Observability stacks reduce ops load for application teams. Flex models emphasize automated maintenance, backups, and scaling inside the STACKIT cloud. Ideal when you want PaaS data services under the same German operator as your VMs/K8s—validate HA topology, backup retention, and region pairing for each service.

  • Confidential computing and key/secrets control

    Confidential Server and Confidential Kubernetes options aim to protect data in use with hardware-backed isolation; Secrets Manager and Key Management Service handle secret storage/rotation and cryptographic operations. Useful for regulated or multi-tenant sensitive workloads beyond disk encryption alone. Confirm attestation models, supported node types, and which compliance reports cover these products.

  • EU colocation with hybrid path to public cloud

    Racks, cages, and private rooms in Neckarsulm, Ellhofen, and Ostermiething facilities—with remote hands, carrier connectivity, and hybrid designs that keep non-migratable hardware next to STACKIT public cloud. Positions STACKIT for gradual cloud adoption without a pure forklift. Colocation is quote-driven and site certifications can vary by facility; request site data sheets early.

  • Object, block, file, backup, and archiving storage

    S3-compatible object storage, high-performance block volumes, NFS file storage, backup storage, and audit-oriented archiving for retention workloads. Supports application data, VM disks, and compliance archives inside the same European footprint as compute. Check durability/replication claims and cross-region options against your RPO/RTO rather than assuming hyperscaler multi-region defaults.

Assurance & compliance: Scaleway vs STACKIT
Assurance & complianceLogo: ScalewayScalewayLogo: STACKITSTACKIT
Independent security / no-logs audit
Not applicable

IaaS provider (not a no-logs VPN). Trust Center references penetration testing and security reports available on request; not a public no-logs audit product claim.

Vendor claimed

Vendor claims BSI C5 Type 2 for a listed IaaS/storage product set; reports available on request (iso@digits.schwarz). Not a VPN-style no-logs audit.

ISO 27001
Verified

ISO/IEC 27001:2022 certificate documentation published (e.g. certificate IS 787020 for SCALEWAY, Paris). Confirm scope covers the services you buy.

Vendor claimed

Certificates page claims ISO/IEC 27001 ISMS (with downloadable cert links) plus ISO 27017 and ISO 27018; also ISO 27001 based on IT baseline protection for named IaaS components.

SOC 2 / SOC 3
Not found

Not listed among public Trust Center compliance badges reviewed (GDPR, HDS, ISO 27001, CSA STAR L1).

Vendor claimed

Vendor states ISAE 3000 (SOC 2) and ISAE 3402 in addition to C5 Type 2; obtain current reports under NDA/request.

HDS (French health data hosting)
Vendor claimed

Vendor security and healthcare pages claim HDS certification; Trust Center lists HDS. Confirm certified service scope for your architecture.

Not listed
CSA STAR Level 1
Vendor claimed

Trust Center announces CSA STAR Level 1 (CCM self-assessment / CAIQ).

Not listed
ANSSI SecNumCloud
Partial

Qualification process started (public news); security pages mark SecNumCloud as ongoing—not obtained as a finished qualification in sources reviewed.

Not listed
GDPR / EU data protection
Vendor claimed

EU controller/processor with published privacy policy and DPA; French entity. Not legal advice.

Vendor claimed

EU legal entity; vendor claims GDPR-aligned operation with processing in own DE/AT data centers and ISO 27018 claims for PII in the cloud.

US CLOUD Act exposure (indicative)
Partial

French SAS / iliad Group; customer IaaS on self-operated EU regions; no US parent found. Controller-side processors and possible third-country transfers per privacy policy; SecNumCloud not complete. Assessment only—not a vendor “safe” claim.

Partial

German operator under Schwarz Digits / Schwarz Group; no known US parent; customer cloud claimed on group-owned EU DCs without named AWS/GCP/Azure data-plane hosts. Partial (not a clean bill): confirm AVV subprocessors and any non-EU support tools. Indicative only—not legal advice.

Data processing agreement (B2B)
Vendor claimed

DPA PDF downloadable on https://www.scaleway.com/en/contracts/ alongside TOMs.

Not found

No self-serve public AVV/DPA URL confirmed during research; expect contract packaging—request AVV, TOMs, and subprocessor list in procurement.

EU AI Act
Not applicable

Infrastructure/GPU host; customer models and apps drive AI Act roles. Not an AI Act conformity product claim.

Not applicable

Primary offering is IaaS/PaaS infrastructure; optional AI Model Serving and related data/AI products may need separate AI Act analysis if you deploy high-risk AI systems.

BSI C5 Type 2Not listed
Vendor claimed

C5 Type 2 claimed for Compute Engine (incl. GPU), Windows/RHEL, server backup/update management, block/object/backup/file storage, archiving—not automatically every PaaS product.

TISAX Level 3Not listed
Vendor claimed

Vendor claims TISAX Level 3; verification via ENX portal (assessment ID ATA163-1 / scope ID SH938N per certificates page).

Considerations & known limitations: Scaleway vs STACKIT
Considerations & known limitationsLogo: ScalewayScalewayLogo: STACKITSTACKIT
SecNumCloud not yet obtained
Medium

ANSSI SecNumCloud is in progress on public materials. Regulated French public-sector tenders that hard-require a qualified cloud today may need another SKU/provider or a delayed migration plan.

Not listed
Smaller service catalogue than US hyperscalers
Medium

Expect fewer proprietary managed services and less global region density than AWS/Azure/GCP. Multi-cloud or complementary SaaS may still be required for parts of the estate.

Not listed
Account-plane processors and possible non-EU transfers
Low

Even with EU workload regions, privacy policy allows processor use and SCC-backed transfers for some controller purposes (support, payments, marketing, etc.). Pull the live subprocessor list for DPIAs.

Not listed
Shared responsibility for guest security
Medium

Scaleway secures the platform; you own OS hardening, IAM, application security, encryption keys and backups. Recent Trust Center advisories on kernel issues illustrate customer patching duties on instances and Kapsule nodes.

Not listed
Dedibox vs Elastic Metal product split
Low

Two bare-metal experiences still coexist while Scaleway documents convergence. Mis-choosing the line can affect API integration, networking features and migration effort.

Not listed
Narrower service map than US hyperscalersNot listed
Medium

STACKIT covers core compute, K8s, databases, and storage, but global specialty services and third-party marketplace depth lag AWS/Azure/GCP. Practical impact: multi-cloud or lift-and-shift of complex hyperscaler architectures may need redesign.

C5 Type 2 is product-scopedNot listed
Medium

Attestation tables list specific IaaS/storage products. Teams assuming every managed database or PaaS SKU is C5 Type 2 covered without reading the scope can mis-state compliance. Practical impact: map each in-scope service before audits.

Limited public subprocessor inventoryNot listed
Low

Marketing asserts own data centers and EU processing; a complete public subprocessor/support-tool list was not found on the pages reviewed. Practical impact: force AVV + subprocessor exhibits before production personal data.

Retail-group operator concentrationNot listed
Low

Economic stability is a stated strength of Schwarz Group ownership, but roadmap and commercial leverage differ from pure-play clouds. Practical impact: negotiate exit, data export, and roadmap commitments explicitly.

Fit

Scaleway

Best fit when

  • Teams that need compute, storage, networking and managed Kubernetes in documented EU multi-AZ regions under a French legal entity
  • AI/ML workloads that require NVIDIA GPUs with European data residency rather than US-region training defaults
  • Workloads that benefit from single-tenant bare metal (Elastic Metal or Dedibox) alongside cloud APIs
  • Healthtech or French-market buyers that need HDS-oriented hosting signals plus a published B2B DPA
  • Platform engineers standardising on Terraform/API-driven provisioning with S3-compatible storage and managed Postgres/MySQL

Poor fit when

  • Organisations that require a finished ANSSI SecNumCloud qualification on day one (process is ongoing, not completed on public pages)
  • Architectures that must run primary production in US or APAC regions on the same cloud account
  • Buyers that need the full hyperscaler catalogue (global edge, proprietary PaaS density, enterprise marketplace breadth)
  • Teams expecting a self-hosted “install Scaleway on your own DC” product rather than a managed cloud
  • Procurement processes that accept only SOC 2 Type II as the primary assurance artefact (not surfaced as a public Trust Center badge here)

Consider instead when

  • When: You need completed SecNumCloud-qualified private cloud or a larger non-EU region footprint under one European operator

    Consider: OVHcloud

    Compare exact qualified product SKUs and region maps; OVH and Scaleway are both French industrial clouds with different strengths.

  • When: You want simpler EU VPS/dedicated economics with a smaller product surface

    Consider: UpCloud, Exoscale, or Cyso Cloud

    Leaner catalogues; validate GPU, HDS and multi-AZ needs separately.

  • When: You need maximum global managed-service depth and partner ecosystem

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Accept US-parent CLOUD Act exposure and design residency/controls explicitly.

  • When: German SMB hosting plus EU cloud under a DE-centric brand is the priority

    Consider: IONOS

    Different product mix and market focus than Scaleway’s developer/AI-oriented public cloud.

STACKIT

Best fit when

  • Public-sector, healthcare, finance, or retail teams that require EU residency under a German operator with dual DE/AT regions
  • Platform teams standardizing on managed Kubernetes (SKE) plus VMs and managed databases in one European cloud
  • Organizations migrating gradually via colocation racks/cages in STACKIT facilities next to public cloud projects
  • Buyers that prioritize BSI C5 Type 2 and ISO 27001 family claims on core compute/storage over hyperscaler marketplace depth
  • Workloads that benefit from GPU compute, confidential computing options, or AI model serving inside the same sovereign stack

Poor fit when

  • Architectures that depend on many specialized AWS/Azure/GCP managed services or global multi-continent regions
  • Teams that must self-host the full cloud control plane rather than consume a managed public cloud
  • Simple single-VM or low-ops hobby hosting where a basic VPS provider is enough
  • Procurement that needs every PaaS product under the same C5 Type 2 table without reviewing scope gaps
  • Use cases requiring non-European data residency as a primary requirement

Consider instead when

  • When: You need a wider multi-country European region map and a large independent cloud portfolio

    Consider: OVHcloud or Scaleway

    Different ownership and product cultures; still not US hyperscaler breadth

  • When: Your workload is mainly simple German VMs/web hosting without managed K8s/PaaS depth

    Consider: IONOS (or similar DE hosts)

    Often simpler packaging for commodity compute

  • When: You require global regions, the largest third-party marketplace, or existing multi-cloud tooling locked to hyperscaler APIs

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Trade EU ownership of the operator for ecosystem scale; apply your own CLOUD Act / transfer analysis

  • When: Swiss or other non-DE sovereignty framing matters more than Schwarz Group scale

    Consider: Exoscale

    Smaller portfolio; different jurisdiction story

Open questions for due diligence

Scaleway

  • What is the exact HDS certificate scope (services, regions, shared responsibility) for our architecture?
  • What is the current ANSSI SecNumCloud milestone and target date for the SKUs we would buy?
  • Which named subprocessors (including any non-EU) process account, billing, support or security telemetry data?
  • For multi-region DR, which products are GA in each AZ (including Milan) at contract time?
  • Are independent SOC 2 / C5 or other reports available under NDA if our assurance programme requires them?

STACKIT

  • Will STACKIT provide a signed AVV/DPA, current TOMs, and a full subprocessor list covering support, monitoring, and marketplace components?
  • Which of our target services (SKE, PostgreSQL Flex, Confidential Kubernetes, etc.) fall inside the latest C5 Type 2 and ISO reports?
  • What are the exact region availability, geo-redundancy options, and SLA credits for our workloads across EU01/EU02 (and any additional regions)?
  • What are exit, data export, and termination assistance terms for large object stores and managed databases?
  • For public-sector or KRITIS use cases: which additional attestations, clearance processes, or reference architectures are required?