STACKIT vs UpCloud

Compare STACKIT and UpCloud on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Amazon Web Services (AWS), DigitalOcean, Google Cloud Platform, Microsoft Azure

Logo: STACKIT

STACKIT

Germany· Cloud Computing

Needs review

Shortlist STACKIT when you want German-entity IaaS/PaaS on Schwarz Group–owned DE/AT infrastructure with managed Kubernetes, scoped BSI C5 Type 2 claims, and optional same-campus colocation. Skip when you need global multi-region hyperscaler breadth or a fully self-hosted control plane—consider OVHcloud or Scaleway for multi-country EU clouds, or AWS/Azure when worldwide services dominate the architecture.

EU-operatedGerman legal entityGroup-owned DE/AT DCsBSI C5 Type 2 (claimed)Managed Kubernetes (SKE)EU colocation + hybrid
Logo: UpCloud

UpCloud

Finland· Cloud Computing

Needs review

Shortlist UpCloud when you want Finnish-contracted IaaS with MaxIOPS storage, CNCF Managed Kubernetes, managed open-source databases, and customer-pinned EU regions—plus optional global PoPs. Skip when you need hyperscaler-only PaaS depth or the absolute lowest bare-metal VPS pricing; consider Hetzner, Scaleway, or AWS/Azure/GCP depending on that gap.

Finnish-operated IaaSMaxIOPS block storageCNCF Managed KubernetesISO 27001 (claimed)Selectable EU regionsZero-cost egress policy
STACKIT vs UpCloud: Snapshot
FeatureLogo: STACKITSTACKITLogo: UpCloudUpCloud
Country of originGermanyFinland
CategoryCloud ComputingCloud Computing
Open sourceNoNo
Self-hostedNoNo
HeadquartersGermanyFinland
Legal entitySchwarz Digits Cloud GmbH & Co. KG (Am Campus 1, 74177 Bad Friedrichshall; imprint lists STACKIT Beteiligungs-GmbH as general partner vehicle in Neckarsulm)UpCloud Oy (Business ID 2431560-5), Aleksanterinkatu 15 B, 00100 Helsinki
Governing lawGermany (imprint also notes ICT infrastructure jurisdiction Germany and Austria)Finland (Terms of Service; arbitration Helsinki)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencyVendor claims STACKIT Cloud runs in group-owned ISO 27001 data centers in Germany and Austria (sites publicly named include Neckarsulm DC01, Ellhofen DC08, Ostermiething DC10; additional EU sites claimed). Cloud regions include EU01 (Germany) and EU02 (Austria). No public evidence found that customer data-plane hosting is on AWS/GCP/Azure. A detailed third-party subprocessor list for all support/analytics tooling was not found on marketing pages—confirm in the AVV.Customer-selected regions across 15 DCs (EU majority: FI, SE, NO, DK, DE, NL, ES, PL, UK; plus US-CHI/NYC/SJO, SG, AU) in colocations (Equinix, Digital Realty, CoreSite, Telia, Verne, Green Mountain, etc.). Customer Data stays in chosen DC. Vendor: EU VMs have no customer-data subprocessors; group subsidiaries only otherwise. Account data in Finland with global support access (incl. US/SG). Payments/hCaptcha are separate third parties.
Summary

German sovereign cloud from Schwarz Digits (Schwarz Group): IaaS, managed Kubernetes, databases, and colocation on group-owned data centers in Germany and Austria.

Finnish IaaS from UpCloud Oy (Helsinki): MaxIOPS block storage, Cloud Servers, managed Kubernetes and databases across 15 global regions with customer-selected residency.

Tags
At a glance: STACKIT vs UpCloud
At a glanceLogo: STACKITSTACKITLogo: UpCloudUpCloud
HQ / legal entityBad Friedrichshall / Neckarsulm area, Germany — Schwarz Digits Cloud GmbH & Co. KGNot listed
ParentSchwarz Digits (Schwarz Group — Lidl/Kaufland)Not listed
HostingGroup-owned data centers in Germany & Austria (e.g. EU01/EU02); not marketed as AWS/Azure resellerNot listed
ModelConsumption-based public cloud + quote-based colocationNot listed
Open sourceUses open-source components; platform itself is managed, not self-hostedNo (platform proprietary)
External marketPublic offering from 2022 (internal roots from 2018)Not listed
HQNot listedHelsinki, Finland
Legal entityNot listedUpCloud Oy (2431560-5)
FoundedNot listed2011
RegionsNot listed15 DCs / 12 countries (EU-heavy + US/APAC)
Self-hostedNot listedNo (public/private cloud IaaS)
Commercial modelNot listedHourly pay-as-you-go; trial credits; zero-cost egress policy
Key capabilities: STACKIT vs UpCloud
Key capabilitiesLogo: STACKITSTACKITLogo: UpCloudUpCloud
EU-operatedYesNot listed
German legal entityYesNot listed
Group-owned DE/AT DCsYesNot listed
BSI C5 Type 2 (claimed)YesNot listed
Managed Kubernetes (SKE)YesNot listed
EU colocation + hybridYesNot listed
Finnish-operated IaaSNot listedYes
MaxIOPS block storageNot listedYes
CNCF Managed KubernetesNot listedYes
ISO 27001 (claimed)Not listedYes
Selectable EU regionsNot listedYes
Zero-cost egress policyNot listedYes

STACKIT

  • Compute Engine VMs and GPUs in group-owned EU regions

    Provision Linux and Windows virtual machines, GPU-backed instances, automated server backup and OS update management from the STACKIT portal, CLI, API, or Terraform. Workloads land in European cloud regions such as EU01 (Germany) and EU02 (Austria) on Schwarz Group–operated infrastructure rather than rented hyperscaler bare metal. Best for teams that need predictable EU residency for general compute and AI/ML training or inference on GPU shapes—confirm available instance families per region before migration.

  • STACKIT Kubernetes Engine (SKE)

    Managed, CNCF-compliant Kubernetes with a highly available control plane, automated Kubernetes/OS upgrades, repair functions, pod and node autoscaling, optional temporary cluster shutdown, and automation via Terraform, SKE API, and CLI. Suited to cloud-native apps, stateful workloads on block storage, and ML pipelines that must stay in European regions. Not a self-hosted kubeadm replacement—you consume a managed service with STACKIT-controlled plane components.

  • Managed databases, messaging, and observability

    Fully managed PostgreSQL Flex, MongoDB Flex, SQL Server Flex, MariaDB, Redis, OpenSearch, and RabbitMQ plus LogMe, Logs, and Observability stacks reduce ops load for application teams. Flex models emphasize automated maintenance, backups, and scaling inside the STACKIT cloud. Ideal when you want PaaS data services under the same German operator as your VMs/K8s—validate HA topology, backup retention, and region pairing for each service.

  • Confidential computing and key/secrets control

    Confidential Server and Confidential Kubernetes options aim to protect data in use with hardware-backed isolation; Secrets Manager and Key Management Service handle secret storage/rotation and cryptographic operations. Useful for regulated or multi-tenant sensitive workloads beyond disk encryption alone. Confirm attestation models, supported node types, and which compliance reports cover these products.

  • EU colocation with hybrid path to public cloud

    Racks, cages, and private rooms in Neckarsulm, Ellhofen, and Ostermiething facilities—with remote hands, carrier connectivity, and hybrid designs that keep non-migratable hardware next to STACKIT public cloud. Positions STACKIT for gradual cloud adoption without a pure forklift. Colocation is quote-driven and site certifications can vary by facility; request site data sheets early.

  • Object, block, file, backup, and archiving storage

    S3-compatible object storage, high-performance block volumes, NFS file storage, backup storage, and audit-oriented archiving for retention workloads. Supports application data, VM disks, and compliance archives inside the same European footprint as compute. Check durability/replication claims and cross-region options against your RPO/RTO rather than assuming hyperscaler multi-region defaults.

UpCloud

  • MaxIOPS clustered block storage

    In-house all-flash block tier rated up to ~100,000 read IOPS at 4K, separate from compute hosts, with Standard and Archive tiers for capacity. Attach up to 16 devices per server (up to 64 TB total); encryption at rest optional. Suits databases and I/O-heavy apps that outgrow commodity cloud disks.

  • Cloud Servers on AMD EPYC with automation

    Linux/Windows VMs with Starter, Premium, and Cloud Native plan families, hot resize options, firewall, utility and SDN private networking. Full lifecycle via control panel, REST API, CLI, Terraform/OpenTofu, Pulumi, and Crossplane—for teams automating fleets rather than clicking one-off VPS.

  • CNCF Managed Kubernetes (UKS)

    Managed control planes with CNCF-certified Kubernetes versions, autoscaler integration, CSI block volumes, load-balancer integration, and private-only clusters. Worker nodes use ordinary Cloud Server plans including Private Cloud hosts—good fit when you want K8s without running etcd yourself.

  • Managed PostgreSQL, MySQL, Valkey, OpenSearch

    Turnkey databases with automated backups, multi-node HA options, private utility/SDN connectivity, and point-in-time recovery on relational plans. Reduces ops load for product teams that still want open engines rather than proprietary hyperscaler databases.

  • Customer-selected global regions (EU-first footprint)

    Fifteen data centers across twelve countries: dense Northern/Central Europe (Helsinki x2, Stockholm, Stavanger, Copenhagen, Amsterdam, Frankfurt, Madrid, Warsaw, London) plus US, Singapore, and Sydney. Customer Data stays in the chosen zone unless you request a move—use EU zones for residency programmes.

  • Zero-cost egress packaging and 99.999% SLA line

    Public pricing emphasises no per-GB internet egress charges under a Fair Transfer Policy, plus Premium-class 99.999% SLA with service credits for unscheduled downtime. Simplifies bills for chatty APIs and multi-service architectures compared with classic egress meters—confirm fair-use limits for extreme transfer cases.

Assurance & compliance: STACKIT vs UpCloud
Assurance & complianceLogo: STACKITSTACKITLogo: UpCloudUpCloud
Independent security attestation (BSI C5 / audits)
Vendor claimed

Vendor claims BSI C5 Type 2 for a listed IaaS/storage product set; reports available on request (iso@digits.schwarz). Not a VPN-style no-logs audit.

Vendor claimed

Vendor states cloud services audited against Finnish PiTuKri criteria by an independent firm; ISO 27001 ISMS regularly audited. Public PiTuKri report not fully reproduced on marketing pages—request artefacts.

ISO 27001
Vendor claimed

Certificates page claims ISO/IEC 27001 ISMS (with downloadable cert links) plus ISO 27017 and ISO 27018; also ISO 27001 based on IT baseline protection for named IaaS components.

Vendor claimed

Vendor asserts ISO 27001 certified ISMS and publishes certificate PDF; independent registry re-check not completed in this draft.

SOC 2 / SOC 3 (ISAE 3000)
Vendor claimed

Vendor states ISAE 3000 (SOC 2) and ISAE 3402 in addition to C5 Type 2; obtain current reports under NDA/request.

Not found

Facility providers list SOC reports; no clear first-party UpCloud SOC 2 Type II product claim found on compliance pages reviewed.

BSI C5 Type 2
Vendor claimed

C5 Type 2 claimed for Compute Engine (incl. GPU), Windows/RHEL, server backup/update management, block/object/backup/file storage, archiving—not automatically every PaaS product.

Not listed
GDPR / EU data protection
Vendor claimed

EU legal entity; vendor claims GDPR-aligned operation with processing in own DE/AT data centers and ISO 27018 claims for PII in the cloud.

Vendor claimed

Finnish controller/processor under GDPR; customer chooses region; DPA in ToS; CISPE Code of Conduct adherence claimed.

US CLOUD Act exposure (indicative)
Partial

German operator under Schwarz Digits / Schwarz Group; no known US parent; customer cloud claimed on group-owned EU DCs without named AWS/GCP/Azure data-plane hosts. Partial (not a clean bill): confirm AVV subprocessors and any non-EU support tools. Indicative only—not legal advice.

Partial

Finnish entity / no known US parent; EU-region VMs can avoid US storage. Material exceptions: optional US DCs, US/SG support affiliates for account ops, US colocations if selected. Assessment not a vendor safety claim. Not legal advice.

Data processing agreement (B2B)
Not found

No self-serve public AVV/DPA URL confirmed during research; expect contract packaging—request AVV, TOMs, and subprocessor list in procurement.

Vendor claimed

DPA incorporated into Terms of Service; binding on acceptance without separate signature per vendor.

TISAX Level 3
Vendor claimed

Vendor claims TISAX Level 3; verification via ENX portal (assessment ID ATA163-1 / scope ID SH938N per certificates page).

Not listed
EU AI Act
Not applicable

Primary offering is IaaS/PaaS infrastructure; optional AI Model Serving and related data/AI products may need separate AI Act analysis if you deploy high-risk AI systems.

Not applicable

General-purpose IaaS/platform; not an AI system provider by primary product.

CISPE Code of ConductNot listed
Vendor claimed

Vendor states adherence to CISPE data protection code for cloud infrastructure providers.

Considerations & known limitations: STACKIT vs UpCloud
Considerations & known limitationsLogo: STACKITSTACKITLogo: UpCloudUpCloud
Narrower service map than US hyperscalers
Medium

STACKIT covers core compute, K8s, databases, and storage, but global specialty services and third-party marketplace depth lag AWS/Azure/GCP. Practical impact: multi-cloud or lift-and-shift of complex hyperscaler architectures may need redesign.

Not listed
C5 Type 2 is product-scoped
Medium

Attestation tables list specific IaaS/storage products. Teams assuming every managed database or PaaS SKU is C5 Type 2 covered without reading the scope can mis-state compliance. Practical impact: map each in-scope service before audits.

Not listed
Limited public subprocessor inventory
Low

Marketing asserts own data centers and EU processing; a complete public subprocessor/support-tool list was not found on the pages reviewed. Practical impact: force AVV + subprocessor exhibits before production personal data.

Not listed
Retail-group operator concentration
Low

Economic stability is a stated strength of Schwarz Group ownership, but roadmap and commercial leverage differ from pure-play clouds. Practical impact: negotiate exit, data export, and roadmap commitments explicitly.

Not listed
Optional non-EU regions and support accessNot listed
Medium

US, Singapore, and Sydney zones are first-class options. Mis-pinned workloads or defaults can place Customer Data outside the EU. Account information is accessible to non-EEA support staff even when VMs stay in Europe.

Narrower catalogue than hyperscalersNot listed
Low

Strong IaaS and focused managed services; missing many proprietary AWS/Azure/GCP PaaS and AI products. Multi-cloud or dual-vendor designs may still be required.

Limited public SOC 2 for UpCloud entityNot listed
Medium

ISO 27001 and PiTuKri claims are published; a customer-facing SOC 2 Type II for UpCloud itself was not found. Enterprise questionnaires may need NDA artefacts or reliance on ISO plus facility reports.

Colocation facility dependencyNot listed
Low

Platform runs in third-party data centres. Facility certifications differ by site; treat them as complementary to UpCloud’s own ISMS, not a substitute for vendor due diligence.

Fair Transfer Policy on zero egressNot listed
Low

Zero-cost egress is a commercial differentiator but is governed by a Fair Transfer Policy—extreme or abusive transfer patterns may fall outside the marketing promise. Validate for CDN-scale or bulk egress designs.

Fit

STACKIT

Best fit when

  • Public-sector, healthcare, finance, or retail teams that require EU residency under a German operator with dual DE/AT regions
  • Platform teams standardizing on managed Kubernetes (SKE) plus VMs and managed databases in one European cloud
  • Organizations migrating gradually via colocation racks/cages in STACKIT facilities next to public cloud projects
  • Buyers that prioritize BSI C5 Type 2 and ISO 27001 family claims on core compute/storage over hyperscaler marketplace depth
  • Workloads that benefit from GPU compute, confidential computing options, or AI model serving inside the same sovereign stack

Poor fit when

  • Architectures that depend on many specialized AWS/Azure/GCP managed services or global multi-continent regions
  • Teams that must self-host the full cloud control plane rather than consume a managed public cloud
  • Simple single-VM or low-ops hobby hosting where a basic VPS provider is enough
  • Procurement that needs every PaaS product under the same C5 Type 2 table without reviewing scope gaps
  • Use cases requiring non-European data residency as a primary requirement

Consider instead when

  • When: You need a wider multi-country European region map and a large independent cloud portfolio

    Consider: OVHcloud or Scaleway

    Different ownership and product cultures; still not US hyperscaler breadth

  • When: Your workload is mainly simple German VMs/web hosting without managed K8s/PaaS depth

    Consider: IONOS (or similar DE hosts)

    Often simpler packaging for commodity compute

  • When: You require global regions, the largest third-party marketplace, or existing multi-cloud tooling locked to hyperscaler APIs

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Trade EU ownership of the operator for ecosystem scale; apply your own CLOUD Act / transfer analysis

  • When: Swiss or other non-DE sovereignty framing matters more than Schwarz Group scale

    Consider: Exoscale

    Smaller portfolio; different jurisdiction story

UpCloud

Best fit when

  • EU product teams needing IaaS with Finnish legal entity and pin-to-zone residency
  • Workloads sensitive to block I/O that benefit from MaxIOPS-class SSDs
  • Cloud-native stacks on managed Kubernetes plus managed PostgreSQL/MySQL/Valkey
  • Multi-service apps where predictable outbound transfer packaging matters
  • Agencies and SaaS operators standardising on API/Terraform automation

Poor fit when

  • Organisations that require a full hyperscaler catalogue (proprietary AI/PaaS breadth)
  • Buyers optimising solely for the lowest-cost bare metal or unlimited-traffic VPS
  • Programmes that forbid any non-EU group support access to account metadata without extra controls
  • Teams that will deploy only to US regions yet still market the stack as EU-sovereign

Consider instead when

  • When: You need cheaper raw compute or dedicated servers more than managed K8s packaging

    Consider: Hetzner

    Often stronger on price for VPS/dedicated; compare managed service depth separately.

  • When: You want a broader French/EU public-cloud portfolio or different regional SKUs

    Consider: OVHcloud or Scaleway

    Different product breadth and commercial culture; still European-operated peers.

  • When: You need hyperscaler-managed platforms, global enterprise contracts, or deep marketplace ecosystems

    Consider: AWS, Google Cloud, or Microsoft Azure

    Trade European HQ simplicity for catalogue depth and global account teams.

  • When: You want a compact European cloud with Swiss roots and a tighter region set

    Consider: Exoscale

    Compare region map and managed feature parity to UpCloud’s 15-DC footprint.

Open questions for due diligence

STACKIT

  • Will STACKIT provide a signed AVV/DPA, current TOMs, and a full subprocessor list covering support, monitoring, and marketplace components?
  • Which of our target services (SKE, PostgreSQL Flex, Confidential Kubernetes, etc.) fall inside the latest C5 Type 2 and ISO reports?
  • What are the exact region availability, geo-redundancy options, and SLA credits for our workloads across EU01/EU02 (and any additional regions)?
  • What are exit, data export, and termination assistance terms for large object stores and managed databases?
  • For public-sector or KRITIS use cases: which additional attestations, clearance processes, or reference architectures are required?

UpCloud

  • Obtain current ISO 27001 certificate scope/dates and any PiTuKri or other audit reports under NDA if required.
  • Confirm DPA Appendix 1 legal names and countries of all group-company subprocessors for your service mix.
  • Document which regions and backup/object-storage endpoints will be allow-listed for EU-only programmes.
  • Ask whether a SOC 2 or equivalent report for UpCloud Oy is available for enterprise review.
  • Validate Fair Transfer Policy thresholds for your expected egress profile.