Logo: Cyso Cloud

Cyso Cloud

Dutch OpenStack IaaS from Cyso B.V. with AMS/FRA regions, managed Kubernetes (KCSP), S3-compatible object storage, and EU data residency for teams avoiding hyperscaler lock-in.

Open source

Cyso Cloud is a Dutch Infrastructure-as-a-Service platform operated by Cyso B.V. in Alkmaar. It is the public and private cloud brand of the Cyso Group, which has run hosting in the Netherlands since 1997. The public cloud lineage started as Fuga Cloud in 2016 and was integrated under the Cyso Cloud name in 2025.

It exists for organisations that want standard OpenStack APIs and EU data residency rather than a US hyperscaler control plane. Regions include Amsterdam and Frankfurt.

The concrete differentiator is that OpenStack IaaS plus Enterprise Managed Kubernetes as a CNCF Kubernetes Certified Service Provider, with S3-compatible object storage and Direct Connect-style private connectivity.

EU-operated (NL)OpenStack IaaSManaged Kubernetes (KCSP)AMS + FRA regionsISO 27001 (claimed)NEN 7510 (claimed)

Shortlist Cyso Cloud when you want Dutch-operated OpenStack IaaS and KCSP managed Kubernetes with AMS/FRA residency and engineer-to-engineer support. Skip when you need global hyperscaler regions or default encryption-at-rest object storage—consider OVHcloud or Scaleway for broader European multi-region IaaS, or keep a hyperscaler for worldwide PaaS depth.

Key capabilities

Vanilla OpenStack compute (roughly 2–64 vCPUs and up to 512 GB RAM flavors), NVMe-backed ephemeral and block volumes, dashboard plus OpenStack APIs/CLI. Deployed on Cyso-managed hardware in Amsterdam and Frankfurt with three availability zones per region so multi-AZ designs are first-class.

Region-scoped object storage with triple-disk redundancy, versioning, lifecycle rules, object lock, pre-signed URLs, and standard S3 clients (AWS CLI, Rclone, MinIO mc, SDKs). Data and replicas stay in the selected AMS or FRA region; default server-side encryption at rest is not applied—plan client-side or customer-key approaches for sensitive objects.

CNCF Kubernetes Certified Service Provider managed control planes with multi-version support, automated upgrades, worker groups (including GPU/high-memory options), HPA/VPA/node autoscaling, Garden Linux workers, Terraform/kubectl/k9s workflows, and cluster hibernation to scale workers to zero on a schedule.

VPC-style private networks, security groups as virtual firewalls, load balancers with health checks, floating/reserved IPs, Anycast DNS, IPv6 dual-stack, native edge DDoS mitigation, and Direct Connect-style private links. SLA text targets 99.99% monthly uptime for listed compute, volume, object, and networking services when multi-AZ conditions are met.

Same OpenStack-based stack can be deployed as a private cloud on customer data-centre hardware (including VMware-alternative messaging) or white-label/wholesale models for partners—useful when public multi-tenant regions are not enough for isolation or residency policy.

At a glance

HQ
Alkmaar, Netherlands
Legal entity
Cyso B.V. (Cyso Group)
Founded
1997 (group); public OpenStack cloud since 2016 (Fuga); Cyso Cloud brand 2025
Regions
Amsterdam, Frankfurt (more under investigation)
Stack
OpenStack + managed Kubernetes (KCSP)
Commercial model
Pay-as-you-go / hourly; optional trial via sales

Best fit when

  • European product/SaaS teams that need VMs, volumes, and S3-compatible storage with explicit Amsterdam or Frankfurt residency
  • Organisations standardising on OpenStack APIs/CLI to reduce hyperscaler lock-in and support multi-cloud portability
  • Teams wanting CNCF KCSP managed Kubernetes with hibernation and pay-as-you-go worker nodes on EU infrastructure
  • Dutch healthcare-adjacent or regulated buyers who need NEN 7510 alongside ISO 27001 claims from a NL operator
  • Buyers evaluating a private OpenStack cloud or VMware alternative on their own data-centre hardware

Poor fit when

  • Workloads that require many global regions, edge PoPs, or a large marketplace of managed PaaS services
  • Storage designs that assume default server-side encryption at rest without customer-managed keys
  • Procurement that must rely only on a fully published subprocessor schedule without vendor engagement
  • Teams that need fully self-serve free tiers or only automated chat support with no human engineering contact

Consider instead when

  • When: You need many European (or global) regions and a broader product catalogue than two live IaaS regions

    Consider: OVHcloud or Scaleway

    Larger EU multi-region footprints; different APIs and commercial models.

  • When: You want Swiss multi-zone simplicity with strong managed Kubernetes emphasis

    Consider: Exoscale

    Swiss operator profile; fewer regions than hyperscalers but clear sovereignty messaging.

  • When: You need maximum global PaaS depth, AI services, and worldwide edge

    Consider: Amazon Web Services, Microsoft Azure, or Google Cloud Platform

    Trade EU ownership for ecosystem breadth; apply your own residency and CLOUD Act analysis.

  • When: You prioritise high-performance European VMs across more city locations than AMS/FRA only

    Consider: UpCloud

    Different stack; compare residency guarantees and support model side by side.

Jurisdiction & ownership

Legal entity
Cyso B.V. (part of Cyso Group B.V.), Wognumsebuurt 3, 1817 BH Alkmaar; KVK 37133395
US parent / control
No known US parent
CLOUD Act exposure (indicative)
Low
Hosting / residency
Primary public IaaS on Cyso-operated hardware in Tier 3 facilities in Amsterdam and Frankfurt (3 AZs per region); vendor states storage replicas/backups stay in the selected EU region. Not marketed as AWS/Azure/GCP-hosted IaaS. Ancillary tools disclosed at group level include website analytics (PostHog) and third parties for payments/support; status tooling has referenced Atlassian Statuspage. Full public customer-workload subprocessor list not found.

No known US corporate parent; Dutch law on standard terms. Indicative CLOUD Act exposure is low for primary EU self-operated hosting, but confirm live subprocessors and any non-EU SaaS in procurement. Not legal advice.

  • Independent security / no-logs auditNot found
  • ISO 27001Vendor claimed
  • SOC 2 / SOC 3Not found
  • GDPR / EU data protectionVendor claimed
  • +4

Considerations & known limitations

  • MediumOnly two live public regions

    Production public cloud is AMS and FRA today. Multi-continent latency, in-country residency outside NL/DE, or extensive multi-region DR across Europe may require another provider or private cloud.

  • MediumNo default object storage encryption at rest

    Official FAQs state no standard server-side encryption at rest; TLS in transit and client-side/SSE-C patterns are recommended. Regulated designs must implement key management outside default storage behaviour.

  • MediumIncomplete public subprocessor inventory

    Primary hosting path is vendor-operated EU hardware, but privacy materials list third parties without a dedicated live subprocessor register for all ancillary processing. Request the schedule under NDA or DPA annex.

  • LowCertifications are vendor-published PDFs

    ISO 27001 and NEN 7510 are claimed with certificate PDFs on Cyso sites; this draft did not independently verify registry entries. Treat as claimed until audit pack is reviewed.

  • LowSmaller ecosystem than hyperscalers

    Fewer managed PaaS services and marketplace options than AWS/Azure/GCP. Expect to run more of the stack yourself on OpenStack/Kubernetes.

Open questions for due diligence

  • Can Cyso provide the current DPA, technical and organisational measures, and a dated subprocessor list covering payments, support, analytics, and status tooling?
  • What is the exact OpenStack release, upgrade cadence, and any divergences from upstream APIs that affect Terraform/automation?
  • For object storage and volumes, what encryption-at-rest or KMS options can be contractually committed for regulated data?
  • What are contractual 24/7 escalation SLAs for severity-1 incidents beyond office-hours tech-to-tech support?
  • Which additional EU regions (if any) have committed go-live dates versus community voting only?

Frequently Asked Questions

Public cloud regions are Amsterdam (Netherlands) and Frankfurt (Germany). Cyso states that data for its storage services—including replicas and backups—remains in the region you select, on hardware it manages in Tier 3 facilities with multiple availability zones. Confirm the live region list and any new sites during procurement; additional European locations are still under investigation.

Cyso markets vanilla OpenStack releases with a simplified dashboard plus OpenStack APIs and CLI. That is the main portability story versus hyperscaler-only tooling. Managed Kubernetes additionally exposes standard Kubernetes APIs (kubectl, Terraform providers, etc.). Always validate the exact OpenStack version and any Cyso-specific extensions against your automation.

No. Official object-storage FAQs state Cyso does not apply standard server-side encryption at rest; objects are stored in chunks with TLS in transit. For sensitive data they recommend client-side encryption or customer-provided key patterns (e.g. SSE-C with S3 tooling). Treat this as a design constraint for regulated workloads.

Consumption is primarily pay-per-use / hourly for compute, storage, and managed control planes, with self-service accounts and published pricing pages. Selected new customers may get a time-boxed free trial via sales. Do not rely on third-party directory pages for euro figures—use the official pricing calculator and contract terms for procurement.

Marketing materials state Cyso signs a data processing agreement under Dutch law and works with EU-based sub-processors. Group privacy policy discloses categories of third parties (payments, support, website analytics such as PostHog) but a complete public customer-workload subprocessor schedule was not found during research. Request the current DPA, TOMs, and subprocessor list before go-live.

Tech-to-tech support is emphasised during Dutch office hours (phone, email; Slack mentioned on product pages) with outage coverage and a public status page. Managed Kubernetes is marketed with a 99.9% SLA; platform SLA documentation cites 99.99% monthly uptime for listed IaaS services under defined multi-AZ conditions. Confirm 24/7 escalation paths and response targets in your contract.