Security platforms handle particularly sensitive information: identities, device information, access decisions, policies, alarms, metadata, and logs. That's why the demand sounds simple at first: "The solution must be hosted in Europe." But the location of a data center only answers part of the question.
A service can store data in Germany and still depend on non-transparent support channels, external administration accounts, proprietary export formats or a supply chain that is difficult to dissolve. Conversely, a globally operated security platform can offer concrete possibilities for regional processing, log storage and customer control. A reliable decision therefore needs more than a label of origin.
Sovereignty arises when a company knows which data is processed where, who has technical access to it, who controls the operation and how the dependency can be resolved later.
Security data is no ordinary cloud workload
With an Office application, the focus is often on storing documents. A security architecture has additional data flows. For example, Zscaler handles Internet and access traffic, policy decisions, and transaction logs. CrowdStrike assesses device and security conditions and provides telemetry for detection and response.
For the sovereignty check, at least five data classes should therefore be separated:
- Content data processed during a security audit
- transaction and connection metadata,
- Identity and device context,
- Security alarms and investigation results,
- Configuration, audit and administration data.
Each class can have a different location, retention period, and operator path. A general statement such as "EU-hosted" does not replace this assignment.
Control Panel 1: Data Location and Actual Processing
The first question is not just "Where is the data?", but "Where is it stored, processed, backed up and restored?" This includes primary systems, backups, telemetry, diagnostic packages, and support exports.
Zscaler describes regional processing and log options for European customers. According to the provider, customers can choose European infrastructure and control the location of their logs. This is an important basis, but must be confirmed for the specific tenant and the actually licensed services.
For a supplementary hosting or operating model, it must be documented which components run on which infrastructure and which data continues to remain in the respective manufacturer's clouds.
Control Panel 2: Keys and Cryptographic Access
Encryption is necessary, but not proof of sovereignty on its own. The decisive factor is who generates, manages, rotates and, in exceptional cases, can use keys. The European Commission explicitly mentions the effective control of the customer over cryptographic data access as a sovereignty criterion.
An architecture letter should therefore show:
- which data is encrypted in transit and at rest,
- which party controls the keys,
- whether customer-side keys or separate key areas are possible,
- how rotation, locking, and recovery work,
- which emergency accesses exist and how they are logged.
Control Panel 3: Operations and Privileged Access
Many risks do not lie in the normal data path, but in operation. Who can change configurations? Who can view support packages? What are the roles of the manufacturer, the hosting provider, the managed service partner and the customer team?
A sovereign operating model needs a verifiable RACI: Who is responsible, who executes, who releases and who is informed? Privileged access should be limited in time, traceable and limited to the specific order. For critical changes, four-eye approvals and a full audit trail are more important than a blanket promise.
Control Panel 4: Legal Space and Supply Chain
The location of the computer center is not automatically identical with the legal area of all parties involved. That's why vendors, affiliates, subcontractors, support locations, and vendor dependencies should be included in the assessment.
STACKIT positions itself as a European cloud with data centers in Germany and Austria and emphasizes open technologies as well as the avoidance of economic migration barriers. For a specific security service, however, this must become a contractually and technically verifiable scope: Which component is actually running there? What remains a global manufacturer service? Which party owes which service?
Control Panel 5: Portability and Exit
Sovereignty is evident at the latest in the change. Can configurations, logs, rules, and evidence be exported in documented formats? How long does the handover take? What data is subsequently deleted? How is the deletion proven?
A good exit plan is created before the contract is signed. It describes data export, configuration handover, key change, deactivation of privileged access and realistic parallel operation. The European rules on cloud switching strengthen portability, but do not replace a technical migration plan.
Control Panel 6: Resilience and Emergency Operation
Local data storage is of little value if a disruption renders security operations unable to act. For Zscaler and CrowdStrike-related operational services, restart, backup communication, configuration backup, responsibilities and dependencies on vendor access must therefore be documented.
The right question is: Which security function is retained in the event of a failure, which falls behind in a controlled manner and who is allowed to activate emergency operation? These answers belong in runbooks and tests, not just in contract annexes.
A label becomes a verifiable operating model
A sensible sovereignty decision does not end with a "German data center". It connects data flows, legal space, keys, operational roles, support access, portability, and resiliency.
This is especially important for Zscaler and CrowdStrike because the platforms cover different tasks and types of data. A complementary hosting and operating model must not blur this reality. It must make visible which controls the manufacturer provides, what responsibility remains with the customer and which services a partner takes over.
The result is a result that security, data protection, purchasing and operations can evaluate together: not a diffuse assertion of sovereignty, but an architecture with verifiable control points.

