DATA SOVEREIGNTY
Storing data in the EU and keeping it under sovereign control are not the same thing.
Data residency is a location. Data sovereignty is a legal guarantee.
Hosting your data in a European data center does not protect it from a U.S. court order if your CDN provider is a U.S.-headquartered company. Regulations like GDPR and NIS2 mandate strict legal control over traffic, logs, and metadata. Meeting those mandates requires infrastructure operated by an entity not subject to extra-territorial jurisdiction, not just infrastructure located within the right geography.
Why the legal risk is structural, not configurable
The sovereignty gap in public CDN and cloud infrastructure cannot be closed through configuration choices. It is a consequence of corporate ownership:
Location does not determine jurisdiction
A U.S.-headquartered CDN provider with European data centres is still a U.S. entity subject to U.S. law. Data stored on its infrastructure anywhere in the world is accessible under a CLOUD Act warrant.
Global control planes cross jurisdictional boundaries
Standard CDNs replicate cache files, access logs, and routing metadata across globally distributed nodes to optimize delivery. Compliance audits that require proof of data isolation fail against architectures where control planes operate globally.
Metadata is as sensitive as content
Public CDN and SaaS environments log traffic patterns, user download paths, and request metadata into centralised databases. For organizations subject to strict data handling obligations, the metadata trail created by routing traffic through a third-party network is itself a compliance liability.
What sovereignty gaps cost your organization
Security and compliance officer
Proving compliant data handling to regional regulators requires the ability to demonstrate that traffic, logs, and metadata never left a defined jurisdictional boundary and were never accessible to a foreign entity.
Platform engineering leader
Building a localized custom proxy stack to bypass global CDN vendors is a significant engineering undertaking, complex to design, time-consuming to deploy, and operationally demanding to maintain.
Government and defence architect
Classified and sensitive workloads require delivery infrastructure that functions entirely within isolated, air-gapped perimeters using local PKI credentials with zero outside dependencies. Standard cloud and CDN architectures are incompatible with these requirements.
Why standard approaches fail sovereignty audits
When trying to establish regional compliance boundaries, engineering teams run into the architectural limits of multi-tenant cloud and public CDN platforms:
Challenge 1
Global data replication violates geo-localization rules
Public CDNs distribute cache files and access logs across unmanaged global nodes. Data that originates within a jurisdictional boundary leaves it as a routine part of how the network operates.
Challenge 2
Corporate ownership overrides local hosting
A local instance of a U.S.-headquartered provider is still subject to U.S. jurisdiction. The CLOUD Act does not respect data center geography, it follows corporate structure.
Challenge 3
Metadata tracking creates hidden compliance exposure
CDN and SaaS platforms log user download paths and traffic metadata into central non-sovereign databases. The payload may be encrypted, but the metadata trail is not.
Challenge 4
Weak data-at-rest encryption leaves cleartext on shared hardware
Standard caching platforms lack high-speed built-in tools to encrypt files on physical hardware. Sensitive data sits in cleartext on shared infrastructure without the per-object encryption that serious compliance requirements demand.
Three pathways to genuine data sovereignty
Varnish provides three distinct deployment options designed to enforce absolute data sovereignty.
Varnish CDNSovereign CDN service
|
Best for fast-growing web platforms that need a fully managed, high-performance cloud CDN operated by an independent European entity, keeping all core data planes immune to the U.S. CLOUD Act.
|
Varnish CDN in a BoxTurnkey partner-hosted edge
|
Best for organizations wanting to rapidly spin up a turnkey, partner-hosted private edge on localized partner ISP or telco networks without managing physical hardware.
|
Varnish EnterpriseSelf-managed private edge
|
Best for highly secure enterprise, government, or defense operations requiring a self-managed, software-defined edge that runs natively inside completely isolated, air-gapped perimeters.
|
How the technical controls enforce the legal guarantee
01
Region-locked routing with a European-owned control plane |
Traffic routes through infrastructure operated entirely by a European entity. No U.S. parent company, no global control plane crossing jurisdictional boundaries, no CLOUD Act exposure. |
02
Private points of presence on sovereign infrastructure |
Pre-configured caching nodes deploy directly onto your own sovereign physical infrastructure, private clouds, or partner ISP points of presence. The delivery speed of a global CDN with the legal certainty of owned infrastructure. |
03
In-process encryption at rest and in transit |
TLS termination and dual-key cache-at-rest encryption run natively within a single process. Encryption keys are dynamically derived per object from client calls — no cleartext data, no static keys on local disks, no shared encryption state. |
04
Air-gapped registries and API infrastructure |
Kubernetes-native ingress controllers and private proxy-caching registries run inside isolated cluster namespaces, routing and storing metadata locally without contacting external public clouds. Software dependencies and S3 storage assets stay within the sovereign perimeter. |
Resources and media
Next steps
Talk to our team to learn more about Varnish sovereignty solutions or start free with Varnish CDN today.


