Digital sovereignty

Digital sovereignty at Costfluent

For Costfluent, digital sovereignty means four things: the company is based in Frankfurt am Main and its contracts follow German law; core services and primary datastores run in Germany; access to your cloud is read-only and revocable; and your cost data can leave with you. Where a provider outside Germany is in the data path, this page names it.

The facts

What the definition rests on

Company

Founded and built in Frankfurt am Main, Germany. The terms of service are governed by German law.

Hosting

Core application services and primary datastores run in Germany. Encrypted recovery backups are kept elsewhere in the EU.

Access

Cloud connections are read-only and can be revoked in the provider at any time. Workload contents, databases and application data stay out of reach.

Portability

Cost reports export as CSV, and on Optimize and Scale the Public API reads the same data from your own tools.

Open source

The Terraform modules that grant access, the Terraform provider and the Kubernetes agent are published under MIT and Apache 2.0 licences.

Self-assessment

Against the EU Cloud Sovereignty Framework

The European Commission's framework scores a cloud service on eight objectives. This is Costfluent's own self-assessment of each one, with the evidence behind it.

ObjectiveCostfluent's answerEvidence
SOV-1
Strategic sovereignty
The company was founded and is built in Frankfurt am Main, and it is operated in Germany.About
SOV-2
Legal and jurisdictional sovereignty
Contracts follow German law, and core services run with a German provider in Germany. The network edge, product email and parts of the connectors run with US companies, so US law can reach those parts of the data path.Security
SOV-3
Data and AI sovereignty
Primary datastores are in Germany and encrypted backups elsewhere in the EU. Costfluent manages the encryption keys; customers do not hold them. Product email and public traffic pass through US providers.Security
SOV-4
Operational sovereignty
Costfluent builds and operates the product itself. Operation depends on a small number of hosting and service providers, named on request.Security
SOV-5
Supply chain sovereignty
Servers and backup storage are rented from EU providers. The origin of their hardware is not assessed.Security
SOV-6
Technology sovereignty
Data leaves through CSV export and, on Optimize and Scale, the Public API. The access modules, the Terraform provider and the Kubernetes agent are open source.API and Terraform
SOV-7
Security and compliance sovereignty
Costfluent holds no C5, ISO 27001 or SOC 2 certification. The controls in place are described on the security page.Security
SOV-8
Environmental sustainability
Not assessed.

This is a self-assessment, and no certificate exists for the framework. Your procurement assesses each objective and sets the level it requires; the framework takes the overall level from the weakest objective.

Sources: Cloud Sovereignty Framework, version 1.2.1, October 2025; Implementation guidance, June 2026. Reviewed:

Related pages

Check the boundaries with your own costs

Start with the permanent Free plan and a read-only connection you can revoke.

Permanent Free plan with no time limit

We value your privacy

We use essential storage to operate the site and, only if you allow it, Google Analytics to understand how it is used. Read more in our Privacy policy.

Cookie preferences

Essential cookies Always on

Required for the website to function properly. These cannot be disabled.

Google Analytics

Records page views and four named actions: sign-up and demo clicks, contact form submissions and lead requests. Google's script and its _ga cookies load only after you allow them. We do not send account, tenant, form, or resource identifiers.