Digital sovereignty
Digital sovereignty at Costfluent
For Costfluent, digital sovereignty means four things: the company is based in Frankfurt am Main and its contracts follow German law; core services and primary datastores run in Germany; access to your cloud is read-only and revocable; and your cost data can leave with you. Where a provider outside Germany is in the data path, this page names it.
The facts
What the definition rests on
Company
Founded and built in Frankfurt am Main, Germany. The terms of service are governed by German law.
Hosting
Core application services and primary datastores run in Germany. Encrypted recovery backups are kept elsewhere in the EU.
Access
Cloud connections are read-only and can be revoked in the provider at any time. Workload contents, databases and application data stay out of reach.
Portability
Cost reports export as CSV, and on Optimize and Scale the Public API reads the same data from your own tools.
Open source
The Terraform modules that grant access, the Terraform provider and the Kubernetes agent are published under MIT and Apache 2.0 licences.
Self-assessment
Against the EU Cloud Sovereignty Framework
The European Commission's framework scores a cloud service on eight objectives. This is Costfluent's own self-assessment of each one, with the evidence behind it.
| Objective | Costfluent's answer | Evidence |
|---|---|---|
| SOV-1 Strategic sovereignty | The company was founded and is built in Frankfurt am Main, and it is operated in Germany. | About |
| SOV-2 Legal and jurisdictional sovereignty | Contracts follow German law, and core services run with a German provider in Germany. The network edge, product email and parts of the connectors run with US companies, so US law can reach those parts of the data path. | Security |
| SOV-3 Data and AI sovereignty | Primary datastores are in Germany and encrypted backups elsewhere in the EU. Costfluent manages the encryption keys; customers do not hold them. Product email and public traffic pass through US providers. | Security |
| SOV-4 Operational sovereignty | Costfluent builds and operates the product itself. Operation depends on a small number of hosting and service providers, named on request. | Security |
| SOV-5 Supply chain sovereignty | Servers and backup storage are rented from EU providers. The origin of their hardware is not assessed. | Security |
| SOV-6 Technology sovereignty | Data leaves through CSV export and, on Optimize and Scale, the Public API. The access modules, the Terraform provider and the Kubernetes agent are open source. | API and Terraform |
| SOV-7 Security and compliance sovereignty | Costfluent holds no C5, ISO 27001 or SOC 2 certification. The controls in place are described on the security page. | Security |
| SOV-8 Environmental sustainability | Not assessed. |
This is a self-assessment, and no certificate exists for the framework. Your procurement assesses each objective and sets the level it requires; the framework takes the overall level from the weakest objective.
Sources: Cloud Sovereignty Framework, version 1.2.1, October 2025; Implementation guidance, June 2026. Reviewed:
Related pages
- Security, hosting and data access
Encryption, deletion and vulnerability reporting.
- About Costfluent
The company and how it builds the product.
Check the boundaries with your own costs
Start with the permanent Free plan and a read-only connection you can revoke.
Permanent Free plan with no time limit