Data sovereignty

What data sovereignty really means for your team.

Every message, task and document your team creates lives on someone's servers, under someone's law. This page explains who can reach that data, the deployment spectrum from EU cloud to air-gapped, and how to evaluate any vendor — including us.
Legal exposure
US CLOUD Act
Deployment
Cloud · VPC · Self-host
In transit
TLS 1.3
Depth
Security page

Updated August 2026

What & why now

Sovereignty means your data answers to your law.

US CLOUD Act · 2018

Data sovereignty is the principle that data is governed by the laws of the place — and controlled by the organisation — that holds it. For a team workspace, that covers every message, task, document, file and call record your company produces.

Most collaboration suites are US-owned. The US CLOUD Act (2018) lets American authorities compel any US-based provider to hand over data it controls, wherever that data is physically stored. An EU data centre changes latency, not jurisdiction.

The tension is no longer theoretical. European data protection authorities have repeatedly flagged transatlantic transfers as a compliance risk, and the EU has announced work on a proposed Cloud and AI Development Act that would weigh provider jurisdiction for sensitive workloads. Procurement teams increasingly ask where data lives — and who can be compelled to produce it.

The durable answer is architectural, not contractual: choose software you can run where your law applies — down to servers you own. That is the premise Polybase is built on: the sovereign team workspace.

US · 2018

CLOUD Act

Compels US-based providers to produce data under their control, regardless of where in the world it is stored.

EU · Chapter V

GDPR transfers

Personal data may leave the EU only through defined legal mechanisms — adequacy decisions, standard contractual clauses, binding corporate rules.

EU · Proposed

Cloud & AI Development Act

The EU has announced work on cloud rules that would weigh provider jurisdiction for sensitive workloads. Proposed, not enacted.

General information, not legal advice.

The deployment spectrum

From convenience to full control.

Sovereignty isn't binary. It's a spectrum of who runs the software, who holds the keys, and whose law can reach the result. Polybase runs at every point on it.

01 · EU Cloud

Our EU cloud

We run Polybase in EU regions and operate it for you. Data stays in the EU; disks are encrypted at the provider level.

Keys: Polybase-managed
02 · Private cloud

Your own VPC

Our Docker images run inside your cloud account and region. You control the network, storage and access — only your team touches the data.

Keys: your cloud KMS
03 · Self-hosted

Your servers

Docker Compose on infrastructure you own — online, single tenant, under your jurisdiction. You hold the data and the encryption keys.

Keys: yours
04 · Air-gapped

Fully offline

Runs fully offline on isolated networks — no telemetry, no outbound calls; calls use a self-hosted LiveKit server.

Keys: yours, exclusively
See who holds the keys, model by model — the full table is on our security page
Evaluating vendors

Seven questions to ask any vendor.

Use this list on us, too. A vendor that takes sovereignty seriously should answer every question in writing.

  1. Under which jurisdiction does the provider operate?

    Ownership decides which authorities can compel disclosure — the US CLOUD Act reaches US-owned providers wherever the data is stored.

  2. Where is the data physically stored — and can you choose?

    Region pinning matters for residency and latency, but location alone does not limit the provider's legal exposure.

  3. Can you run the software on infrastructure you own?

    Self-hosting is the only model where no third party can be compelled — because no third party holds your data.

  4. Who holds the encryption keys in each deployment model?

    If the vendor holds the keys, the vendor can be ordered to use them. Key ownership should move to you with the deployment model.

  5. Does it run without an internet connection?

    Air-gap capability is the strongest proof that the product has no hidden dependency on the vendor's cloud.

  6. Can you take your data out — completely, in open formats?

    Sovereignty includes exit. Look for portable backups and standard export formats, not proprietary archives.

  7. What happens to your workspace if the vendor disappears?

    Software you run yourself keeps running. A pure SaaS subscription stops with the company that sells it.

Our answers: EU cloud, your VPC, or self-hosted and air-gapped; keys move with the model; portable, SQLite-based database backups. Details on the security page.

Honest limits

What sovereignty doesn't solve

Owning your infrastructure moves legal and operational control to you — it doesn't make problems disappear. Saying so plainly is part of being credible:

  • Sovereignty is not security. A self-hosted server with weak passwords is worse than a well-run cloud. Hardening, updates and access control remain your job on self-host.
  • It is not automatic compliance. Your own servers settle the residency question, but GDPR obligations — lawful bases, records, subject rights — stay with you wherever the software runs. Polybase is designed around GDPR principles; it cannot be compliant on your behalf.
  • It is not a certification. Polybase is not SOC 2 or ISO 27001 certified yet — both are on our roadmap. We answer security questionnaires and architecture questions today.
  • Air-gap has real trade-offs. Fully offline means you manage updates and backups yourself, and video calls need a self-hosted LiveKit server inside your network.
FAQ

Common questions

What is data sovereignty?

Data sovereignty means data is governed by the laws of the country where it is held and controlled by the organisation that produces it. For a team workspace, it is the question of who can access, move, or be compelled to disclose your messages, tasks, documents and files.

Does hosting in an EU data centre protect data from the US CLOUD Act?

No. The CLOUD Act applies to US-based providers wherever they store data, so an EU region operated by a US company remains within reach of US legal process. Jurisdiction follows the provider, not the data centre.

What is the difference between data residency and data sovereignty?

Residency is where data is physically stored; sovereignty is whose law and whose decisions govern it. A US provider's Frankfurt region gives you residency without sovereignty. Self-hosting on your own infrastructure gives you both.

How does Polybase support data sovereignty?

Polybase runs as our EU-region cloud, in your own VPC, or fully self-hosted — including air-gapped networks, where it runs fully offline and video calls use a self-hosted LiveKit server. On your infrastructure you hold the data and the encryption keys, so there is nothing a third party can be compelled to hand over.

Next steps

Ready to own your workspace?

Read the technical depth behind this page, see Polybase live, or partner with us to deploy it for your clients.