SDIS 02
Sovereign Cloud Architectures
Technical Patterns for Jurisdictional Control Over Compute, Storage, and Operations
Sovereign Digital Infrastructure Series
Abstract
“Sovereign cloud” is now a checkbox on public-sector RFPs, but the term describes a wide spectrum of architectures with very different resilience properties. This paper catalogs the technical patterns used to build sovereign cloud platforms — from simple regional isolation to full confidential-computing stacks with local key custody and escrowed operations — and evaluates each against the four-plane framework introduced in SDIS-01. It traces the market and technical history of sovereign cloud offerings, with particular attention to the gap between marketed sovereignty and architecturally verifiable sovereignty, examines eleven detailed case studies including the EU Cloud Sovereignty Framework and France’s SecNumCloud qualification, and specifies a reference architecture that composes with the compute-sovereignty patterns in SDIS-05 and the zero-trust controls in SDIS-08. It closes with an implementation roadmap, a self-assessment checklist, and a glossary.
Keywords
- sovereign cloud
- Gaia-X
- SecNumCloud
- confidential computing
- hyperscaler dependency
Citation
Burnard, B. (2026). Sovereign Cloud Architectures (SDIS 02). D-AI Research. https://doi.org/10.5281/zenodo.22081556