Skip to main content

Fiche #5: Data Sovereignty & GDPR

STOA's hybrid architecture is designed so that sensitive business data and user identities remain within your perimeter, while metadata and metrics are hosted in EU-sovereign infrastructure.

5 Key Points​

1. Clear Data Boundary: What Stays vs What Leaves​

A key question for any enterprise: "Where does my data go?" STOA makes this explicit:

No inbound connections required. All communication is initiated from your infrastructure.

2. Three Deployment Models for Every Sovereignty Level​

ModelData ResidencyBest For
Hybrid (default)Business data on-prem, metadata in EU cloudMost enterprises
Full On-Premises100% on your infrastructureAir-gapped, defense, banking
Multi-CloudDistributed across regionsGlobal organizations

3. Regulatory Coverage: GDPR, DORA, NIS2​

RegulationKey RequirementHow STOA Helps
GDPRData minimization, right of accessConfigurable log anonymization, per-consumer usage export
DORAICT risk management, 24h incident reportingFull audit trail, real-time alerting, structured logs
NIS2Supply chain security, sovereigntyAPI provenance tracking, EU-hosted control plane

4. CLOUD Act Protection​

The US CLOUD Act can compel US-headquartered providers to hand over data stored abroad. STOA mitigates this:

  • Control Plane hosted in EU (OVHcloud / Scaleway β€” not AWS/Azure/GCP)
  • Business data is designed to remain within your premises in hybrid mode
  • Full on-prem option eliminates any cloud dependency entirely
  • Open-source codebase β€” no hidden data exfiltration, fully auditable
US CLOUD Act Exposure Matrix
─────────────────────────────────────────
β”‚ US Provider β”‚ EU Provider β”‚ On-Prem
──────────────┼─────────────┼─────────────┼────────
Metadata β”‚ ⚠️ Risk β”‚ βœ… Safe β”‚ βœ… Safe
Payloads β”‚ ❌ Risk β”‚ βœ… Safe β”‚ βœ… Safe
Credentials β”‚ ❌ Risk β”‚ βœ… Safe β”‚ βœ… Safe
─────────────────────────────────────────
STOA default: EU cloud (metadata) + On-prem (payloads)

5. Encryption at Every Layer​

LayerMechanism
In TransitTLS 1.3 (external), mTLS (internal)
At RestAES-256 (databases), AES-256-GCM (Vault)
Field-LevelPII field encryption in logs
SecretsHashiCorp Vault with automatic rotation

Objections & Answers​

ObjectionAnswer
"Any cloud component is a sovereignty risk"Full on-premises deployment is supported with no required cloud dependency. Your cluster, your rules.
"EU hosting doesn't protect against CLOUD Act"Correct if the provider is US-headquartered. STOA's EU option uses EU-sovereign providers (OVHcloud, Scaleway).
"We need SOC 2 / ISO 27001 certification"On the roadmap: SOC 2 Type II (Q4 2026), ISO 27001 (2027). Current architecture is designed to meet these standards.
"GDPR requires right to deletion β€” can STOA do that?"Yes. Per-consumer data isolation allows targeted deletion. Audit logs can be configured with retention policies.
"Our DPO won't approve SaaS"Share the data boundary diagram above. Only API metadata (names, descriptions) goes to cloud. Or deploy fully on-prem.

Further Reading​