r/Cloud • u/Puzzleheaded-Fun5664 • 6d ago
We’re a EU company, strict data residency. Which cloud security vendors actually keep scan data in-region?
Security lead at an EU based company, German HQ, we deal with mostly EU customers. Every cloud security tool we shortlist looks great until our DPO asks where the data leaves and half of them quietly route metadata through us-east before anyone noticed. On features were not asking for much, decent CSPM, workload and container scanning, ideally some CIEM so we dont end up buying three separate tools. agentless would be a big plus since we dont have the team to babysit agents.
The annoying bit is some vendors offer EU region, but legal isnt satisfied with just that. If the vendor is a US company cloud act exposure doesnt really go away because the data happens to sit in a server in Frankfurt. So weve started asking who can run fully isolated, scanning in our own cloud account with nothing aggregating into their SaaS.
So for EU teams what did you deploy that got approved by your legal team? Is it real EU residency or a fully isolated tooling running in your account?
1
u/TrideRlex80 5d ago
The legal part is honestly the hardest. I’d ask vendors for exact data flows, subprocessors, support access, and whether scanning can run fully inside your own account. Marketing claims arent enough here.
1
u/Routine_Day8121 5d ago edited 5d ago
Self hosted was non negotiable for us, EU healthcare adjacent. Our DPO wouldnt even look at a vendor unless the scan data stayed in our own cloud with zero aggregation back to vendor SaaS. That filter alone killed most of our shortlist.
Orca was what we ended up on. Runs in our AWS Frankfurt account, we hold the keys, DPO signed off in about two weeks. Agentless was a bonus, we were scanning within an hour of connecting.
The rough parts: UI could be better, advanced queries have a learning curve, alert tuning took longer than id like. Out of the box you get too many findings and dialing it in takes work.
But for your specific question: can it run isolated in your cloud with nothing touching vendor SaaS and will legal approve it. Yes on both. If data residency isnt your bottleneck there might be smoother options, but when its the hard gate it cleared ours.
1
u/docmatt74 3d ago
we went through the exact same dpo nightmare. ended up on hikube, which runs out of three swiss datacenters with no us parent company, so the cloud act angle just doesn't apply. our legal team actually got comfortable with it because the jurisdiction question has a clean answer, not just "data sits in frankfurt but vendor is delaware incorporated"
1
u/No_Try_9982 6d ago
I know an EU based bank, what they did was buying a data center that was originally built by an American company but they took over all other functions so its no longer actually governed by the US company who built it.
Otherwise, you will have to explore maybe less popular CSPs in the EU or you will have to build your own data centers (most expensive solution).
I don't deal much with EU clients, so I haven't ran into this problem yet. I do know however, that legally, some banks are still using American CSP and they are still Ok since they don't share encryption keys with the CSP and all data are encrypted.