1. Parent company in the EU
Who legally controls the company? No US group, no US-investor controlling majority, no US listing.
Kopexa status
Kopexa GmbH, based in Germany. No US parent, no US controlling majority. No US law applicable.
5 pillars of real sovereignty
Four legal properties, one technical. Each must be provable on its own, otherwise all that remains of the promise is sovereign washing. Here is every property with our status.
Who legally controls the company? No US group, no US-investor controlling majority, no US listing.
Kopexa status
Kopexa GmbH, based in Germany. No US parent, no US controlling majority. No US law applicable.
Data, backups, logs, metadata and all sub-processors must reside in the EU/EEA, with evidence.
Kopexa status
SaaS in the Paris region (EU). Backups + logs in the same region. Sub-processor list public at /legal/sub-processors.
If the provider holds the key, encryption protects nothing against authority access via the provider.
Kopexa status
Provider-managed keys by default. BYOK available in the on-premise setup, integrated with your KMS or HSM.
Which law applies to a data request? CLOUD Act orders must be contractually excluded.
Kopexa status
No US law applicable to Kopexa (no US group in the ownership chain). DPA in self-service at avv.kopexa.com.
Black-box providers are risky from a sovereignty perspective. Customers need publicly auditable evidence.
Kopexa status
KSPEC is open source under the Elastic License v2 on GitHub. DPA as self-service at avv.kopexa.com. Sub-processors public at /legal/sub-processors.
Who benefits
BSIG Section 8a, IT-Grundschutz, the KRITIS regulation. A sovereign cloud is not a wish but an obligation. Following the DSK ruling, Microsoft 365 is restricted in several German federal states.
DORA Articles 28-30 require a clear third-party risk assessment. For critical cloud services, BaFin supervision expects the sovereignty question to be answered explicitly.
Patient data, study data and genomic data fall under GDPR Article 9 with elevated protection needs. US cloud solutions are hard to justify here, both to supervisory authorities and to patients.
FAQ
See the demo, the Sovereign Washing Guide, or the ISMS platform itself.