PostgreSQL Sovereignty: Beyond "Hosted in Switzerland"
Major managed PostgreSQL services: Amazon RDS, Google Cloud SQL, Azure Database for PostgreSQL. All run on US-owned infrastructure under US law. Your application data, financial records, and customer information are accessible under the CLOUD Act without Swiss judicial process.
Running PostgreSQL on Swiss infrastructure solves the data residency question. However, sovereignty is more than where data is stored. The EU Cloud Sovereignty Framework defines eight dimensions that determine whether your provider is truly sovereign.
PostgreSQL and the license question
PostgreSQL is released under the PostgreSQL License, a permissive open-source license similar to BSD and MIT. It places no restrictions on commercial use, distribution, or modification. There is no re-licensing risk, no dual-license commercial trap, and no vendor controlling the project roadmap.
One of the most permissive open-source licenses in production use, the PostgreSQL License means: full data portability via standard SQL and pg_dump, no lock-in through license terms, and freedom to run PostgreSQL on any infrastructure you choose.
VSHN operates PostgreSQL using CloudNativePG, a fully open-source Kubernetes operator. CloudNativePG is a Linux Foundation project. There is no proprietary service layer between your data and the database engine.
PostgreSQL sovereignty compared
| Dimension | Amazon RDS | Google Cloud SQL | Azure Database | VSHN Managed PostgreSQL |
|---|---|---|---|---|
| Ownership | Amazon (USA) | Google (USA) | Microsoft (USA) | VSHN AG (Switzerland) |
| Governing law | US law | US law | US law | Swiss law |
| CLOUD Act | Exposed | Exposed | Exposed | Not exposed |
| Data location | AWS EU/Zurich regions | GCP Zurich region | Azure EU regions | Switzerland (Cloudscale, Exoscale, or your choice) |
| Source code | Proprietary service layer | Proprietary service layer | Proprietary service layer | Fully open source (CloudNativePG) |
| Staff access from abroad | Support staff worldwide, including USA and India | Maintenance and support staff in 30+ countries, including USA and India | Teams worldwide; remote access from outside EU and EFTA for repairs | VSHN Canada for night-time scheduled work; none with the Swiss-only option |
| Certifications | SOC 2, ISO 27001 | SOC 2, ISO 27001 | SOC 2, ISO 27001 | ISO 27001, ISAE 3402 Type II |
VSHN sovereignty self-assessment
We applied the EU's Cloud Sovereignty Framework (v1.2.1, October 2025) to our own services. This framework was used to score providers in the EU's EUR 180M sovereign cloud tender in April 2026. Three pure-European providers achieved SEAL-3, while a consortium involving Google Cloud scored only SEAL-2.
This is a self-assessment, not a formal SEAL certification. We publish it for transparency so customers can evaluate our sovereignty profile using the same structured criteria the EU uses.
| # | Dimension | Weight | Assessment | Evidence |
|---|---|---|---|---|
| SOV-1 | Strategic | 15% | Strong | Swiss AG, no foreign parent, all shareholders Swiss citizens (Commercial Register) |
| SOV-2 | Legal | 10% | Strong | Swiss law (GTC), no CLOUD Act, EU adequacy decision |
| SOV-3 | Data & AI | 10% | Strong | Swiss DCs by default. Sovereign key management via Managed OpenBao + Swiss HSM |
| SOV-4 | Operational | 15% | Strong | Swiss 24/7 ops, Swiss-only support option. All services on vanilla Kubernetes |
| SOV-5 | Supply Chain | 20% | Strong | Infrastructure-agnostic: customer chooses provider. Open-source software |
| SOV-6 | Technology | 15% | Strong | 100% open source. VSHN contributes to K8up (CNCF Sandbox) and maintains Project Syn |
| SOV-7 | Security | 10% | Strong | ISO 27001, ISAE 3402 Type II, Swiss SOC. FINMA-regulated customers. Supports DORA and NIS2 compliance requirements |
| SOV-8 | Environmental | 5% | Moderate | DC operators: Green Datacenter AG (ISO 22301/27001/27701), Exoscale sustainability. VSHN CSR policy |
Overall: SEAL-3 equivalent. This is the same level achieved by the winners of the EU's own sovereignty tender. No bidder in the EU's own tender reached SEAL-4: it requires complete EU control with no critical non-EU dependencies, and every cloud provider depends on hardware made in Asia and the US and on open-source projects governed by US-based foundations such as the Linux Foundation and CNCF. Structural gaps are shared by every cloud provider.
Try Swiss infrastructure: Servala (managed services, free trial), Exoscale (Swiss IaaS). Want help choosing? Contact us.
Get a sovereignty assessment for your database layer
Running Amazon RDS or Google Cloud SQL and concerned about jurisdictional risk? We assess your sovereignty profile against the EU framework and plan a migration to Swiss-hosted PostgreSQL.