
Sovereign Cloud
Meet your requirements for location, access, data residency, and operational controls without compromising cloud services, SLAs, or pricing with Oracle Cloud Infrastructure (OCI) solutions for sovereignty.
Learn about the five key pillars of sovereign AI.
Why sovereign cloud?
Maintain control over your operations and assets in the cloud to ensure productivity and resilience while retaining a competitive advantage.
-
Meet evolving compliance, legal, and regulatory needs
With the ability to audit and report, customize compliance, and control IT systems.
-
Restrict access to data and operational information flows
With a distributed cloud approach, smart access and governance capabilities, and region and operations isolation.
-
Operate in the cloud, isolated from others and the internet
Without additional spending and compromising on technology.
-
Address AI sovereignty needs for data and AI infrastructure
With Oracle’s full AI stack in the public cloud or in your data center.
Sovereign cloud—Oracle meets you where you are
Achieving sovereignty requires more than a one-size-fits-all solution. Depending on your organization and where it operates, you may have different needs in different locations. OCI offers flexible solution options built off the same platform. Get the same cloud services, APIs, and SLAs at the same price point, regardless of whether you need to achieve compliance in the public cloud, have completely isolated lights-out operations, or accommodate any scenario in between.
Oracle Cloud Infrastructure’s sovereign cloud solutions
-
EU Sovereign Cloud
Oracle EU Sovereign Cloud offers more than 200 of the same services as Oracle’s public cloud. These are physically separated cloud regions located and operated entirely within the European Union and aligned with EU standards of practice.
-
Government Cloud
Oracle Cloud operates government cloud regions that are isolated from commercial customers. Designed for public sector agencies in the United States, UK, and Australia, the regions meet data sovereignty requirements for public sector while offering same set of services, support, and billing as OCI’s public cloud.
-
Dedicated Region
An independent, complete cloud region in a customer-defined data center, with both data and control planes on-premises to meet data residency and low-latency requirements.
-
Isolated cloud
Secure, air-gapped regions designed to meet the highest demands of global customers’ mission-critical classified workloads.
-
OCI public cloud regions
Oracle Cloud spans more than 35 interconnected commercial regions across 24 countries. The multiple geographically separated regions within one country provide more control over data residency for customers to achieve local compliance and implement disaster recovery.
-
Oracle Alloy
Oracle Alloy enables partners to become in-country cloud providers and offer a robust cloud ecosystem to their local customers while fulfilling digital sovereignty and regulatory compliance requirements.
Sovereign cloud use cases
Due to the increasing pressure from industry and regional regulators and geopolitical events, sovereignty in the cloud has become an important consideration not only for the public sector but also for private enterprises.
Compliant cloud for winning customer trust
Organizations proactively prioritizing compliance gain a competitive edge and build a reputation for trustworthiness and ethical operations. All Oracle Cloud services are designed to meet various compliance standards and the highest levels of security—all the way up to Top Secret levels across all deployment models.
Adopting compliant cloud disaster recovery to enhance business continuity
Cloud backup and disaster recovery provides reliable methods to secure all types of sensitive data from infrastructure failures and malicious attacks. Oracle’s distributed cloud services enable various methods and topologies for data and applications—in the cloud, on-premises, or using hybrid approach. Oracle’s multi-region realm setup helps achieve a greater degree of sovereignty.
Applying a distributed cloud strategy to meet regulatory needs
By leveraging a distributed cloud infrastructure, organizations can meet compliance requirements while benefiting from the scalability and flexibility of cloud computing. Oracle’s distributed cloud services offer you more options to control your data, ensuring data sovereignty and security.
Highly regulated industries
Secure data and protect patient privacy in the cloud
Healthcare organizations can better adapt to modern challenges with the cloud. With solutions such as a data lakehouse, AI, and machine learning (ML), electronic health record (EHR) data is no longer siloed, televisits can be utilized at scale, and organizations can rapidly respond to changes in supply and regulations. Oracle Cloud services regularly undergo independent third-party audits, including ISO 27000 series, SOC, HDS, HIPAA, and HITRUST.
Maintain complete control over data and financial governance
The financial services industry is one of the most demanding in terms of regulation and security. Financial transactions require high-performance processing and architectures that enable stable operations. Specialized on-premises cloud solutions such as Oracle Cloud Infrastructure (OCI) Dedicated Region and Oracle Alloy continue to deliver greater business value to our customers faster and easier than ever before while maintaining stringent levels of control and governance.
End-to-end policy and control over applications and infrastructure from core to edge
Distributed cloud architecture allows telcos to store and process data in a geographically distributed manner to improve performance by reducing latency, improving data access times, and achieving greater sovereignty by storing data in compliance with local regulations and data protection laws. Oracle’s distributed cloud services can help telcos achieve both performance and sovereignty.
Telecommunication:
Governments across the globe
Cloud regions optimized for scale, designed with security first, aligned with a nation’s security initiatives
The U.S. Department of Defense, UK Government and Defence, and the Australian Government and Defence cloud regions are sovereign, dedicated cloud regions designed in collaboration with local defense and government agencies to meet data sovereignty requirements and access a complete cloud infrastructure platform supporting highly secret and top secret, classified, and mission-critical workloads.
Boost public sector innovation and help ensure data sovereignty
Many government agencies have selected OCI Dedicated Region to accelerate digital transformation. Between the new services and the data sovereignty offerings, OCI Dedicated Region is strengthening government digital infrastructure for the modern economy.
Protect mission-critical workloads with OCI’s dedicated two-region model
Mission continuity is essential for global customers entrusted with highly classified, sensitive data. Oracle Cloud Infrastructure’s two-region deployment strategy enables you to deploy resilient services in multiple geographically separated locations within the same national/regional borders to help you build true business continuity and disaster protection and meet regulatory and sovereignty requirements.
Sovereign Cloud Solutions Navigator
Digital sovereignty is a complex and rapidly evolving area, and a wide range of cloud solutions are available to help you address different requirements. By evaluating your digital sovereignty requirements and better understanding the available sovereign cloud capabilities, you can identify sovereign cloud solutions from Oracle Cloud Infrastructure (OCI) that help you address your specific needs.
Explore your sovereign cloud options from Oracle
Learn about options for controlling data localization.
Anywhere in the world
Run workloads and store data using OCI’s 48 commercial, government, and sovereign public cloud regions in 24 countries for both private companies and public sector organizations.
In Europe
Oracle EU Sovereign Cloud helps customers address EU data residency and sovereignty requirements with two separate sovereign cloud regions. OCI also operates nine other commercial regions across Europe, as well as two commercial regions and two government regions in the UK.
In your data center
Deploy entire cloud regions in your data center with our dedicated cloud solutions. Extend the cloud to run applications and databases behind your firewall using Oracle Cloud@Customer.
Learn about options for controlling user access.
By all organizations
Both private companies and public sector organizations can operate in OCI’s 38 commercial public cloud regions.
Only by users with specific government authorization or in a certain location
OCI operates separate clouds for government use in the US, UK, and Australia. Access to these clouds is limited to authorized users.
Oracle EU Sovereign Cloud is located and operated entirely within the European Union and is operated in alignment with EU data privacy requirements.
Only by users in your organization or authorized by you
Organizations can choose a dedicated cloud solution in a data center they control and limit access to only their organization or stakeholders.
Learn about options for controlling connectivity and isolation.
To any global cloud region
Customers can choose any of Oracle’s commercial public cloud regions to store their data and can control its movement to any other region. Organizations can set policies to restrict data movement or access.
Only to regions in specific geographies or with specific authorization
Oracle separates regions for different uses into distinct realms that are not connected.
Regions for each type of use are separated from each other, with independent access, accounts, operations, and support.
Isolated regions can be operated while disconnected for mission-critical workloads.
Only to regions dedicated to your use
Dedicated cloud regions controlled by a single organization are separated into a distinct realm that is separated from all other regions. Dedicated regions are operated independently, with separate access, accounts, operations, and support.
Learn about options for controlling data localization.
A global operations and support team
Oracle’s global operations and support team serves our regions worldwide, including our commercial regions.
Personnel restricted by governance and compliance policies
Government clouds and Oracle EU Sovereign Cloud are operated and supported by personnel that meet the specific requirements of each cloud. This can include residency or clearance status.
Personnel restricted by requirements specific to your organization
Operations and support teams can be subject to specific requirements if needed for classified or specialized use cases or for partner-led operations.
Learn about options for controlling governance and compliance.
And align with current standards
Oracle manages more than 80 global, regional, and industry-specific programs to provide third-party attestations and advisories for standards and actively maintains these programs to align with these standards for both private companies and public sector organizations.
And government requirements
Oracle operates several separate clouds authorized for use under specific government compliance frameworks. Oracle EU Sovereign Cloud is aligned with EU data sovereignty requirements.
Oracle’s US government clouds offer services with FedRAMP High and DISA IL6 authorization, as well as Oracle National Security Regions for classified workloads. Oracle also offers government clouds for the UK and Australia. Oracle Cloud Isolated Region is available for customers needing the highest levels of mission support.
And organization-specific needs
Customers can work with Oracle to customize specific commercial, technical, and operational aspects to address their needs in dedicated cloud regions and other restricted cloud offerings.
Learn about options for security, encryption, and key management.
Including a full portfolio of security capabilities built on a zero trust architecture
Oracle helps reduce risk by providing a comprehensive set of simple, prescriptive, and integrated security capabilities that can help organizations secure their OCI tenancy.
Including encryption keys that you can control
OCI encrypts data at rest and in transit. Encryption keys can be managed by Oracle for simplicity or by you for more control.
Including external key management controlled independently of the cloud provider
External key management allows you to use on-premises hardware security modules and third-party key management services that Oracle can’t access.
Digital Sovereignty
Many governments are implementing digital sovereignty regulations that govern digital operations and cloud use. Businesses and public sector organizations should develop a comprehensive digital sovereignty strategy and evaluate sovereign cloud solutions to address evolving regulatory requirements.
What is digital sovereignty?
Digital sovereignty refers to the regulations that specify how organizations manage their digital assets, including their use of the cloud. Organizations may require data to remain within a certain jurisdiction and specify how it must be managed. Other areas of regulation include technical portability, operations, and in-country business continuity. Digital sovereignty is complex; laws rapidly evolve and can vary widely in different jurisdictions. Sovereign cloud solutions are evolving alongside these regulatory changes to address the growing demand for digital sovereignty.
-
A range of cloud solutions can help address digital sovereignty needs
The commercial public cloud can address some aspects of digital sovereignty. For example, organizations may store their data in a cloud region within their country to satisfy data residency requirements. Many organizations, however, find they need more-specialized sovereign cloud capabilities to meet regulatory requirements while using sensitive data and applications in the cloud. When evaluating sovereign cloud solutions, it’s critical to understand the capabilities of different sovereign cloud solutions.
Capabilities that address digital sovereignty requirements
Customers can use a variety of sovereign cloud capabilities to help them address digital sovereignty requirements.
-
Data and infrastructure localization
Control how data is hosted.
-
Restrict data and access
Choose separate clouds for different uses.
-
Local operations and support
Restrict cloud personnel.
-
Local regulatory support
Your choice of technologies including Kubernetes and containers.
-
Network isolation
Use separated clouds and disconnected operations.
-
Data privacy and encryption
Control encryption keys and more.
Digital sovereignty needs differ
Organizations have widely different digital sovereignty requirements. Cloud providers must be able to offer a range of cloud solutions to address their customers’ specific and localized needs. These solutions include clouds restricted to operations in a specific country or a specific geography, clouds dedicated to a single organization, clouds for use by ministries of a single government, and clouds for use by defense and intelligence organizations. By offering each country and each organization its own cloud, cloud providers put the benefits of the cloud and greater digitalization within reach for users across the world.
A common cloud platform enables digital sovereignty
Cloud providers that add sovereign cloud capabilities to their public cloud platform shouldn’t compromise the functional, operational, and economic benefits their customers already receive. Sovereign cloud solutions should provide a common platform to users with the same experience as commercial public clouds. Cloud providers should offer the same services, usage rates, support, and service level agreements as an extension of their existing commercial programs and business relationships. In this way, organizations can use their existing skills, processes, and tooling as they adopt sovereign cloud solutions.
Digital sovereignty by design
Most global, hyperscale public clouds have been designed for security but not sovereignty. The autonomy necessary for digital sovereignty can be difficult to achieve using clouds with large, general-use regions in a globally connected network. Cloud solutions architected with sovereignty in mind can more easily offer these protections. For example, several providers, including Oracle, have created separate cloud regions for sensitive data used by the US government. Separating these regions strengthens protections against unauthorized user access and data movement. Operating them separately simplifies addressing compliance frameworks.
Digital sovereignty use cases
-
Organizations protecting personal information
The General Data Protection Regulation (GDPR) in the European Union is just one of a growing set of local data privacy and protection laws that govern how organizations must store and handle personal identifiable information (PII). Sovereign cloud solutions can help organizations responsibly manage this data in the cloud to address digital sovereignty requirements.
-
Regulated industries requiring the protection of sensitive data
Many companies are subject to digital sovereignty regulations specific to their industry, such as the European Union’s Digital Operational Resilience Act, which applies to financial organizations. A sovereign cloud enables organizations to innovate in the cloud while addressing the compliance requirements arising from digital sovereignty regulations.
-
Global organizations operating in multiple jurisdictions
A company operating in different locations must comply with the different local digital sovereignty regulations in each of the jurisdictions. A sovereign cloud can help global organizations manage and navigate the dynamic and emerging global digital sovereignty landscape.
-
Public sector and government agencies operating in the cloud
Many governments have created specific guidance for how the public sector should operate in the cloud, such as FedRAMP in the US, Canada’s Protected B classification, or the Information System Security Management and Assessment Program in Japan. Sovereign cloud capabilities can help public sector organizations operate in accordance with local digital sovereignty compliance frameworks.
-
National and government clouds
Governments have authorized services from cloud providers to be used for government workloads and sensitive data; examples include clouds that Oracle operates that are authorized for public sector use in the US, the UK, and Australia. Additionally, governments may more directly authorize a cloud service for workloads and industries of national interest to establish digital sovereignty—for example, the government cloud of the Sultanate of Oman.
OCI’s distributed cloud: Cloud services everywhere you need them
Expanding cloud options for customers with more public cloud, multicloud, hybrid cloud, and dedicated cloud capabilities.