Oracle UK Sovereign Cloud

Oracle UK Sovereign Cloud is the first and only dedicated dual-region cloud offered by a major cloud service provider for eligible organisations that require UK data and operational sovereignty. Eligible government and defence customers can access a hyperscale cloud infrastructure platform that offers the services needed to build and run applications in a highly secure, compliant, scalable, and private community cloud.

Oracle UK Sovereign Cloud regions

Two Separate Regions

Oracle delivers two geographically separate regions as part of the Oracle UK Sovereign Cloud:

  • London, England
  • Newport, Wales

PASF Accreditation

The data centre facilities maintain UK Police Assured Secure Facilities (PASF) accreditation. The regions also align with the security principles outlined by the UK National Cyber Security Centre (NCSC) and are built upon the parameters necessary to store UK OFFICIAL SENSITIVE data.

Connectivity

Both regions are interconnected via a highly resilient, private high-speed backbone to facilitate a responsive, distributed architecture that enables disaster recovery and high availability. The Oracle UK Sovereign Cloud regions are physically isolated from other Oracle cloud regions and are located in their own secure data centre rooms within the UK data centre sites.

Both regions offer the following connectivity:

  • Internet
  • FastConnect

Operational sovereignty

The control and monitoring systems for the Oracle UK Sovereign Cloud are self-contained inside the sovereign cloud realm, further maintaining its UK sovereignty. The only authorised Oracle staff to conduct operations, customer support, security operations, and other functions for the regions are UK citizens who reside within the UK and maintain UK Security Check (SC) clearance.

A gentleman and a lady working in the datacenter

UK Sovereign Cloud capabilities

Supporting mission-critical workloads and improving business agility

  • Reinvent workflows to accommodate new realities

    Citizens have rising expectations for convenience, meaning governments must now create a more resilient, scalable architecture to meet their demands. Oracle Cloud Infrastructure (OCI) is the first major cloud vendor to support Layer 2 (L2) network virtualization, offering compatibility for databases, network appliances, and virtualization environments. Governments can migrate their mission-critical applications without re-architecting or sacrificing control and visibility.

  • Reduce security risks by limiting the attack surface

    Security and risk management are very important government considerations, and they require a secure cloud infrastructure based on least privileged access. Secure by design, zero trust as its mandate, OCI prevents threats from gaining access to customer data by isolating network virtualization. This greatly reduces the risk from hypervisor-based attacks and provides superior tenant isolation compared to earlier public cloud designs.

  • Ensure business continuity with a disaster recovery plan

    Governments must be resilient even when faced with natural disasters, public safety concerns, or national security threats. If a large-scale outage affects production applications, governments need the ability to restore the workloads quickly. Oracle’s unique dual-region cloud strategy enables UK Sovereign Cloud to deploy applications in multiple geographically separated locations—without having sensitive data leave the country. From high-bandwidth file synchronization to backup/restore and detailed database failover options, Oracle Cloud offers extremely cost-effective resiliency and disaster recovery (DR) solutions.

  • Invest in automation and focus on more critical functions

    Governments have an increasingly diverse set of data sources that consume significant amounts of storage and risk exceeding the capacity of existing systems. This data is often locked away in silos preventing teams from gaining valuable insights. Consolidate 10s-1000s of databases on a unified service leveraging autonomous services to automate patching and performance tuning of the operating system and the database. Use Oracle Analytics Cloud for data preparation, machine learning, visualization, reporting, and augmented analysis on all types of data—in the cloud, on-premises, or in a hybrid deployment.

  • Data sovereignty and security

    Designed to reflect the requirements of the UK Government, Oracle UK Sovereign Cloud is a fully sovereign, dedicated dual-region cloud that is restricted to UK Government and Defence customers and UK Government-sponsored third parties.

Oracle Cloud offered increased security compared to our existing infrastructure. Oracle builds security into the architecture from the bottom up, which reduces concerns of persistent threats and helps protect our workloads.
Steve Holborow Deputy Director, Architecture and Information Assurance, Government Shared Services, UK Cabinet Office

Run your most critical applications securely

Designed in collaboration with multiple UK Government and Defence ministries, the Oracle UK Sovereign Cloud adheres to the security principles outlined by the UK National Cyber Security Centre (NCSC) and is built upon the parameters necessary to store UK OFFICIAL SENSITIVE data. Customer data is always stored on UK soil and the only authorised Oracle personnel operating and supporting the environment are UK citizens that hold an active Security Check (SC) clearance.

Featured OCI Public Sector and Government blogs

Oracle UK Sovereign Cloud data centres achieve Police Assured Secure Facilities (PASF) assurance

Site visits were conducted by a PASF-qualified assessor, and the Oracle UK Sovereign Cloud data centres meet the established PASF requirements. UK law enforcement workloads and critical data are able to be hosted in the Oracle UK Sovereign Cloud.

Service availability

UK Sovereign Cloud region
Cloud services South West
Compute
Oracle Cloud Infrastructure Compute
Oracle Cloud Infrastructure Secure Desktops
Storage
Oracle Cloud Infrastructure Block Volumes
Oracle Cloud Infrastructure File Storage
Oracle Cloud Infrastructure Object Storage
Oracle Cloud Infrastructure Archive Storage
Networking
Oracle Cloud Infrastructure Virtual Cloud Network
Oracle Cloud Infrastructure Web Application Accelerator
Oracle Cloud Infrastructure Flexible Load Balancer
Oracle Cloud Infrastructure Flexible Network Load Balancer
Oracle Cloud Infrastructure DNS
Oracle Cloud Infrastructure Site-to-Site Virtual Private Network
Oracle Cloud Infrastructure FastConnect
Oracle AI Database
Oracle Autonomous AI Database
Oracle Autonomous AI Database on Dedicated Exadata Infrastructure
Oracle Base Database Service
Oracle Exadata Database Service
Oracle Exadata Database Service on Exascale Infrastructure
Oracle Exadata Cloud@Customer
Oracle Data Safe
Oracle Database Zero Data Loss Autonomous Recovery Service
Oracle Cloud Infrastructure GoldenGate
Databases
Oracle MySQL HeatWave
Oracle Cloud Infrastructure Database with PostgreSQL
Oracle NoSQL Database
Oracle Cloud Infrastructure Search with OpenSearch
Oracle Cloud Infrastructure Cache
Analytics and AI
Oracle Analytics Cloud
Oracle AI Data Platform
Oracle Fusion Data Intelligence
Oracle Big Data Service
Oracle Cloud Infrastructure Data Catalog
Oracle Cloud Infrastructure Data Integration
Oracle Cloud Infrastructure Data Flow
Oracle Cloud Infrastructure Streaming
Oracle Cloud Infrastructure Connector Hub
Oracle Cloud Infrastructure Data Science
Oracle Cloud Infrastructure Generative AI
Oracle Cloud Infrastructure Language
Oracle Cloud Infrastructure Speech
Oracle Cloud Infrastructure Document Understanding
Oracle Digital Assistant
Oracle Cloud Infrastructure AI Agent Platform
Developer services
Oracle Cloud Infrastructure Kubernetes Engine (OKE)
Oracle Cloud Infrastructure Container Instances
Oracle Cloud Infrastructure Container Registry
Oracle Cloud Infrastructure Functions
Oracle APEX Application Development
Oracle Database Tools Service
API Management
Oracle Integration
Oracle Cloud Infrastructure Notifications
Oracle Cloud Infrastructure Email Delivery
Oracle Cloud Infrastructure Queue
Oracle Visual Builder Studio
Oracle Visual Builder
Oracle Cloud Infrastructure DevOps
Oracle Cloud Infrastructure Resource Manager
Oracle Cloud Infrastructure Cloud Shell
Identity and security
Oracle Cloud Infrastructure Identity and Access Management
Oracle Access Governance
Oracle Cloud Guard
Oracle Security Zones
Oracle Threat Intelligence Service
Oracle Cloud Infrastructure Network Firewall
Oracle Cloud Infrastructure Web Application Firewall
Oracle Cloud Infrastructure Certificates
Oracle Cloud Infrastructure Vulnerability Scanning Service
Oracle Cloud Infrastructure Key Management Service
Oracle Cloud Infrastructure Zero Trust Packet Routing
Oracle Cloud Infrastructure Bastion
Observability and management
Oracle Cloud Infrastructure Application Performance Monitoring
Oracle Cloud Infrastructure Stack Monitoring
Oracle Cloud Infrastructure Logging
Oracle Cloud Infrastructure Fleet Application Management
Oracle Cloud Infrastructure Monitoring
Oracle Cloud Infrastructure Log Analytics
Oracle Cloud Infrastructure Events Service
Oracle Cloud Infrastructure Database Management
Oracle Cloud Infrastructure Ops Insights
Java Management Service
Oracle Autonomous Linux
Oracle OS Management Hub
Hybrid
Oracle Cloud VMware Solution
Migration and disaster recovery
Oracle Cloud Migrations
Oracle Cloud Infrastructure Database Migration
Oracle Cloud Infrastructure Full Stack Disaster Recovery
Billing and cost management
Oracle Cloud Infrastructure FinOps, Cloud Cost Management, and Governance Services
Support Rewards for Oracle Cloud
Governance and administration
Oracle Cloud Infrastructure Cloud Advisor
Oracle Cloud Infrastructure FinOps, Cloud Cost Management, and Governance Services
Marketplace
Oracle Cloud Marketplace

The same low pricing as commercial regions

In contrast to services from other providers, OCI services are priced the same for all global regions, including Oracle UK Sovereign Cloud regions. The Oracle Universal Credit model with committed use discounts, software license portability, and rewards for OCI consumption are also available. Customers can calculate the cost of their workloads using the OCI Cost Estimator; as an example, the cost estimator for virtual machine instances is shown below. Learn more on our OCI Pricing page.

General information

What are the benefits of the Oracle UK Sovereign Cloud?

  1. It is purpose-built for workloads that require UK sovereignty.
  2. Oracle provides a UK Sovereign Operating Model to support UK OFFICIAL-SENSITIVE workloads.
  3. The UK Sovereign Operating Model limits access to the infrastructure contained in the realm to only Oracle's authorised UK personnel.
  4. The cloud offers disaster recovery and high availability capabilities for customers to help ensure that their data remains inside the UK sovereign environment.

What is a Sovereign Operating Model and what does it mean for the Oracle UK Sovereign Cloud?

The Sovereign Operating Model helps ensure that your content stored in, or run on or through, Oracle UK Sovereign Cloud services. Your content will not leave the environment. Additionally, only authorised personnel who meet certain stipulations will be granted access to operate and manage the services. These are:

  1. Located in the UK at time of access
  2. UK resident
    • “Residing in the UK” means living in England, Wales, Scotland, or Northern Ireland
    • Minimum of five years of residency in the UK, with no more than six months outside of the UK at any one time
  3. UK citizen
    • Can live and work in the UK free of any immigration controls
    • Ability to hold a UK passport
  4. UK Security Check (SC) cleared

Further information shall be made available in the PaaS and IaaS Public Cloud Services Pillar Document.

How does Oracle facilitate the sovereignty and security of data within this dedicated cloud?

  1. The UK Sovereign Cloud data centres are physically located in the UK. Only authorised personnel who meet the stipulations listed below have physical access to the Oracle infrastructure in the facility.
    • UK residents
      • “Residing in the UK” means living in England, Wales, Scotland, or Northern Ireland
      • Minimum of five years of residency in the UK, with no more than six months outside of the UK at any one time
    • UK citizens
      • UK Security Check (SC) cleared
  2. Your content stored in our UK sovereign data centres does not leave the cloud throughout its lifecycle without your express permission or permission granted on your behalf.
  3. The NCSC Sanitisation Assurance (CAS-S) scheme is used for secure sanitisation and disposal to comply with NCSC standards.
  4. The Data Processing Agreement for Oracle Services applies to Oracle’s processing of personal information on your behalf in order to provide the services specified in your Services Agreement.
  5. UK data protection law applies, meaning the UK General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018.
  6. Oracle applies additional UK compliance schemes to these regions.

The operational teams that support the regions are located in the UK, and only authorised personnel have logical or physical access to the environment. All control, monitoring, and logging systems are also located in the UK. Oracle’s UK Security Controller tightly controls the approval process that determines which Oracle staff are authorised to access the logical or physical environment.

When did this dedicated dual-region cloud for customers become available?

The Oracle UK Sovereign Cloud realm consists of two regions: London, which was made available on December 3, 2019, and Newport, which was made available on July 31, 2020.

What connectivity is available to this cloud?

The Oracle UK Sovereign Cloud is connected to and accessible via the internet. The two regions are interconnected via a secure, non-internet backbone for inter-region traffic. Additionally, the regions offer Oracle Cloud Infrastructure (OCI) FastConnect connectivity options.

Who is eligible to gain access to this cloud?

Please contact your Oracle representative for information.

How is separation between customers enforced?

The answer to this is multilayered. To summarise:

  • The Oracle UK Sovereign Cloud is a realm that is physically isolated from any other Oracle realm, for example, the OCI commercial realm US East region.
    • A tenancy (which is a customer environment within the cloud realm) only exists in a single realm.
    • A customer’s tenancy will only exist in the Oracle UK Sovereign Cloud realm and will only have access to the Oracle UK Sovereign Cloud regions.
    • Customers with tenancies in other OCI realms have no access to the Oracle UK Sovereign Cloud regions.
  • The Oracle Cloud Infrastructure architecture was designed for security, with isolated network virtualisation, highly secure firmware installation, a controlled physical network, and network segmentation. Within Oracle UK Sovereign Cloud:
    • The compute and storage resources in each customer’s tenancy are enclosed in a distinct virtual cloud network (VCN) created for them. A VCN is a software-defined network that resembles the on-premises physical network used by customers to run their workloads.
    • Oracle is an original device manufacturer (ODM) with an in-house hardware development group that designs custom motherboards for OCI servers and develops firmware that runs on those motherboards, such as BIOS and BMC. A dedicated hardware security group also works with the hardware group to build security hardware. These Oracle teams have built the following security components, which are incorporated into OCI servers:
      • Hardware root of trust (RoT) - If a customer has complete access to the physical server they can reconfigure hardware peripherals or modify any firmware to support their workloads. The OCI Hardware Root of Trust helps negate the security risk of persistent firmware malware on the server (such as UEFI BIOS malware and NVMe drive malware) by installing known-good images of all firmware on an OCI server when provisioning tenancies between customers.
      • Off-box virtualisation hardware - Oracle Cloud Infrastructure uses Oracle’s custom-designed SmartNIC that isolates and virtualizes the network. The SmartNIC is isolated by hardware and software from the host, preventing a compromised cloud instance from affecting the network. OCI maintains greater external control of host network functionality and can prevent network traversal attacks. The privileged OCI control plane code runs on this dedicated hardware, referred to as off-box virtualisation, which is separate and segregated from the server processor running untrusted customer applications. The hypervisor is reduced to basic functionality, such as launching virtual machines and allocating memory, while all the privileged cloud control plane code is off-loaded to the off-box virtualisation hardware. This configuration has two security benefits: It reduces the attack surface of the hypervisor, and it helps limit the blast radius of a hypervisor security issue so it doesn’t impact cloud control plane operations.
        • All network traffic from customer applications is sent or received by the server’s NIC and flows through the off-box virtualisation running OCI control plane code. The cloud control computer is invisible to customers and is not accessible from customer applications due to server hardware configurations. As a result, customers don’t see this extra hop in their network path.
  • Access to a customer’s tenancy is managed by that customer. OCI Identity and Access Management (IAM) provides features such as authentication, single sign-on (SSO), and identity lifecycle management for Oracle Cloud.

Please contact your Oracle representative for further details.

Why has Oracle changed the name of the realm?

The Oracle UK Sovereign Cloud reflects the purpose of the regions and aligns with the naming of other similar realms that Oracle operates for customers, such as the Oracle EU Sovereign Cloud.

Has any security or sovereignty aspect changed that could affect UK government workloads in the realm?

No. All fundamentals of the Oracle UK Sovereign Cloud remain the same as when it was called the Oracle Cloud for UK Government and Defence. The realm still provides the same data and operational sovereignty in the UK, and Oracle continually works to strengthen and improve its sovereign security controls and practices. Oracle remains the only hyperscale cloud provider offering a UK sovereign cloud that's purposely designed for customer workloads and information marked OFFICIAL SENSITIVE.

Are third-party services available?

Yes. Oracle allows a curated set of approved third-party service providers to securely offer services that are beneficial to this customer community. It is up to the individual customer to decide whether to contract with these third-party providers and to understand the terms under which their services are being offered.

Get started with Oracle UK Sovereign Cloud