The platform under your cloud.
From the data center to the node.
enum GmbH, a German company with no US parent, runs its public cloud on servers it operates itself, in a Tier III+ data centre in Frankfurt and on its own network. This page goes through the layers a risk assessment asks about, from the building to your Kubernetes cluster.
Frankfurt am Main · AS215998
01 · Data centre
Your data stays in Frankfurt, under German and EU law.
Production runs in a Tier III+ data centre in Frankfurt am Main. The facility operator holds ISO 27001 and EN 50600 for the site, and enum's own ISO 27001 certification is in progress, with a target of Q4 2026.
- Tier III+ · Frankfurt
- Operator: ISO 27001, EN 50600
- enum ISO 27001 · Q4 2026
02 · Rack
One accountable operator for the whole platform.
enum GmbH in Cologne operates every server in these racks itself, with no US parent and no reseller in between, so the US CLOUD Act does not reach the data. The racks form one shared platform; what is yours alone is an isolated Kubernetes cluster.
- enum GmbH · Cologne
- No US parent
- Servers run by enum
03 · Server
A failed server is a routine event.
Your worker nodes are spread across servers and failure domains. When a server fails, its nodes are replaced automatically, so one machine going down is not an incident for you.
- Spread across failure domains
- Failed nodes replaced automatically
04 · Compute
Current-generation AMD EPYC.
Every node runs on current-generation AMD EPYC server CPUs, made for running many virtual machines side by side.
- AMD EPYC
05 · Storage
NVMe block storage, written three times.
Block storage volumes sit on NVMe. A write is acknowledged only once it is on three failure domains, so losing a host loses no data.
- NVMe · 3 replicas
06 · Network
Our own network, with no single point of failure.
Traffic runs over enum's own autonomous system, AS215998, with IP ranges from enum's own RIPE allocation. Every connection is redundant, so if one fails, your traffic keeps flowing.
- AS215998
- IPv4 + IPv6
- eBPF network policies
- Private by default
07 · Cluster
Your cluster: isolated, highly available, self-healing.
Every cluster has its own control plane, replicated across three failure domains with automatic failover and a 99.9% SLA on its API. A controller reconciles each cluster continuously and replaces nodes that fail, without a ticket.
- Own control plane
- 3 failure domains
- 99.9% API SLA
- Self-healing
Questions from reviews.
Answered.
Does each customer get dedicated hardware?
No. enum is a public cloud platform on shared infrastructure. Your worker nodes are virtual machines on servers that other customers use too. What is yours alone is the Kubernetes cluster: it has its own isolated control plane, replicated across three failure domains.
Do you run your own network?
Yes. enum operates its own autonomous system, AS215998, registered with RIPE NCC, and announces IP ranges from its own allocation over IPv4 and IPv6. Two carriers and peering are active at the same time, with BGP failover between them. The network is listed on PeeringDB.
Who holds the data centre certifications?
The Frankfurt data centre is certified to ISO 27001 and EN 50600; those certificates belong to the facility operator. enum's own ISO 27001 certification is in progress, with a target of Q4 2026.
What happens when a server fails?
Block storage writes are already on three failure domains, so no data is lost. The Kubernetes control plane fails over automatically, and the controller that reconciles every cluster replaces the affected nodes.
Review the platform with us.
Talk to our team.
Bring your security questionnaire or architecture review. We walk you through the data centre, the network and how your clusters run on them.