The platform under your cloud.
From the data center to the node.

enum GmbH, a German company with no US parent, runs its public cloud on servers it operates itself, in a Tier III+ data centre in Frankfurt and on its own network. This page goes through the layers a risk assessment asks about, from the building to your Kubernetes cluster.

Frankfurt am Main · AS215998

01 · Data centre

Your data stays in Frankfurt, under German and EU law.

Production runs in a Tier III+ data centre in Frankfurt am Main. The facility operator holds ISO 27001 and EN 50600 for the site, and enum's own ISO 27001 certification is in progress, with a target of Q4 2026.

  • Tier III+ · Frankfurt
  • Operator: ISO 27001, EN 50600
  • enum ISO 27001 · Q4 2026

02 · Rack

One accountable operator for the whole platform.

enum GmbH in Cologne operates every server in these racks itself, with no US parent and no reseller in between, so the US CLOUD Act does not reach the data. The racks form one shared platform; what is yours alone is an isolated Kubernetes cluster.

  • enum GmbH · Cologne
  • No US parent
  • Servers run by enum

03 · Server

A failed server is a routine event.

Your worker nodes are spread across servers and failure domains. When a server fails, its nodes are replaced automatically, so one machine going down is not an incident for you.

  • Spread across failure domains
  • Failed nodes replaced automatically

04 · Compute

Current-generation AMD EPYC.

Every node runs on current-generation AMD EPYC server CPUs, made for running many virtual machines side by side.

  • AMD EPYC

05 · Storage

NVMe block storage, written three times.

Block storage volumes sit on NVMe. A write is acknowledged only once it is on three failure domains, so losing a host loses no data.

  • NVMe · 3 replicas

06 · Network

Our own network, with no single point of failure.

Traffic runs over enum's own autonomous system, AS215998, with IP ranges from enum's own RIPE allocation. Every connection is redundant, so if one fails, your traffic keeps flowing.

  • AS215998
  • IPv4 + IPv6
  • eBPF network policies
  • Private by default
See the network

07 · Cluster

Your cluster: isolated, highly available, self-healing.

Every cluster has its own control plane, replicated across three failure domains with automatic failover and a 99.9% SLA on its API. A controller reconciles each cluster continuously and replaces nodes that fail, without a ticket.

  • Own control plane
  • 3 failure domains
  • 99.9% API SLA
  • Self-healing

Questions from reviews.
Answered.

Does each customer get dedicated hardware?

No. enum is a public cloud platform on shared infrastructure. Your worker nodes are virtual machines on servers that other customers use too. What is yours alone is the Kubernetes cluster: it has its own isolated control plane, replicated across three failure domains.

Do you run your own network?

Yes. enum operates its own autonomous system, AS215998, registered with RIPE NCC, and announces IP ranges from its own allocation over IPv4 and IPv6. Two carriers and peering are active at the same time, with BGP failover between them. The network is listed on PeeringDB.

Who holds the data centre certifications?

The Frankfurt data centre is certified to ISO 27001 and EN 50600; those certificates belong to the facility operator. enum's own ISO 27001 certification is in progress, with a target of Q4 2026.

What happens when a server fails?

Block storage writes are already on three failure domains, so no data is lost. The Kubernetes control plane fails over automatically, and the controller that reconciles every cluster replaces the affected nodes.

Review the platform with us.
Talk to our team.

Bring your security questionnaire or architecture review. We walk you through the data centre, the network and how your clusters run on them.