# enum GmbH – Full Content > enum GmbH is a European public cloud platform delivering enterprise-grade Managed Kubernetes, S3-compatible Object Storage, and VPC Networking. Built on its own infrastructure in a German Tier III+ data center. Combines hyperscaler engineering with full European sovereignty and zero US dependencies. Structured overview: https://enum.co/llms.txt --- ## Homepage Source: https://enum.co # The European Cloud Platform. Going live Q3 2026 # Infrastructure You Can Trust - **Own Autonomous System**: AS215998. Own IP space. Direct peering at European Internet Exchanges. No reselling, no middlemen. - **AMD EPYC. NVMe.**: Latest hardware generation. Fast storage. Low latencies. - **Frankfurt. Tier III+.**: ISO 27001. EN50600. 24/7 Security. - **API-First**: CLI, API, Terraform. Provision infrastructure in seconds, not days. - **99.9% SLA**: Highly available by design. Automatic failover. We mean it. - **S3-Compatible Storage**: S3-compatible. Redundant. Your data never leaves the EU. # One Command. Your Infrastructure. - **European without compromise**: Full sovereignty, full developer experience. You shouldn't have to choose. - **Fully Automatable**: CLI, API, Terraform. Integrate into any CI/CD pipeline. - **Resilient**: Automatic failover, self-healing services, redundant storage. ### enum Kubernetes Engine - **Highly Available Control Plane**: Redundant control plane with automatic failover and zero-downtime upgrades. Your cluster stays stable - even while we patch. - **Technical Excellence**: Immutable OS, eBPF-based networking, optimized for scaling workloads. - **Scalable & Production-Ready**: Scales effortlessly in every direction - with automated monitoring, patching, and recovery. Built for the big leagues. - **Immutable by Design. Minimal Attack Surface.**: Immutable infrastructure for maximum security, minimal attack surface - security integrated from the start. ### enum Object Storage - **S3-Compatible. Drop-in for AWS.**: Full support for well-known tools and SDKs - seamlessly integrable into existing workflows. Drop-in replacement that just works. - **Petabyte-Ready. On NVMe.**: Scales with your data, not against you. Tiered storage with NVMe-accelerated performance - throughput that grows with your requirements. - **Data in Europe. No US Routing.**: Your data never leaves the EU. No routing through US data centers, no CLOUD Act risks. GDPR compliance without workarounds. - **Redundant. Automatic.**: Every object is replicated three times across independent failure domains. Resilience for data you can't afford to lose. ### Networking - **VPC Network Isolation**: Dedicated virtual networks with full traffic segmentation. Your workloads, completely isolated. - **L4 Load Balancing**: High-performance load balancing powered by eBPF. Native Kubernetes integration. - **enum DNS**: Authoritative DNS with low-latency resolution. Fully integrated into the platform. - **Cloud NAT Gateway**: Optional managed NAT gateway with a stable egress IP and egress filtering. Clusters egress via host-based NAT by default. **European Cloud Platform** # Start building on enum. Going live Q3 2026 --- ## enum Kubernetes Engine Source: https://enum.co/kubernetes-engine **Flagship Product** # enum Kubernetes Engine. Sovereign Managed Kubernetes for teams that need hyperscaler-grade engineering without US jurisdiction. Self-service, HA control plane included, production-ready in minutes. enum Kubernetes Engine (EKE) is a self-service Kubernetes platform operated entirely in Germany under EU law. It runs upstream, unmodified Kubernetes with an isolated, highly available control plane per cluster included at no extra charge, private-by-default clusters, and full GDPR data sovereignty from a German GmbH. ### Why enum Kubernetes Engine? Hyperscaler-grade Kubernetes, operated in Germany under EU law - **HA Control Plane Included**: Every cluster gets an isolated, highly available control plane across independent failure domains, with automatic failover and zero-downtime upgrades. No per-cluster-hour charge. - **Upstream Kubernetes, No Fork**: Standard upstream Kubernetes with best-practice tooling. Existing manifests, Helm charts, and GitOps pipelines port over unchanged. - **Self-Service via API and CLI**: Provision clusters through enumctl, the REST API, or Terraform. Sensible defaults, no infrastructure assembly. First cluster in minutes, not days. - **European Sovereignty by Design**: German GmbH, German data centers in Frankfurt, German and EU law only. No US parent, no US subprocessors, no transatlantic data flows. ### Ideal for - Regulated workloads under GDPR, NIS2, or DORA - SaaS and FinTech platforms needing EU-only data flows - Microservices architectures requiring high availability - CI/CD pipelines with GitOps workflows - Teams migrating from AWS EKS, Google GKE, or Azure AKS ### Frequently Asked Questions **What is a GDPR-compliant Managed Kubernetes solution from Germany?** A GDPR-compliant Managed Kubernetes solution from Germany is a Kubernetes platform operated by a German company in German data centers under German and EU law only, with no US parent and no US subprocessors. enum Kubernetes Engine runs in Frankfurt, includes an HA control plane per cluster, and is operated by enum GmbH under exclusive German jurisdiction with no CLOUD Act exposure. **Is enum Kubernetes Engine NIS2 and DORA ready?** Yes. enum is a German GmbH operating in a German Tier III+ data center under German and EU law, with no US subprocessors and no transatlantic data flows. That structure aligns with NIS2 supply-chain requirements and DORA ICT third-party risk rules. NIS2 and DORA readiness is a structural property of where the company and data sit, not a separate certification. **How does enum Kubernetes Engine differ from AWS EKS and Google GKE?** enum includes a highly available control plane per cluster at no per-cluster-hour charge, provisions clusters private by default with host-based NAT, and bills load balancing at flat fees. AWS EKS and Google GKE bill the control plane per cluster-hour and leave NAT, private networking, and load balancing as separate paid components. All three run upstream Kubernetes, so manifests and Helm charts port over. **Is enum subject to the US CLOUD Act?** No. enum GmbH is a German company with no US entity in its corporate structure, so it is not subject to the US CLOUD Act or FISA Section 702. Selecting an EU region at a US-headquartered provider does not remove that exposure, because the corporate jurisdiction of the company holding the data is what counts. **What does Managed Kubernetes cost at enum?** Compute is billed per hour with optional one to three year commitment discounts. Block storage is billed per GB per month. The HA control plane is included at no extra charge, host-based NAT is included, and load balancing is a flat monthly fee with an IPv4 address included. All prices are in euros and exclude VAT. **How fast is a cluster provisioned, and how does provisioning work?** A cluster is ready in minutes through self-service. You provision it via the enumctl CLI, the REST API, or Terraform, with sensible defaults so no manual infrastructure assembly is needed. Clusters are private by default and run upstream Kubernetes, so existing manifests and GitOps pipelines work without changes. **In which regions does enum operate Kubernetes?** enum operates its primary Kubernetes region in Frankfurt, Germany, in a Tier III+ data center, with further European regions on the roadmap. All regions run on enum's own infrastructure and own network (AS215998), inside the European Union. **Can I migrate from AWS EKS or GKE to enum?** Yes. enum runs upstream, unmodified Kubernetes, so standard manifests, Helm charts, and GitOps workflows port over without code changes. enum object storage is S3-API compatible, so rclone, aws-cli, and the AWS SDKs work as-is. Migration support is available if you need help with the cutover. ### enum vs. AWS EKS What is included versus what costs extra. | Feature | enum | AWS EKS | |---|---|---| | HA Control Plane | Included per cluster, no per-cluster-hour charge | Billed per cluster-hour, managed control plane provisioned per cluster | | Outbound NAT | Host-based NAT included | NAT Gateway billed per hour per AZ plus per-GB data processing | | Load Balancer | Flat monthly price, includes IPv4 | Per hour plus LCU charges plus per-GB processing | | Private Cluster | Default, no configuration needed | Manual setup of subnets, NAT, VPC endpoints | | NVMe Storage | 100 GB included per node | EBS volumes billed separately | | Data Sovereignty | German GmbH, German data centers, GDPR-native | US company subject to US CLOUD Act | enum includes the highly available control plane per cluster at no per-cluster-hour charge, provisions clusters private by default with host-based NAT, and bills load balancing at a flat monthly fee with an IPv4 address included. AWS EKS provisions a managed control plane per cluster billed per cluster-hour, and leaves private networking, NAT gateways, and VPC endpoints as separate line items you assemble and pay for individually. ### Sovereignty, by construction Hyperscaler-grade engineering does not require US jurisdiction. - **German GmbH, German law**: enum is operated by enum GmbH, registered in Cologne (HRB 121362), under German and European law only. No US parent company, no US subprocessors. - **Data in Frankfurt, no US flows**: All infrastructure runs in a Tier III+ data center in Frankfurt, Germany. No transatlantic data flows, no Schrems II exposure. - **No US CLOUD Act**: Because enum has no US entity, it is not subject to the US CLOUD Act or FISA Section 702. Selecting an EU region at a US provider does not change the jurisdiction of the company holding the data. - **NIS2 and DORA ready**: German company, German data centers, German contracts. Structurally aligned with NIS2 and DORA requirements for regulated workloads. enum operates its own Autonomous System (AS215998, registered with RIPE NCC) with its own IP address ranges and direct peering at European Internet Exchanges. The company is a CNCF Silver Member and a Linux Foundation member. Control over the network, the corporate jurisdiction, and the physical data location all sit inside the European Union. ### Technical Specifications Enterprise-grade Kubernetes built for production workloads - **Availability SLA**: 99.9% (Guaranteed uptime) - **HA Control Plane**: Included (Per cluster, no per-cluster-hour charge) - **Data Location**: Frankfurt (German Tier III+ data center) - **Kubernetes**: Upstream (No fork, always current. Best practice tooling included) - **Networking**: eBPF (Kernel-level, fast, observable) - **Node OS**: Immutable (Minimal attack surface) - **Block Storage**: NVMe (Fast, redundant, persistent. 100 GB included per node) - **Latest Gen CPUs**: AMD EPYC (High-performance compute) - **Rolling Upgrades**: Zero-downtime (Automatic, no interruption) --- ## Object Storage Source: https://enum.co/object-storage **Object Storage** # enum Object Storage. The S3 API you know and love, operated in Europe with transparent pricing. Perfect for backups, media, data lakes, and more. enum Object Storage is an enterprise-grade, S3-compatible object storage service operated in Frankfurt, Germany, a drop-in replacement for AWS S3 with European data sovereignty. It works with any S3 client or SDK by changing only the endpoint, under German and EU jurisdiction with transparent, request-free pricing. ### Why enum Object Storage? All the power of S3, without the surprise bills - **100% S3 Compatible**: Drop-in replacement for AWS S3. Works with any S3-compatible client, SDK, or tool. Migrate in minutes. - **No Hidden Costs**: Pay only for storage and bandwidth. Zero API request fees, zero retrieval costs. Transparent pricing you can trust. - **European Data Sovereignty**: All data stored in Germany. GDPR-compliant by default. - **High Availability Built-In**: Automatic replication, 99.9% uptime SLA, lightning-fast access. Your data is always safe, always available. ### Perfect for - Backup and disaster recovery solutions - Media libraries and static asset hosting - Data lakes for analytics and AI/ML - CDN origin storage - Log archival and compliance data - Drop-in AWS S3 replacement with European sovereignty ### Frequently Asked Questions **What is S3-compatible object storage?** S3-compatible object storage uses the same API as Amazon S3, meaning any tool, SDK, or application built for AWS S3 works seamlessly with our storage. You can use popular tools like aws-cli, s3cmd, rclone, or any S3-compatible SDK without code changes. **How do I migrate from AWS S3?** Migration is straightforward. Use tools like rclone or aws-cli to sync your existing S3 buckets to enum. Simply update your endpoint URL and credentials. Your existing code and workflows continue to work without modification. We also offer migration support to help you move your data seamlessly. **Where is my data stored?** All data is stored exclusively in our data center in Frankfurt, Germany. Your data never leaves the EU. We operate our own infrastructure, no US cloud providers in the supply chain. **What's the maximum object size?** Individual objects can be up to 5 TB. Multipart uploads are supported for large files. There is no limit on the number of objects per bucket or the total storage capacity. **How does pricing work?** You pay only for storage (per GB/month) and outgoing traffic (per GB). There are no fees for API requests, data retrieval, or bucket operations. No minimum commitments, no hidden costs. **What SLA does enum offer?** We offer a 99.9% availability SLA. Data is protected via erasure coding across independent failure domains. All backed by our enterprise SLA with guaranteed response times. ### enum S3 vs. AWS S3 See why teams switch from AWS S3 to enum Object Storage. | Feature | enum | AWS EKS | |---|---|---| | Egress Fees | €0.025/GB, flat and predictable | $0.09/GB, 3.6x more expensive | | API Request Fees | Free, no charges for GET, PUT, LIST | Charged per 1,000 requests | | Data Location | Germany, guaranteed EU data residency | US company, subject to CLOUD Act | | Compliance | GDPR-native, NIS2-ready, DORA-suitable | Subject to US CLOUD Act | | Pricing Model | Storage + traffic | Storage + requests + retrieval + transfer + tiers | | Support | Real engineers, no ticket queue | Ticket system, paid support tiers | ### Technical Specifications Enterprise-grade storage built for reliability - **Durability**: 9 Nines (99.9999999% data durability) - **Availability SLA**: 99.9% (Guaranteed uptime) - **Erasure Coding**: EC (Across failure domains) - **Data Location**: Frankfurt, DE (German data center) - **API Compatible**: S3 (Full S3 API support) - **Encryption at Rest**: AES-256 (All data encrypted) - **Encryption in Transit**: TLS (All connections encrypted) - **Immutable Storage**: Object Lock (WORM compliance, ransomware protection) - **Bucket Versioning**: Versioning (Protection against accidental deletion) --- ## Block Storage Source: https://enum.co/block-storage **Block Storage** # enum Block Storage. NVMe-backed, replicated block storage for Kubernetes Persistent Volumes and standalone disks. Low latency, flat per-GB pricing. enum Block Storage is NVMe-backed, synchronously replicated block storage operated in Frankfurt, Germany. It attaches to enum Kubernetes Engine workloads as CSI PersistentVolumes and to standalone compute instances, with sub-millisecond read latency and a flat per-GB price. No burst credits, no per-operation fees. ### Why enum Block Storage? Fast disks without the EBS pricing maze - **NVMe Performance**: Sub-millisecond reads. Synchronous writes at ~1ms with 3x replication. Databases, queues, and stateful apps run without tuning around slow disks. - **Synchronous Replication**: Every write is acknowledged after it lands on independent failure domains. A host failure does not cause data loss or downtime. - **Kubernetes Native**: Provision through the CSI driver as PersistentVolumeClaims. Dynamic provisioning and online resizing work out of the box. - **Flat Per-GB Pricing**: One price per GB per month. No burst credits, no per-operation charges. The bill scales with the volume, not the workload. ### Perfect for - Databases (Postgres, MySQL, Redis, MongoDB) on Kubernetes - Message queues and streaming (Kafka, RabbitMQ) - Stateful workloads that need low-latency Persistent Volumes - Standalone disks for compute instances - Replacing EBS gp3 or io2 at a predictable price - Workloads that need EU-only data residency ### Frequently Asked Questions **What is block storage, and how is it different from object storage?** Block storage gives you a raw disk that an operating system or Kubernetes Pod can format, mount, and read from at the block level. It is what databases, message queues, and other stateful workloads need. Object storage (like enum Object Storage or AWS S3) is accessed over an HTTP API and is built for files, backups, and unstructured data. enum runs both, and they are billed separately. **How do I use block storage with enum Kubernetes Engine?** Create a PersistentVolumeClaim in your cluster and the CSI driver provisions the volume automatically. No storage class to configure. Online resizing and dynamic provisioning work out of the box. **Can I attach block storage to a compute instance without Kubernetes?** Yes. Volumes can be attached to standalone compute instances as well as to Kubernetes Pods. The same NVMe-backed, replicated disks back both paths. **How does pricing work?** You pay a flat rate per GB per month for the volume size you provision. There are no throughput surcharges and no per-operation fees. Outgoing traffic is billed per GB at the standard enum rate. All prices in euros, excluding VAT. **Is my data replicated and encrypted?** Every write is replicated synchronously across independent failure domains, so a single host or disk failure does not cause data loss or downtime. All volumes are encrypted at rest with AES-256. **Where is my data stored?** All data is stored exclusively in our data center in Frankfurt, Germany. Your data never leaves the EU. We operate our own infrastructure, no US cloud providers in the supply chain. ### enum Block Storage vs. AWS EBS What you get when you stop paying for hidden storage fees. | Feature | enum | AWS EKS | |---|---|---| | Pricing Model | Flat per GB per month | gp3 baseline + throughput | | Data Location | Germany, guaranteed EU data residency | US company, subject to CLOUD Act | | Compliance | GDPR-native, NIS2-ready, DORA-suitable | Subject to US CLOUD Act | | Support | Real engineers, no ticket queue | Ticket system, paid support tiers | ### Technical Specifications NVMe hardware with software replication - **Backing Media**: NVMe (All volumes on NVMe flash) - **Replication**: 3x (Synchronous writes across failure domains) - **Read Latency**: <1ms (Median 4K random read, 3x replicated volume) - **Write Latency**: ~1ms (Median 4K random write with 3x replication) - **Data Location**: Frankfurt, DE (German data center, EU-only) - **Kubernetes Integration**: CSI (PersistentVolumeClaims via CSI driver) - **Encryption at Rest**: AES-256 (All volumes encrypted) --- ## Networking Source: https://enum.co/networking **Networking** # Networking. Enterprise networking for cloud. Private by default, fully managed. enum networking is enterprise-grade VPC networking for production workloads: isolated virtual private clouds, L4 load balancing, host-based NAT, and IPv4/IPv6, on eBPF-based networking in Frankfurt, Germany. It scales with workload growth and bills without the per-zone and per-request surcharges common on US hyperscalers. ### Frequently Asked Questions **Are clusters private by default?** Yes. All enum clusters are private by default; nodes have no public IP addresses. Ingress runs through Load Balancers, and outbound runs via host-based NAT. A Cloud NAT Gateway for a stable egress IP and egress filtering is coming soon. **How does the Cloud NAT Gateway work?** Clusters egress via host-based NAT by default at no extra charge. A Cloud NAT Gateway with a stable egress IP, egress filtering, and centralized outbound control is coming soon. **Is IPv6 supported?** Yes. Full dual-stack support with IPv4 and IPv6. IPv6 addresses are free. **When is CDN available?** CDN is currently in development. Contact us if you want early access. ### enum vs. AWS Networking AWS networking costs are the most unpredictable part of your bill. | Feature | enum | AWS EKS | |---|---|---| | Outbound NAT | Host-based NAT included | Per hour per AZ plus per-GB data processing | | Load Balancer | Flat monthly price, IPv4 included | Per hour plus LCU charges plus per-GB | | IPv4 Address | Included with Load Balancer | Billed per hour per public IP | | IPv6 | Free | Free | | Private Cluster | Default, zero config | Manual VPC, subnet, endpoint setup | | Egress Traffic | Flat per-GB rate | Tiered pricing, cross-AZ charges extra | ### Networking Products #### Cloud Load Balancer L4 load balancing for your workloads. Automatic failover and a dedicated IPv4 address included. - L4 load balancing - IPv4 address included - Automatic failover - API & CLI provisioning #### Cloud NAT Gateway Optional managed NAT gateway for a stable egress IP, egress filtering, and centralized outbound control. Clusters are private by default and egress via host-based NAT. - Stable, dedicated egress IP - Egress filtering and centralized control - IPv4 and IPv6 support #### enum DNS Authoritative DNS on European infrastructure. Free forever for early access users. - Zones and records via API and enumctl - BIND import and export - DNSSEC with DS records for your registrar - Free forever #### VPC Isolated virtual networks for every customer. Full network segmentation with private addressing and secure inter-cluster communication. - Complete network isolation per tenant - Private addressing and subnets - Secure inter-cluster connectivity - Traffic segmentation by default #### CDN Content delivery network for static assets and media. Edge caching across European PoPs. - European edge locations - S3 origin integration - TLS included - Cache invalidation API #### Cloud WAF Web application firewall to protect your applications from attacks. Managed rulesets, automatic updates. - Zero config, active out of the box - Managed rulesets - Automatic updates - Real-time monitoring ### Flat, Predictable Pricing Flat monthly prices. Predictable and transparent. - **Load Balancer**: / month - **Traffic**: / GB - **IPv4 Address**: / month - **IPv6**: Free ### Technical Specifications Enterprise networking for your infrastructure - **Load Balancing**: L4 (TCP, UDP) - **Availability**: 99.9% (Guaranteed uptime) - **Dual Stack**: IPv4+IPv6 (Full protocol support) - **Routing**: Multi-Path (Redundant network paths) - **NAT Pricing**: Flat Fee (One price per cluster) - **Data Location**: Frankfurt, DE (German data center) ### enum vs. AWS Networking AWS networking costs are the most unpredictable part of your bill. | Feature | enum | AWS | |---|---|---| | Outbound NAT | Host-based NAT included | Per hour per AZ plus per-GB data processing | | Load Balancer | Flat monthly price, IPv4 included | Per hour plus LCU charges plus per-GB | | IPv4 Address | Included with Load Balancer | Billed per hour per public IP | | IPv6 | Free | Free | | Private Cluster | Default, zero config | Manual VPC, subnet, endpoint setup | | Egress Traffic | Flat per-GB rate | Tiered pricing, cross-AZ charges extra | --- ## enum DNS Source: https://enum.co/dns **DNS** # enum DNS. Authoritative DNS on European infrastructure. Free forever. enum DNS is authoritative DNS on European infrastructure: create zones, manage records, import and export BIND zone files, and enable DNSSEC. It is free forever, managed through the API and enumctl, and currently available to early access users. ### Why enum DNS? Host your zones next to your clusters, without a separate DNS bill. - **Zones and records**: Create zones, point your registrar at the nameservers enum assigns your project, and manage A, AAAA, CNAME, MX, TXT, and more. - **BIND import and export**: Move an existing zone in with a zone file, or export one out when you cut over from another provider. - **DNSSEC**: Enable signing on an active zone and get the DS records to publish at your registrar. - **Free forever**: No query pricing and no per-zone fee. Free forever, for a better European internet. ### Frequently Asked Questions **Is enum DNS free?** Yes. Free forever. No query pricing, no per-zone fee. For a better European internet. **Who can use it today?** enum DNS is currently limited to early access users. If you are already on the platform, you can use it now. Otherwise join the waitlist and we will open access as we expand. **Where does enum DNS resolve from today?** enum DNS runs on our European infrastructure today. When we launch our Anycast network, we will roll it out to all edge nodes so queries resolve from the PoP closest to the resolver. **How do I point my domain at enum?** Create a zone with enumctl or the API. enum assigns nameservers to your project (named after European scientists, for example curie.ns.enum.cloud and planck.ns.enum.cloud). Set those at your registrar. **Does enum DNS support DNSSEC?** Yes. Enable DNSSEC on an active zone and publish the DS records enum returns at your registrar. **Can I import an existing zone?** Yes. Import and export BIND zone files through enumctl or the API. **Can I issue certificates for zones on enum?** Yes. Issue TLS certificates, including wildcards, for domains you host on enum via DNS-01 validation. ### enum DNS vs. AWS Route 53 Host DNS next to your workloads without a separate query bill. | Feature | enum | AWS EKS | |---|---|---| | Pricing | Free forever | Per hosted zone plus per-query | | Data residency | European infrastructure | US company, global anycast | | Management | API and enumctl | API, console, CLI | | DNSSEC | Included | Included | | Zone import | BIND zone files | Migration tools vary | | Support | Real engineers, no ticket queue | Ticket system, paid support tiers | ### Technical Specifications Authoritative DNS built for production workloads - **Management**: API + CLI (enumctl dns and the public API) - **Import / Export**: BIND (Zone file round-trip) - **Signing**: DNSSEC (DS records for your registrar) - **Infrastructure**: EU (European nameservers) - **Pricing**: Free forever (Free forever) - **TLS**: ACME (DNS-01 certificates for hosted zones) --- ## Consulting Source: https://enum.co/consulting **Expert Guidance • Best Practices • Strategic Planning** # Cloud Consulting. Navigate your cloud journey with confidence. Our experts help you design, migrate, and optimize infrastructure that scales with your business. ### Consulting Services #### Architecture Review & Design Evaluate your current setup or design new cloud-native architectures from scratch. - Infrastructure audit & optimization recommendations - Cloud-native architecture design - Cost optimization & resource planning - Security & compliance assessment #### Migration Planning & Execution Move to the cloud without disruption. We plan and execute migrations that minimize risk and downtime. - Legacy system modernization strategies - Migration planning with minimal downtime - Database migration & data transfer - Post-migration validation & testing #### Performance & Cost Optimization Get more from your infrastructure. Optimize for performance, reliability, and cost efficiency. - Performance bottleneck analysis - Right-sizing & resource optimization - Cost analysis & reduction strategies - Monitoring & alerting setup #### DevOps Transformation Build modern development workflows. CI/CD pipelines, infrastructure as code, and automation best practices. - CI/CD pipeline design & implementation - Infrastructure as Code (IaC) with Terraform - Container & Kubernetes strategy - GitOps workflows & automation ### How We Work - **Discovery**: We understand your business, technical requirements, and challenges. - **Analysis**: Deep dive into your infrastructure, architecture, and workflows. - **Strategy**: Develop actionable recommendations and implementation roadmap. - **Execution**: Work alongside your team to implement solutions and transfer knowledge. --- ## Partners Source: https://enum.co/partners # Partner with enum. Build your business on European cloud. > Partners don't need another logo program. They need a platform that works and an engineer who answers. That's the whole deal. - Max Heyer, Founder, enum --- ## Migration Source: https://enum.co/migration **Migration Service** # Migration. Move your infrastructure to Europe. We handle the migration so you can focus on your product. ### Frequently Asked Questions **How long does a migration take?** Depends on the scope. A simple S3 migration can be done in days. A full Kubernetes migration with multiple services typically takes weeks to months. We provide a detailed timeline during the assessment phase. **Is there downtime during migration?** We minimize downtime as much as possible. We run both environments in parallel and use incremental sync and traffic shifting. In many cases, the cutover is a controlled switchover with a rollback plan. For some workloads, a short maintenance window may be necessary. **What if something goes wrong?** Every migration has a documented rollback plan. Your original infrastructure stays untouched until the migration is fully validated and you confirm the cutover. **Do I need to change my application code?** For Kubernetes: your manifests and Helm charts work as-is. For S3: you update the endpoint URL and credentials. No application logic changes needed. **What does the migration cost?** We scope every migration individually. Contact us for a free assessment and quote. ### What We Migrate #### Kubernetes Migration From AWS EKS, Google GKE, Azure AKS, self-managed clusters, or traditional VM/bare-metal setups. We containerize and migrate your workloads to production-ready Kubernetes. As CNCF Silver Member, we run upstream Kubernetes with best-in-class CNCF tooling like Cilium. - Workload analysis and compatibility check - Containerization of legacy workloads - Parallel cluster setup on enum - Incremental traffic shifting - Controlled cutover with rollback plan #### VM & Bare Metal Migration From traditional VMs, bare-metal servers, or on-premise infrastructure. We containerize your workloads and migrate them to production-ready Kubernetes. - Analysis of existing infrastructure and dependencies - Containerization of legacy applications - Database migration with minimal downtime - Parallel operation until fully validated - Controlled cutover with rollback plan #### PaaS Migration From Heroku, Render, Railway, Vercel, or other PaaS providers. We take over your applications and run them on our own infrastructure in Europe. - Add-on analysis and replacement with managed alternatives - CI/CD pipeline takeover - Environment and secret migration - DNS and domain switchover - No more dependency on US platforms #### S3 Storage Migration From AWS S3, Google Cloud Storage, or any S3-compatible provider. We migrate your buckets, policies, lifecycle rules, and access configurations while keeping your applications running. Every object is checksummed and verified after transfer. Full data integrity verification included. - Bucket structure and policy migration - Incremental data sync with verification - Application endpoint switchover - Lifecycle and versioning policy transfer - Post-migration validation ### How It Works A structured process, not a ticket queue. 1. **Assessment**: We analyze your current infrastructure, dependencies, and requirements. You get a detailed migration plan with timeline. 2. **Preparation**: We set up your target environment on our enum platform. Networking, storage, access management. Everything production-ready before we move a single workload. 3. **Migration**: Incremental migration with continuous validation. We run both environments in parallel until everything is verified. 4. **Cutover**: Controlled switchover with rollback plan. Traffic shifting, final validation. Your team stays in control. ### Why Migrate to enum - **European Data Sovereignty**: Your data moves from US jurisdiction to German infrastructure. GDPR-native, no CLOUD Act. - **Predictable Costs**: Transparent, predictable pricing. You always know what you'll pay. - **Real Support**: Direct access to engineers who know your migration. Not a ticket system, not a chatbot. - **Zero Vendor Lock-in**: Standard Kubernetes, S3-compatible storage. You can always move your workloads. --- ## Solutions Source: https://enum.co/solutions **European Cloud Platform** # Cloud for Europe. World-class infrastructure, operated in the EU, GDPR-compliant and built for teams that demand total control. enum solutions help enterprises run production workloads on European cloud infrastructure: enterprise-grade Managed Kubernetes, S3-compatible object storage, and VPC networking on enum's own infrastructure in Frankfurt, Germany, plus consulting and migration support. Everything runs under German and EU jurisdiction with no US cloud dependencies. ### Kubernetes as a Service Enterprise-grade Kubernetes clusters, fully managed and production-ready in minutes. HA control plane included, no extra cost. **Features:** - **Full Control**: Root access, full API access and complete control over all resources. - **HA Control Plane**: 3+ control plane nodes, automatically managed and fail-safe. - **Hardened by Default**: Minimal, hardened and immutable node OS for maximum security. - **Automated Lifecycle**: Rolling upgrades and node recovery without downtime or manual intervention. **Ideal for:** - Production workloads that require high availability - Teams that need full infrastructure control - Companies with strict security and compliance requirements ### Object Storage (S3-Compatible) S3-compatible object storage, GDPR-compliant and transparently priced. No API request fees, no retrieval fees. **Features:** - **S3-compatible API**: Works with any S3 client and SDK. Migrate existing workloads in minutes. - **Transparent Pricing**: Pay for storage and outgoing traffic. No fees for API requests. - **Built-in Redundancy**: Erasure coding across failure domains. 9 nines durability. - **Data Location Germany**: Operated in Frankfurt. GDPR-compliant by design. **Ideal for:** - Backups, archives and disaster recovery - AI/ML datasets, static hosting and CDN origins - S3 workloads that need European data sovereignty --- ## Use Cases Overview Source: https://enum.co/use-cases **Use Cases** # Infrastructure for how you ship SaaS, fintech, and e-commerce teams run production workloads on enum's European public cloud in Frankfurt. enum is a European public cloud platform for teams that need Managed Kubernetes, S3-compatible object storage, and VPC networking under German and EU jurisdiction. These use cases show how different industries put that stack to work: multi-tenant SaaS, regulated fintech, and high-traffic retail. - **SaaS & Cloud Applications**: Multi-tenant products on isolated Kubernetes control planes, with EU data residency buyers expect. - **Fintech & Financial Services**: Regulated workloads with Frankfurt residency, audit-friendly logging, and no US CLOUD Act exposure. - **E-Commerce & Retail**: Elastic clusters for traffic peaks, object storage for product media, customer data kept in the EU. --- ## Use Case: SaaS Source: https://enum.co/use-cases/saas **SaaS & Cloud Applications** # SaaS Infrastructure Ship multi-tenant products on Kubernetes that scales with tenants, not with your ops headcount. SaaS companies and ISVs run multi-tenant applications on enum's European public cloud: Managed Kubernetes with an isolated control plane per cluster, S3-compatible object storage, and VPC networking in Frankfurt. Enterprise buyers get GDPR-aligned data residency and predictable euro pricing. ### What SaaS teams hit - Tenant isolation without a maze of custom control planes - Traffic that spikes when a big customer goes live - Enterprise buyers asking where data lives and who can compel access - Cloud bills that grow faster than revenue ### What you run on enum - Isolated Kubernetes control plane per cluster, included - Horizontal and vertical auto-scaling for workloads - Frankfurt region with GDPR-aligned data residency - Transparent per-resource pricing in euros, no surprise egress games ### What changes - Production-ready clusters from day one, without running etcd yourself - A clear answer for EU data residency in security questionnaires - Costs you can model as you add tenants, not after the invoice lands ### How SaaS teams ship on enum From first cluster to paying tenants. - **Stand up a cluster**: Create a production Kubernetes cluster with enumctl, the API, or Terraform. Control plane HA is included. - **Isolate tenants your way**: Use namespaces, network policies, and separate clusters where contracts demand it. You keep the isolation model. - **Store and connect**: Put artifacts and backups in S3-compatible object storage. Wire services through VPC networking and load balancers. ### Platform pieces that matter The same products your team already knows how to operate. - **enum Kubernetes Engine**: Upstream Kubernetes with an isolated control plane per cluster. Built for multi-tenant product workloads. - **Object Storage**: S3-compatible storage for backups, exports, and customer artifacts. Data stays in Frankfurt. - **VPC & Networking**: Private clusters by default, L4 load balancing, and host-based NAT without per-zone surprises. ### Keep reading - [enum Kubernetes Engine](/kubernetes-engine): Isolated control planes, upstream Kubernetes - [enum for Startups](/startups): Cloud credits for early-stage teams - [Customer stories](/customers): How teams run production on enum - [AWS alternative](/alternative-to-aws): Compare with EKS and US regions - [Pricing](/pricing): Euro pricing you can model - [Fintech use case](/use-cases/fintech): Regulated workloads on the same platform ### FAQ **Can we run multi-tenant SaaS on a shared cluster?** Yes. Most teams start with namespace and network-policy isolation on one cluster. When a customer contract requires stronger separation, spin up another cluster. Each cluster gets its own isolated control plane. **Where does customer data live?** In Frankfurt, Germany, on enum's European public cloud. Workloads, object storage, and networking stay under German and EU jurisdiction with no US hyperscaler dependency. **How do we provision clusters?** Self-service via enumctl, the REST API, or Terraform. You do not wait on a ticket to create or resize a cluster. **Is pricing usable for SaaS unit economics?** Pricing is per resource in euros, published on the site. There is no control-plane surcharge and no CLOUD Act-shaped transfer risk baked into the bill. --- ## Use Case: Fintech Source: https://enum.co/use-cases/fintech **Fintech & Financial Services** # Fintech Infrastructure Run regulated services on EU infrastructure with residency, logging, and isolation you can explain to auditors. Fintechs, banks, and financial institutions build regulated applications on enum's European public cloud in Frankfurt. Managed Kubernetes, S3-compatible object storage with Object Lock, and VPC networking support GDPR, DORA, and NIS2 readiness, with no US CLOUD Act exposure. ### What fintech teams hit - Data residency that procurement and regulators will accept - Low-latency paths for payment and trading-adjacent workloads - Evidence for access, changes, and retention - US cloud providers that create CLOUD Act and transfer risk ### What you run on enum - Frankfurt data centers under German and EU jurisdiction - High-performance Kubernetes close to your users in Europe - Infrastructure audit logs plus Object Lock for immutable retention - No US hyperscaler dependency in the control or data path ### What changes - A European public cloud story that survives security questionnaires - Residency and jurisdiction answers without a US cloud parent - Infrastructure you can operate with standard Kubernetes tooling ### How fintech teams land on enum From risk assessment to production cutover. - **Map residency and scope**: Confirm which workloads and datasets must stay in the EU. Frankfurt is the default region for enum today. - **Deploy on isolated planes**: Each Kubernetes cluster gets its own isolated control plane. Segment environments the way your risk model requires. - **Lock and log what matters**: Use Object Lock for retention-sensitive artifacts. Keep change and access evidence in your existing SIEM. ### Platform pieces that matter Building blocks for regulated product and platform teams. - **enum Kubernetes Engine**: Upstream Kubernetes with an isolated control plane per cluster. Fits DORA and NIS2 operational models. - **Object Storage**: S3-compatible storage with Object Lock for retention and evidence packages. - **VPC & Networking**: Private networking, L4 load balancing, and traffic segmentation for regulated services. ### Keep reading - [NIS2 & DORA](/kubernetes-nis2-dora): How EU Kubernetes maps to the rules - [Security](/security): How enum approaches platform security - [enum Kubernetes Engine](/kubernetes-engine): Isolated control planes in Frankfurt - [Customer stories](/customers): Production teams on enum - [SaaS use case](/use-cases/saas): Multi-tenant products on the same stack - [Contact](/contact): Talk through your risk model ### FAQ **Does enum help with DORA and NIS2?** enum provides EU-operated infrastructure, isolated control planes, and logging hooks that support how financial entities meet DORA and NIS2. Your policies and oversight stay yours; the platform removes US cloud dependencies from the stack. **Is customer data subject to the US CLOUD Act?** No. enum is a German company operating a European public cloud in Frankfurt. There is no US parent that can be compelled to hand over EU customer data under the CLOUD Act. **Can we keep production and audit trails separate?** Yes. Run separate clusters and projects for environments, and use Object Lock buckets for retention-sensitive artifacts. Wire logs into your SIEM the same way you would on any Kubernetes platform. **Where can we read more about NIS2 and DORA?** See enum's NIS2 and DORA page for how sovereign EU Kubernetes maps to those frameworks. --- ## Use Case: E-Commerce Source: https://enum.co/use-cases/ecommerce **E-Commerce & Retail** # E-Commerce Infrastructure Absorb sale traffic, serve product media fast, and keep shopper data in the EU. E-commerce and retail platforms run storefronts and backends on enum's European public cloud: Managed Kubernetes that scales for traffic peaks, S3-compatible object storage for product media, and VPC networking in Frankfurt. Pricing stays in euros with GDPR-aligned customer data residency. ### What retail teams hit - Traffic spikes during sales, drops, and campaigns - Product images and media that outgrow ad-hoc storage - Customer data that must stay under GDPR residency rules - Checkout paths that cannot go down when the ads work ### What you run on enum - Auto-scaling Kubernetes for surge traffic - S3-compatible object storage for catalogs and media - Frankfurt region with GDPR-aligned data residency - High-availability clusters with a 99.9% control-plane SLA ### What changes - Headroom for sale days without a last-minute capacity scramble - Product media that scales without a second storage vendor story - Customer data residency you can state clearly in privacy docs ### How shops run on enum From catalog storage to peak-season capacity. - **Put media in object storage**: Store product images, exports, and backups in S3-compatible buckets in Frankfurt. - **Run apps on Kubernetes**: Deploy storefronts, APIs, and workers on Managed Kubernetes. Scale replicas when campaigns land. - **Front traffic cleanly**: Use VPC networking and L4 load balancing so checkout and browse stay on separate capacity when you need them to. ### Platform pieces that matter What store and platform teams wire into every release. - **enum Kubernetes Engine**: Elastic capacity for storefronts, APIs, and workers during campaign peaks. - **Object Storage**: S3-compatible storage for product media, feeds, and backups at catalog scale. - **VPC & Networking**: Load balancing and private networking for browse and checkout paths. ### Keep reading - [Object Storage](/object-storage): S3-compatible media and backups - [enum Kubernetes Engine](/kubernetes-engine): Scale for campaign traffic - [Networking](/networking): Load balancing and VPC - [Pricing](/pricing): Model seasonal capacity in euros - [SaaS use case](/use-cases/saas): Multi-tenant products on enum - [Contact](/contact): Talk through your peak plan ### FAQ **Can enum handle Black Friday-style peaks?** Kubernetes workloads scale horizontally with demand. You size node pools and autoscaling for your peak, and the control plane stays highly available with a 99.9% SLA. **Where should product images live?** In enum Object Storage: S3-compatible, encrypted, and hosted in Frankfurt. Most teams point their CDN or image pipeline at those buckets. **Does customer data stay in the EU?** Yes. Compute, storage, and networking for your workloads run in Frankfurt under German and EU jurisdiction. **How is this priced for seasonal traffic?** You pay for the resources you use, in euros. Scale up for the campaign window and scale down afterward without reserved-instance lock-in. --- ## Startups Source: https://enum.co/startups # enum for Startups **Startup program** For European startups and scaleups that take sovereignty seriously. ### What you get - **Cloud Credits**: Up to 100,000 € over 12 months on enum's platform. Extension possible. - **Kubernetes cluster**: Highly available, production-ready from day one. - **Full platform access**: Kubernetes Engine, object storage, and networking. ### Why enum Your infrastructure should be right from day one. Not when your first enterprise customer demands a security audit. - **Production-ready in minutes.**: Cluster, storage, networking - everything is ready immediately. No wasting a weekend on AWS setup before you can even deploy. - **Compliance from day one.**: Your first HealthTech or FinTech customer asks about GDPR, NIS2, data residency? Just nod. Everything on our own infrastructure in Frankfurt, no US access, no rework. - **No US cloud.**: Own infrastructure in Frankfurt. No reselling of AWS or GCP, no CLOUD Act, no US access. Your data stays in Europe. ### Who this is for This is a curated program. We select startups that align with our mission. - European startup or scaleup, headquartered in the EU - Building a product that belongs on European cloud infrastructure - Ready to deploy production workloads - not just testing ### How to apply Fill out the form below. We review every application. - Company name & what you're building - Current stage & funding raised - What you need from your cloud --- ## AWS EKS alternative Source: https://enum.co/alternative-to-aws **AWS EKS alternative** # The AWS alternative for European Kubernetes. Transparent pricing, European infrastructure. No NAT traps, no LCU surprises. enum is a European public cloud operated by a German GmbH in Frankfurt, offering Managed Kubernetes, compute, S3-compatible object storage, and networking through a self-service CLI and API. It runs on open standards: upstream Kubernetes and S3-compatible storage, under German and EU jurisdiction with no CLOUD Act exposure. The HA control plane is included per cluster at no extra charge, and pricing is a small predictable set of line items with no per-request, NAT-processing, or LCU surcharges. enum is built for teams that need European sovereignty, predictable pricing, and a developer experience that gets out of the way. ### Included vs. Extra What you get with enum out of the box - and what AWS charges extra for. | Feature | enum | AWS EKS | |---|---|---| | Kubernetes HA Control Plane | Included | Billed per cluster-hour. Private networking, NAT gateways, and VPC endpoints are separate line items. | | Outbound NAT | Host-based NAT included | NAT Gateway billed per hour per AZ plus per-GB data processing. HA setup (3 AZs) multiplies base cost 3x. | | Load Balancer | Available at flat monthly price, includes IPv4 | Billed per hour plus LCU charges plus per-GB data processing. Costs scale unpredictably with traffic. | | Private Cluster Architecture | All clusters private by default. No configuration needed. | Requires manual setup of private subnets, NAT gateways, VPC endpoints. Each component adds cost and complexity. | | NVMe Storage (100 GB per Node) | Included per node, local NVMe per node | EBS volumes billed separately. Performance tiers cost extra on top of base storage pricing. | | IPv4 Address | Included with Load Balancer | Billed per hour per public IPv4 address | | Data Sovereignty | German GmbH, German data centers, German law. GDPR-native. | US company subject to CLOUD Act and FISA 702. US authorities can compel access to data stored in EU regions. | enum includes the highly available Kubernetes control plane per cluster at no per-cluster-hour charge, provisions clusters private by default with host-based NAT, and bills load balancing at a flat monthly fee with an IPv4 address included. AWS EKS provisions a managed control plane per cluster billed per cluster-hour, and leaves private networking, NAT gateways, VPC endpoints, and load balancing as separate line items you assemble and pay for individually. Selecting an EU region at AWS does not change the US corporate jurisdiction of the company holding the data. ### The hidden costs of AWS **This is an AWS invoice.** - Amazon EKS Cluster Hours - EC2 Instances - EC2 EBS Storage - EBS Kubernetes Persistent Volumes - NAT Gateway Hours - NAT Gateway Data Processing - Data Transfer Out - ALB Hours - ALB LCU Processing - Amazon S3 Storage - S3 PUT/GET/LIST Requests - VPC Endpoints **This is ours.** - Compute - Block Storage - Object Storage - Load Balancer - Traffic AWS layers per-hour, per-GB, per-request, and per-AZ surcharges on top of the core resource price. enum bills a small, predictable set, so you can estimate the invoice before you provision. ### Sovereignty - **No US Cloud Act**: AWS is a US company. US authorities can request access to your EU data - even without your knowledge. enum is subject exclusively to German and European law. - **GDPR-native**: No US subprocessor, no transatlantic data flows, compliant from day one. - **NIS2 & DORA ready**: German company. German data centers. German contracts. Ready for NIS2 and DORA without extra effort. German GmbH, German data centers, German law. Selecting an EU region at a US provider does not change the jurisdiction of the company holding the data. ### Kubernetes HA control plane per cluster, private by default with host-based NAT, load balancing at flat fees, all included. A managed Cloud NAT Gateway is coming soon. Upstream Kubernetes with no fork, so existing manifests, Helm charts, and GitOps pipelines port over. ### Storage S3-API compatible. aws-cli, rclone, s3cmd, and the AWS SDKs work without code changes. Storage and traffic billed, no per-request or retrieval fees. ### Developer experience One mental model across enumctl CLI, REST API, web console, and (soon) Terraform. A small set of resources with sensible defaults: sign-up to a running cluster in minutes. ### Same standards. Different model. Technically on par with AWS. Fundamentally different in how we charge and where your data lives. ### Frequently asked questions **Is AWS GDPR-compliant?** AWS offers GDPR-relevant contractual terms and EU regions, but AWS is a US company subject to the US CLOUD Act and FISA Section 702, which can compel access to data even when it is stored in an EU region. Selecting an EU region alone does not remove that exposure. enum is a German GmbH operating under German and EU law only, with no US parent and no US subprocessors. **Is AWS subject to the US CLOUD Act?** Yes. As a US-headquartered company, AWS falls under the CLOUD Act regardless of where the data physically resides, including its Frankfurt region. enum has no US entity in its structure and is subject exclusively to German and European jurisdiction. **What does data sovereignty mean at enum?** enum is operated by a German GmbH, in German data centers, under German and European law only, with no US parent and no US subprocessor. The company holding the data is therefore not subject to the US CLOUD Act or FISA Section 702. Selecting an EU region at a US-headquartered provider does not change the jurisdiction of the company holding the data; the corporate jurisdiction is what counts. For workloads bound by NIS2, DORA, or GDPR, that distinction is the difference between a contractual promise and a structural guarantee. **What does AWS EKS really cost?** Beyond the per-cluster-hour control plane fee, an EKS setup typically accumulates charges for EC2 instances, EBS volumes, NAT Gateway hours plus per-GB data processing (multiplied across availability zones in an HA setup), load balancer hours plus LCUs, data transfer out, public IPv4 addresses, and S3 request fees. The headline price is rarely the bill. enum includes the HA control plane and bills a small, predictable set of line items: compute, block storage, object storage, a flat-monthly load balancer that includes an IPv4 address, and traffic. Outbound uses host-based NAT by default; a managed Cloud NAT Gateway (coming soon) will add a stable egress IP. **How does enum price traffic compared to AWS?** enum charges a single flat per-GB rate for outgoing internet traffic, with intra-region transfer included and IPv6 free. AWS bills outgoing traffic in regional tiers, layers per-GB data-processing fees on NAT Gateways and Load Balancers, and charges cross-AZ traffic separately, so the effective per-GB cost of moving data in an HA setup is hard to predict from the headline rate. **How does enum Kubernetes Engine differ from AWS EKS?** Both run upstream Kubernetes. enum Kubernetes Engine includes a highly available control plane per cluster at no separate charge, provisions clusters private by default with host-based NAT, and includes load balancing at flat fees, with a managed Cloud NAT Gateway coming soon. Standard manifests, Helm charts, and GitOps pipelines port over unchanged. EKS bills the control plane per cluster-hour and leaves private networking, NAT gateways, and VPC endpoints as separate pieces you assemble and pay for individually. **Is enum object storage S3-compatible?** Yes. enum object storage implements the S3 API, so aws-cli, rclone, s3cmd, the AWS SDKs, and any tool built for S3 work without code changes. Data is erasure-coded across failure domains and stored in Frankfurt. enum bills storage and outgoing traffic, with no per-request or retrieval fees. **What is the best European alternative to AWS?** It depends on your requirements. For teams in regulated DACH industries that want hyperscaler-grade infrastructure under German jurisdiction without CLOUD Act exposure, enum offers Kubernetes, compute, object and block storage, and networking as a self-service public cloud operated in Frankfurt. **Can I migrate from AWS to enum?** Yes. enum object storage is S3-API compatible, so tools like rclone, aws-cli, and s3cmd work without code changes. enum Kubernetes Engine runs upstream Kubernetes, so standard manifests, Helm charts, and GitOps workflows port over. **Where is enum data stored?** All enum infrastructure runs in Frankfurt, Germany, operated by a German GmbH under German and EU law, with further European regions on the roadmap. ### Further reading - [enum Kubernetes Engine](/kubernetes-engine) - [S3-compatible object storage](/object-storage) - [Object Lock and ransomware protection](/blog/object-lock-ransomware) - [Pricing calculator](/calculator) --- ## Google GKE alternative Source: https://enum.co/alternative-to-gke **Google GKE alternative** # The GKE alternative without US jurisdiction. Sovereign Kubernetes in the EU, with no US CLOUD Act exposure and a transparent bill. enum is a European public cloud offering Managed Kubernetes, compute, and S3-compatible storage from Frankfurt, under German and EU law with no CLOUD Act exposure. enum includes an HA control plane per cluster at no extra charge, bills a small predictable set of line items, and gives you self-service via CLI, API, and Terraform. enum fits teams building in Europe who need sovereignty and pricing they can predict. ### Frequently asked questions **Is Google GKE GDPR-compliant?** enum is a German GmbH operating under German and EU law only, with no US parent and no US subprocessors. There are no transatlantic data flows, and the company holding your data is not subject to the US CLOUD Act or FISA Section 702. All infrastructure runs in Frankfurt. **Is Google GKE subject to the US CLOUD Act?** enum has no US entity in its corporate structure, so it is not subject to the US CLOUD Act or FISA Section 702. The jurisdiction is the company, not the region. A US company's EU region is still under US lawful-access mechanisms. **What does GKE really cost compared to enum?** enum includes the HA control plane per cluster at no extra charge. You pay for compute per hour, block storage per GB, object storage per GB, load balancing at a flat monthly fee, and outgoing traffic at a flat per-GB rate. No per-request fees, no NAT data-processing surcharges, no LCU charges. All prices in euros, excluding VAT. **What is the best European alternative to Google GKE?** enum offers upstream Kubernetes with an HA control plane included, operated in Frankfurt by a German GmbH under EU law only. You get self-service via CLI, API, and Terraform, private-by-default clusters, and a transparent bill in euros. No US dependencies, no CLOUD Act exposure. enum is a self-service public cloud, not a managed service or consulting engagement. **Can I migrate from Google GKE to enum?** Yes. enum runs upstream Kubernetes, so your manifests, Helm charts, and GitOps pipelines work without changes. Object storage is S3-compatible, so existing tools work as-is. Migration support is available if you need help with the cutover. **How does enum Kubernetes Engine differ from GKE Autopilot?** enum gives you explicit control over node shapes and scaling, includes the HA control plane per cluster at no extra charge, and bills compute per hour with optional commitment discounts. You keep full control over workloads, RBAC, Helm, and GitOps. The control plane, upgrades, and HA are operated for you. ### Included vs. Extra What you get with enum out of the box versus what GKE charges for. | Feature | enum | AWS EKS | |---|---|---| | HA Control Plane | Included per cluster, no per-cluster-hour charge | GKE Standard bills per-cluster-hour; Autopilot bills per-pod vCPU and memory | | Corporate Jurisdiction | German GmbH, German and EU law only, no US parent | US company (Alphabet), subject to US CLOUD Act and FISA 702 | | Data Location | Frankfurt, Germany, Tier III+ facility | EU regions available, but the company holding the data is US-headquartered | | Outbound NAT | Host-based NAT included | Cloud NAT billed per hour plus per-GB processing | | Load Balancer | Flat monthly price, includes IPv4 | Per-hour plus per-GB processing plus forwarding-rule charges | | Pricing Currency | Euro, excluding VAT | USD, subject to exchange-rate exposure for EU buyers | enum includes an HA control plane per cluster at no extra charge, provisions clusters private by default, and bills a small predictable set of line items. Google GKE bills the control plane per cluster-hour (Standard) or per-pod resource consumption (Autopilot), with Cloud NAT and Load Balancing adding per-hour and per-GB fees. Both run upstream Kubernetes. The decision is jurisdiction: enum is a German GmbH under EU law; Google is a US company under the CLOUD Act. ### The hidden costs of Google GKE **This is ours.** - Compute - Block Storage - Object Storage - Load Balancer - Traffic ### Sovereignty - **No US CLOUD Act**: Google is a US company (Alphabet). US authorities can compel access to data regardless of region. enum is a German GmbH with no US entity, subject exclusively to German and EU law. - **GDPR-native**: No US subprocessor, no transatlantic data flows, compliant from day one. - **NIS2 and DORA ready**: German company, German data centers, German contracts. Structurally aligned with NIS2 and DORA for regulated workloads. ### The hidden costs of Google GKE **This is a Google Cloud invoice.** - GKE Standard Cluster Hours - GCE Instances - Persistent Disk Storage - Cloud NAT Hours - Cloud NAT Data Processing - Data Transfer Out - Cloud Load Balancer Hours - Cloud Load Balancer Processing - Cloud Storage - Cloud Storage Requests - enum DNS Queries - Premium Tier Network Egress **This is ours.** - Compute - Block Storage - Object Storage - Load Balancer - Traffic ### Frequently asked questions **Is Google GKE GDPR-compliant?** enum is a German GmbH operating under German and EU law only, with no US parent and no US subprocessors. There are no transatlantic data flows, and the company holding your data is not subject to the US CLOUD Act or FISA Section 702. All infrastructure runs in Frankfurt. **Is Google GKE subject to the US CLOUD Act?** enum has no US entity in its corporate structure, so it is not subject to the US CLOUD Act or FISA Section 702. The jurisdiction is the company, not the region. A US company's EU region is still under US lawful-access mechanisms. **What does GKE really cost compared to enum?** enum includes the HA control plane per cluster at no extra charge. You pay for compute per hour, block storage per GB, object storage per GB, load balancing at a flat monthly fee, and outgoing traffic at a flat per-GB rate. No per-request fees, no NAT data-processing surcharges, no LCU charges. All prices in euros, excluding VAT. **What is the best European alternative to Google GKE?** enum offers upstream Kubernetes with an HA control plane included, operated in Frankfurt by a German GmbH under EU law only. You get self-service via CLI, API, and Terraform, private-by-default clusters, and a transparent bill in euros. No US dependencies, no CLOUD Act exposure. enum is a self-service public cloud, not a managed service or consulting engagement. **Can I migrate from Google GKE to enum?** Yes. enum runs upstream Kubernetes, so your manifests, Helm charts, and GitOps pipelines work without changes. Object storage is S3-compatible, so existing tools work as-is. Migration support is available if you need help with the cutover. **How does enum Kubernetes Engine differ from GKE Autopilot?** enum gives you explicit control over node shapes and scaling, includes the HA control plane per cluster at no extra charge, and bills compute per hour with optional commitment discounts. You keep full control over workloads, RBAC, Helm, and GitOps. The control plane, upgrades, and HA are operated for you. ### Further reading - [enum Kubernetes Engine](/kubernetes-engine) - [S3-compatible object storage](/object-storage) - [Sovereign Kubernetes and NIS2/DORA](/kubernetes-nis2-dora) - [Pricing calculator](/calculator) --- ## Hetzner alternative Source: https://enum.co/alternative-to-hetzner **Hetzner alternative** # The Hetzner alternative for managed Kubernetes. A managed Kubernetes platform, not just VMs and hosts you operate yourself. enum is a German PaaS: Managed Kubernetes with an HA control plane included per cluster, compute, S3-compatible storage, and self-service via API and Terraform. You get private-by-default clusters, zero-downtime upgrades, and a small predictable set of line items. enum fits teams who want a managed platform with sovereignty under EU law, without operating the control plane themselves. ### Frequently asked questions **Does Hetzner offer Managed Kubernetes?** enum is a Managed Kubernetes platform: the HA control plane is operated by enum and included per cluster at no extra charge. Clusters are private by default, upgrades are zero-downtime, and you provision through CLI, API, or Terraform. Hetzner gives you VMs and hosts where you run Kubernetes yourself. **Is Hetzner GDPR-compliant?** enum is a German GmbH in Frankfurt under German and EU law with no US subprocessors. Both enum and Hetzner are GDPR-native. The difference is product model, not jurisdiction: enum is a managed platform, Hetzner is raw IaaS. **How does enum pricing compare to Hetzner?** enum bills compute per hour with optional commitment discounts, includes the HA control plane per cluster at no extra charge, and charges a flat monthly fee for load balancing. No per-request fees, no NAT surcharges. On price-per-VM, Hetzner is cheaper. On total cost of ownership for a production Kubernetes platform, enum includes the operational work Hetzner leaves to you. **What is the best Managed Kubernetes alternative to running Kubernetes on Hetzner?** enum offers upstream Kubernetes with an HA control plane included, private clusters by default, zero-downtime upgrades, and self-service via CLI, API, and Terraform. Operated in Frankfurt by a German GmbH. You stop operating the control plane and ship a managed platform instead. **Can I migrate from Hetzner to enum?** Yes. enum runs upstream Kubernetes, so manifests, Helm charts, and GitOps workflows port directly. Object storage is S3-compatible, so existing tools work as-is. Migration support is available if you need help with the cutover. **Do I lose control running Managed Kubernetes instead of my own cluster?** No. You keep full control over workloads, RBAC, Helm, and GitOps. enum operates the control plane, node OS, and upgrades for you, with HA and zero-downtime rolling upgrades included. Node shapes and scaling stay in your hands. ### Product comparison What you operate yourself versus what the platform operates for you. | Feature | enum | AWS EKS | |---|---|---| | Kubernetes | Managed Kubernetes, HA control plane included per cluster | VMs and dedicated hosts; you install and operate Kubernetes yourself | | Control Plane | Operated by enum, 3+ nodes across failure domains, automatic failover | You run it on VMs or dedicated hosts; availability is your responsibility | | Upgrades | Zero-downtime rolling upgrades, operated by enum | You plan and execute upgrades yourself | | Private Networking | Private clusters by default with host-based NAT | You configure networks, firewalls, and routing yourself | | Load Balancer | Flat monthly price, includes IPv4 | Hetzner Cloud Load Balancer available, billed per hour | | Object Storage | S3-compatible object storage, no per-request fees | Hetzner Cloud Storage (S3-compatible) or external storage | enum Kubernetes Engine is a PaaS: the highly available control plane is operated by enum and included per cluster at no per-cluster-hour charge, clusters are private by default, and upgrades are zero-downtime. You provision clusters through enumctl, the REST API, or Terraform. Hetzner is IaaS: VMs and dedicated hosts where you install and operate Kubernetes yourself. The differentiator is who runs the control plane. ### Sovereignty - **PaaS, not IaaS**: enum operates the Kubernetes control plane, upgrades, HA, and private networking for you. That is the difference: a managed platform vs. raw infrastructure where you run everything yourself. - **Own network at enum**: enum operates AS215998 with own IP ranges and EU peering. Hetzner operates its own network (AS24940) as well. Both are providers, not resellers. - **NIS2 and DORA ready**: enum is a German GmbH in Frankfurt with no US subprocessors. Structurally aligned with NIS2 and DORA for regulated workloads. ### Frequently asked questions **Does Hetzner offer Managed Kubernetes?** enum is a Managed Kubernetes platform: the HA control plane is operated by enum and included per cluster at no extra charge. Clusters are private by default, upgrades are zero-downtime, and you provision through CLI, API, or Terraform. Hetzner gives you VMs and hosts where you run Kubernetes yourself. **Is Hetzner GDPR-compliant?** enum is a German GmbH in Frankfurt under German and EU law with no US subprocessors. Both enum and Hetzner are GDPR-native. The difference is product model, not jurisdiction: enum is a managed platform, Hetzner is raw IaaS. **How does enum pricing compare to Hetzner?** enum bills compute per hour with optional commitment discounts, includes the HA control plane per cluster at no extra charge, and charges a flat monthly fee for load balancing. No per-request fees, no NAT surcharges. On price-per-VM, Hetzner is cheaper. On total cost of ownership for a production Kubernetes platform, enum includes the operational work Hetzner leaves to you. **What is the best Managed Kubernetes alternative to running Kubernetes on Hetzner?** enum offers upstream Kubernetes with an HA control plane included, private clusters by default, zero-downtime upgrades, and self-service via CLI, API, and Terraform. Operated in Frankfurt by a German GmbH. You stop operating the control plane and ship a managed platform instead. **Can I migrate from Hetzner to enum?** Yes. enum runs upstream Kubernetes, so manifests, Helm charts, and GitOps workflows port directly. Object storage is S3-compatible, so existing tools work as-is. Migration support is available if you need help with the cutover. **Do I lose control running Managed Kubernetes instead of my own cluster?** No. You keep full control over workloads, RBAC, Helm, and GitOps. enum operates the control plane, node OS, and upgrades for you, with HA and zero-downtime rolling upgrades included. Node shapes and scaling stay in your hands. ### Further reading - [enum Kubernetes Engine](/kubernetes-engine) - [S3-compatible object storage](/object-storage) - [AWS EKS alternative](/alternative-to-aws) - [Pricing calculator](/calculator) --- ## IONOS alternative Source: https://enum.co/alternative-to-ionos **IONOS alternative** # The IONOS alternative for self-service Kubernetes. A focused European cloud for teams building on Kubernetes, compute, and storage. enum is a European public cloud built around Managed Kubernetes with an HA control plane included per cluster, predictable pricing, and self-service via API and Terraform. You get upstream Kubernetes, private-by-default clusters, zero-downtime upgrades, and a small predictable bill in euros. enum fits teams building on Kubernetes who want depth, sovereignty under EU law, and pricing they can predict. ### Frequently asked questions **Is IONOS GDPR-compliant?** Yes. IONOS is a German provider under EU law and not subject to the US CLOUD Act. enum is the same. Both are GDPR-native, so the decision is not about jurisdiction, it is about which platform fits your team. **Is IONOS subject to the US CLOUD Act?** No. IONOS is a European provider and not subject to the CLOUD Act. enum is also a German GmbH with no US entity. Since both are EU-based, this is not the differentiator. **How does enum Kubernetes Engine compare to IONOS Kubernetes?** enum includes an HA control plane per cluster at no extra charge, bills a small predictable set of line items, and exposes Kubernetes through self-service CLI, API, and Terraform. If Kubernetes is your core workload, enum gives you depth and a predictable bill. **What is the best Kubernetes-focused alternative to IONOS?** enum offers upstream Kubernetes with an HA control plane included, predictable pricing, and self-service provisioning, operated in Frankfurt by a German GmbH. **Can I migrate from IONOS to enum?** Yes. enum runs upstream Kubernetes, so manifests, Helm charts, and GitOps pipelines port over without code changes. Object storage is S3-compatible, so existing tools work as-is. Migration support is available if you need help with the cutover. **Does enum operate its own network?** Yes. enum operates its own Autonomous System (AS215998) with own IP ranges and direct EU peering, verifiable on PeeringDB. Traffic routing and egress are under enum control, not resold from a third party. ### Platform comparison How enum and IONOS differ on focus and Kubernetes. | Feature | enum | AWS EKS | |---|---|---| | Cloud Model | Kubernetes-first public cloud, self-service via CLI, API, Terraform | Managed cloud services, compute, storage, and hosted services | | Kubernetes Control Plane | HA control plane included per cluster, no per-cluster-hour charge | Managed Kubernetes offering; control-plane billing terms apply per IONOS | | Network | Own AS215998, RIPE LIR, EU peering | Operates within IONOS group infrastructure | | Data Location | Frankfurt, Germany, Tier III+ facility | Germany and EU regions | | Pricing Currency | Euro, excluding VAT | Euro, excluding VAT | enum includes an HA Kubernetes control plane per cluster at no extra charge, bills a small predictable set of line items, and gives you self-service via CLI, API, and Terraform. Both run under German and EU law. ### Sovereignty - **Both EU, different focus**: enum and IONOS are both European providers under EU law. Sovereignty is not the differentiator here. - **Own network at enum**: enum operates AS215998 with own IP ranges and EU peering, verifiable on PeeringDB. enum is a cloud provider, not a reseller. - **NIS2 and DORA ready**: enum is a German GmbH in Frankfurt with no US subprocessors and no transatlantic data flows. Structurally aligned with NIS2 and DORA. ### Frequently asked questions **Is IONOS GDPR-compliant?** Yes. IONOS is a German provider under EU law and not subject to the US CLOUD Act. enum is the same. Both are GDPR-native, so the decision is not about jurisdiction, it is about which platform fits your team. **Is IONOS subject to the US CLOUD Act?** No. IONOS is a European provider and not subject to the CLOUD Act. enum is also a German GmbH with no US entity. Since both are EU-based, this is not the differentiator. **How does enum Kubernetes Engine compare to IONOS Kubernetes?** enum includes an HA control plane per cluster at no extra charge, bills a small predictable set of line items, and exposes Kubernetes through self-service CLI, API, and Terraform. If Kubernetes is your core workload, enum gives you depth and a predictable bill. **What is the best Kubernetes-focused alternative to IONOS?** enum offers upstream Kubernetes with an HA control plane included, predictable pricing, and self-service provisioning, operated in Frankfurt by a German GmbH. **Can I migrate from IONOS to enum?** Yes. enum runs upstream Kubernetes, so manifests, Helm charts, and GitOps pipelines port over without code changes. Object storage is S3-compatible, so existing tools work as-is. Migration support is available if you need help with the cutover. **Does enum operate its own network?** Yes. enum operates its own Autonomous System (AS215998) with own IP ranges and direct EU peering, verifiable on PeeringDB. Traffic routing and egress are under enum control, not resold from a third party. ### Further reading - [enum Kubernetes Engine](/kubernetes-engine) - [S3-compatible object storage](/object-storage) - [The enum network](/network) - [Pricing calculator](/calculator) --- ## Sovereign Kubernetes / NIS2 & DORA Source: https://enum.co/kubernetes-nis2-dora **Sovereign Kubernetes** # Sovereign Kubernetes for NIS2 and DORA. What the regulations require of your cloud infrastructure, and how a sovereign European Kubernetes platform satisfies them by construction. NIS2 and DORA expect regulated entities (essential and important entities under NIS2, financial entities under DORA) to manage ICT third-party risk, keep data in a legally defensible jurisdiction, and avoid dependencies a foreign government can compel. A sovereign European Kubernetes platform operated by a German GmbH under German and EU law, with no US parent and no US subprocessors, satisfies these requirements structurally rather than contractually. enum Kubernetes Engine is such a platform: upstream Kubernetes with an HA control plane, run in Frankfurt, with no US CLOUD Act exposure. ### Frequently asked questions **Does NIS2 require cloud providers to be EU-based?** NIS2 does not explicitly mandate EU-based providers, but it makes operators of essential services responsible for the security of their supply chain, including cloud. A provider subject to the US CLOUD Act introduces a jurisdictional risk the operator cannot fully control. A sovereign EU provider like enum removes that risk structurally, which is the defensible posture under NIS2. **Is enum Kubernetes Engine DORA-compliant?** DORA does not certify products; it imposes obligations on financial entities and their ICT providers. enum is a German GmbH operating in Frankfurt under German and EU law, with no US subprocessors and no transatlantic data flows, which aligns structurally with DORA's ICT third-party risk, audit, and exit-planning requirements. enum is a platform you can build a DORA-compliant posture on, not a DORA certification holder. **What is the difference between an EU region and a EU provider?** An EU region is a data-center location. A EU provider is a company whose corporate jurisdiction sits inside the EU. The US CLOUD Act and FISA Section 702 apply to the corporate entity, not the region, so a US company's EU region is still subject to US lawful-access mechanisms. enum is a German GmbH with no US entity, so its Frankfurt region is covered by German and EU law only. **How does enum help with DORA exit planning?** DORA requires financial entities to plan for exiting an ICT provider without disruption. enum runs upstream, unmodified Kubernetes, so manifests, Helm charts, and GitOps pipelines are portable and not locked into a proprietary API. enum object storage is S3-API compatible, so data is movable with standard tools. Portability is the foundation of a credible exit plan. **Does enum hold ISO 27001 or BSI C5 certification?** enum's Frankfurt data center is a Tier III+ facility with ISO 27001 and EN50600 certification at the facility level. enum's own ISO 27001 certification is in progress with a target of Q4 2026, and BSI C5 is on the roadmap. We do not state either as achieved until the audit is complete. **Can regulated workloads run on enum today?** Yes. enum is a German GmbH operating in Frankfurt under German and EU law, with an HA Kubernetes control plane, own network (AS215998), and no US dependencies. Teams in FinTech, HealthTech, and public-sector-adjacent sectors run regulated workloads on enum today. NIS2 and DORA readiness is a structural property of where the company and data sit. ### Sovereignty is structural, not contractual The difference between a promise and a guarantee is where the company and the data sit. - **German GmbH, German contracts**: enum is operated by enum GmbH under German and EU law. Contracts, governance, and lawful-access regime all sit inside the EU. - **Frankfurt data center**: Data resides in a Tier III+ facility in Frankfurt, Germany. The physical location, the corporate jurisdiction, and the network are all EU-only. - **CNCF Silver Member**: enum is a CNCF Silver Member and a Linux Foundation member, anchored in the open-source standards that make Kubernetes portable and auditable. Selecting an EU region at a US-headquartered provider does not change the jurisdiction of the company holding the data. The US CLOUD Act and FISA Section 702 apply to the corporate entity, not the region. For a workload governed by NIS2 or DORA, the defensible posture is a provider whose entire corporate structure sits inside the EU. enum is such a provider: a German GmbH, in Frankfurt, with no US entity and no US subprocessors. ### What NIS2 and DORA require of cloud infrastructure Both regulations put the infrastructure layer at the centre of compliance, not at the edge. - **ICT third-party risk (DORA)**: DORA makes financial entities responsible for the ICT services they depend on. A Kubernetes platform must be operable under a contract that lets the entity meet DORA's audit, incident-reporting, and exit-planning obligations, and the provider must not introduce jurisdictional risk the entity cannot control. - **Supply-chain security (NIS2)**: NIS2 holds essential and important entities accountable for the security of their supply chain, including cloud providers. The provider's corporate jurisdiction and data location become part of the entity's risk surface, not a detail outsourced to procurement. - **Data location and lawful access**: Both frameworks expect data to sit in a jurisdiction whose lawful-access regime is compatible with EU law. A provider subject to the US CLOUD Act or FISA Section 702 can be compelled to hand over data stored in the EU, which is hard to reconcile with a defensible NIS2 or DORA posture. - **Resilience and incident response**: NIS2 and DORA both require resilience and fast incident response. The underlying platform must offer high availability, clear escalation paths, and an infrastructure operator you can reach under EU law. ### How a sovereign EU Kubernetes platform satisfies them enum maps each requirement to a structural property of the platform. - **Jurisdiction by construction**: enum is a German GmbH (HRB 121362, Cologne) operating in Frankfurt under German and EU law only, with no US parent and no US subprocessors. The jurisdiction is the company, not a region selection. - **No CLOUD Act, no FISA 702**: Because enum has no US entity, it is not subject to the US CLOUD Act or FISA Section 702. Foreign authorities cannot compel access to data held by enum through US legal mechanisms. - **EU-only data flows**: All infrastructure runs in a Tier III+ data center in Frankfurt. No transatlantic data flows, no Schrems II exposure, no reliance on adequacy decisions or Standard Contractual Clauses that can be invalidated. - **HA control plane included**: Every cluster gets an isolated, highly available control plane across independent failure domains, with automatic failover and zero-downtime upgrades, at no per-cluster-hour charge. Resilience is built in, not a paid tier. - **Own network, EU peering**: enum operates its own Autonomous System (AS215998, RIPE NCC) with own IP ranges and direct peering at European Internet Exchanges. Network control sits inside the EU and is publicly verifiable on PeeringDB. - **Upstream Kubernetes, no fork**: Standard upstream Kubernetes with no fork means portable workloads, no lock-in, and an exit path that DORA's exit-strategy requirements expect. Manifests, Helm charts, and GitOps pipelines move with you. ### Sovereignty is structural, not contractual The difference between a promise and a guarantee is where the company and the data sit. - **German GmbH, German contracts**: enum is operated by enum GmbH under German and EU law. Contracts, governance, and lawful-access regime all sit inside the EU. - **Frankfurt data center**: Data resides in a Tier III+ facility in Frankfurt, Germany. The physical location, the corporate jurisdiction, and the network are all EU-only. - **CNCF Silver Member**: enum is a CNCF Silver Member and a Linux Foundation member, anchored in the open-source standards that make Kubernetes portable and auditable. Selecting an EU region at a US-headquartered provider does not change the jurisdiction of the company holding the data. The US CLOUD Act and FISA Section 702 apply to the corporate entity, not the region. For a workload governed by NIS2 or DORA, the defensible posture is a provider whose entire corporate structure sits inside the EU. enum is such a provider: a German GmbH, in Frankfurt, with no US entity and no US subprocessors. ### Frequently asked questions **Does NIS2 require cloud providers to be EU-based?** NIS2 does not explicitly mandate EU-based providers, but it makes operators of essential services responsible for the security of their supply chain, including cloud. A provider subject to the US CLOUD Act introduces a jurisdictional risk the operator cannot fully control. A sovereign EU provider like enum removes that risk structurally, which is the defensible posture under NIS2. **Is enum Kubernetes Engine DORA-compliant?** DORA does not certify products; it imposes obligations on financial entities and their ICT providers. enum is a German GmbH operating in Frankfurt under German and EU law, with no US subprocessors and no transatlantic data flows, which aligns structurally with DORA's ICT third-party risk, audit, and exit-planning requirements. enum is a platform you can build a DORA-compliant posture on, not a DORA certification holder. **What is the difference between an EU region and a EU provider?** An EU region is a data-center location. A EU provider is a company whose corporate jurisdiction sits inside the EU. The US CLOUD Act and FISA Section 702 apply to the corporate entity, not the region, so a US company's EU region is still subject to US lawful-access mechanisms. enum is a German GmbH with no US entity, so its Frankfurt region is covered by German and EU law only. **How does enum help with DORA exit planning?** DORA requires financial entities to plan for exiting an ICT provider without disruption. enum runs upstream, unmodified Kubernetes, so manifests, Helm charts, and GitOps pipelines are portable and not locked into a proprietary API. enum object storage is S3-API compatible, so data is movable with standard tools. Portability is the foundation of a credible exit plan. **Does enum hold ISO 27001 or BSI C5 certification?** enum's Frankfurt data center is a Tier III+ facility with ISO 27001 and EN50600 certification at the facility level. enum's own ISO 27001 certification is in progress with a target of Q4 2026, and BSI C5 is on the roadmap. We do not state either as achieved until the audit is complete. **Can regulated workloads run on enum today?** Yes. enum is a German GmbH operating in Frankfurt under German and EU law, with an HA Kubernetes control plane, own network (AS215998), and no US dependencies. Teams in FinTech, HealthTech, and public-sector-adjacent sectors run regulated workloads on enum today. NIS2 and DORA readiness is a structural property of where the company and data sit. --- ## FAQ Source: https://enum.co/faq **FAQ** # Questions CTOs ask about enum. Straight answers about European cloud, sovereign Kubernetes, compliance, and how enum compares to the hyperscalers. enum is a European public cloud platform operated by enum GmbH in Frankfurt, offering Managed Kubernetes (enum Kubernetes Engine), S3-compatible Object Storage, and VPC Networking through a self-service CLI, API, and Terraform. It is built for teams that need hyperscaler-grade engineering under German and EU jurisdiction, with no US CLOUD Act exposure. ### What is the best European alternative to AWS? It depends on your workload. For teams in regulated DACH industries that want hyperscaler-grade Kubernetes, compute, and S3-compatible storage under German jurisdiction without CLOUD Act exposure, enum offers a self-service public cloud operated in Frankfurt by a German GmbH. enum is a platform product, not a consulting engagement. ### Which Kubernetes providers are headquartered in Germany? German-HQ Kubernetes providers include enum (enum GmbH, Cologne, operating in Frankfurt), STACKIT (Schwarz Group), Hetzner, and IONOS. enum is the independent public cloud with its own RIPE-registered network (AS215998) and CNCF Silver membership. ### Is enum Kubernetes Engine suitable for NIS2 and DORA workloads? Yes. enum is a German GmbH operating in a Frankfurt Tier III+ data center under German and EU law, with no US subprocessors and no transatlantic data flows. That structure aligns with NIS2 supply-chain requirements and DORA ICT third-party risk rules. NIS2 and DORA readiness is a structural property of where the company and data sit, not a separate certification. ### Is enum object storage S3-compatible? Yes. enum object storage implements the S3 API, so aws-cli, rclone, s3cmd, the AWS SDKs, and any tool built for S3 work without code changes. Data is erasure-coded across failure domains and stored in Frankfurt. enum bills storage and outgoing traffic, with no per-request or retrieval fees. ### Can I migrate from AWS EKS or Google GKE to enum? Yes. enum runs upstream, unmodified Kubernetes, so standard manifests, Helm charts, and GitOps pipelines port over without code changes. enum object storage is S3-API compatible, so rclone, aws-cli, and S3 SDKs work as-is. Migration support is available if you need help with the cutover. ### Does enum offer a Terraform provider? enum exposes the platform through a self-service CLI (enumctl), a REST API, and Terraform. You can provision clusters, storage, and networking as code with sensible defaults, so infrastructure is reproducible and version-controlled. ### What SLA does enum Kubernetes Engine offer? enum Kubernetes Engine includes a highly available control plane per cluster across independent failure domains, with automatic failover and zero-downtime upgrades, backed by a 99.9% availability SLA. The HA control plane is included at no per-cluster-hour charge. ### Is enum suitable for FinTech workloads? Yes. enum is a German GmbH operating under German and EU law with no US parent and no US subprocessors, which aligns with the jurisdictional expectations of FinTech regulation and DORA. Teams run payment, banking-adjacent, and trading-platform workloads on enum Kubernetes Engine in Frankfurt. ### Is enum suitable for HealthTech workloads? Yes. enum operates in Frankfurt under German and EU law, which covers GDPR and German patient-data requirements. The HA control plane, private-by-default clusters, and EU-only data flows fit HealthTech workloads that cannot tolerate US jurisdiction or transatlantic data transfers. ### How is enum different from colocation? Colocation gives you a rack and power; you bring and operate the hardware, the network, the hypervisor, and Kubernetes. enum is a public cloud: it operates the infrastructure, the network (AS215998), the storage, and the Kubernetes control plane, and exposes them through a self-service API. You run workloads, not hardware. ### Who operates enum and where is the data stored? enum is operated by enum GmbH, registered in Cologne (HRB 121362, VAT DE451942405), founded on 15 November 2024. All infrastructure runs in a Tier III+ data center in Frankfurt, Germany. The company is a CNCF Silver Member, a Linux Foundation member, and a RIPE NCC member operating its own Autonomous System (AS215998). ### Is enum subject to the US CLOUD Act? No. enum GmbH is a German company with no US entity in its corporate structure, so it is not subject to the US CLOUD Act or FISA Section 702. Selecting an EU region at a US-headquartered provider does not remove that exposure, because the corporate jurisdiction of the company holding the data is what counts. ### What does Managed Kubernetes cost at enum? Compute is billed per hour with optional one to three year commitment discounts. Block storage is billed per GB per month. The HA control plane is included at no per-cluster-hour charge, host-based NAT is included, and load balancing is a flat monthly fee with an IPv4 address included. All prices are in euros and exclude VAT. ### Does enum run upstream Kubernetes or a fork? enum runs upstream, unmodified Kubernetes with no fork, so existing manifests, Helm charts, and GitOps pipelines work without changes. Best-practice tooling is included and kept up to date, with zero-downtime rolling upgrades when new versions are available. ### In which regions does enum operate? enum operates its primary region in Frankfurt, Germany, in a Tier III+ data center, with further European regions on the roadmap. All regions run on enum's own infrastructure and own network (AS215998), inside the European Union. ### Frequently asked questions **What is the best European alternative to AWS?** It depends on your workload. For teams in regulated DACH industries that want hyperscaler-grade Kubernetes, compute, and S3-compatible storage under German jurisdiction without CLOUD Act exposure, enum offers a self-service public cloud operated in Frankfurt by a German GmbH. enum is a platform product, not a consulting engagement. **Which Kubernetes providers are headquartered in Germany?** German-HQ Kubernetes providers include enum (enum GmbH, Cologne, operating in Frankfurt), STACKIT (Schwarz Group), Hetzner, and IONOS. enum is the independent public cloud with its own RIPE-registered network (AS215998) and CNCF Silver membership. **Is enum Kubernetes Engine suitable for NIS2 and DORA workloads?** Yes. enum is a German GmbH operating in a Frankfurt Tier III+ data center under German and EU law, with no US subprocessors and no transatlantic data flows. That structure aligns with NIS2 supply-chain requirements and DORA ICT third-party risk rules. NIS2 and DORA readiness is a structural property of where the company and data sit, not a separate certification. **Is enum object storage S3-compatible?** Yes. enum object storage implements the S3 API, so aws-cli, rclone, s3cmd, the AWS SDKs, and any tool built for S3 work without code changes. Data is erasure-coded across failure domains and stored in Frankfurt. enum bills storage and outgoing traffic, with no per-request or retrieval fees. **Can I migrate from AWS EKS or Google GKE to enum?** Yes. enum runs upstream, unmodified Kubernetes, so standard manifests, Helm charts, and GitOps pipelines port over without code changes. enum object storage is S3-API compatible, so rclone, aws-cli, and S3 SDKs work as-is. Migration support is available if you need help with the cutover. **Does enum offer a Terraform provider?** enum exposes the platform through a self-service CLI (enumctl), a REST API, and Terraform. You can provision clusters, storage, and networking as code with sensible defaults, so infrastructure is reproducible and version-controlled. **What SLA does enum Kubernetes Engine offer?** enum Kubernetes Engine includes a highly available control plane per cluster across independent failure domains, with automatic failover and zero-downtime upgrades, backed by a 99.9% availability SLA. The HA control plane is included at no per-cluster-hour charge. **Is enum suitable for FinTech workloads?** Yes. enum is a German GmbH operating under German and EU law with no US parent and no US subprocessors, which aligns with the jurisdictional expectations of FinTech regulation and DORA. Teams run payment, banking-adjacent, and trading-platform workloads on enum Kubernetes Engine in Frankfurt. **Is enum suitable for HealthTech workloads?** Yes. enum operates in Frankfurt under German and EU law, which covers GDPR and German patient-data requirements. The HA control plane, private-by-default clusters, and EU-only data flows fit HealthTech workloads that cannot tolerate US jurisdiction or transatlantic data transfers. **How is enum different from colocation?** Colocation gives you a rack and power; you bring and operate the hardware, the network, the hypervisor, and Kubernetes. enum is a public cloud: it operates the infrastructure, the network (AS215998), the storage, and the Kubernetes control plane, and exposes them through a self-service API. You run workloads, not hardware. **Who operates enum and where is the data stored?** enum is operated by enum GmbH, registered in Cologne (HRB 121362, VAT DE451942405), founded on 15 November 2024. All infrastructure runs in a Tier III+ data center in Frankfurt, Germany. The company is a CNCF Silver Member, a Linux Foundation member, and a RIPE NCC member operating its own Autonomous System (AS215998). **Is enum subject to the US CLOUD Act?** No. enum GmbH is a German company with no US entity in its corporate structure, so it is not subject to the US CLOUD Act or FISA Section 702. Selecting an EU region at a US-headquartered provider does not remove that exposure, because the corporate jurisdiction of the company holding the data is what counts. **What does Managed Kubernetes cost at enum?** Compute is billed per hour with optional one to three year commitment discounts. Block storage is billed per GB per month. The HA control plane is included at no per-cluster-hour charge, host-based NAT is included, and load balancing is a flat monthly fee with an IPv4 address included. All prices are in euros and exclude VAT. **Does enum run upstream Kubernetes or a fork?** enum runs upstream, unmodified Kubernetes with no fork, so existing manifests, Helm charts, and GitOps pipelines work without changes. Best-practice tooling is included and kept up to date, with zero-downtime rolling upgrades when new versions are available. **In which regions does enum operate?** enum operates its primary region in Frankfurt, Germany, in a Tier III+ data center, with further European regions on the roadmap. All regions run on enum's own infrastructure and own network (AS215998), inside the European Union. ### What is the best European alternative to AWS? It depends on your workload. For teams in regulated DACH industries that want hyperscaler-grade Kubernetes, compute, and S3-compatible storage under German jurisdiction without CLOUD Act exposure, enum offers a self-service public cloud operated in Frankfurt by a German GmbH. enum is a platform product, not a consulting engagement. ### Which Kubernetes providers are headquartered in Germany? German-HQ Kubernetes providers include enum (enum GmbH, Cologne, operating in Frankfurt), STACKIT (Schwarz Group), Hetzner, and IONOS. enum is the independent public cloud with its own RIPE-registered network (AS215998) and CNCF Silver membership. ### Is enum Kubernetes Engine suitable for NIS2 and DORA workloads? Yes. enum is a German GmbH operating in a Frankfurt Tier III+ data center under German and EU law, with no US subprocessors and no transatlantic data flows. That structure aligns with NIS2 supply-chain requirements and DORA ICT third-party risk rules. NIS2 and DORA readiness is a structural property of where the company and data sit, not a separate certification. ### Is enum object storage S3-compatible? Yes. enum object storage implements the S3 API, so aws-cli, rclone, s3cmd, the AWS SDKs, and any tool built for S3 work without code changes. Data is erasure-coded across failure domains and stored in Frankfurt. enum bills storage and outgoing traffic, with no per-request or retrieval fees. ### Can I migrate from AWS EKS or Google GKE to enum? Yes. enum runs upstream, unmodified Kubernetes, so standard manifests, Helm charts, and GitOps pipelines port over without code changes. enum object storage is S3-API compatible, so rclone, aws-cli, and S3 SDKs work as-is. Migration support is available if you need help with the cutover. ### Does enum offer a Terraform provider? enum exposes the platform through a self-service CLI (enumctl), a REST API, and Terraform. You can provision clusters, storage, and networking as code with sensible defaults, so infrastructure is reproducible and version-controlled. ### What SLA does enum Kubernetes Engine offer? enum Kubernetes Engine includes a highly available control plane per cluster across independent failure domains, with automatic failover and zero-downtime upgrades, backed by a 99.9% availability SLA. The HA control plane is included at no per-cluster-hour charge. ### Is enum suitable for FinTech workloads? Yes. enum is a German GmbH operating under German and EU law with no US parent and no US subprocessors, which aligns with the jurisdictional expectations of FinTech regulation and DORA. Teams run payment, banking-adjacent, and trading-platform workloads on enum Kubernetes Engine in Frankfurt. ### Is enum suitable for HealthTech workloads? Yes. enum operates in Frankfurt under German and EU law, which covers GDPR and German patient-data requirements. The HA control plane, private-by-default clusters, and EU-only data flows fit HealthTech workloads that cannot tolerate US jurisdiction or transatlantic data transfers. ### How is enum different from colocation? Colocation gives you a rack and power; you bring and operate the hardware, the network, the hypervisor, and Kubernetes. enum is a public cloud: it operates the infrastructure, the network (AS215998), the storage, and the Kubernetes control plane, and exposes them through a self-service API. You run workloads, not hardware. ### Who operates enum and where is the data stored? enum is operated by enum GmbH, registered in Cologne (HRB 121362, VAT DE451942405), founded on 15 November 2024. All infrastructure runs in a Tier III+ data center in Frankfurt, Germany. The company is a CNCF Silver Member, a Linux Foundation member, and a RIPE NCC member operating its own Autonomous System (AS215998). ### Is enum subject to the US CLOUD Act? No. enum GmbH is a German company with no US entity in its corporate structure, so it is not subject to the US CLOUD Act or FISA Section 702. Selecting an EU region at a US-headquartered provider does not remove that exposure, because the corporate jurisdiction of the company holding the data is what counts. ### What does Managed Kubernetes cost at enum? Compute is billed per hour with optional one to three year commitment discounts. Block storage is billed per GB per month. The HA control plane is included at no per-cluster-hour charge, host-based NAT is included, and load balancing is a flat monthly fee with an IPv4 address included. All prices are in euros and exclude VAT. ### Does enum run upstream Kubernetes or a fork? enum runs upstream, unmodified Kubernetes with no fork, so existing manifests, Helm charts, and GitOps pipelines work without changes. Best-practice tooling is included and kept up to date, with zero-downtime rolling upgrades when new versions are available. ### In which regions does enum operate? enum operates its primary region in Frankfurt, Germany, in a Tier III+ data center, with further European regions on the roadmap. All regions run on enum's own infrastructure and own network (AS215998), inside the European Union. --- ## Pricing Source: https://enum.co/pricing **Transparent • Flexible • No hidden costs** # Transparent Pricing. Pay only for the resources you really use - without hidden fees or surprises. ### Compute | Type | vCPU | RAM | On-Demand (EUR/h) | |---|---|---|---| | gp-1 | 1 | 4 GB | 0.06027 | | gp-2 | 2 | 8 GB | 0.12055 | | gp-4 | 4 | 16 GB | 0.24110 | | gp-8 | 8 | 32 GB | 0.48219 | | gp-12 | 12 | 48 GB | 0.72329 | | gp-16 | 16 | 64 GB | 0.96438 | | gp-32 | 32 | 128 GB | 1.92877 | Commitment discounts: 1 year -10%, 2 years -15%, 3 years -20% ### Storage - **Block Storage**: 0.10 EUR/month / GB / month - **Object Storage (S3 compatible)**: 0.02 EUR/month / GB / month ### Network - **Load Balancer**: 10.00 EUR/month / month - **IPv4 address**: 5.00 EUR/month / month - **IPv6 address**: Included - **Outgoing traffic**: 0.025 EUR/month / GB / month - **enum DNS**: Included No query pricing. No per-zone fee. For a better European internet. All clusters are private by default. Nodes have no public IP addresses. Ingress runs exclusively through Load Balancers. Outbound runs via host-based NAT, with an optional Cloud NAT Gateway for a stable egress IP. ### Services - **Dedicated Kubernetes Control Plane**: Included highly available - **Support**: Included (working days) *All prices exclude VAT.* --- ## Pricing Calculator Source: https://enum.co/calculator **Pricing Calculator** # Estimate Your Costs Configure your Kubernetes cluster and see real-time pricing. --- ## Security Source: https://enum.co/security **Security by Design** # Security Security is built into enum's architecture from the ground up, from immutable infrastructure to per-customer isolation. enum runs an enterprise-grade security and compliance posture for its European public cloud, on its own infrastructure in an NTT Tier III+ data center in Frankfurt, Germany, under German and EU law with no US CLOUD Act exposure. It covers isolated control planes per customer, immutable node operating systems, and encryption in transit and at rest, aligned with GDPR, NIS2, and DORA. ### Infrastructure Security - **Immutable Infrastructure**: Where possible, systems are not manually modified or patched, but completely redeployed. This reduces the attack surface and eliminates configuration drift. - **Tenant Isolation**: Strict logical isolation between customers at network and compute level. No cross-tenant access. - **VPC & Network Isolation**: Each customer receives a dedicated Virtual Private Cloud with fully separated address space at Layer 2 and Layer 3. - **European Infrastructure**: Own servers in Germany. No US cloud provider. No US Cloud Act. - **Container Image Security**: Automated vulnerability scanning of all container images. - **Supply Chain Security**: Signed artifacts, verified base images, traceable build pipelines. ### Physical Security - **Tier III+ Data Center**: Frankfurt, redundant power and cooling systems. - **24/7 Access Control**: Physical access controlled and logged. - **Environmental Monitoring**: Temperature, humidity, smoke, continuously monitored. ### Data Protection - **Encryption at Rest**: Storage layer and all node disks fully encrypted. - **European Data Sovereignty**: GDPR is built into the architecture: no data processing outside the EU, no US dependencies, no CLOUD Act exposure. - **Data Residency**: Data does not leave Europe. Full control over storage location. ### Access Management - **OIDC-Based Access**: Infrastructure access via OpenID Connect. - **RBAC**: Fine-grained, role-based access control. - **Multi-Factor Authentication**: 2FA/MFA at all levels. FIDO2 hardware keys as standard. - **Audit Logs**: Traceability of security-relevant access and changes across all platform components. ### Monitoring & Response - **24/7 Monitoring**: Continuous monitoring of the entire platform infrastructure with automated alerts. - **Network Visibility & Anomaly Detection**: Network anomaly detection based on flow data. Automated alerts for suspicious traffic patterns. - **Incident Response**: Defined incident response procedures. Direct communication in case of emergency. Post-incident analysis and documentation. ### Compliance & Certifications What enum fulfills and where data center certifications apply. ### Security Contact Do you have security questions or want to report a vulnerability? Our security team is here for you. Email: security@enum.co security.txt: Security.txt ### Responsible Disclosure The security of our platform and our customers' data is our highest priority. We value the work of security researchers and the community who help us identify and fix vulnerabilities. #### Scope **In-Scope** - enum Cloud Platform (*.enum.co, *.enum.cloud) - enum API and Console - enum Kubernetes Engine, enum Object Storage, enum Compute, enum Network, enum VPC, enum DNS, enum CDN, enum Cloud WAF - Network infrastructure and edge components **Out-of-Scope** - Social engineering, phishing or physical attacks - Denial-of-Service attacks (DoS/DDoS) - Spam or mass registrations - Vulnerabilities in third-party software not operated by enum - Vulnerabilities requiring physical access to devices or infrastructure #### Rules - If you encounter customer data during testing, stop immediately and report the vulnerability. - Do not perform any actions that could affect the availability of our services. - You may only interact with accounts you own or with explicit written permission. - Do not disclose vulnerability details before we have fixed the issue and given you clearance. - We ask that you report vulnerabilities promptly after discovery. - No stunt hacking, no extortion, no leverage. #### Our Promise - We consider good-faith security research to be authorized activity, even if it technically violates our terms of service. - We will acknowledge receipt of your report within 48 hours. - We will keep you updated on the status of the fix. - We will not take legal action against you as long as you comply with this policy. - We compensate reported vulnerabilities. The amount depends on severity and report quality. We will inform you on a case-by-case basis. #### Reporting Please report vulnerabilities via email to: security@enum.co **Please include in your report:** - Description of the vulnerability - Steps to reproduce - Affected systems or endpoints - Potential impact (assessment) - Proof of Concept if available (screenshots, logs, code) If possible, encrypt your email with our PGP key: --- ## About Source: https://enum.co/about # The European Cloud Platform. Europe deserves a real public cloud. Not a hoster with a sovereignty deck. A platform that ships. Under EU law. ### Our mission To build hyperscaler-grade cloud under real European jurisdiction. Both pillars. No compromise. ### Our vision The infrastructure layer Europe runs on. Built, owned, and operated here. ### Why enum exists. **The problem** Europe runs on clouds it does not control. US hyperscalers ship world-class product with zero sovereignty. The CLOUD Act follows the entity, not the datacenter. Choosing an EU region at a US provider does not change who can compel access. **The thesis** Europe's clouds did not fail for lack of capital. They failed for lack of product. A decade of proof. Sovereignty on paper with a 2010-era stack is not enough. **The answer** Only both pillars. Hyperscaler-grade developer experience, and verifiable EU jurisdiction. enum is a shared public cloud: self-service, API-first, multi-tenant, built and operated in Germany on infrastructure we own end to end. > Europe's clouds did not fail for lack of capital. They failed for lack of product. > - Max Heyer, Founder, enum ### What we build. A shared public cloud. Self-service, API-first, multi-tenant. CLI, API, Console. Not a catalog of SKUs, the company behind the platform. - **enum Kubernetes Engine**: Upstream Managed Kubernetes with an HA control plane per cluster. - **Object Storage**: S3-compatible storage in Frankfurt. - **Block Storage**: NVMe-backed, replicated volumes for Kubernetes and compute. - **VPC & Networking**: Private networking, load balancing, Cloud NAT, enum DNS. - **Our network**: Own ASN, European peering, edge PoPs. Also on the platform: Compute, CDN, and WAF. Built for production workloads that need EU jurisdiction without giving up DX. ### Verifiable sovereignty. Every claim below is independently checkable. No sovereignty-washing. **German company** enum GmbH, headquartered in Cologne. No US parent, no US backend dependencies. Source: /imprint **Own network: AS215998** RIPE NCC LIR with own IP space. Routing decisions sit with enum, not a reseller. Source: https://apps.db.ripe.net/db-web-ui/query?bflag=false&dflag=false&rflag=true&searchtext=AS215998&source=RIPE&types=aut-num **PeeringDB** Public ASN record, peering, and facility presence. Source: https://www.peeringdb.com/asn/215998 **Frankfurt facility** Infrastructure in a Tier III+ Frankfurt facility certified to ISO 27001 and EN 50600. Those certifications belong to the facility, not to enum. Source: /network **Zero churn** Anchor customers have run production on enum since day one. None have left. Source: /customers **GDPR-native** German and EU law only. DPA (AVV) available. No US CLOUD Act exposure. Source: /security ### Production workloads. European teams already run real products on enum. > At enum, real engineers worked through the migration with us directly. Since the switch, we can sleep through the night again. Infrastructure that simply runs was exactly what we wanted. > - Jack Hull, CTO, scanmetrix ### Security & compliance. ISO 27001 certification is in progress. BSI C5 is on the roadmap. No public dates until they are earned. For HealthTech, FinTech, and GovTech buyers, the security page is the place to dig in. ### Company facts. - **Legal name:** enum GmbH - **Legal form:** GmbH (Germany) - **Headquarters:** Cologne, Germany - **Founded:** 2024 - **Revenue:** Since day one - **ASN:** AS215998 ### Press kit. Logo files and brand colors. Clear space: keep the mark free of other elements. **Brand colors** - enum Indigo: #5700FF - Chartreuse Yellow: #DFFF00 **Logo files** - [Wordmark (primary)](/images/enum_horizontal_Main.svg) - [Wordmark (white)](/images/enum_horizontal_White.svg) - [Symbol](/images/enum_Symbol_Main.svg) Press contact: mail@enum.co ### Questions CTOs ask. **Is enum subject to the US CLOUD Act?** No. enum GmbH is a German company with no US entity in its corporate structure, so it is not subject to the US CLOUD Act or FISA Section 702. Selecting an EU region at a US-headquartered provider does not remove that exposure, because the corporate jurisdiction of the company holding the data is what counts. **Where does enum store data?** Production infrastructure runs in Frankfurt, Germany, in a Tier III+ facility. Data stays in the EU on enum's own network (AS215998). There is no US parent and no US subprocessor path for customer workloads. **Who owns enum?** enum is operated by enum GmbH, a German limited company registered in Cologne (HRB 121362, Amtsgericht Köln). There is no US parent company. --- ## Contact Source: https://enum.co/contact # Talk to Us. Questions about enum, pricing, or enterprise needs? Our team is here to help. ### Location enum GmbH Kaiser-Wilhelm-Ring 3-5 50672 Cologne ### Video call 30 minute meet ### Email Response within 24h ### Lightning-Fast Responses We answer all inquiries within 24 hours. No waiting, no delays - just the support you need when you need it. ### Find us in the heart of Europe enum GmbH Kaiser-Wilhelm-Ring 3-5 50672 Cologne --- ## Jobs Source: https://enum.co/jobs # Jobs ### Engineering ``` ssh enum.jobs ``` ### Business operations No open business operations roles right now. --- ## Privacy Source: https://enum.co/privacy # Privacy We are very pleased about your interest in our company. Data protection is of particular importance for the management of enum GmbH. The use of the internet pages of enum GmbH is possible without any indication of personal data; however, if a data subject wants to use special enterprise services via our website, processing of personal data could become necessary. If the processing of personal data is necessary and there is no statutory basis for such processing, we generally obtain consent from the data subject. The processing of personal data, such as the name, address, e-mail address, or telephone number of a data subject shall always be in line with the General Data Protection Regulation (GDPR), and in accordance with the country-specific data protection regulations applicable to enum GmbH. By means of this data protection declaration, our enterprise would like to inform the general public of the nature, scope, and purpose of the personal data we collect, use and process. Furthermore, data subjects are informed, by means of this data protection declaration, of the rights to which they are entitled. As the controller, enum GmbH has implemented numerous technical and organizational measures to ensure the most complete protection of personal data processed through this website. However, Internet-based data transmissions may in principle have security gaps, so absolute protection may not be guaranteed. For this reason, every data subject is free to transfer personal data to us via alternative means, e.g. by telephone. ### 1. Definitions The data protection declaration of enum GmbH is based on the terms used by the European legislator for the adoption of the General Data Protection Regulation (GDPR). Our data protection declaration should be legible and understandable for the general public, as well as our customers and business partners. To ensure this, we would like to first explain the terminology used. ### 2. Name and Address of the controller Controller for the purposes of the General Data Protection Regulation (GDPR), other data protection laws applicable in Member states of the European Union and other provisions related to data protection is: ### 3. Cookies The Internet pages of enum GmbH use cookies. Cookies are text files that are stored in a computer system via an Internet browser. Many Internet sites and servers use cookies. Many cookies contain a so-called cookie ID. A cookie ID is a unique identifier of the cookie. It consists of a character string through which Internet pages and servers can be assigned to the specific Internet browser in which the cookie was stored. This allows visited Internet sites and servers to differentiate the individual browser of the dats subject from other Internet browsers that contain other cookies. A specific Internet browser can be recognized and identified using the unique cookie ID. Through the use of cookies, enum GmbH can provide the users of this website with more user-friendly services that would not be possible without the cookie setting. By means of a cookie, the information and offers on our website can be optimized with the user in mind. Cookies allow us, as previously mentioned, to recognize our website users. The purpose of this recognition is to make it easier for users to utilize our website. The website user that uses cookies, e.g. does not have to enter access data each time the website is accessed, because this is taken over by the website, and the cookie is thus stored on the user's computer system. Another example is the cookie of a shopping cart in an online shop. The online store remembers the articles that a customer has placed in the virtual shopping cart via a cookie. The data subject may, at any time, prevent the setting of cookies through our website by means of a corresponding setting of the Internet browser used, and may thus permanently deny the setting of cookies. Furthermore, already set cookies may be deleted at any time via an Internet browser or other software programs. This is possible in all popular Internet browsers. If the data subject deactivates the setting of cookies in the Internet browser used, not all functions of our website may be entirely usable. ### 4. Collection of general data and information The website of enum GmbH collects a series of general data and information when a data subject or automated system calls up the website. This general data and information are stored in the server log files. Collected may be (1) the browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system reaches our website (so-called referrers), (4) the sub-websites, (5) the date and time of access to the Internet site, (6) an Internet protocol address (IP address), (7) the Internet service provider of the accessing system, and (8) any other similar data and information that may be used in the event of attacks on our information technology systems. When using these general data and information, enum GmbH does not draw any conclusions about the data subject. Rather, this information is needed to (1) deliver the content of our website correctly, (2) optimize the content of our website as well as its advertisement, (3) ensure the long-term viability of our information technology systems and website technology, and (4) provide law enforcement authorities with the information necessary for criminal prosecution in case of a cyber-attack. Therefore, enum GmbH analyzes anonymously collected data and information statistically, with the aim of increasing the data protection and data security of our enterprise, and to ensure an optimal level of protection for the personal data we process. The anonymous data of the server log files are stored separately from all personal data provided by a data subject. ### 5. Contact possibility via the website The website of enum GmbH contains information that enables a quick electronic contact to our enterprise, as well as direct communication with us, which also includes a general address of the so-called electronic mail (e-mail address). If a data subject contacts the controller by e-mail or via a contact form, the personal data transmitted by the data subject are automatically stored. Such personal data transmitted on a voluntary basis by a data subject to the data controller are stored for the purpose of processing or contacting the data subject. There is no transfer of this personal data to third parties. ### 6. Routine erasure and blocking of personal data The data controller shall process and store the personal data of the data subject only for the period necessary to achieve the purpose of storage, or as far as this is granted by the European legislator or other legislators in laws or regulations to which the controller is subject to. If the storage purpose is not applicable, or if a storage period prescribed by the European legislator or another competent legislator expires, the personal data are routinely blocked or erased in accordance with legal requirements. ### 8. Data protection for applications and the application procedures The data controller shall collect and process the personal data of applicants for the purpose of the processing of the application procedure. The processing may also be carried out electronically. This is the case, in particular, if an applicant submits corresponding application documents by e-mail or by means of a web form on the website to the controller. If the data controller concludes an employment contract with an applicant, the submitted data will be stored for the purpose of processing the employment relationship in compliance with legal requirements. If no employment contract is concluded with the applicant by the controller, the application documents shall be automatically erased two months after notification of the refusal decision, provided that no other legitimate interests of the controller are opposed to the erasure. Other legitimate interest in this relation is, e.g. a burden of proof in a procedure under the General Equal Treatment Act (AGG). ### 9. Legal basis for the processing Art. 6(1) lit. a GDPR serves as the legal basis for processing operations for which we obtain consent for a specific processing purpose. If the processing of personal data is necessary for the performance of a contract to which the data subject is party, as is the case, for example, when processing operations are necessary for the supply of goods or to provide any other service, the processing is based on Article 6(1) lit. b GDPR. The same applies to such processing operations which are necessary for carrying out pre-contractual measures, for example in the case of inquiries concerning our products or services. Is our company subject to a legal obligation by which processing of personal data is required, such as for the fulfillment of tax obligations, the processing is based on Art. 6(1) lit. c GDPR. In rare cases, the processing of personal data may be necessary to protect the vital interests of the data subject or of another natural person. This would be the case, for example, if a visitor were injured in our company and his name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other third party. Then the processing would be based on Art. 6(1) lit. d GDPR. Finally, processing operations could be based on Article 6(1) lit. f GDPR. This legal basis is used for processing operations which are not covered by any of the abovementioned legal grounds, if processing is necessary for the purposes of the legitimate interests pursued by our company or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data. Such processing operations are particularly permissible because they have been specifically mentioned by the European legislator. He considered that a legitimate interest could be assumed if the data subject is a client of the controller (Recital 47 Sentence 2 GDPR). ### 10. The legitimate interests pursued by the controller or by a third party Where the processing of personal data is based on Article 6(1) lit. f GDPR our legitimate interest is to carry out our business in favor of the well-being of all our employees and the shareholders. ### 11. Period for which the personal data will be stored The criteria used to determine the period of storage of personal data is the respective statutory retention period. After expiration of that period, the corresponding data is routinely deleted, as long as it is no longer necessary for the fulfillment of the contract or the initiation of a contract. ### 12. Provision of personal data as statutory or contractual requirement; Requirement necessary to enter into a contract; Obligation of the data subject to provide the personal data; possible consequences of failure to provide such data We clarify that the provision of personal data is partly required by law (e.g. tax regulations) or can also result from contractual provisions (e.g. information on the contractual partner). Sometimes it may be necessary to conclude a contract that the data subject provides us with personal data, which must subsequently be processed by us. The data subject is, for example, obliged to provide us with personal data when our company signs a contract with him or her. The non-provision of the personal data would have the consequence that the contract with the data subject could not be concluded. Before personal data is provided by the data subject, the data subject must contact any employee. The employee clarifies to the data subject whether the provision of the personal data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the personal data and the consequences of non-provision of the personal data. ### 13. Existence of automated decision-making As a responsible company, we do not use automatic decision-making or profiling. ### 7. Rights of the data subject --- ## Imprint Source: https://enum.co/imprint # Imprint Information according to § 5 TMG **enum GmbH** Kaiser-Wilhelm-Ring 3-5 50672 Cologne Commercial register: HRB 121362 Register court: Amtsgericht Köln VAT ID: DE451942405 Represented by: Max Heyer, Founder ### Contact E-Mail: mail@enum.co --- ## Network Source: https://enum.co/network # The enum network. Own Autonomous System, direct peering at European Internet Exchanges, Frankfurt in production, edge presence across Europe. This is what separates a cloud provider from a reseller. ### Built for Resilience from the Ground Up Redundancy is built into the network at every layer. Our network is designed for resilience from the ground up. Multiple independent carriers. Automatic failover at the BGP level. No single point of failure between your application and the internet. When an upstream fails, our network reroutes traffic automatically. No manual intervention, no downtime. - **Multi-Homing & Multi-Path**: Multiple carriers active simultaneously, multiple paths per provider. If one fails, the others take over. Automatically. - **BGP Failover**: Routing decisions in seconds, not hours. Our network reacts before your users notice. - **Redundant Paths**: Every packet has multiple paths to its destination. No single provider, no single cable is a risk. ### Anycast Network. One IP address. Multiple locations. Traffic is automatically routed to the nearest PoP. Our Anycast network distributes DNS queries and content delivery across multiple European locations. Every request is automatically routed to the geographically nearest Point of Presence. The result: Lower latency, higher availability, better performance. Frankfurt is in production. Edge PoPs across Europe are coming soon. - **enum DNS**: Anycast-based DNS resolution at European edge locations. Sub-10ms response times for most of Europe. - **CDN**: Content delivery via edge PoPs across Europe. Static assets close to your users, with the full region in Frankfurt. - **Automatic Failover**: If a PoP goes down, Anycast routes traffic automatically to the next location. No manual intervention needed. ### European Jurisdiction. End to End. No data processing outside the EU. No CLOUD Act. No compromises. enum is a German company with its own infrastructure in European data centers. Our network operates via its own Autonomous System, registered with RIPE NCC. This is not a retroactive localization option. This is the architecture. For companies under NIS2, DORA, or KRITIS requirements, this means: Every component of your cloud infrastructure is verifiably European. From the server to BGP announcement. - German company - Own AS, own IP ranges from RIPE inventory - Frankfurt in production - No reselling, no US cloud provider **What does it mean that enum operates its own Autonomous System?** enum is registered as AS215998 with RIPE NCC. We control our own IP address ranges and routing decisions. Traffic takes the path we choose, not the path a transit provider forces on us. We can switch carriers without any IP address changing. **Where does enum have network presence?** The full region in Frankfurt, Germany, is in production. Edge PoPs for enum DNS and CDN are coming soon across Europe. Berlin is available as a full second region on demand. **Is enum's network compliant with NIS2 and DORA requirements?** enum is a German GmbH operating entirely within the EU. No data processing leaves European jurisdiction. No CLOUD Act exposure. Every component, from the server to the BGP announcement, is verifiably European. This makes enum suitable for organizations under NIS2, DORA, or KRITIS obligations. **Can I verify enum's network on PeeringDB?** Yes. AS215998 is publicly listed on PeeringDB. You can verify our peering relationships, IP ranges, and network details there at any time. --- ## Roadmap Source: https://enum.co/roadmap **Roadmap** # What we're building. See what's coming. No marketing fluff, just our engineering priorities. ### 2024-2026: Foundation Building (Shipped) ### Q1 2026 (Shipped) - S3 Versioning (Object Storage) - S3 Lifecycle (Object Storage) - S3 Server-Side Encryption (SSE-C) (Object Storage) - S3 CORS (Object Storage) - S3 Object Lock (Object Storage) - API (Developer Experience) - enumctl (Developer Experience, Preview) - Machine Types (Kubernetes) - Startup Program (Platform) ### Q2 2026 (Shipped) - enumctl (Developer Experience) ### Q3 2026 (In Progress) - enum DNS (Networking) - IAM (Platform) - Container Registry (Platform) ### Q4 2026 (Planned) - Anycast Edge Network (Networking) - Virtual Private Cloud (Networking, Preview) - enum Managed Kubernetes (Kubernetes) - Terraform Provider (Developer Experience) - Console (Platform, Preview) - ISO 27001 Certification (Compliance) ### 2027: Europe's AI backbone (Planned) - CDN (Networking, Preview) - Cloud WAF (Networking, Preview) - BSI C5 Certification (Compliance) --- ## Changelog Source: https://enum.co/changelog **Changelog** # What's New Stay up to date with the latest updates, features, and improvements to the enum cloud platform. ### Service accounts and API keys, enumctl 2026.09.4 (2026-09-03) ## enumctl 2026.09.4 - Create a service account with a one-shot key via `sa create --key` (defaults to a 90-day expiry), or pass `--print-token-only` to output just the token - Create API keys that never expire with the new `--no-expiry` flag - Manage service account API keys under `service-accounts keys` (or `sa keys`) - List API keys across an entire project with `enumctl sa keys list` by omitting the service account ID - Expiry error messages are now lowercase for consistent CLI output ## Platform - Service accounts and API keys are now available for automated workflows and CI/CD pipelines - API keys support optional expiration and use identifiable prefix tokens - Adopted object storage buckets are deletion-protected by default - Raised default S3 user quotas ## API and SDKs - ServiceAccountService API for creating and managing service accounts and API keys - New `UpdateObjectStorageBucket` RPC to configure bucket settings and deletion protection - Go SDK (`client-go`) and TypeScript SDK (`client-ts`) updated with `ServiceAccountService` support - TypeScript SDK updated with bucket deletion protection and `UpdateObjectStorageBucket` support ### Script-friendly enumctl, org defaults, enumctl 2026.08.3 (2026-08-27) ## enumctl 2026.08.3 - Choose how results print with `-o` / `--output`: `table` (default), `json`, or `yaml` - Set a default organization with `enumctl config set organization` or `enumctl organizations select` - On SSH or other headless machines, `enumctl auth login` uses device authorization (or force it with `enumctl auth login --device`): open the printed URL on another device to finish sign-in - Point `enumctl kubernetes kubeconfig` at a specific path with `-f` / `--file` (or `-` for stdout) - New buckets are deletion-protected by default; toggle with `--deletion-protection`, or later with `enumctl storage buckets protect` / `unprotect` - Singular aliases work alongside plurals: `enumctl project`, `enumctl storage bucket`, `enumctl org`, and similar ### Object storage IAM defaults and bucket config, enumctl 2026.08.2 (2026-08-26) ## Object Storage - New object storage users start with no permissions (AWS `CreateUser` defaults). Attach a managed or inline policy before they can use S3 - Attach managed IAM policies (`AmazonS3FullAccess`, `AmazonS3ReadOnlyAccess`, `IAMFullAccess`) or inline policy documents to object storage users - Manage bucket configuration through enum: versioning, Object Lock, default encryption, lifecycle, CORS, bucket policy, and tags - Enable Object Lock at bucket create time (`--object-lock` / `object_lock_enabled`) - Configuration set via the S3 API is mirrored into enum List/Get - Clearer errors when a delete hits a non-empty bucket or another S3 precondition ## DNS - Zones receive individual nameserver pairs if they would collide with another project's nameserver - Creating a zone whose apex is already claimed stays pending instead of failing immediately ## enumctl 2026.08.2 - `enumctl storage buckets get` returns live bucket configuration - `--object-lock` on bucket create - Set and clear bucket versioning, Object Lock, encryption, lifecycle, CORS, policy, and tags - `enumctl storage users policies` to list, attach, detach, and manage inline user policies ## API and SDKs - ObjectStorageUserPolicyService and bucket configuration RPCs on ObjectStorageBucketService - Per-token API rate limiting - Go and TypeScript clients updated ### Regions, CNAME flattening, enumctl 2026.08.1 (2026-08-07) ## Regions - Browse regions and availability zones in the catalog (`fra` is live) - Projects have a default region used when a create omits the region - Place object storage users and buckets in a region ## DNS - Apex `CNAME` records flatten to the target's A/AAAA addresses when served, so you can point the zone apex at another hostname - DNSSEC handoff now includes DNSKEY fields as well as DS records, for registrars that take a key ## enumctl 2026.08.1 - `enumctl regions list` and `enumctl zones list` - `--region` on object storage user and bucket create ## API and SDKs - RegionService to list and get regions and availability zones - Region on projects and object storage; DNSKEY on DNSSEC status; apex CNAME flattening - Go and TypeScript clients updated ### enum DNS, enumctl 2026.07.2 (2026-07-31) ## enum DNS - Create and manage DNS zones and records on enum, free forever - Import and export zones as BIND zone files - Enable DNSSEC and get DS records for your registrar - Point the zone apex at another hostname with a CNAME - Issue TLS certificates, including wildcards, for domains you host on enum - Read the [announcement post](/blog/free-dns-forever-for-a-better-european-internet) ## enumctl 2026.07.2 - Manage DNS zones and records with `enumctl dns` ## API - Manage DNS zones and records through the API ### Object Storage Sync, enumctl 2026.06.4 (2026-06-25) ## Object Storage - Object storage buckets created directly against the S3 API (for example with `aws s3`) now sync into enum and appear alongside buckets created through enum ## enumctl 2026.06.4 - Check for newer enumctl releases and print a hint on run; `enumctl --version` does an explicit check - `object-storage users` and `object-storage buckets` commands now take positional args instead of flags - Rename the `--display-name` flag to `--name` ## API - Deprecate the `displayName` parameter for creating object storage users in favor of `name` ## SDKs - Node.js SDK: object storage resource status `active` is renamed to `ready` - Node.js SDK: drop the legacy initial access key and the `revoked_at` field from object storage types ### Go SDK (2026-06-08) ## SDKs - Release the Go SDK for the enum API: `go get github.com/enumco/client-go` - Manage organizations, projects, Kubernetes clusters, and object storage from Go ### enumctl 2026.06.1, Object Storage Updates (2026-06-05) ## Object Storage - Project and bucket quotas are soft limits that support can raise within minutes ## enumctl 2026.06.1 - Add commands to list, create, and delete object storage buckets - Add delete for object storage keys and users - Drop the required organization ID from projects list - Add a Nix install option, alongside the existing Homebrew and AUR (Arch Linux) packages ## API and SDKs - Manage object storage buckets from the Node.js SDK - Return bucket status from the API ### Object Storage Buckets (2026-04-28) ## Object Storage - Create, list, and delete object storage buckets through the API, without a separate S3 client ### enumctl 2026.04.5, Object Storage Updates, API Launch (2026-04-14) ## enumctl 2026.04.5 - Add support to manage object storage users and keys - Add support to manage organizations and projects - Fix token refresh during re-authentication - Add homebrew support ## enum Object Storage - Add support for CORS - Add support for object locks - Add support for lifecycle policies - Add support for versioning - Add support for SSE-C ## API - Add support for object storage - Add public docs - Release node.js SDK ### Price Calculator Launch (2026-03-20) ## Platform - New interactive Pricing Calculator to estimate monthly costs before provisioning ### Startup Program Launch (2026-01-10) ## Platform - The enum Startup Program is now open for applications - Eligible startups receive platform credits and dedicated onboarding support - Apply at enum.co/startups --- ## Customers Source: https://enum.co/customers **Customers** # You're in good company. European teams running real production workloads on enum. --- ## Customer: scanmetrix Source: https://enum.co/customers/scanmetrix # Migrated in one week. Stable in production since the migration. scanmetrix runs its facility management platform for 32+ tenants on enum Kubernetes Engine in Frankfurt. Kubernetes, S3, and networking operate under German jurisdiction. ### Stats - **99.95%**: Availability since the migration - **-95%**: Load time for tenant APIs and S3 queries - **< 5 min**: Tenant onboarding (before: hours) - **300+**: S3 buckets, millions of requests per day ### The company scanmetrix is a German SaaS company that builds an ERP platform for facility management and technical service providers. The company has been in the market for more than seven years and works with FM companies, refrigeration and HVAC businesses, cleaning services, and security companies across Germany. The platform covers dispatch planning, maintenance management, contract management, billing with DATEV integration, an offline-capable tablet app for technicians, and AI-assisted maintenance predictions. ### The challenge - With the previous German provider, Kubernetes and S3 availability sat at 97% despite managed Kubernetes. - Networking behaved unpredictably and forced long debugging sessions. - The multi-tenant architecture did not scale cleanly. - Some days brought several incidents, eating into development time. ### Why enum - **Direct access to engineers**: No support loops through sales or first-level teams. scanmetrix talks directly to enum engineers who can debug, decide, and fix the issue. Debugging sessions shrink from days to hours. - **Upstream Kubernetes**: Manifests, Helm Charts, and GitOps pipelines ran without changes. No proprietary APIs, no provider-specific workarounds. Teams that know standard Kubernetes can work in production on enum. - **Kubernetes knowledge from production**: enum has run Kubernetes in production for years, not as a marketing label. The team knows pod disruption budgets, storage classes, and network policies from real operating cases. That matters when something has to be debugged under load. - **Scales across Kubernetes and S3**: Kubernetes workloads and S3 storage scale independently. New tenants mean new namespaces, not rearchitecting. scanmetrix can grow without redesigning the platform at every step. - **Hands-on migration support**: enum worked through the migration directly instead of just handing over access. The move took one week, including S3 data transfer and DNS cutover. The seven-person scanmetrix team could keep building product instead of managing the migration alone. - **S3 as a product, not an add-on**: 300+ buckets and millions of requests per day need more than attached storage. At enum, S3, routing, and latency work together cleanly. Object Storage gets the same care as Kubernetes. - **Billing in euros**: Costs are clear, billed in euros, and tied to actual usage. No currency swings, no hidden line items. For a small team, that is easier to plan than a cloud bill that looks different every month. - **A platform team that thinks with you**: enum thinks through architecture decisions instead of just forwarding tickets. Recommendations come early, not after several escalations. That shortens the path from problem to fix. ### Architecture What runs on enum and how the parts work together. Each tenant runs up to 10 services and multiple S3 buckets. - **enum Kubernetes Engine**: One cluster with 32+ tenant namespaces, clean isolation, and production workloads. - **enum Object Storage (S3)**: 300+ buckets for service reports, photos, and compliance artifacts. - **enum Networking**: Ingress and load balancing. - **ArgoCD**: GitOps deployments for all tenant namespaces. ### Results - 99.95% availability since the migration, after 97% at the previous provider. - Load time for tenant APIs and S3 queries reduced by 95%. - Tenant onboarding from hours to under 5 minutes. - Multi-tenancy simplified: one cluster with clean namespace isolation. - Monitoring expanded into a standardized observability stack together with enum. - The seven-person team builds product instead of infrastructure. - All data stays in Frankfurt, GDPR-native and without US dependencies. ### Self-service without a helpdesk On top of enum, scanmetrix built its own tenant manager and connected it to ArgoCD. Signup, namespace provisioning, and instance booking are automated. scanmetrix customers can sign up in self-service today and book their own instance within minutes, without anyone at scanmetrix touching the process. > At enum, real engineers worked through the migration with us directly. Since the switch, we can sleep through the night again. Infrastructure that simply runs was exactly what we wanted. - Jack Hull, CTO, scanmetrix ### Sovereignty as an enabler scanmetrix is preparing for ISO 27001 certification and uses enum's German infrastructure as its compliance foundation. For scanmetrix, German jurisdiction is not a checkbox. It is a sales argument with customers in regulated industries. ### What's next scanmetrix is adding scanmetrix Cortex, an AI assistant, plus new modules for ESG reporting and predictive maintenance. enum remains the technical base for that work. --- ## Customer: meinMPP Source: https://enum.co/customers/meinmpp # meinMPP runs its platform without an internal DevOps team. meinMPP runs its employee PC program on enum Kubernetes Engine. enum handles operations, from CI/CD to 24/7 on-call, in Frankfurt under German jurisdiction. ### Stats - **< 15 min**: Incident response (down from up to 12h) - **0**: internal DevOps team - **End to end**: operations by enum - **Enterprise**: ready for HR data ### The company meinMPP runs the Employee PC Program (MPP), a state-supported tech benefit for employers. Employees lease private tech of their choice through salary sacrifice, roughly 30% cheaper than buying it outright, including full protection. For employers, the program is free and mostly automated. Employers from startups to enterprise companies offer it to their teams. The product includes a public-facing shop with 2,000+ products, self-managed employee budgets, automated payroll exports, and HR integrations. ### The challenge - Operations sat with an agency and external providers. During incidents, meinMPP sometimes waited up to 12 hours for a response. - Enterprise customers ask for German hosting, clear contracting parties, and solid GDPR paperwork. - The public-facing shop has to absorb traffic peaks when large customers roll out the program across their organizations. - Payroll exports and HR integrations have to be right because mistakes flow straight into payroll. - The team was stuck in incidents instead of building the product and platform. ### Why enum - **Full operation instead of an internal team**: enum handles CI/CD, monitoring, alerting, and 24/7 on-call with an SLA. meinMPP gets the operating model of an internal DevOps team without building one. - **One accountable partner**: Before, the agency, operations, and external providers were split apart. During incidents, that led to finger-pointing and waiting. With enum, the platform, operations, and 24/7 on-call sit with one partner under one SLA. - **Direct access to the engineers who run it**: meinMPP talks directly to the engineers operating the platform, not a first-level queue. That is why response time went from hours to minutes. - **Frankfurt, German jurisdiction**: HR and compliance teams ask about data location, contracting party, and legal jurisdiction. enum gives meinMPP Frankfurt, a German GmbH, and GDPR-native infrastructure. That makes enterprise sales conversations easier. - **Built for payroll-critical workloads**: Payroll exports feed real salary runs. Errors are expensive. enum monitors the platform and catches issues before they reach payroll. - **Fire-and-forget scaling**: Traffic peaks happen when large customers roll out the program across their organizations. For meinMPP, scaling is fire and forget: the team scales the product and software, enum scales the platform and plans capacity ahead of demand. ### Operations: DevOps as a Service enum runs the platform end to end, like an internal DevOps team: - Development environment and CI/CD pipelines - Platform operations on enum Kubernetes Engine - Observability and monitoring - Alerting and 24/7 on-call with SLA - Incident response under 15 minutes - Auto-scaling for traffic peaks during enterprise rollouts - Updates, patching, and security - Backups ### Architecture What runs on enum and how the parts work together. - **enum Kubernetes Engine**: One cluster in Frankfurt for the platform backend and online shop. - **enum Object Storage (S3)**: Product images, customer documents, and artifacts. - **enum Networking**: Ingress and load balancing in Frankfurt. - **GitOps**: Declarative deployments via standard Kubernetes tooling. ### Results - Incident response reduced from up to 12 hours to under 15 minutes. - 24/7 on-call with SLA, operated by enum. - Traffic peaks during enterprise rollouts are absorbed automatically. - Employees order tech through the public-facing shop, whether they work at startups or enterprise companies. - HR teams get automated payroll exports instead of manual follow-up. - All data stays in Frankfurt, under German jurisdiction and without US dependencies. - meinMPP runs the platform without an internal DevOps team. > enum gave us a platform team without us having to hire one. We focus on our product, not Kubernetes. - Dominik Albers, Founder, meinMPP ### Sovereignty as an enabler Enterprise customers want verifiable German hosting. enum provides Frankfurt, German jurisdiction, and GDPR-native infrastructure. For meinMPP, that is not a checkbox. It is a sales argument with HR and compliance teams. ### What's next meinMPP is adding new product categories and HR integrations. enum remains the technical base. --- ## Customer: BasePeak Source: https://enum.co/customers/basepeak # Sovereign Cloud and AI, built on enum from day one. BasePeak runs its sovereign AI platform, BasePeak.AI and BasePeak.WORK, on enum Kubernetes Engine in Frankfurt. From the first commit, under German jurisdiction, for public administration and regulated industries. ### Stats - **Day 1**: Built on enum since the first day. - **100%**: Open-source based stack - **2**: products on one sovereign base - **0**: US dependencies, all data under German jurisdiction ### The company BasePeak is a German startup building sovereign AI infrastructure for organisations that cannot send data to US clouds. Its two products, BasePeak.AI and BasePeak.WORK, form a workspace where people and AI agents collaborate, built on open source and running as SaaS or on-premise. The company was founded by Thorsten Klein, who worked on k3s at Rancher Labs and created k3d. Customers include public administration, such as the city of Dormagen, and regulated enterprises. ### The challenge - Sovereign AI is only as trustworthy as the infrastructure underneath it. A German AI platform on a US-headquartered cloud undermines the promise. - Regulated and public-sector customers require verifiable German hosting, a German contracting party, and no US CLOUD Act exposure. For them it is a sales argument, not a checkbox. - As a startup, BasePeak had no legacy to migrate and no team to spare on operating infrastructure. The platform had to be production-ready from day one. - AI workloads demand predictable compute, storage for large knowledge bases, and low-latency networking between agents, models, and integrations. ### Why enum - **Sovereignty that matches the product**: BasePeak sells sovereign AI. enum provides the sovereign base: Frankfurt, a German GmbH, German and EU law only, no US parent, no CLOUD Act. The infrastructure and the product tell the same story. - **Built greenfield, no migration tax**: Because BasePeak started on enum, there was nothing to migrate. No re-platforming, no data-residency workarounds, no dual-running. The team spent its first weeks building product, not moving it. - **CNCF-conformant upstream Kubernetes**: BasePeak is built on open source and values portability. enum runs CNCF-conformant upstream Kubernetes with standard manifests, Helm, and GitOps, with no proprietary APIs. What runs on enum runs anywhere. - **NVMe storage fast enough to self-host S3**: BasePeak runs its own Garage S3 cluster on enum Kubernetes Engine, on top of enum's NVMe-backed block storage. Performance is great, so the team gets sovereign, self-controlled object storage without giving up speed. - **Direct access to engineers**: As a small team, BasePeak talks directly to the engineers who run the platform. No first-level queue, no ticket loops. Decisions and fixes happen in the same conversation. - **enum for Startups**: BasePeak joined the enum for Startups program, which brings cloud credits and conditions tailored to early-stage European teams. That lowered the barrier to building on sovereign infrastructure from day one. - **Predictable, euro-denominated billing**: For a startup, a cloud bill that swings with currency and hidden line items is a planning problem. enum bills in euros, tied to real usage, so costs are forecastable. ### Architecture What runs on enum and how the parts fit together. - **enum Kubernetes Engine**: Runs BasePeak.AI and the self-hosted Garage S3 cluster in Frankfurt, scaling with complex multi-tenant application deployments. BasePeak.WORK will launch on the same base. - **enum NVMe Block Storage**: NVMe-backed block storage delivering high performance for the Garage S3 cluster and AI workloads. - **Garage (self-hosted S3)**: BasePeak's own S3-compatible storage for knowledge bases, documents, and artifacts, running on enum Kubernetes Engine. - **enum Networking**: Ingress and low-latency routing between agents, models, and integrations. ### Results - A sovereign AI platform live in production, built on enum from the first commit, with no migration and no legacy cloud. - Sovereignty as a sales argument: Frankfurt hosting and German jurisdiction open doors with public administration and regulated enterprises. - A self-hosted Garage S3 cluster on enum Kubernetes Engine, with great NVMe storage performance, grounding AI answers in knowledge bases and artifacts. - An open-source stack on CNCF-conformant upstream Kubernetes, fully portable. - A small team focused on product, with infrastructure operated by a partner that thinks with them. - All data stays in Frankfurt, under German jurisdiction, with no US dependencies. > I worked on k3s at Rancher Labs and created k3d, so I know what good Kubernetes looks like. enum stands out: CNCF-conformant, upstream Kubernetes, done exceptionally well. - Thorsten Klein, Founder, BasePeak ### Sovereignty as an enabler BasePeak's customers, public administration and regulated industries, choose it because data stays under European control. enum provides the foundation: Frankfurt, a German GmbH, and GDPR-native infrastructure with no US CLOUD Act exposure. For BasePeak, sovereignty is not a checkbox. It is the product. ### What's next BasePeak is expanding BasePeak.AI across more public-sector and regulated customers and preparing the launch of BasePeak.WORK, with new agents, integrations, and the BasePeak Exchange for sharing them. enum remains the sovereign base underneath. --- ## Blog Source: https://enum.co/blog **Blog** # The enum blog News, engineering notes, and product updates from the team behind the European public cloud platform. ### Posts - **We built DNS. The hard part wasn't DNS.** (2026-08-17) Anyone can create a DNS zone for a domain they don't own. The four ways providers handle that gap, why three of them let a stranger block or take over your domain, and how enum verifies ownership through the parent's delegation. - **Free DNS, forever. For a better European internet** (2026-07-31) Host DNS zones on enum at no cost, forever. Zones, records, BIND import/export, DNSSEC, and TLS certificates. Built in Europe, for a better European internet. - **How to ransomware-proof S3 backups with Object Lock** (2026-04-30) S3 Object Lock turns your bucket into write-once storage. Even with valid credentials, ransomware can't delete what's locked. Here's how it works on enum. --- ## Blog: We built DNS. The hard part wasn't DNS. Source: https://enum.co/blog/we-built-dns-the-hard-part-wasnt-dns Published: 2026-08-17 | Author: Roman Zipp Anyone can create a DNS zone for a domain they don't own. The four ways providers handle that gap, why three of them let a stranger block or take over your domain, and how enum verifies ownership through the parent's delegation. DNS is old, well understood, and used everywhere. And yet, when you try to build a DNS product around it, you run into some surprisingly unresolved-looking problems. We ran into a few of them while building [enum DNS](https://enum.co/blog/free-dns-forever-for-a-better-european-internet), which we shipped at the end of July. Here are the ones we found most interesting. ## Why we built it Hyperscalers have built up an impressive catalogue of services over the years. Europe, meanwhile, still hasn't caught on. We believe Europe needs infrastructure of its own, one that wins on innovation and simplicity. And while other cloud providers charge per zone, per record, or even per DNS query, we think DNS, as the backbone of the internet, should be free. Switching your authoritative nameservers is the cheapest step towards European sovereignty there is, whether that is for your company or just for your side projects. ## The two moving parts Everything at enum is driven by a reconciler called `enumd`. The pattern is the one most people know from Kubernetes: you declare what a resource should look like, and the reconciler works in the background until the real world matches. Alongside it runs the observer, which watches for drift, the actual state having moved away from the declared state, and releases a resource for another reconcile when it finds any. No callbacks, no manual intervention. The system converges on its own. For the data plane we run an established open source authoritative nameserver, picked after a long evaluation. It came down to performance and to the API the reconciler uses to manage zones and records. Native replication on top of that keeps enum DNS highly available. We know better than to reinvent the wheel everywhere. Open source carries all cloud infrastructure, and we believe in the power of open software. It is also why we are members of the CNCF and the Linux Foundation. ## Proving a domain is yours Moving a domain to enum starts with [`enumctl`](https://docs.enum.co/cli/overview/) and `enumctl dns zones create example.com`. Before a single record of yours goes live, we have to be sure the domain really belongs to the person creating it. There are four ways to establish that, and three of them are worse than they look. ### 1. First to create wins The simple rule: you create a zone, the zone is taken, nobody else may create it. And that is exactly the problem, because it hands any user a denial of service against every other user. **Example**: Bob owns the domain `bobshop.com` and wants to move it to MyDNS24. But he has reckoned without Mallory, who creates zones for already registered domains at MyDNS24 in bulk. When Bob tries to create his `bobshop.com` zone and move his nameservers, he gets an error: "domain already taken". This is not hypothetical. Several DNS providers we tested work exactly this way. It is trivial to implement, ownership never has to be proven at any point, and getting a wrongly blocked domain released means going through the provider's support. ### 2. First to delegate wins The intuitive alternative is not to enforce uniqueness on zone creation at all, and to let the delegation decide instead. That one is only better at first glance. **Example**: Bob wants to move `bobshop.com` to BettererDNS. BettererDNS tells him to change the NS records at his registrar to `ns1/ns2.betterer-dns.cloud`, and he does. BettererDNS now checks at intervals whether the NS records of `bobshop.com` point at its own nameservers. Mallory is watching Bob's domain and notices the nameserver change. She creates a `bobshop.com` zone at BettererDNS too, which nothing prevents. Now BettererDNS runs its check again, and this is where it gets tricky. Both Bob and Mallory have a `bobshop.com` zone. The NS records of `bobshop.com` point at `ns1/ns2.betterer-dns.cloud`. So who is the rightful owner? If BettererDNS does not distinguish between the two and instead picks, say, the most recently created zone, Mallory has just taken over Bob's domain. The DoS is gone, but a race condition took its place. ```mermaid sequenceDiagram participant Bob participant TLD as .com nameservers participant BettererDNS participant Mallory Bob->>BettererDNS: create zone bobshop.com Bob->>TLD: set NS to ns1/ns2.betterer-dns.cloud Mallory->>BettererDNS: create zone bobshop.com BettererDNS->>TLD: which nameservers serve bobshop.com? TLD-->>BettererDNS: ns1/ns2.betterer-dns.cloud Note over BettererDNS: the answer matches both zones BettererDNS-->>Mallory: zone activated ``` ### People have been warning about this for years The GitHub project "[Can I Take Over DNS?](https://github.com/indianajson/can-i-take-over-dns)" has been documenting this for years and lists plenty of large DNS providers where a DNS takeover is possible. Names like Linode, Name.com, and in edge cases even Google and Azure. ### 3. A second factor The third option is to have the user create a TXT record at their current DNS provider, one the new provider generates uniquely for that zone. Same idea as Google Site Verification or Vercel's domain verification. Proof of ownership is unambiguous, and we still rejected it. It is an extra step, in a second control panel, at the provider you are trying to leave, and it does not follow from anything the user is already doing. ### 4. Doing it right When you create a DNS zone at enum, you get assigned a random pair of two nameservers, and that pair is stable for the entire enum project. `enumctl dns zones create example.com` hands them back to you to set at your registrar, in this example `curie.ns.enum.cloud` and `planck.ns.enum.cloud`. Attentive readers will have noticed that our DNS servers are named after well-known European researchers. **Example**: Bob moves `bobshop.com` to enum and is assigned `curie` and `planck`. If Mallory now shows up wanting to take over `bobshop.com`, she is out of luck, because her enum project has the nameservers `gauss` and `bohr`. The reconciler now checks in the background which nameservers `bobshop.com` is delegated to. To do that we don't ask the domain itself, we ask the `.com` nameservers. A regular NS query would be answered from the zone apex, and we serve that apex ourselves, so we would only read back what we published a moment earlier. The parent holds the delegation, and the parent is the one link in this chain we cannot write to. If Bob's `curie` and `planck` are both listed there, ownership is confirmed and unambiguously tied to one project. ```mermaid sequenceDiagram participant Bob participant TLD as .com nameservers participant Enum as enum participant Mallory Bob->>Enum: create zone bobshop.com Enum-->>Bob: use curie and planck Mallory->>Enum: create zone bobshop.com Enum-->>Mallory: use gauss and bohr Bob->>TLD: set NS to curie and planck Enum->>TLD: which nameservers serve bobshop.com? TLD-->>Enum: curie and planck Note over Enum: only Bob's pair is delegated Enum-->>Bob: verified, records go live rect rgba(200, 60, 60, 0.18) Enum-->>Mallory: claim stays unverified, nothing served end ``` #### What if both create the zone? At enum any project may create a zone for `bobshop.com`, several at the same time if it comes to that. We block nothing, because blocking was the whole problem in point 1. In the live DNS the zone still exists only once. As long as nobody is verified, the apex NS set is the union of all claims. If Bob and Mallory both create `bobshop.com`, four nameservers are listed there: `curie`, `planck`, `gauss` and `bohr`. That is necessary for the registrar pre-check to work for both of them, since each one needs to see their own nameservers answering. As soon as Bob has switched his NS records, the reconciler sees `curie` and `planck` at the parent. Bob is verified, the apex NS set collapses to his pair, and Mallory's claim is left sitting there. Mallory was never able to do anything during any of this. An unverified claim publishes NS and SOA and nothing else, never a single record. Her entries sat in our database and were never served. #### How long does that take? That depends on your registrar and on how quickly the change reaches the TLD. The observer checks regularly in the background, but you can trigger the check yourself at any time: ``` $ enumctl dns zones verify bobshop.com ``` #### Taking no chances The pool of european scientists is finite, so two projects can end up with the same pair. On its own that means nothing, because a pair only has to tell claims apart when two projects claim the same domain. If that does happen and the two share a pair, that one domain gets its own randomly generated pair to verify against, instead of the project's default. #### When the delegation disappears again The check runs continuously. If the NS records of a verified zone stop pointing at enum, we wait 48 hours. If nothing changes, we take the zone out of the live DNS and the claim drops back into verification. A brief hiccup at the registrar or a flaky lookup does not start the clock, only a delegation that genuinely points somewhere else. That way nobody gets switched off in the middle of a migration, and a domain that moved on long ago does not stay stuck with us forever. Claims that were never verified are cleaned up after 28 days, which also means Mallory's stockpile of created zones drains by itself. ## What happens to your records As soon as the zone exists, you can create records (`enumctl dns records create www.example.com A 203.0.113.15`) or import them (`enumctl dns zones import example.com -f example.com.zone`), before your ownership has been confirmed. The reconciler only takes them live once it is. Until then they sit in the database, visible to you and to nobody else. ### The SOA record There is one exception, and it is the SOA (Start of Authority) record. Some registrars do not let you simply change the NS records of a domain. They first ask the new nameservers directly whether the zone exists there at all, and refuse the change if no answer comes back. That is a catch-22. We confirm ownership through delegation, meaning the domain's NS records have to point at enum. But to change those NS records at the registrar, the zone has to be answering at our end already. So the zone does go live immediately, just not with any of your records. Only with the SOA and the NS set at the apex. ``` $ enumctl dns zones create bobshop.com $ dig SOA bobshop.com @curie.ns.enum.cloud +short curie.ns.enum.cloud. dns.enum.co. 2026080301 10800 3600 604800 3600 ``` ## Tricking the RFC This is an everyday case: you run a marketing site, you don't host it yourself, and the domain itself should point at that external service via a CNAME record. DNS does not allow a CNAME record to exist alongside other records, per RFC 1034: > If a CNAME RR is present at a node, no other data should be present; this ensures that the data for a canonical name and its aliases cannot be different. At the apex of the domain, the root of the zone (`example.com`), NS and SOA records have to be present regardless. So a CNAME at the apex is not allowed. enum DNS allows it anyway. When a CNAME record is created for the domain itself, `enumctl dns records create example.com CNAME external-site.com`, the reconciler resolves the target into ordinary A and AAAA records and keeps them up to date. ``` $ dig +noall +answer external-site.com A external-site.com AAAA external-site.com. 300 IN A 203.0.113.42 external-site.com. 300 IN AAAA 2001:db8:1::42 ``` If the target changes its address, that update happens on its own: on its next pass the observer sees the difference between desired and actual state, and the reconciler writes the new addresses into the zone. We resolve the target once, from our vantage point, and serve that one answer to everybody. If the target is geo-aware or load balanced, its own nameservers would hand different clients different addresses, and flattening collapses all of that into whatever we happened to see. Every provider that flattens at the apex has this limitation, ours included. The TTL is ours, not the target's. The flattened A and AAAA records carry the TTL you set on the apex record, and whatever TTL the target published is discarded. Set it low if the target moves around. So an end user visiting the domain never gets the CNAME record that was created, since that would violate the RFC. They get A and AAAA records back. ``` $ dig +noall +answer bobshop.com A bobshop.com AAAA bobshop.com. 300 IN A 203.0.113.42 bobshop.com. 300 IN AAAA 2001:db8:1::42 ``` ### Why not just let the nameserver handle it Authoritative nameservers can do apex aliases themselves, through a native ALIAS record. We deliberately do not use that. A native ALIAS is only resolved at query time. The answer comes into existence the moment the query arrives and never sits in the zone, which means it cannot be signed. A zone with DNSSEC would serve addresses without a signature at the apex, and any validating resolver throws those away. So we resolve one level earlier, in the reconciler. What ends up in the zone are ordinary A and AAAA records, and they get signed like everything else. ## Try it [enum DNS](https://enum.co/dns) is free. Run `enumctl dns zones create example.com`, set the two nameservers at your registrar, and the rest happens on its own. See the [docs](https://docs.enum.co/cli/overview/) for BIND zone file import, DNSSEC and everything else `enumctl` can do. --- ## Blog: Free DNS, forever. For a better European internet Source: https://enum.co/blog/free-dns-forever-for-a-better-european-internet Published: 2026-07-31 | Author: Max Heyer Host DNS zones on enum at no cost, forever. Zones, records, BIND import/export, DNSSEC, and TLS certificates. Built in Europe, for a better European internet. Free DNS, forever. For a better European internet. That is the deal with enum DNS. Host your zones on infrastructure we run in Europe, pay nothing for queries or zones, and keep that forever. We are building public cloud here on purpose: European operators, European nameservers, and DNS that does not nickel-and-dime you for every lookup. enum DNS is available today for early access users. You can host zones, manage records, import and export BIND zone files, turn on DNSSEC, and issue TLS certificates for domains you host on enum. If you are already on the platform, you can use it now. If you are not, [join the waitlist](https://enum.co/#waitlist) and we will open it up as we expand access. ## What you get **Zones and records.** Create a zone, point your registrar at the nameservers enum assigns your project, add records. Standard types: A, AAAA, CNAME, MX, TXT, and the rest. **BIND import and export.** Move an existing zone in with a zone file, or export one out. Useful when you are cutting over from another provider and do not want to retype records by hand. **DNSSEC.** Enable signing on an active zone and get the DS records to publish at your registrar. **Certificates.** Issue TLS certificates, including wildcards, for domains you host on enum. ## Getting started Create a zone: ```bash enumctl dns zones create example.com ``` enum prints the nameservers for your project. They are named after European scientists, so you might end up pointing your domain at `curie.ns.enum.cloud` and `planck.ns.enum.cloud`. Set those at your registrar, then add records: ```bash enumctl dns records create www.example.com A 203.0.113.10 ``` Import an existing zone file: ```bash enumctl dns zones import example.com --file example.com.zone ``` Enable DNSSEC when the zone is active: ```bash enumctl dns zones enable-dnssec example.com ``` The same surface is on the API. Full command reference is in the [docs](https://docs.enum.co). ## Free forever enum DNS has no query pricing and no per-zone fee. Host as many zones as you need. That is not a launch promo: free forever is the product, for a better European internet. ## What's next GA is on the [roadmap](https://enum.co/roadmap) for later this year, along with broader access beyond early access. Preview now is the real product: API, enumctl, DNSSEC, import/export, and TLS certificates. When we launch our Anycast network, we will roll enum DNS out to all edge nodes so queries resolve from the PoP closest to the resolver. Questions? [mail@enum.co](mailto:mail@enum.co). --- ## Blog: How to ransomware-proof S3 backups with Object Lock Source: https://enum.co/blog/object-lock-ransomware Published: 2026-04-30 | Author: Max Heyer S3 Object Lock turns your bucket into write-once storage. Even with valid credentials, ransomware can't delete what's locked. Here's how it works on enum. The modern ransomware playbook ends with a step most teams haven't planned for: before encrypting production, the attackers kill your backups. They log into your S3 bucket with credentials pulled from a developer's machine and delete the recovery objects. Or, worse, they overwrite them with garbage, wait for the corruption to replicate to your offsite copy, then trigger the encryption. Your tested restore procedure now restores poison. If your bucket trusts whoever holds the API key to delete or overwrite, your backups aren't backups. They're a liability with a versioning history. That's the problem S3 Object Lock solves. ## The S3 default isn't enough A standard S3 bucket has two delete behaviors. With versioning off, a `DELETE` removes the object permanently. With versioning on, a `DELETE` creates a delete marker. The object is still there, hidden, but anyone with `s3:DeleteObjectVersion` can remove it for good. Both behaviors require nothing more than valid credentials. If an attacker has your access keys, they have your backups. You can mitigate this with separate credentials, scoped IAM policies, MFA delete, separate accounts. All of those help. None of them are sufficient. Your protection still lives at the credential layer, exactly the layer attackers spend their time compromising. Object Lock moves the protection somewhere they can't reach: the storage layer itself. ## What Object Lock does S3 Object Lock implements a **Write-Once-Read-Many** model on top of the standard S3 API. Once an object version is locked, it cannot be deleted or overwritten until its retention period expires. Not by the bucket owner. Not by an admin. Not by anyone. Two mechanisms: **Retention period.** A timestamp on the object version. Until that timestamp passes, the object is immutable. You can extend it. Depending on the mode, you cannot shorten it. **Legal hold.** A binary flag with no expiry. While set, the object can't be deleted. Used for litigation hold, regulatory investigations, anything that needs indefinite immutability. Two prerequisites: 1. **Versioning must be enabled.** Object Lock locks specific object _versions_, not object names. Without versioning, the concept doesn't apply. 2. **Object Lock must be enabled at bucket creation.** You can't retroactively enable it on an existing bucket. Provision your buckets with Object Lock from day one. Migrating later means copying every object to a new bucket, which gets painful fast. ## Governance Mode vs Compliance Mode Object Lock has two modes, and the choice matters more than most teams realize. **Governance Mode.** Objects are locked, but a principal with the `s3:BypassGovernanceRetention` permission can override the lock. Useful for "we want immutability, but we need an emergency escape hatch." **Compliance Mode.** Objects are locked. Period. No principal, including the root account, can delete the object or shorten its retention until the period expires. If you're using Object Lock as ransomware protection, only Compliance Mode counts. Governance Mode protects against operator error. Compliance Mode protects against attackers who fully own your account. The trade-off is real: in Compliance Mode, a fat-fingered retention policy ("oops, 10 years instead of 10 days") costs you storage you can't reclaim until the timer runs out. The right answer for most workloads is 14 to 30 days for routine backups, with longer windows reserved for explicit regulatory requirements. A common failure mode: teams default to Governance Mode "just in case," then never enforce restrictions on the bypass permission. That's worse than no Object Lock at all. It provides the feeling of safety without the protection. ## Setting it up on enum enum's object storage is fully Object Lock compatible. Same API surface as AWS S3, same semantics. Create a bucket with Object Lock enabled: ```bash enumctl storage buckets create backups-prod \ --object-lock \ --region fra ``` Set a default retention configuration so every uploaded object inherits it: ```bash aws s3api put-object-lock-configuration \ --bucket backups-prod \ --endpoint-url https://fra.storage.enum.cloud \ --object-lock-configuration '{ "ObjectLockEnabled": "Enabled", "Rule": { "DefaultRetention": { "Mode": "COMPLIANCE", "Days": 30 } } }' ``` Upload a backup: ```bash aws s3 cp pg-dump-2026-04-30.sql.gz \ s3://backups-prod/postgres/ \ --endpoint-url https://fra.storage.enum.cloud ``` Now try to delete a specific version. `--version-id` is the destructive form: what an attacker would use to permanently remove the object, not just hide it behind a delete marker: ```bash aws s3api delete-object \ --bucket backups-prod \ --key postgres/pg-dump-2026-04-30.sql.gz \ --version-id \ --endpoint-url https://fra.storage.enum.cloud An error occurred (AccessDenied) when calling the DeleteObject operation: Access Denied because object protected by object lock. ``` That's the entire point. The credential is valid. The IAM policy allows the action. The storage layer refuses anyway. Verify the lock status on any object: ```bash aws s3api get-object-retention \ --bucket backups-prod \ --key postgres/pg-dump-2026-04-30.sql.gz \ --version-id \ --endpoint-url https://fra.storage.enum.cloud ``` ```json { "Retention": { "Mode": "COMPLIANCE", "RetainUntilDate": "2026-05-30T14:22:11+00:00" } } ``` For a complete backup workflow, point Restic, pgBackRest, Velero, or whatever you already use at the bucket. They write to S3 normally; the bucket's default retention applies the lock automatically. Your tooling doesn't need to know. ## What Object Lock doesn't do Object Lock is one layer. Not the entire defense. **It doesn't protect what you haven't backed up yet.** If your attacker waits to encrypt production until after a clean snapshot rolls out of your retention window, you're back where you started. Industry medians for ransomware dwell time are still over a week. A 7-day retention is too short. Pick something longer than your worst-case detection time. **It doesn't protect against malicious uploads.** An attacker with write credentials can upload garbage and lock it, leaving you paying for storage you can't delete. Restrict who holds write credentials. Monitor object counts and sizes. Enforce key prefix conventions through bucket policies. **It doesn't replace least-privilege IAM.** Backup credentials should still be scoped narrowly: read-only for restore tooling, append-only for backup writers. Object Lock is a backstop, not the only line. The lock is an enabler. The recovery procedure is the actual product. ## Get started Object Lock is available on enum's object storage in Frankfurt today. Default retention configurations, Compliance Mode, Legal Hold, all supported, S3-API compatible. Full reference in the [docs](https://docs.enum.co). Questions about migrating? [mail@enum.co](mailto:mail@enum.co). ---