# enum GmbH – Full Content > enum GmbH is a European public cloud platform delivering enterprise-grade Managed Kubernetes, S3-compatible Object Storage, and VPC Networking. Built on its own infrastructure in a German Tier III+ data center. Combines hyperscaler engineering with full European sovereignty and zero US dependencies. Structured overview: https://enum.co/llms.txt --- ## Homepage Source: https://enum.co # The European Cloud Platform. # Infrastructure You Can Trust - **Own Autonomous System**: AS215998. Own IP space. Direct peering at European Internet Exchanges. No reselling, no middlemen. - **AMD EPYC. NVMe.**: Latest hardware generation. Fast storage. Low latencies. - **Frankfurt. Tier III+.**: ISO 27001. EN50600. 24/7 Security. - **API-First**: CLI, API, Terraform. Provision infrastructure in seconds, not days. - **99.9% SLA**: Highly available by design. Automatic failover. We mean it. - **S3-Compatible Storage**: S3-compatible. Redundant. Your data never leaves the EU. # One Command. Your Infrastructure. - **European without compromise**: Full sovereignty, full developer experience. You shouldn't have to choose. - **Fully Automatable**: CLI, API, Terraform. Integrate into any CI/CD pipeline. - **Resilient**: Automatic failover, self-healing services, redundant storage. ### enum Kubernetes Engine - **Highly Available Control Plane**: Redundant control plane with automatic failover and zero-downtime upgrades. Your cluster stays stable - even while we patch. - **Technical Excellence**: Immutable OS, eBPF-based networking, optimized for scaling workloads. - **Scalable & Production-Ready**: Scales effortlessly in every direction - with automated monitoring, patching, and recovery. Built for the big leagues. - **Immutable by Design. Minimal Attack Surface.**: Immutable infrastructure for maximum security, minimal attack surface - security integrated from the start. ### enum Object Storage - **S3-Compatible. Drop-in for AWS.**: Full support for well-known tools and SDKs - seamlessly integrable into existing workflows. Drop-in replacement that just works. - **Petabyte-Ready. On NVMe.**: Scales with your data, not against you. Tiered storage with NVMe-accelerated performance - throughput that grows with your requirements. - **Data in Europe. No US Routing.**: Your data never leaves the EU. No routing through US data centers, no CLOUD Act risks. GDPR compliance without workarounds. - **Redundant. Automatic.**: Every object is replicated three times across independent failure domains. Resilience for data you can't afford to lose. ### Networking - **VPC Network Isolation**: Dedicated virtual networks with full traffic segmentation. Your workloads, completely isolated. - **L4 Load Balancing**: High-performance load balancing powered by eBPF. Native Kubernetes integration. - **Cloud DNS**: DNS as a Service with low-latency resolution. Fully integrated into the platform. - **Cloud NAT Gateway**: Optional managed NAT gateway with a stable egress IP and egress filtering. Clusters egress via host-based NAT by default. **European Cloud Platform** # Start building on enum. --- ## enum Kubernetes Engine Source: https://enum.co/kubernetes-engine **Flagship Product** # enum Kubernetes Engine. Sovereign Managed Kubernetes for teams that need hyperscaler-grade engineering without US jurisdiction. Self-service, HA control plane included, production-ready in minutes. enum Kubernetes Engine (EKE) is a self-service Kubernetes platform operated entirely in Germany under EU law. It runs upstream, unmodified Kubernetes with an isolated, highly available control plane per cluster included at no extra charge, private-by-default clusters, and full GDPR data sovereignty from a German GmbH. ### Why enum Kubernetes Engine? Hyperscaler-grade Kubernetes, operated in Germany under EU law - **HA Control Plane Included**: Every cluster gets an isolated, highly available control plane across independent failure domains, with automatic failover and zero-downtime upgrades. No per-cluster-hour charge. - **Upstream Kubernetes, No Fork**: Standard upstream Kubernetes with best-practice tooling. Existing manifests, Helm charts, and GitOps pipelines port over unchanged. - **Self-Service via API and CLI**: Provision clusters through enumctl, the REST API, or Terraform. Sensible defaults, no infrastructure assembly. First cluster in minutes, not days. - **European Sovereignty by Design**: German GmbH, German data centers in Frankfurt, German and EU law only. No US parent, no US subprocessors, no transatlantic data flows. ### Ideal for - Regulated workloads under GDPR, NIS2, or DORA - SaaS and FinTech platforms needing EU-only data flows - Microservices architectures requiring high availability - CI/CD pipelines with GitOps workflows - Teams migrating from AWS EKS, Google GKE, or Azure AKS ### Frequently Asked Questions **What is a GDPR-compliant Managed Kubernetes solution from Germany?** A GDPR-compliant Managed Kubernetes solution from Germany is a Kubernetes platform operated by a German company in German data centers under German and EU law only, with no US parent and no US subprocessors. enum Kubernetes Engine runs in Frankfurt, includes an HA control plane per cluster, and is operated by enum GmbH under exclusive German jurisdiction with no CLOUD Act exposure. **Is enum Kubernetes Engine NIS2 and DORA ready?** Yes. enum is a German GmbH operating in a German Tier III+ data center under German and EU law, with no US subprocessors and no transatlantic data flows. That structure aligns with NIS2 supply-chain requirements and DORA ICT third-party risk rules. NIS2 and DORA readiness is a structural property of where the company and data sit, not a separate certification. **How does enum Kubernetes Engine differ from AWS EKS and Google GKE?** enum includes a highly available control plane per cluster at no per-cluster-hour charge, provisions clusters private by default with host-based NAT, and bills load balancing at flat fees. AWS EKS and Google GKE bill the control plane per cluster-hour and leave NAT, private networking, and load balancing as separate paid components. All three run upstream Kubernetes, so manifests and Helm charts port over. **Is enum subject to the US CLOUD Act?** No. enum GmbH is a German company with no US entity in its corporate structure, so it is not subject to the US CLOUD Act or FISA Section 702. Selecting an EU region at a US-headquartered provider does not remove that exposure, because the corporate jurisdiction of the company holding the data is what counts. **What does Managed Kubernetes cost at enum?** Compute is billed per hour with optional one to three year commitment discounts. Block storage is billed per GB per month. The HA control plane is included at no extra charge, host-based NAT is included, and load balancing is a flat monthly fee with an IPv4 address included. All prices are in euros and exclude VAT. **How fast is a cluster provisioned, and how does provisioning work?** A cluster is ready in minutes through self-service. You provision it via the enumctl CLI, the REST API, or Terraform, with sensible defaults so no manual infrastructure assembly is needed. Clusters are private by default and run upstream Kubernetes, so existing manifests and GitOps pipelines work without changes. **In which regions does enum operate Kubernetes?** enum operates its primary Kubernetes region in Frankfurt, Germany, in a Tier III+ data center, with further European regions on the roadmap. All regions run on enum's own infrastructure and own network (AS215998), inside the European Union. **Can I migrate from AWS EKS or GKE to enum?** Yes. enum runs upstream, unmodified Kubernetes, so standard manifests, Helm charts, and GitOps workflows port over without code changes. enum object storage is S3-API compatible, so rclone, aws-cli, and the AWS SDKs work as-is. Migration support is available if you need help with the cutover. ### enum vs. AWS EKS What is included versus what costs extra. | Feature | enum | AWS EKS | |---|---|---| | HA Control Plane | Included per cluster, no per-cluster-hour charge | Billed per cluster-hour, managed control plane provisioned per cluster | | Outbound NAT | Host-based NAT included | NAT Gateway billed per hour per AZ plus per-GB data processing | | Load Balancer | Flat monthly price, includes IPv4 | Per hour plus LCU charges plus per-GB processing | | Private Cluster | Default, no configuration needed | Manual setup of subnets, NAT, VPC endpoints | | NVMe Storage | 100 GB included per node | EBS volumes billed separately | | Data Sovereignty | German GmbH, German data centers, GDPR-native | US company subject to US CLOUD Act | enum includes the highly available control plane per cluster at no per-cluster-hour charge, provisions clusters private by default with host-based NAT, and bills load balancing at a flat monthly fee with an IPv4 address included. AWS EKS provisions a managed control plane per cluster billed per cluster-hour, and leaves private networking, NAT gateways, and VPC endpoints as separate line items you assemble and pay for individually. ### Sovereignty, by construction Hyperscaler-grade engineering does not require US jurisdiction. - **German GmbH, German law**: enum is operated by enum GmbH, registered in Cologne (HRB 121362), under German and European law only. No US parent company, no US subprocessors. - **Data in Frankfurt, no US flows**: All infrastructure runs in a Tier III+ data center in Frankfurt, Germany. No transatlantic data flows, no Schrems II exposure. - **No US CLOUD Act**: Because enum has no US entity, it is not subject to the US CLOUD Act or FISA Section 702. Selecting an EU region at a US provider does not change the jurisdiction of the company holding the data. - **NIS2 and DORA ready**: German company, German data centers, German contracts. Structurally aligned with NIS2 and DORA requirements for regulated workloads. enum operates its own Autonomous System (AS215998, registered with RIPE NCC) with its own IP address ranges and direct peering at European Internet Exchanges. The company is a CNCF Silver Member and a Linux Foundation member. Control over the network, the corporate jurisdiction, and the physical data location all sit inside the European Union. ### Technical Specifications Enterprise-grade Kubernetes built for production workloads - **Availability SLA**: 99.9% (Guaranteed uptime) - **HA Control Plane**: Included (Per cluster, no per-cluster-hour charge) - **Data Location**: Frankfurt (German Tier III+ data center) - **Kubernetes**: Upstream (No fork, always current. Best practice tooling included) - **Networking**: eBPF (Kernel-level, fast, observable) - **Node OS**: Immutable (Minimal attack surface) - **Block Storage**: NVMe (Fast, redundant, persistent. 100 GB included per node) - **Latest Gen CPUs**: AMD EPYC (High-performance compute) - **Rolling Upgrades**: Zero-downtime (Automatic, no interruption) --- ## Object Storage Source: https://enum.co/object-storage **Object Storage** # enum Object Storage. The S3 API you know and love, operated in Europe with transparent pricing. Perfect for backups, media, data lakes, and more. enum Object Storage is an enterprise-grade, S3-compatible object storage service operated in Frankfurt, Germany, a drop-in replacement for AWS S3 with European data sovereignty. It works with any S3 client or SDK by changing only the endpoint, under German and EU jurisdiction with transparent, request-free pricing. ### Why enum Object Storage? All the power of S3, without the surprise bills - **100% S3 Compatible**: Drop-in replacement for AWS S3. Works with any S3-compatible client, SDK, or tool. Migrate in minutes. - **No Hidden Costs**: Pay only for storage and bandwidth. Zero API request fees, zero retrieval costs. Transparent pricing you can trust. - **European Data Sovereignty**: All data stored in Germany. GDPR-compliant by default. - **High Availability Built-In**: Automatic replication, 99.9% uptime SLA, lightning-fast access. Your data is always safe, always available. ### Perfect for - Backup and disaster recovery solutions - Media libraries and static asset hosting - Data lakes for analytics and AI/ML - CDN origin storage - Log archival and compliance data - Drop-in AWS S3 replacement with European sovereignty ### Frequently Asked Questions **What is S3-compatible object storage?** S3-compatible object storage uses the same API as Amazon S3, meaning any tool, SDK, or application built for AWS S3 works seamlessly with our storage. You can use popular tools like aws-cli, s3cmd, rclone, or any S3-compatible SDK without code changes. **How do I migrate from AWS S3?** Migration is straightforward. Use tools like rclone or aws-cli to sync your existing S3 buckets to enum. Simply update your endpoint URL and credentials. Your existing code and workflows continue to work without modification. We also offer migration support to help you move your data seamlessly. **Where is my data stored?** All data is stored exclusively in our data center in Frankfurt, Germany. Your data never leaves the EU. We operate our own infrastructure, no US cloud providers in the supply chain. **What's the maximum object size?** Individual objects can be up to 5 TB. Multipart uploads are supported for large files. There is no limit on the number of objects per bucket or the total storage capacity. **How does pricing work?** You pay only for storage (per GB/month) and outgoing traffic (per GB). There are no fees for API requests, data retrieval, or bucket operations. No minimum commitments, no hidden costs. **What SLA does enum offer?** We offer a 99.9% availability SLA. Data is protected via erasure coding across independent failure domains. All backed by our enterprise SLA with guaranteed response times. ### enum S3 vs. AWS S3 See why teams switch from AWS S3 to enum Object Storage. | Feature | enum | AWS EKS | |---|---|---| | Egress Fees | €0.025/GB, flat and predictable | $0.09/GB, 3.6x more expensive | | API Request Fees | Free, no charges for GET, PUT, LIST | Charged per 1,000 requests | | Data Location | Germany, guaranteed EU data residency | US company, subject to CLOUD Act | | Compliance | GDPR-native, NIS2-ready, DORA-suitable | Subject to US CLOUD Act | | Pricing Model | Storage + traffic | Storage + requests + retrieval + transfer + tiers | | Support | Real engineers, no ticket queue | Ticket system, paid support tiers | ### Technical Specifications Enterprise-grade storage built for reliability - **Durability**: 9 Nines (99.9999999% data durability) - **Availability SLA**: 99.9% (Guaranteed uptime) - **Erasure Coding**: EC (Across failure domains) - **Data Location**: Frankfurt, DE (German data center) - **API Compatible**: S3 (Full S3 API support) - **Encryption at Rest**: AES-256 (All data encrypted) - **Encryption in Transit**: TLS (All connections encrypted) - **Immutable Storage**: Object Lock (WORM compliance, ransomware protection) - **Bucket Versioning**: Versioning (Protection against accidental deletion) --- ## Block Storage Source: https://enum.co/block-storage **Block Storage** # enum Block Storage. NVMe-backed, replicated block storage for Kubernetes Persistent Volumes and standalone disks. Low latency, flat per-GB pricing. enum Block Storage is NVMe-backed, synchronously replicated block storage operated in Frankfurt, Germany. It attaches to enum Kubernetes Engine workloads as CSI PersistentVolumes and to standalone compute instances, with sub-millisecond read latency and a flat per-GB price. No burst credits, no per-operation fees. ### Why enum Block Storage? Fast disks without the EBS pricing maze - **NVMe Performance**: Sub-millisecond reads. Synchronous writes at ~1ms with 3x replication. Databases, queues, and stateful apps run without tuning around slow disks. - **Synchronous Replication**: Every write is acknowledged after it lands on independent failure domains. A host failure does not cause data loss or downtime. - **Kubernetes Native**: Provision through the CSI driver as PersistentVolumeClaims. Dynamic provisioning and online resizing work out of the box. - **Flat Per-GB Pricing**: One price per GB per month. No burst credits, no per-operation charges. The bill scales with the volume, not the workload. ### Perfect for - Databases (Postgres, MySQL, Redis, MongoDB) on Kubernetes - Message queues and streaming (Kafka, RabbitMQ) - Stateful workloads that need low-latency Persistent Volumes - Standalone disks for compute instances - Replacing EBS gp3 or io2 at a predictable price - Workloads that need EU-only data residency ### Frequently Asked Questions **What is block storage, and how is it different from object storage?** Block storage gives you a raw disk that an operating system or Kubernetes Pod can format, mount, and read from at the block level. It is what databases, message queues, and other stateful workloads need. Object storage (like enum Object Storage or AWS S3) is accessed over an HTTP API and is built for files, backups, and unstructured data. enum runs both, and they are billed separately. **How do I use block storage with enum Kubernetes Engine?** Create a PersistentVolumeClaim in your cluster and the CSI driver provisions the volume automatically. No storage class to configure. Online resizing and dynamic provisioning work out of the box. **Can I attach block storage to a compute instance without Kubernetes?** Yes. Volumes can be attached to standalone compute instances as well as to Kubernetes Pods. The same NVMe-backed, replicated disks back both paths. **How does pricing work?** You pay a flat rate per GB per month for the volume size you provision. There are no throughput surcharges and no per-operation fees. Outgoing traffic is billed per GB at the standard enum rate. All prices in euros, excluding VAT. **Is my data replicated and encrypted?** Every write is replicated synchronously across independent failure domains, so a single host or disk failure does not cause data loss or downtime. All volumes are encrypted at rest with AES-256. **Where is my data stored?** All data is stored exclusively in our data center in Frankfurt, Germany. Your data never leaves the EU. We operate our own infrastructure, no US cloud providers in the supply chain. ### enum Block Storage vs. AWS EBS What you get when you stop paying for hidden storage fees. | Feature | enum | AWS EKS | |---|---|---| | Pricing Model | Flat per GB per month | gp3 baseline + throughput | | Data Location | Germany, guaranteed EU data residency | US company, subject to CLOUD Act | | Compliance | GDPR-native, NIS2-ready, DORA-suitable | Subject to US CLOUD Act | | Support | Real engineers, no ticket queue | Ticket system, paid support tiers | ### Technical Specifications NVMe hardware with software replication - **Backing Media**: NVMe (All volumes on NVMe flash) - **Replication**: 3x (Synchronous writes across failure domains) - **Read Latency**: <1ms (Median 4K random read, 3x replicated volume) - **Write Latency**: ~1ms (Median 4K random write with 3x replication) - **Data Location**: Frankfurt, DE (German data center, EU-only) - **Kubernetes Integration**: CSI (PersistentVolumeClaims via CSI driver) - **Encryption at Rest**: AES-256 (All volumes encrypted) --- ## Networking Source: https://enum.co/networking **Networking** # Networking. Enterprise networking for cloud. Private by default, fully managed. enum networking is enterprise-grade VPC networking for production workloads: isolated virtual private clouds, L4 load balancing, host-based NAT, and IPv4/IPv6, on eBPF-based networking in Frankfurt, Germany. It scales with workload growth and bills without the per-zone and per-request surcharges common on US hyperscalers. ### Frequently Asked Questions **Are clusters private by default?** Yes. All enum clusters are private by default; nodes have no public IP addresses. Ingress runs through Load Balancers, and outbound runs via host-based NAT. A Cloud NAT Gateway for a stable egress IP and egress filtering is coming soon. **How does the Cloud NAT Gateway work?** Clusters egress via host-based NAT by default at no extra charge. A Cloud NAT Gateway with a stable egress IP, egress filtering, and centralized outbound control is coming soon. **Is IPv6 supported?** Yes. Full dual-stack support with IPv4 and IPv6. IPv6 addresses are free. **When is CDN available?** CDN is currently in development. Contact us if you want early access. ### enum vs. AWS Networking AWS networking costs are the most unpredictable part of your bill. | Feature | enum | AWS EKS | |---|---|---| | Outbound NAT | Host-based NAT included | Per hour per AZ plus per-GB data processing | | Load Balancer | Flat monthly price, IPv4 included | Per hour plus LCU charges plus per-GB | | IPv4 Address | Included with Load Balancer | Billed per hour per public IP | | IPv6 | Free | Free | | Private Cluster | Default, zero config | Manual VPC, subnet, endpoint setup | | Egress Traffic | Flat per-GB rate | Tiered pricing, cross-AZ charges extra | ### Networking Products #### Cloud Load Balancer L4 load balancing for your workloads. Automatic failover and a dedicated IPv4 address included. - L4 load balancing - IPv4 address included - Automatic failover - API & CLI provisioning #### Cloud NAT Gateway Optional managed NAT gateway for a stable egress IP, egress filtering, and centralized outbound control. Clusters are private by default and egress via host-based NAT. - Stable, dedicated egress IP - Egress filtering and centralized control - IPv4 and IPv6 support #### Cloud DNS Managed DNS with low-latency resolution. Hosted in our European infrastructure. - Low-latency resolution - European infrastructure - API and CLI management - DNSSEC support #### VPC Isolated virtual networks for every customer. Full network segmentation with private addressing and secure inter-cluster communication. - Complete network isolation per tenant - Private addressing and subnets - Secure inter-cluster connectivity - Traffic segmentation by default #### CDN Content delivery network for static assets and media. Edge caching across European PoPs. - European edge locations - S3 origin integration - TLS included - Cache invalidation API #### Cloud WAF Web application firewall to protect your applications from attacks. Managed rulesets, automatic updates. - Zero config, active out of the box - Managed rulesets - Automatic updates - Real-time monitoring ### Flat, Predictable Pricing Flat monthly prices. Predictable and transparent. - **Load Balancer**: / month - **Traffic**: / GB - **IPv4 Address**: / month - **IPv6**: Free ### Technical Specifications Enterprise networking for your infrastructure - **Load Balancing**: L4 (TCP, UDP) - **Availability**: 99.9% (Guaranteed uptime) - **Dual Stack**: IPv4+IPv6 (Full protocol support) - **Routing**: Multi-Path (Redundant network paths) - **NAT Pricing**: Flat Fee (One price per cluster) - **Data Location**: Frankfurt, DE (German data center) ### enum vs. AWS Networking AWS networking costs are the most unpredictable part of your bill. | Feature | enum | AWS | |---|---|---| | Outbound NAT | Host-based NAT included | Per hour per AZ plus per-GB data processing | | Load Balancer | Flat monthly price, IPv4 included | Per hour plus LCU charges plus per-GB | | IPv4 Address | Included with Load Balancer | Billed per hour per public IP | | IPv6 | Free | Free | | Private Cluster | Default, zero config | Manual VPC, subnet, endpoint setup | | Egress Traffic | Flat per-GB rate | Tiered pricing, cross-AZ charges extra | --- ## Professional Services Source: https://enum.co/professional-services # Professional Services. Infrastructure operations, platform engineering, and migration support. An engineering team, not a ticket queue. ### Sound Familiar? You're growing fast, but your infrastructure can't keep up. Your developers spend more time firefighting than building. Every deployment is a risk. And when things break at 3am, there's nobody to call. - Developers stuck doing ops instead of shipping features - No clear ownership over production - Deployments that feel like playing Russian roulette - Security patches piling up because nobody has time - Scaling issues hitting at the worst possible moment - The fear that tomorrow everything is "suddenly offline" ### This is Not Managed Hosting **Managed Hosting:** - You get servers and a ticket system - Support reacts when you report problems - Open a ticket, wait hours for a response - You're responsible for your stack - One-size-fits-all configuration **enum:** - You get an engineering team that owns your application - We proactively monitor, audit, and optimize - We take full responsibility - Tailored to your stack, continuously improved ### Faster Time to Production **Building It Yourself:** - Months of hiring and onboarding - Build tooling and processes from scratch - On-call rotation needs multiple engineers - Knowledge silos and single points of failure - Constant distraction from product work **enum:** - Experienced team from day one - 24/7 coverage with SLA - Productive in days, not months - Battle-tested best practices included - Scales with your needs ### Your Entire Stack. Our Responsibility. #### enum platform (usage-based) - Highly available Kubernetes clusters - Our platform, no reselling - Scalability that meets your requirements #### Platform Operations (1,500 €) - GitOps, CI/CD, monitoring stack, best-practice bundle - Ingress, TLS, GitOps delivery - Continuous optimization, support #### Application Operations (2,500 €) - Databases, caches, queues - Your custom application, highly available and optimized - Your stack, our responsibility. We adapt to you. #### 24/7 On-Call (Custom) - 99.9% SLA guaranteed - <15min incident response - Real engineers, no call center ### What We Actually Do - **Proactive Monitoring**: We detect problems before your users do. - **Deployment Management**: Safe, traceable deployments. - **Security & Patches**: Continuous updates, vulnerability scanning, hardened configurations. - **Architecture Audits**: We regularly review and challenge your setup. Then we improve it. - **Incident Response**: Our engineers proactively intervene when issues arise. RCA and post mortem included. - **Capacity Planning**: We plan ahead so you never hit a wall. - **Backup & Disaster Recovery**: Automated backups, tested recovery procedures, documented disaster recovery plans. - **Compliance & Documentation**: Audit-ready documentation, compliance reporting for NIS2, DORA, and GDPR. We keep your infrastructure accountable. --- ## Consulting Source: https://enum.co/consulting **Expert Guidance • Best Practices • Strategic Planning** # Cloud Consulting. Navigate your cloud journey with confidence. Our experts help you design, migrate, and optimize infrastructure that scales with your business. ### Consulting Services #### Architecture Review & Design Evaluate your current setup or design new cloud-native architectures from scratch. - Infrastructure audit & optimization recommendations - Cloud-native architecture design - Cost optimization & resource planning - Security & compliance assessment #### Migration Planning & Execution Move to the cloud without disruption. We plan and execute migrations that minimize risk and downtime. - Legacy system modernization strategies - Migration planning with minimal downtime - Database migration & data transfer - Post-migration validation & testing #### Performance & Cost Optimization Get more from your infrastructure. Optimize for performance, reliability, and cost efficiency. - Performance bottleneck analysis - Right-sizing & resource optimization - Cost analysis & reduction strategies - Monitoring & alerting setup #### DevOps Transformation Build modern development workflows. CI/CD pipelines, infrastructure as code, and automation best practices. - CI/CD pipeline design & implementation - Infrastructure as Code (IaC) with Terraform - Container & Kubernetes strategy - GitOps workflows & automation ### How We Work - **Discovery**: We understand your business, technical requirements, and challenges. - **Analysis**: Deep dive into your infrastructure, architecture, and workflows. - **Strategy**: Develop actionable recommendations and implementation roadmap. - **Execution**: Work alongside your team to implement solutions and transfer knowledge. --- ## Partners Source: https://enum.co/partners # Partner with enum. Build your business on European cloud. > Partners don't need another logo program. They need a platform that works and an engineer who answers. That's the whole deal. - Max Heyer, Founder, enum --- ## Migration Source: https://enum.co/migration **Migration Service** # Migration. Move your infrastructure to Europe. We handle the migration so you can focus on your product. ### Frequently Asked Questions **How long does a migration take?** Depends on the scope. A simple S3 migration can be done in days. A full Kubernetes migration with multiple services typically takes weeks to months. We provide a detailed timeline during the assessment phase. **Is there downtime during migration?** We minimize downtime as much as possible. We run both environments in parallel and use incremental sync and traffic shifting. In many cases, the cutover is a controlled switchover with a rollback plan. For some workloads, a short maintenance window may be necessary. **What if something goes wrong?** Every migration has a documented rollback plan. Your original infrastructure stays untouched until the migration is fully validated and you confirm the cutover. **Do I need to change my application code?** For Kubernetes: your manifests and Helm charts work as-is. For S3: you update the endpoint URL and credentials. No application logic changes needed. **What does the migration cost?** We scope every migration individually. Contact us for a free assessment and quote. ### What We Migrate #### Kubernetes Migration From AWS EKS, Google GKE, Azure AKS, self-managed clusters, or traditional VM/bare-metal setups. We containerize and migrate your workloads to production-ready Kubernetes. As CNCF Silver Member, we run upstream Kubernetes with best-in-class CNCF tooling like Cilium. - Workload analysis and compatibility check - Containerization of legacy workloads - Parallel cluster setup on enum - Incremental traffic shifting - Controlled cutover with rollback plan #### VM & Bare Metal Migration From traditional VMs, bare-metal servers, or on-premise infrastructure. We containerize your workloads and migrate them to production-ready Kubernetes. - Analysis of existing infrastructure and dependencies - Containerization of legacy applications - Database migration with minimal downtime - Parallel operation until fully validated - Controlled cutover with rollback plan #### PaaS Migration From Heroku, Render, Railway, Vercel, or other PaaS providers. We take over your applications and run them on our own infrastructure in Europe. - Add-on analysis and replacement with managed alternatives - CI/CD pipeline takeover - Environment and secret migration - DNS and domain switchover - No more dependency on US platforms #### S3 Storage Migration From AWS S3, Google Cloud Storage, or any S3-compatible provider. We migrate your buckets, policies, lifecycle rules, and access configurations while keeping your applications running. Every object is checksummed and verified after transfer. Full data integrity verification included. - Bucket structure and policy migration - Incremental data sync with verification - Application endpoint switchover - Lifecycle and versioning policy transfer - Post-migration validation ### How It Works A structured process, not a ticket queue. 1. **Assessment**: We analyze your current infrastructure, dependencies, and requirements. You get a detailed migration plan with timeline. 2. **Preparation**: We set up your target environment on our enum platform. Networking, storage, access management. Everything production-ready before we move a single workload. 3. **Migration**: Incremental migration with continuous validation. We run both environments in parallel until everything is verified. 4. **Cutover**: Controlled switchover with rollback plan. Traffic shifting, final validation. Your team stays in control. ### Why Migrate to enum - **European Data Sovereignty**: Your data moves from US jurisdiction to German infrastructure. GDPR-native, no CLOUD Act. - **Predictable Costs**: Transparent, predictable pricing. You always know what you'll pay. - **Real Support**: Direct access to engineers who know your migration. Not a ticket system, not a chatbot. - **Zero Vendor Lock-in**: Standard Kubernetes, S3-compatible storage. You can always move your workloads. --- ## Solutions Source: https://enum.co/solutions **European Cloud Platform** # Cloud for Europe. World-class infrastructure, operated in the EU, GDPR-compliant and built for teams that demand total control. enum solutions help enterprises run production workloads on European cloud infrastructure: enterprise-grade Managed Kubernetes, S3-compatible object storage, and VPC networking on enum's own infrastructure in Frankfurt, Germany, plus professional services, consulting, and migration support. Everything runs under German and EU jurisdiction with no US cloud dependencies. ### Kubernetes as a Service Enterprise-grade Kubernetes clusters, fully managed and production-ready in minutes. HA control plane included, no extra cost. **Features:** - **Full Control**: Root access, full API access and complete control over all resources. - **HA Control Plane**: 3+ control plane nodes, automatically managed and fail-safe. - **Hardened by Default**: Minimal, hardened and immutable node OS for maximum security. - **Automated Lifecycle**: Rolling upgrades and node recovery without downtime or manual intervention. **Ideal for:** - Production workloads that require high availability - Teams that need full infrastructure control - Companies with strict security and compliance requirements ### Object Storage (S3-Compatible) S3-compatible object storage, GDPR-compliant and transparently priced. No API request fees, no retrieval fees. **Features:** - **S3-compatible API**: Works with any S3 client and SDK. Migrate existing workloads in minutes. - **Transparent Pricing**: Pay for storage and outgoing traffic. No fees for API requests. - **Built-in Redundancy**: Erasure coding across failure domains. 9 nines durability. - **Data Location Germany**: Operated in Frankfurt. GDPR-compliant by design. **Ideal for:** - Backups, archives and disaster recovery - AI/ML datasets, static hosting and CDN origins - S3 workloads that need European data sovereignty --- ## Use Cases Overview Source: https://enum.co/use-cases **Use Cases** # Infrastructure for how you ship SaaS, fintech, and e-commerce teams run production workloads on enum's European public cloud in Frankfurt. enum is a European public cloud platform for teams that need Managed Kubernetes, S3-compatible object storage, and VPC networking under German and EU jurisdiction. These use cases show how different industries put that stack to work: multi-tenant SaaS, regulated fintech, and high-traffic retail. - **SaaS & Cloud Applications**: Multi-tenant products on isolated Kubernetes control planes, with EU data residency buyers expect. - **Fintech & Financial Services**: Regulated workloads with Frankfurt residency, audit-friendly logging, and no US CLOUD Act exposure. - **E-Commerce & Retail**: Elastic clusters for traffic peaks, object storage for product media, customer data kept in the EU. --- ## Use Case: SaaS Source: https://enum.co/use-cases/saas **SaaS & Cloud Applications** # SaaS Infrastructure Ship multi-tenant products on Kubernetes that scales with tenants, not with your ops headcount. SaaS companies and ISVs run multi-tenant applications on enum's European public cloud: Managed Kubernetes with an isolated control plane per cluster, S3-compatible object storage, and VPC networking in Frankfurt. Enterprise buyers get GDPR-aligned data residency and predictable euro pricing. ### What SaaS teams hit - Tenant isolation without a maze of custom control planes - Traffic that spikes when a big customer goes live - Enterprise buyers asking where data lives and who can compel access - Cloud bills that grow faster than revenue ### What you run on enum - Isolated Kubernetes control plane per cluster, included - Horizontal and vertical auto-scaling for workloads - Frankfurt region with GDPR-aligned data residency - Transparent per-resource pricing in euros, no surprise egress games ### What changes - Production-ready clusters from day one, without running etcd yourself - A clear answer for EU data residency in security questionnaires - Costs you can model as you add tenants, not after the invoice lands ### How SaaS teams ship on enum From first cluster to paying tenants. - **Stand up a cluster**: Create a production Kubernetes cluster with enumctl, the API, or Terraform. Control plane HA is included. - **Isolate tenants your way**: Use namespaces, network policies, and separate clusters where contracts demand it. You keep the isolation model. - **Store and connect**: Put artifacts and backups in S3-compatible object storage. Wire services through VPC networking and load balancers. ### Platform pieces that matter The same products your team already knows how to operate. - **enum Kubernetes Engine**: Upstream Kubernetes with an isolated control plane per cluster. Built for multi-tenant product workloads. - **Object Storage**: S3-compatible storage for backups, exports, and customer artifacts. Data stays in Frankfurt. - **VPC & Networking**: Private clusters by default, L4 load balancing, and host-based NAT without per-zone surprises. ### Keep reading - [enum Kubernetes Engine](/kubernetes-engine): Isolated control planes, upstream Kubernetes - [enum for Startups](/startups): Cloud credits for early-stage teams - [Customer stories](/customers): How teams run production on enum - [AWS alternative](/alternative-to-aws): Compare with EKS and US regions - [Pricing](/pricing): Euro pricing you can model - [Fintech use case](/use-cases/fintech): Regulated workloads on the same platform ### FAQ **Can we run multi-tenant SaaS on a shared cluster?** Yes. Most teams start with namespace and network-policy isolation on one cluster. When a customer contract requires stronger separation, spin up another cluster. Each cluster gets its own isolated control plane. **Where does customer data live?** In Frankfurt, Germany, on enum's European public cloud. Workloads, object storage, and networking stay under German and EU jurisdiction with no US hyperscaler dependency. **How do we provision clusters?** Self-service via enumctl, the REST API, or Terraform. You do not wait on a ticket to create or resize a cluster. **Is pricing usable for SaaS unit economics?** Pricing is per resource in euros, published on the site. There is no control-plane surcharge and no CLOUD Act-shaped transfer risk baked into the bill. --- ## Use Case: Fintech Source: https://enum.co/use-cases/fintech **Fintech & Financial Services** # Fintech Infrastructure Run regulated services on EU infrastructure with residency, logging, and isolation you can explain to auditors. Fintechs, banks, and financial institutions build regulated applications on enum's European public cloud in Frankfurt. Managed Kubernetes, S3-compatible object storage with Object Lock, and VPC networking support GDPR, DORA, and NIS2 readiness, with no US CLOUD Act exposure. ### What fintech teams hit - Data residency that procurement and regulators will accept - Low-latency paths for payment and trading-adjacent workloads - Evidence for access, changes, and retention - US cloud providers that create CLOUD Act and transfer risk ### What you run on enum - Frankfurt data centers under German and EU jurisdiction - High-performance Kubernetes close to your users in Europe - Infrastructure audit logs plus Object Lock for immutable retention - No US hyperscaler dependency in the control or data path ### What changes - A European public cloud story that survives security questionnaires - Residency and jurisdiction answers without a US cloud parent - Infrastructure you can operate with standard Kubernetes tooling ### How fintech teams land on enum From risk assessment to production cutover. - **Map residency and scope**: Confirm which workloads and datasets must stay in the EU. Frankfurt is the default region for enum today. - **Deploy on isolated planes**: Each Kubernetes cluster gets its own isolated control plane. Segment environments the way your risk model requires. - **Lock and log what matters**: Use Object Lock for retention-sensitive artifacts. Keep change and access evidence in your existing SIEM. ### Platform pieces that matter Building blocks for regulated product and platform teams. - **enum Kubernetes Engine**: Upstream Kubernetes with an isolated control plane per cluster. Fits DORA and NIS2 operational models. - **Object Storage**: S3-compatible storage with Object Lock for retention and evidence packages. - **VPC & Networking**: Private networking, L4 load balancing, and traffic segmentation for regulated services. ### Keep reading - [NIS2 & DORA](/kubernetes-nis2-dora): How EU Kubernetes maps to the rules - [Security](/security): How enum approaches platform security - [enum Kubernetes Engine](/kubernetes-engine): Isolated control planes in Frankfurt - [Customer stories](/customers): Production teams on enum - [SaaS use case](/use-cases/saas): Multi-tenant products on the same stack - [Contact](/contact): Talk through your risk model ### FAQ **Does enum help with DORA and NIS2?** enum provides EU-operated infrastructure, isolated control planes, and logging hooks that support how financial entities meet DORA and NIS2. Your policies and oversight stay yours; the platform removes US cloud dependencies from the stack. **Is customer data subject to the US CLOUD Act?** No. enum is a German company operating a European public cloud in Frankfurt. There is no US parent that can be compelled to hand over EU customer data under the CLOUD Act. **Can we keep production and audit trails separate?** Yes. Run separate clusters and projects for environments, and use Object Lock buckets for retention-sensitive artifacts. Wire logs into your SIEM the same way you would on any Kubernetes platform. **Where can we read more about NIS2 and DORA?** See enum's NIS2 and DORA page for how sovereign EU Kubernetes maps to those frameworks. --- ## Use Case: E-Commerce Source: https://enum.co/use-cases/ecommerce **E-Commerce & Retail** # E-Commerce Infrastructure Absorb sale traffic, serve product media fast, and keep shopper data in the EU. E-commerce and retail platforms run storefronts and backends on enum's European public cloud: Managed Kubernetes that scales for traffic peaks, S3-compatible object storage for product media, and VPC networking in Frankfurt. Pricing stays in euros with GDPR-aligned customer data residency. ### What retail teams hit - Traffic spikes during sales, drops, and campaigns - Product images and media that outgrow ad-hoc storage - Customer data that must stay under GDPR residency rules - Checkout paths that cannot go down when the ads work ### What you run on enum - Auto-scaling Kubernetes for surge traffic - S3-compatible object storage for catalogs and media - Frankfurt region with GDPR-aligned data residency - High-availability clusters with a 99.9% control-plane SLA ### What changes - Headroom for sale days without a last-minute capacity scramble - Product media that scales without a second storage vendor story - Customer data residency you can state clearly in privacy docs ### How shops run on enum From catalog storage to peak-season capacity. - **Put media in object storage**: Store product images, exports, and backups in S3-compatible buckets in Frankfurt. - **Run apps on Kubernetes**: Deploy storefronts, APIs, and workers on Managed Kubernetes. Scale replicas when campaigns land. - **Front traffic cleanly**: Use VPC networking and L4 load balancing so checkout and browse stay on separate capacity when you need them to. ### Platform pieces that matter What store and platform teams wire into every release. - **enum Kubernetes Engine**: Elastic capacity for storefronts, APIs, and workers during campaign peaks. - **Object Storage**: S3-compatible storage for product media, feeds, and backups at catalog scale. - **VPC & Networking**: Load balancing and private networking for browse and checkout paths. ### Keep reading - [Object Storage](/object-storage): S3-compatible media and backups - [enum Kubernetes Engine](/kubernetes-engine): Scale for campaign traffic - [Networking](/networking): Load balancing and VPC - [Pricing](/pricing): Model seasonal capacity in euros - [SaaS use case](/use-cases/saas): Multi-tenant products on enum - [Contact](/contact): Talk through your peak plan ### FAQ **Can enum handle Black Friday-style peaks?** Kubernetes workloads scale horizontally with demand. You size node pools and autoscaling for your peak, and the control plane stays highly available with a 99.9% SLA. **Where should product images live?** In enum Object Storage: S3-compatible, encrypted, and hosted in Frankfurt. Most teams point their CDN or image pipeline at those buckets. **Does customer data stay in the EU?** Yes. Compute, storage, and networking for your workloads run in Frankfurt under German and EU jurisdiction. **How is this priced for seasonal traffic?** You pay for the resources you use, in euros. Scale up for the campaign window and scale down afterward without reserved-instance lock-in. --- ## Startups Source: https://enum.co/startups # enum for Startups **Startup program** For European startups and scaleups that take sovereignty seriously. ### What you get - **Cloud Credits**: Up to 100,000 € over 12 months on enum's platform. Extension possible. - **Kubernetes cluster**: Highly available, production-ready from day one. - **Full platform access**: Kubernetes Engine, object storage, and networking. ### Why enum Your infrastructure should be right from day one. Not when your first enterprise customer demands a security audit. - **Production-ready in minutes.**: Cluster, storage, networking - everything is ready immediately. No wasting a weekend on AWS setup before you can even deploy. - **Compliance from day one.**: Your first HealthTech or FinTech customer asks about GDPR, NIS2, data residency? Just nod. Everything on our own infrastructure in Frankfurt, no US access, no rework. - **No US cloud.**: Own infrastructure in Frankfurt. No reselling of AWS or GCP, no CLOUD Act, no US access. Your data stays in Europe. ### Who this is for This is a curated program. We select startups that align with our mission. - European startup or scaleup, headquartered in the EU - Building a product that belongs on European cloud infrastructure - Ready to deploy production workloads - not just testing ### How to apply Fill out the form below. We review every application. - Company name & what you're building - Current stage & funding raised - What you need from your cloud --- ## AWS EKS alternative Source: https://enum.co/alternative-to-aws **AWS EKS alternative** # The AWS alternative for European Kubernetes. Transparent pricing, European infrastructure. No NAT traps, no LCU surprises. enum is a European public cloud operated by a German GmbH in Frankfurt, offering Managed Kubernetes, compute, S3-compatible object storage, and networking through a self-service CLI and API. It runs on open standards: upstream Kubernetes and S3-compatible storage, under German and EU jurisdiction with no CLOUD Act exposure. The HA control plane is included per cluster at no extra charge, and pricing is a small predictable set of line items with no per-request, NAT-processing, or LCU surcharges. enum is built for teams that need European sovereignty, predictable pricing, and a developer experience that gets out of the way. ### Included vs. Extra What you get with enum out of the box - and what AWS charges extra for. | Feature | enum | AWS EKS | |---|---|---| | Kubernetes HA Control Plane | Included | Billed per cluster-hour. Private networking, NAT gateways, and VPC endpoints are separate line items. | | Outbound NAT | Host-based NAT included | NAT Gateway billed per hour per AZ plus per-GB data processing. HA setup (3 AZs) multiplies base cost 3x. | | Load Balancer | Available at flat monthly price, includes IPv4 | Billed per hour plus LCU charges plus per-GB data processing. Costs scale unpredictably with traffic. | | Private Cluster Architecture | All clusters private by default. No configuration needed. | Requires manual setup of private subnets, NAT gateways, VPC endpoints. Each component adds cost and complexity. | | NVMe Storage (100 GB per Node) | Included per node, local NVMe per node | EBS volumes billed separately. Performance tiers cost extra on top of base storage pricing. | | IPv4 Address | Included with Load Balancer | Billed per hour per public IPv4 address | | Data Sovereignty | German GmbH, German data centers, German law. GDPR-native. | US company subject to CLOUD Act and FISA 702. US authorities can compel access to data stored in EU regions. | enum includes the highly available Kubernetes control plane per cluster at no per-cluster-hour charge, provisions clusters private by default with host-based NAT, and bills load balancing at a flat monthly fee with an IPv4 address included. AWS EKS provisions a managed control plane per cluster billed per cluster-hour, and leaves private networking, NAT gateways, VPC endpoints, and load balancing as separate line items you assemble and pay for individually. Selecting an EU region at AWS does not change the US corporate jurisdiction of the company holding the data. ### The hidden costs of AWS **This is an AWS invoice.** - Amazon EKS Cluster Hours - EC2 Instances - EC2 EBS Storage - EBS Kubernetes Persistent Volumes - NAT Gateway Hours - NAT Gateway Data Processing - Data Transfer Out - ALB Hours - ALB LCU Processing - Amazon S3 Storage - S3 PUT/GET/LIST Requests - VPC Endpoints **This is ours.** - Compute - Block Storage - Object Storage - Load Balancer - Traffic AWS layers per-hour, per-GB, per-request, and per-AZ surcharges on top of the core resource price. enum bills a small, predictable set, so you can estimate the invoice before you provision. ### Sovereignty - **No US Cloud Act**: AWS is a US company. US authorities can request access to your EU data - even without your knowledge. enum is subject exclusively to German and European law. - **GDPR-native**: No US subprocessor, no transatlantic data flows, compliant from day one. - **NIS2 & DORA ready**: German company. German data centers. German contracts. Ready for NIS2 and DORA without extra effort. German GmbH, German data centers, German law. Selecting an EU region at a US provider does not change the jurisdiction of the company holding the data. ### Kubernetes HA control plane per cluster, private by default with host-based NAT, load balancing at flat fees, all included. A managed Cloud NAT Gateway is coming soon. Upstream Kubernetes with no fork, so existing manifests, Helm charts, and GitOps pipelines port over. ### Storage S3-API compatible. aws-cli, rclone, s3cmd, and the AWS SDKs work without code changes. Storage and traffic billed, no per-request or retrieval fees. ### Developer experience One mental model across enumctl CLI, REST API, web console, and (soon) Terraform. A small set of resources with sensible defaults: sign-up to a running cluster in minutes. ### Same standards. Different model. Technically on par with AWS. Fundamentally different in how we charge and where your data lives. ### Frequently asked questions **Is AWS GDPR-compliant?** AWS offers GDPR-relevant contractual terms and EU regions, but AWS is a US company subject to the US CLOUD Act and FISA Section 702, which can compel access to data even when it is stored in an EU region. Selecting an EU region alone does not remove that exposure. enum is a German GmbH operating under German and EU law only, with no US parent and no US subprocessors. **Is AWS subject to the US CLOUD Act?** Yes. As a US-headquartered company, AWS falls under the CLOUD Act regardless of where the data physically resides, including its Frankfurt region. enum has no US entity in its structure and is subject exclusively to German and European jurisdiction. **What does data sovereignty mean at enum?** enum is operated by a German GmbH, in German data centers, under German and European law only, with no US parent and no US subprocessor. The company holding the data is therefore not subject to the US CLOUD Act or FISA Section 702. Selecting an EU region at a US-headquartered provider does not change the jurisdiction of the company holding the data; the corporate jurisdiction is what counts. For workloads bound by NIS2, DORA, or GDPR, that distinction is the difference between a contractual promise and a structural guarantee. **What does AWS EKS really cost?** Beyond the per-cluster-hour control plane fee, an EKS setup typically accumulates charges for EC2 instances, EBS volumes, NAT Gateway hours plus per-GB data processing (multiplied across availability zones in an HA setup), load balancer hours plus LCUs, data transfer out, public IPv4 addresses, and S3 request fees. The headline price is rarely the bill. enum includes the HA control plane and bills a small, predictable set of line items: compute, block storage, object storage, a flat-monthly load balancer that includes an IPv4 address, and traffic. Outbound uses host-based NAT by default; a managed Cloud NAT Gateway (coming soon) will add a stable egress IP. **How does enum price traffic compared to AWS?** enum charges a single flat per-GB rate for outgoing internet traffic, with intra-region transfer included and IPv6 free. AWS bills outgoing traffic in regional tiers, layers per-GB data-processing fees on NAT Gateways and Load Balancers, and charges cross-AZ traffic separately, so the effective per-GB cost of moving data in an HA setup is hard to predict from the headline rate. **How does enum Kubernetes Engine differ from AWS EKS?** Both run upstream Kubernetes. enum Kubernetes Engine includes a highly available control plane per cluster at no separate charge, provisions clusters private by default with host-based NAT, and includes load balancing at flat fees, with a managed Cloud NAT Gateway coming soon. Standard manifests, Helm charts, and GitOps pipelines port over unchanged. EKS bills the control plane per cluster-hour and leaves private networking, NAT gateways, and VPC endpoints as separate pieces you assemble and pay for individually. **Is enum object storage S3-compatible?** Yes. enum object storage implements the S3 API, so aws-cli, rclone, s3cmd, the AWS SDKs, and any tool built for S3 work without code changes. Data is erasure-coded across failure domains and stored in Frankfurt. enum bills storage and outgoing traffic, with no per-request or retrieval fees. **What is the best European alternative to AWS?** It depends on your requirements. For teams in regulated DACH industries that want hyperscaler-grade infrastructure under German jurisdiction without CLOUD Act exposure, enum offers Kubernetes, compute, object and block storage, and networking as a self-service public cloud operated in Frankfurt. **Can I migrate from AWS to enum?** Yes. enum object storage is S3-API compatible, so tools like rclone, aws-cli, and s3cmd work without code changes. enum Kubernetes Engine runs upstream Kubernetes, so standard manifests, Helm charts, and GitOps workflows port over. **Where is enum data stored?** All enum infrastructure runs in Frankfurt, Germany, operated by a German GmbH under German and EU law, with further European regions on the roadmap. ### Further reading - [enum Kubernetes Engine](/kubernetes-engine) - [S3-compatible object storage](/object-storage) - [Object Lock and ransomware protection](/blog/object-lock-ransomware) - [Pricing calculator](/calculator) --- ## Google GKE alternative Source: https://enum.co/alternative-to-gke **Google GKE alternative** # The GKE alternative without US jurisdiction. Sovereign Kubernetes in the EU, with no US CLOUD Act exposure and a transparent bill. enum is a European public cloud offering Managed Kubernetes, compute, and S3-compatible storage from Frankfurt, under German and EU law with no CLOUD Act exposure. enum includes an HA control plane per cluster at no extra charge, bills a small predictable set of line items, and gives you self-service via CLI, API, and Terraform. enum fits teams building in Europe who need sovereignty and pricing they can predict. ### Frequently asked questions **Is Google GKE GDPR-compliant?** enum is a German GmbH operating under German and EU law only, with no US parent and no US subprocessors. There are no transatlantic data flows, and the company holding your data is not subject to the US CLOUD Act or FISA Section 702. All infrastructure runs in Frankfurt. **Is Google GKE subject to the US CLOUD Act?** enum has no US entity in its corporate structure, so it is not subject to the US CLOUD Act or FISA Section 702. The jurisdiction is the company, not the region. A US company's EU region is still under US lawful-access mechanisms. **What does GKE really cost compared to enum?** enum includes the HA control plane per cluster at no extra charge. You pay for compute per hour, block storage per GB, object storage per GB, load balancing at a flat monthly fee, and outgoing traffic at a flat per-GB rate. No per-request fees, no NAT data-processing surcharges, no LCU charges. All prices in euros, excluding VAT. **What is the best European alternative to Google GKE?** enum offers upstream Kubernetes with an HA control plane included, operated in Frankfurt by a German GmbH under EU law only. You get self-service via CLI, API, and Terraform, private-by-default clusters, and a transparent bill in euros. No US dependencies, no CLOUD Act exposure. enum is a self-service public cloud, not a managed service or consulting engagement. **Can I migrate from Google GKE to enum?** Yes. enum runs upstream Kubernetes, so your manifests, Helm charts, and GitOps pipelines work without changes. Object storage is S3-compatible, so existing tools work as-is. Migration support is available if you need help with the cutover. **How does enum Kubernetes Engine differ from GKE Autopilot?** enum gives you explicit control over node shapes and scaling, includes the HA control plane per cluster at no extra charge, and bills compute per hour with optional commitment discounts. You keep full control over workloads, RBAC, Helm, and GitOps. The control plane, upgrades, and HA are operated for you. ### Included vs. Extra What you get with enum out of the box versus what GKE charges for. | Feature | enum | AWS EKS | |---|---|---| | HA Control Plane | Included per cluster, no per-cluster-hour charge | GKE Standard bills per-cluster-hour; Autopilot bills per-pod vCPU and memory | | Corporate Jurisdiction | German GmbH, German and EU law only, no US parent | US company (Alphabet), subject to US CLOUD Act and FISA 702 | | Data Location | Frankfurt, Germany, Tier III+ facility | EU regions available, but the company holding the data is US-headquartered | | Outbound NAT | Host-based NAT included | Cloud NAT billed per hour plus per-GB processing | | Load Balancer | Flat monthly price, includes IPv4 | Per-hour plus per-GB processing plus forwarding-rule charges | | Pricing Currency | Euro, excluding VAT | USD, subject to exchange-rate exposure for EU buyers | enum includes an HA control plane per cluster at no extra charge, provisions clusters private by default, and bills a small predictable set of line items. Google GKE bills the control plane per cluster-hour (Standard) or per-pod resource consumption (Autopilot), with Cloud NAT and Load Balancing adding per-hour and per-GB fees. Both run upstream Kubernetes. The decision is jurisdiction: enum is a German GmbH under EU law; Google is a US company under the CLOUD Act. ### The hidden costs of Google GKE **This is ours.** - Compute - Block Storage - Object Storage - Load Balancer - Traffic ### Sovereignty - **No US CLOUD Act**: Google is a US company (Alphabet). US authorities can compel access to data regardless of region. enum is a German GmbH with no US entity, subject exclusively to German and EU law. - **GDPR-native**: No US subprocessor, no transatlantic data flows, compliant from day one. - **NIS2 and DORA ready**: German company, German data centers, German contracts. Structurally aligned with NIS2 and DORA for regulated workloads. ### The hidden costs of Google GKE **This is a Google Cloud invoice.** - GKE Standard Cluster Hours - GCE Instances - Persistent Disk Storage - Cloud NAT Hours - Cloud NAT Data Processing - Data Transfer Out - Cloud Load Balancer Hours - Cloud Load Balancer Processing - Cloud Storage - Cloud Storage Requests - Cloud DNS Queries - Premium Tier Network Egress **This is ours.** - Compute - Block Storage - Object Storage - Load Balancer - Traffic ### Frequently asked questions **Is Google GKE GDPR-compliant?** enum is a German GmbH operating under German and EU law only, with no US parent and no US subprocessors. There are no transatlantic data flows, and the company holding your data is not subject to the US CLOUD Act or FISA Section 702. All infrastructure runs in Frankfurt. **Is Google GKE subject to the US CLOUD Act?** enum has no US entity in its corporate structure, so it is not subject to the US CLOUD Act or FISA Section 702. The jurisdiction is the company, not the region. A US company's EU region is still under US lawful-access mechanisms. **What does GKE really cost compared to enum?** enum includes the HA control plane per cluster at no extra charge. You pay for compute per hour, block storage per GB, object storage per GB, load balancing at a flat monthly fee, and outgoing traffic at a flat per-GB rate. No per-request fees, no NAT data-processing surcharges, no LCU charges. All prices in euros, excluding VAT. **What is the best European alternative to Google GKE?** enum offers upstream Kubernetes with an HA control plane included, operated in Frankfurt by a German GmbH under EU law only. You get self-service via CLI, API, and Terraform, private-by-default clusters, and a transparent bill in euros. No US dependencies, no CLOUD Act exposure. enum is a self-service public cloud, not a managed service or consulting engagement. **Can I migrate from Google GKE to enum?** Yes. enum runs upstream Kubernetes, so your manifests, Helm charts, and GitOps pipelines work without changes. Object storage is S3-compatible, so existing tools work as-is. Migration support is available if you need help with the cutover. **How does enum Kubernetes Engine differ from GKE Autopilot?** enum gives you explicit control over node shapes and scaling, includes the HA control plane per cluster at no extra charge, and bills compute per hour with optional commitment discounts. You keep full control over workloads, RBAC, Helm, and GitOps. The control plane, upgrades, and HA are operated for you. ### Further reading - [enum Kubernetes Engine](/kubernetes-engine) - [S3-compatible object storage](/object-storage) - [Sovereign Kubernetes and NIS2/DORA](/kubernetes-nis2-dora) - [Pricing calculator](/calculator) --- ## Hetzner alternative Source: https://enum.co/alternative-to-hetzner **Hetzner alternative** # The Hetzner alternative for managed Kubernetes. A managed Kubernetes platform, not just VMs and hosts you operate yourself. enum is a German PaaS: Managed Kubernetes with an HA control plane included per cluster, compute, S3-compatible storage, and self-service via API and Terraform. You get private-by-default clusters, zero-downtime upgrades, and a small predictable set of line items. enum fits teams who want a managed platform with sovereignty under EU law, without operating the control plane themselves. ### Frequently asked questions **Does Hetzner offer Managed Kubernetes?** enum is a Managed Kubernetes platform: the HA control plane is operated by enum and included per cluster at no extra charge. Clusters are private by default, upgrades are zero-downtime, and you provision through CLI, API, or Terraform. Hetzner gives you VMs and hosts where you run Kubernetes yourself. **Is Hetzner GDPR-compliant?** enum is a German GmbH in Frankfurt under German and EU law with no US subprocessors. Both enum and Hetzner are GDPR-native. The difference is product model, not jurisdiction: enum is a managed platform, Hetzner is raw IaaS. **How does enum pricing compare to Hetzner?** enum bills compute per hour with optional commitment discounts, includes the HA control plane per cluster at no extra charge, and charges a flat monthly fee for load balancing. No per-request fees, no NAT surcharges. On price-per-VM, Hetzner is cheaper. On total cost of ownership for a production Kubernetes platform, enum includes the operational work Hetzner leaves to you. **What is the best Managed Kubernetes alternative to running Kubernetes on Hetzner?** enum offers upstream Kubernetes with an HA control plane included, private clusters by default, zero-downtime upgrades, and self-service via CLI, API, and Terraform. Operated in Frankfurt by a German GmbH. You stop operating the control plane and ship a managed platform instead. **Can I migrate from Hetzner to enum?** Yes. enum runs upstream Kubernetes, so manifests, Helm charts, and GitOps workflows port directly. Object storage is S3-compatible, so existing tools work as-is. Migration support is available if you need help with the cutover. **Do I lose control running Managed Kubernetes instead of my own cluster?** No. You keep full control over workloads, RBAC, Helm, and GitOps. enum operates the control plane, node OS, and upgrades for you, with HA and zero-downtime rolling upgrades included. Node shapes and scaling stay in your hands. ### Product comparison What you operate yourself versus what the platform operates for you. | Feature | enum | AWS EKS | |---|---|---| | Kubernetes | Managed Kubernetes, HA control plane included per cluster | VMs and dedicated hosts; you install and operate Kubernetes yourself | | Control Plane | Operated by enum, 3+ nodes across failure domains, automatic failover | You run it on VMs or dedicated hosts; availability is your responsibility | | Upgrades | Zero-downtime rolling upgrades, operated by enum | You plan and execute upgrades yourself | | Private Networking | Private clusters by default with host-based NAT | You configure networks, firewalls, and routing yourself | | Load Balancer | Flat monthly price, includes IPv4 | Hetzner Cloud Load Balancer available, billed per hour | | Object Storage | S3-compatible object storage, no per-request fees | Hetzner Cloud Storage (S3-compatible) or external storage | enum Kubernetes Engine is a PaaS: the highly available control plane is operated by enum and included per cluster at no per-cluster-hour charge, clusters are private by default, and upgrades are zero-downtime. You provision clusters through enumctl, the REST API, or Terraform. Hetzner is IaaS: VMs and dedicated hosts where you install and operate Kubernetes yourself. The differentiator is who runs the control plane. ### Sovereignty - **PaaS, not IaaS**: enum operates the Kubernetes control plane, upgrades, HA, and private networking for you. That is the difference: a managed platform vs. raw infrastructure where you run everything yourself. - **Own network at enum**: enum operates AS215998 with own IP ranges and EU peering. Hetzner operates its own network (AS24940) as well. Both are providers, not resellers. - **NIS2 and DORA ready**: enum is a German GmbH in Frankfurt with no US subprocessors. Structurally aligned with NIS2 and DORA for regulated workloads. ### Frequently asked questions **Does Hetzner offer Managed Kubernetes?** enum is a Managed Kubernetes platform: the HA control plane is operated by enum and included per cluster at no extra charge. Clusters are private by default, upgrades are zero-downtime, and you provision through CLI, API, or Terraform. Hetzner gives you VMs and hosts where you run Kubernetes yourself. **Is Hetzner GDPR-compliant?** enum is a German GmbH in Frankfurt under German and EU law with no US subprocessors. Both enum and Hetzner are GDPR-native. The difference is product model, not jurisdiction: enum is a managed platform, Hetzner is raw IaaS. **How does enum pricing compare to Hetzner?** enum bills compute per hour with optional commitment discounts, includes the HA control plane per cluster at no extra charge, and charges a flat monthly fee for load balancing. No per-request fees, no NAT surcharges. On price-per-VM, Hetzner is cheaper. On total cost of ownership for a production Kubernetes platform, enum includes the operational work Hetzner leaves to you. **What is the best Managed Kubernetes alternative to running Kubernetes on Hetzner?** enum offers upstream Kubernetes with an HA control plane included, private clusters by default, zero-downtime upgrades, and self-service via CLI, API, and Terraform. Operated in Frankfurt by a German GmbH. You stop operating the control plane and ship a managed platform instead. **Can I migrate from Hetzner to enum?** Yes. enum runs upstream Kubernetes, so manifests, Helm charts, and GitOps workflows port directly. Object storage is S3-compatible, so existing tools work as-is. Migration support is available if you need help with the cutover. **Do I lose control running Managed Kubernetes instead of my own cluster?** No. You keep full control over workloads, RBAC, Helm, and GitOps. enum operates the control plane, node OS, and upgrades for you, with HA and zero-downtime rolling upgrades included. Node shapes and scaling stay in your hands. ### Further reading - [enum Kubernetes Engine](/kubernetes-engine) - [S3-compatible object storage](/object-storage) - [AWS EKS alternative](/alternative-to-aws) - [Pricing calculator](/calculator) --- ## IONOS alternative Source: https://enum.co/alternative-to-ionos **IONOS alternative** # The IONOS alternative for self-service Kubernetes. A focused European cloud for teams building on Kubernetes, compute, and storage. enum is a European public cloud built around Managed Kubernetes with an HA control plane included per cluster, predictable pricing, and self-service via API and Terraform. You get upstream Kubernetes, private-by-default clusters, zero-downtime upgrades, and a small predictable bill in euros. enum fits teams building on Kubernetes who want depth, sovereignty under EU law, and pricing they can predict. ### Frequently asked questions **Is IONOS GDPR-compliant?** Yes. IONOS is a German provider under EU law and not subject to the US CLOUD Act. enum is the same. Both are GDPR-native, so the decision is not about jurisdiction, it is about which platform fits your team. **Is IONOS subject to the US CLOUD Act?** No. IONOS is a European provider and not subject to the CLOUD Act. enum is also a German GmbH with no US entity. Since both are EU-based, this is not the differentiator. **How does enum Kubernetes Engine compare to IONOS Kubernetes?** enum includes an HA control plane per cluster at no extra charge, bills a small predictable set of line items, and exposes Kubernetes through self-service CLI, API, and Terraform. If Kubernetes is your core workload, enum gives you depth and a predictable bill. **What is the best Kubernetes-focused alternative to IONOS?** enum offers upstream Kubernetes with an HA control plane included, predictable pricing, and self-service provisioning, operated in Frankfurt by a German GmbH. **Can I migrate from IONOS to enum?** Yes. enum runs upstream Kubernetes, so manifests, Helm charts, and GitOps pipelines port over without code changes. Object storage is S3-compatible, so existing tools work as-is. Migration support is available if you need help with the cutover. **Does enum operate its own network?** Yes. enum operates its own Autonomous System (AS215998) with own IP ranges and direct EU peering, verifiable on PeeringDB. Traffic routing and egress are under enum control, not resold from a third party. ### Platform comparison How enum and IONOS differ on focus and Kubernetes. | Feature | enum | AWS EKS | |---|---|---| | Cloud Model | Kubernetes-first public cloud, self-service via CLI, API, Terraform | Managed cloud services, compute, storage, and hosted services | | Kubernetes Control Plane | HA control plane included per cluster, no per-cluster-hour charge | Managed Kubernetes offering; control-plane billing terms apply per IONOS | | Network | Own AS215998, RIPE LIR, EU peering | Operates within IONOS group infrastructure | | Data Location | Frankfurt, Germany, Tier III+ facility | Germany and EU regions | | Pricing Currency | Euro, excluding VAT | Euro, excluding VAT | enum includes an HA Kubernetes control plane per cluster at no extra charge, bills a small predictable set of line items, and gives you self-service via CLI, API, and Terraform. Both run under German and EU law. ### Sovereignty - **Both EU, different focus**: enum and IONOS are both European providers under EU law. Sovereignty is not the differentiator here. - **Own network at enum**: enum operates AS215998 with own IP ranges and EU peering, verifiable on PeeringDB. enum is a cloud provider, not a reseller. - **NIS2 and DORA ready**: enum is a German GmbH in Frankfurt with no US subprocessors and no transatlantic data flows. Structurally aligned with NIS2 and DORA. ### Frequently asked questions **Is IONOS GDPR-compliant?** Yes. IONOS is a German provider under EU law and not subject to the US CLOUD Act. enum is the same. Both are GDPR-native, so the decision is not about jurisdiction, it is about which platform fits your team. **Is IONOS subject to the US CLOUD Act?** No. IONOS is a European provider and not subject to the CLOUD Act. enum is also a German GmbH with no US entity. Since both are EU-based, this is not the differentiator. **How does enum Kubernetes Engine compare to IONOS Kubernetes?** enum includes an HA control plane per cluster at no extra charge, bills a small predictable set of line items, and exposes Kubernetes through self-service CLI, API, and Terraform. If Kubernetes is your core workload, enum gives you depth and a predictable bill. **What is the best Kubernetes-focused alternative to IONOS?** enum offers upstream Kubernetes with an HA control plane included, predictable pricing, and self-service provisioning, operated in Frankfurt by a German GmbH. **Can I migrate from IONOS to enum?** Yes. enum runs upstream Kubernetes, so manifests, Helm charts, and GitOps pipelines port over without code changes. Object storage is S3-compatible, so existing tools work as-is. Migration support is available if you need help with the cutover. **Does enum operate its own network?** Yes. enum operates its own Autonomous System (AS215998) with own IP ranges and direct EU peering, verifiable on PeeringDB. Traffic routing and egress are under enum control, not resold from a third party. ### Further reading - [enum Kubernetes Engine](/kubernetes-engine) - [S3-compatible object storage](/object-storage) - [The enum network](/network) - [Pricing calculator](/calculator) --- ## Sovereign Kubernetes / NIS2 & DORA Source: https://enum.co/kubernetes-nis2-dora **Sovereign Kubernetes** # Sovereign Kubernetes for NIS2 and DORA. What the regulations require of your cloud infrastructure, and how a sovereign European Kubernetes platform satisfies them by construction. NIS2 and DORA expect regulated entities (essential and important entities under NIS2, financial entities under DORA) to manage ICT third-party risk, keep data in a legally defensible jurisdiction, and avoid dependencies a foreign government can compel. A sovereign European Kubernetes platform operated by a German GmbH under German and EU law, with no US parent and no US subprocessors, satisfies these requirements structurally rather than contractually. enum Kubernetes Engine is such a platform: upstream Kubernetes with an HA control plane, run in Frankfurt, with no US CLOUD Act exposure. ### Frequently asked questions **Does NIS2 require cloud providers to be EU-based?** NIS2 does not explicitly mandate EU-based providers, but it makes operators of essential services responsible for the security of their supply chain, including cloud. A provider subject to the US CLOUD Act introduces a jurisdictional risk the operator cannot fully control. A sovereign EU provider like enum removes that risk structurally, which is the defensible posture under NIS2. **Is enum Kubernetes Engine DORA-compliant?** DORA does not certify products; it imposes obligations on financial entities and their ICT providers. enum is a German GmbH operating in Frankfurt under German and EU law, with no US subprocessors and no transatlantic data flows, which aligns structurally with DORA's ICT third-party risk, audit, and exit-planning requirements. enum is a platform you can build a DORA-compliant posture on, not a DORA certification holder. **What is the difference between an EU region and a EU provider?** An EU region is a data-center location. A EU provider is a company whose corporate jurisdiction sits inside the EU. The US CLOUD Act and FISA Section 702 apply to the corporate entity, not the region, so a US company's EU region is still subject to US lawful-access mechanisms. enum is a German GmbH with no US entity, so its Frankfurt region is covered by German and EU law only. **How does enum help with DORA exit planning?** DORA requires financial entities to plan for exiting an ICT provider without disruption. enum runs upstream, unmodified Kubernetes, so manifests, Helm charts, and GitOps pipelines are portable and not locked into a proprietary API. enum object storage is S3-API compatible, so data is movable with standard tools. Portability is the foundation of a credible exit plan. **Does enum hold ISO 27001 or BSI C5 certification?** enum's Frankfurt data center is a Tier III+ facility with ISO 27001 and EN50600 certification at the facility level. enum's own ISO 27001 certification is in progress with a target of Q4 2026, and BSI C5 is on the roadmap. We do not state either as achieved until the audit is complete. **Can regulated workloads run on enum today?** Yes. enum is a German GmbH operating in Frankfurt under German and EU law, with an HA Kubernetes control plane, own network (AS215998), and no US dependencies. Teams in FinTech, HealthTech, and public-sector-adjacent sectors run regulated workloads on enum today. NIS2 and DORA readiness is a structural property of where the company and data sit. ### Sovereignty is structural, not contractual The difference between a promise and a guarantee is where the company and the data sit. - **German GmbH, German contracts**: enum is operated by enum GmbH under German and EU law. Contracts, governance, and lawful-access regime all sit inside the EU. - **Frankfurt data center**: Data resides in a Tier III+ facility in Frankfurt, Germany. The physical location, the corporate jurisdiction, and the network are all EU-only. - **CNCF Silver Member**: enum is a CNCF Silver Member and a Linux Foundation member, anchored in the open-source standards that make Kubernetes portable and auditable. Selecting an EU region at a US-headquartered provider does not change the jurisdiction of the company holding the data. The US CLOUD Act and FISA Section 702 apply to the corporate entity, not the region. For a workload governed by NIS2 or DORA, the defensible posture is a provider whose entire corporate structure sits inside the EU. enum is such a provider: a German GmbH, in Frankfurt, with no US entity and no US subprocessors. ### What NIS2 and DORA require of cloud infrastructure Both regulations put the infrastructure layer at the centre of compliance, not at the edge. - **ICT third-party risk (DORA)**: DORA makes financial entities responsible for the ICT services they depend on. A Kubernetes platform must be operable under a contract that lets the entity meet DORA's audit, incident-reporting, and exit-planning obligations, and the provider must not introduce jurisdictional risk the entity cannot control. - **Supply-chain security (NIS2)**: NIS2 holds essential and important entities accountable for the security of their supply chain, including cloud providers. The provider's corporate jurisdiction and data location become part of the entity's risk surface, not a detail outsourced to procurement. - **Data location and lawful access**: Both frameworks expect data to sit in a jurisdiction whose lawful-access regime is compatible with EU law. A provider subject to the US CLOUD Act or FISA Section 702 can be compelled to hand over data stored in the EU, which is hard to reconcile with a defensible NIS2 or DORA posture. - **Resilience and incident response**: NIS2 and DORA both require resilience and fast incident response. The underlying platform must offer high availability, clear escalation paths, and an infrastructure operator you can reach under EU law. ### How a sovereign EU Kubernetes platform satisfies them enum maps each requirement to a structural property of the platform. - **Jurisdiction by construction**: enum is a German GmbH (HRB 121362, Cologne) operating in Frankfurt under German and EU law only, with no US parent and no US subprocessors. The jurisdiction is the company, not a region selection. - **No CLOUD Act, no FISA 702**: Because enum has no US entity, it is not subject to the US CLOUD Act or FISA Section 702. Foreign authorities cannot compel access to data held by enum through US legal mechanisms. - **EU-only data flows**: All infrastructure runs in a Tier III+ data center in Frankfurt. No transatlantic data flows, no Schrems II exposure, no reliance on adequacy decisions or Standard Contractual Clauses that can be invalidated. - **HA control plane included**: Every cluster gets an isolated, highly available control plane across independent failure domains, with automatic failover and zero-downtime upgrades, at no per-cluster-hour charge. Resilience is built in, not a paid tier. - **Own network, EU peering**: enum operates its own Autonomous System (AS215998, RIPE NCC) with own IP ranges and direct peering at European Internet Exchanges. Network control sits inside the EU and is publicly verifiable on PeeringDB. - **Upstream Kubernetes, no fork**: Standard upstream Kubernetes with no fork means portable workloads, no lock-in, and an exit path that DORA's exit-strategy requirements expect. Manifests, Helm charts, and GitOps pipelines move with you. ### Sovereignty is structural, not contractual The difference between a promise and a guarantee is where the company and the data sit. - **German GmbH, German contracts**: enum is operated by enum GmbH under German and EU law. Contracts, governance, and lawful-access regime all sit inside the EU. - **Frankfurt data center**: Data resides in a Tier III+ facility in Frankfurt, Germany. The physical location, the corporate jurisdiction, and the network are all EU-only. - **CNCF Silver Member**: enum is a CNCF Silver Member and a Linux Foundation member, anchored in the open-source standards that make Kubernetes portable and auditable. Selecting an EU region at a US-headquartered provider does not change the jurisdiction of the company holding the data. The US CLOUD Act and FISA Section 702 apply to the corporate entity, not the region. For a workload governed by NIS2 or DORA, the defensible posture is a provider whose entire corporate structure sits inside the EU. enum is such a provider: a German GmbH, in Frankfurt, with no US entity and no US subprocessors. ### Frequently asked questions **Does NIS2 require cloud providers to be EU-based?** NIS2 does not explicitly mandate EU-based providers, but it makes operators of essential services responsible for the security of their supply chain, including cloud. A provider subject to the US CLOUD Act introduces a jurisdictional risk the operator cannot fully control. A sovereign EU provider like enum removes that risk structurally, which is the defensible posture under NIS2. **Is enum Kubernetes Engine DORA-compliant?** DORA does not certify products; it imposes obligations on financial entities and their ICT providers. enum is a German GmbH operating in Frankfurt under German and EU law, with no US subprocessors and no transatlantic data flows, which aligns structurally with DORA's ICT third-party risk, audit, and exit-planning requirements. enum is a platform you can build a DORA-compliant posture on, not a DORA certification holder. **What is the difference between an EU region and a EU provider?** An EU region is a data-center location. A EU provider is a company whose corporate jurisdiction sits inside the EU. The US CLOUD Act and FISA Section 702 apply to the corporate entity, not the region, so a US company's EU region is still subject to US lawful-access mechanisms. enum is a German GmbH with no US entity, so its Frankfurt region is covered by German and EU law only. **How does enum help with DORA exit planning?** DORA requires financial entities to plan for exiting an ICT provider without disruption. enum runs upstream, unmodified Kubernetes, so manifests, Helm charts, and GitOps pipelines are portable and not locked into a proprietary API. enum object storage is S3-API compatible, so data is movable with standard tools. Portability is the foundation of a credible exit plan. **Does enum hold ISO 27001 or BSI C5 certification?** enum's Frankfurt data center is a Tier III+ facility with ISO 27001 and EN50600 certification at the facility level. enum's own ISO 27001 certification is in progress with a target of Q4 2026, and BSI C5 is on the roadmap. We do not state either as achieved until the audit is complete. **Can regulated workloads run on enum today?** Yes. enum is a German GmbH operating in Frankfurt under German and EU law, with an HA Kubernetes control plane, own network (AS215998), and no US dependencies. Teams in FinTech, HealthTech, and public-sector-adjacent sectors run regulated workloads on enum today. NIS2 and DORA readiness is a structural property of where the company and data sit. --- ## FAQ Source: https://enum.co/faq **FAQ** # Questions CTOs ask about enum. Straight answers about European cloud, sovereign Kubernetes, compliance, and how enum compares to the hyperscalers. enum is a European public cloud platform operated by enum GmbH in Frankfurt, offering Managed Kubernetes (enum Kubernetes Engine), S3-compatible Object Storage, and VPC Networking through a self-service CLI, API, and Terraform. It is built for teams that need hyperscaler-grade engineering under German and EU jurisdiction, with no US CLOUD Act exposure. ### What is the best European alternative to AWS? It depends on your workload. For teams in regulated DACH industries that want hyperscaler-grade Kubernetes, compute, and S3-compatible storage under German jurisdiction without CLOUD Act exposure, enum offers a self-service public cloud operated in Frankfurt by a German GmbH. enum is a platform product, not a consulting engagement. ### Which Kubernetes providers are headquartered in Germany? German-HQ Kubernetes providers include enum (enum GmbH, Cologne, operating in Frankfurt), STACKIT (Schwarz Group), Hetzner, and IONOS. enum is the independent public cloud with its own RIPE-registered network (AS215998) and CNCF Silver membership. ### Is enum Kubernetes Engine suitable for NIS2 and DORA workloads? Yes. enum is a German GmbH operating in a Frankfurt Tier III+ data center under German and EU law, with no US subprocessors and no transatlantic data flows. That structure aligns with NIS2 supply-chain requirements and DORA ICT third-party risk rules. NIS2 and DORA readiness is a structural property of where the company and data sit, not a separate certification. ### Is enum object storage S3-compatible? Yes. enum object storage implements the S3 API, so aws-cli, rclone, s3cmd, the AWS SDKs, and any tool built for S3 work without code changes. Data is erasure-coded across failure domains and stored in Frankfurt. enum bills storage and outgoing traffic, with no per-request or retrieval fees. ### Can I migrate from AWS EKS or Google GKE to enum? Yes. enum runs upstream, unmodified Kubernetes, so standard manifests, Helm charts, and GitOps pipelines port over without code changes. enum object storage is S3-API compatible, so rclone, aws-cli, and S3 SDKs work as-is. Migration support is available if you need help with the cutover. ### Does enum offer a Terraform provider? enum exposes the platform through a self-service CLI (enumctl), a REST API, and Terraform. You can provision clusters, storage, and networking as code with sensible defaults, so infrastructure is reproducible and version-controlled. ### What SLA does enum Kubernetes Engine offer? enum Kubernetes Engine includes a highly available control plane per cluster across independent failure domains, with automatic failover and zero-downtime upgrades, backed by a 99.9% availability SLA. The HA control plane is included at no per-cluster-hour charge. ### Is enum suitable for FinTech workloads? Yes. enum is a German GmbH operating under German and EU law with no US parent and no US subprocessors, which aligns with the jurisdictional expectations of FinTech regulation and DORA. Teams run payment, banking-adjacent, and trading-platform workloads on enum Kubernetes Engine in Frankfurt. ### Is enum suitable for HealthTech workloads? Yes. enum operates in Frankfurt under German and EU law, which covers GDPR and German patient-data requirements. The HA control plane, private-by-default clusters, and EU-only data flows fit HealthTech workloads that cannot tolerate US jurisdiction or transatlantic data transfers. ### How is enum different from colocation? Colocation gives you a rack and power; you bring and operate the hardware, the network, the hypervisor, and Kubernetes. enum is a public cloud: it operates the infrastructure, the network (AS215998), the storage, and the Kubernetes control plane, and exposes them through a self-service API. You run workloads, not hardware. ### Who operates enum and where is the data stored? enum is operated by enum GmbH, registered in Cologne (HRB 121362, VAT DE451942405), founded on 15 November 2024. All infrastructure runs in a Tier III+ data center in Frankfurt, Germany. The company is a CNCF Silver Member, a Linux Foundation member, and a RIPE NCC member operating its own Autonomous System (AS215998). ### Is enum subject to the US CLOUD Act? No. enum GmbH is a German company with no US entity in its corporate structure, so it is not subject to the US CLOUD Act or FISA Section 702. Selecting an EU region at a US-headquartered provider does not remove that exposure, because the corporate jurisdiction of the company holding the data is what counts. ### What does Managed Kubernetes cost at enum? Compute is billed per hour with optional one to three year commitment discounts. Block storage is billed per GB per month. The HA control plane is included at no per-cluster-hour charge, host-based NAT is included, and load balancing is a flat monthly fee with an IPv4 address included. All prices are in euros and exclude VAT. ### Does enum run upstream Kubernetes or a fork? enum runs upstream, unmodified Kubernetes with no fork, so existing manifests, Helm charts, and GitOps pipelines work without changes. Best-practice tooling is included and kept up to date, with zero-downtime rolling upgrades when new versions are available. ### In which regions does enum operate? enum operates its primary region in Frankfurt, Germany, in a Tier III+ data center, with further European regions on the roadmap. All regions run on enum's own infrastructure and own network (AS215998), inside the European Union. ### Frequently asked questions **What is the best European alternative to AWS?** It depends on your workload. For teams in regulated DACH industries that want hyperscaler-grade Kubernetes, compute, and S3-compatible storage under German jurisdiction without CLOUD Act exposure, enum offers a self-service public cloud operated in Frankfurt by a German GmbH. enum is a platform product, not a consulting engagement. **Which Kubernetes providers are headquartered in Germany?** German-HQ Kubernetes providers include enum (enum GmbH, Cologne, operating in Frankfurt), STACKIT (Schwarz Group), Hetzner, and IONOS. enum is the independent public cloud with its own RIPE-registered network (AS215998) and CNCF Silver membership. **Is enum Kubernetes Engine suitable for NIS2 and DORA workloads?** Yes. enum is a German GmbH operating in a Frankfurt Tier III+ data center under German and EU law, with no US subprocessors and no transatlantic data flows. That structure aligns with NIS2 supply-chain requirements and DORA ICT third-party risk rules. NIS2 and DORA readiness is a structural property of where the company and data sit, not a separate certification. **Is enum object storage S3-compatible?** Yes. enum object storage implements the S3 API, so aws-cli, rclone, s3cmd, the AWS SDKs, and any tool built for S3 work without code changes. Data is erasure-coded across failure domains and stored in Frankfurt. enum bills storage and outgoing traffic, with no per-request or retrieval fees. **Can I migrate from AWS EKS or Google GKE to enum?** Yes. enum runs upstream, unmodified Kubernetes, so standard manifests, Helm charts, and GitOps pipelines port over without code changes. enum object storage is S3-API compatible, so rclone, aws-cli, and S3 SDKs work as-is. Migration support is available if you need help with the cutover. **Does enum offer a Terraform provider?** enum exposes the platform through a self-service CLI (enumctl), a REST API, and Terraform. You can provision clusters, storage, and networking as code with sensible defaults, so infrastructure is reproducible and version-controlled. **What SLA does enum Kubernetes Engine offer?** enum Kubernetes Engine includes a highly available control plane per cluster across independent failure domains, with automatic failover and zero-downtime upgrades, backed by a 99.9% availability SLA. The HA control plane is included at no per-cluster-hour charge. **Is enum suitable for FinTech workloads?** Yes. enum is a German GmbH operating under German and EU law with no US parent and no US subprocessors, which aligns with the jurisdictional expectations of FinTech regulation and DORA. Teams run payment, banking-adjacent, and trading-platform workloads on enum Kubernetes Engine in Frankfurt. **Is enum suitable for HealthTech workloads?** Yes. enum operates in Frankfurt under German and EU law, which covers GDPR and German patient-data requirements. The HA control plane, private-by-default clusters, and EU-only data flows fit HealthTech workloads that cannot tolerate US jurisdiction or transatlantic data transfers. **How is enum different from colocation?** Colocation gives you a rack and power; you bring and operate the hardware, the network, the hypervisor, and Kubernetes. enum is a public cloud: it operates the infrastructure, the network (AS215998), the storage, and the Kubernetes control plane, and exposes them through a self-service API. You run workloads, not hardware. **Who operates enum and where is the data stored?** enum is operated by enum GmbH, registered in Cologne (HRB 121362, VAT DE451942405), founded on 15 November 2024. All infrastructure runs in a Tier III+ data center in Frankfurt, Germany. The company is a CNCF Silver Member, a Linux Foundation member, and a RIPE NCC member operating its own Autonomous System (AS215998). **Is enum subject to the US CLOUD Act?** No. enum GmbH is a German company with no US entity in its corporate structure, so it is not subject to the US CLOUD Act or FISA Section 702. Selecting an EU region at a US-headquartered provider does not remove that exposure, because the corporate jurisdiction of the company holding the data is what counts. **What does Managed Kubernetes cost at enum?** Compute is billed per hour with optional one to three year commitment discounts. Block storage is billed per GB per month. The HA control plane is included at no per-cluster-hour charge, host-based NAT is included, and load balancing is a flat monthly fee with an IPv4 address included. All prices are in euros and exclude VAT. **Does enum run upstream Kubernetes or a fork?** enum runs upstream, unmodified Kubernetes with no fork, so existing manifests, Helm charts, and GitOps pipelines work without changes. Best-practice tooling is included and kept up to date, with zero-downtime rolling upgrades when new versions are available. **In which regions does enum operate?** enum operates its primary region in Frankfurt, Germany, in a Tier III+ data center, with further European regions on the roadmap. All regions run on enum's own infrastructure and own network (AS215998), inside the European Union. ### What is the best European alternative to AWS? It depends on your workload. For teams in regulated DACH industries that want hyperscaler-grade Kubernetes, compute, and S3-compatible storage under German jurisdiction without CLOUD Act exposure, enum offers a self-service public cloud operated in Frankfurt by a German GmbH. enum is a platform product, not a consulting engagement. ### Which Kubernetes providers are headquartered in Germany? German-HQ Kubernetes providers include enum (enum GmbH, Cologne, operating in Frankfurt), STACKIT (Schwarz Group), Hetzner, and IONOS. enum is the independent public cloud with its own RIPE-registered network (AS215998) and CNCF Silver membership. ### Is enum Kubernetes Engine suitable for NIS2 and DORA workloads? Yes. enum is a German GmbH operating in a Frankfurt Tier III+ data center under German and EU law, with no US subprocessors and no transatlantic data flows. That structure aligns with NIS2 supply-chain requirements and DORA ICT third-party risk rules. NIS2 and DORA readiness is a structural property of where the company and data sit, not a separate certification. ### Is enum object storage S3-compatible? Yes. enum object storage implements the S3 API, so aws-cli, rclone, s3cmd, the AWS SDKs, and any tool built for S3 work without code changes. Data is erasure-coded across failure domains and stored in Frankfurt. enum bills storage and outgoing traffic, with no per-request or retrieval fees. ### Can I migrate from AWS EKS or Google GKE to enum? Yes. enum runs upstream, unmodified Kubernetes, so standard manifests, Helm charts, and GitOps pipelines port over without code changes. enum object storage is S3-API compatible, so rclone, aws-cli, and S3 SDKs work as-is. Migration support is available if you need help with the cutover. ### Does enum offer a Terraform provider? enum exposes the platform through a self-service CLI (enumctl), a REST API, and Terraform. You can provision clusters, storage, and networking as code with sensible defaults, so infrastructure is reproducible and version-controlled. ### What SLA does enum Kubernetes Engine offer? enum Kubernetes Engine includes a highly available control plane per cluster across independent failure domains, with automatic failover and zero-downtime upgrades, backed by a 99.9% availability SLA. The HA control plane is included at no per-cluster-hour charge. ### Is enum suitable for FinTech workloads? Yes. enum is a German GmbH operating under German and EU law with no US parent and no US subprocessors, which aligns with the jurisdictional expectations of FinTech regulation and DORA. Teams run payment, banking-adjacent, and trading-platform workloads on enum Kubernetes Engine in Frankfurt. ### Is enum suitable for HealthTech workloads? Yes. enum operates in Frankfurt under German and EU law, which covers GDPR and German patient-data requirements. The HA control plane, private-by-default clusters, and EU-only data flows fit HealthTech workloads that cannot tolerate US jurisdiction or transatlantic data transfers. ### How is enum different from colocation? Colocation gives you a rack and power; you bring and operate the hardware, the network, the hypervisor, and Kubernetes. enum is a public cloud: it operates the infrastructure, the network (AS215998), the storage, and the Kubernetes control plane, and exposes them through a self-service API. You run workloads, not hardware. ### Who operates enum and where is the data stored? enum is operated by enum GmbH, registered in Cologne (HRB 121362, VAT DE451942405), founded on 15 November 2024. All infrastructure runs in a Tier III+ data center in Frankfurt, Germany. The company is a CNCF Silver Member, a Linux Foundation member, and a RIPE NCC member operating its own Autonomous System (AS215998). ### Is enum subject to the US CLOUD Act? No. enum GmbH is a German company with no US entity in its corporate structure, so it is not subject to the US CLOUD Act or FISA Section 702. Selecting an EU region at a US-headquartered provider does not remove that exposure, because the corporate jurisdiction of the company holding the data is what counts. ### What does Managed Kubernetes cost at enum? Compute is billed per hour with optional one to three year commitment discounts. Block storage is billed per GB per month. The HA control plane is included at no per-cluster-hour charge, host-based NAT is included, and load balancing is a flat monthly fee with an IPv4 address included. All prices are in euros and exclude VAT. ### Does enum run upstream Kubernetes or a fork? enum runs upstream, unmodified Kubernetes with no fork, so existing manifests, Helm charts, and GitOps pipelines work without changes. Best-practice tooling is included and kept up to date, with zero-downtime rolling upgrades when new versions are available. ### In which regions does enum operate? enum operates its primary region in Frankfurt, Germany, in a Tier III+ data center, with further European regions on the roadmap. All regions run on enum's own infrastructure and own network (AS215998), inside the European Union. --- ## Pricing Source: https://enum.co/pricing **Transparent • Flexible • No hidden costs** # Transparent Pricing. Pay only for the resources you really use - without hidden fees or surprises. ### Compute | Type | vCPU | RAM | On-Demand (EUR/h) | |---|---|---|---| | gp-1 | 1 | 4 GB | 0.06027 | | gp-2 | 2 | 8 GB | 0.12055 | | gp-4 | 4 | 16 GB | 0.24110 | | gp-8 | 8 | 32 GB | 0.48219 | | gp-12 | 12 | 48 GB | 0.72329 | | gp-16 | 16 | 64 GB | 0.96438 | | gp-32 | 32 | 128 GB | 1.92877 | Commitment discounts: 1 year -10%, 2 years -15%, 3 years -20% ### Storage - **Block Storage**: 0.10 EUR/month / GB / month - **Object Storage (S3 compatible)**: 0.02 EUR/month / GB / month ### Network - **Load Balancer**: 10.00 EUR/month / month - **IPv4 address**: 5.00 EUR/month / month - **IPv6 address**: Included - **Outgoing traffic**: 0.025 EUR/month / GB / month All clusters are private by default. Nodes have no public IP addresses. Ingress runs exclusively through Load Balancers. Outbound runs via host-based NAT, with an optional Cloud NAT Gateway for a stable egress IP. ### Services - **Dedicated Kubernetes Control Plane**: Included highly available - **Support**: Included (working days) - **DevOps as a Service**: Custom professional services *All prices exclude VAT.* --- ## Pricing Calculator Source: https://enum.co/calculator **Pricing Calculator** # Estimate Your Costs Configure your Kubernetes cluster and see real-time pricing. --- ## Security Source: https://enum.co/security **Security by Design** # Security Security is built into enum's architecture from the ground up, from immutable infrastructure to per-customer isolation. enum runs an enterprise-grade security and compliance posture for its European public cloud, on its own infrastructure in an NTT Tier III+ data center in Frankfurt, Germany, under German and EU law with no US CLOUD Act exposure. It covers isolated control planes per customer, immutable node operating systems, and encryption in transit and at rest, aligned with GDPR, NIS2, and DORA. ### Infrastructure Security - **Immutable Infrastructure**: Where possible, systems are not manually modified or patched, but completely redeployed. This reduces the attack surface and eliminates configuration drift. - **Tenant Isolation**: Strict logical isolation between customers at network and compute level. No cross-tenant access. - **VPC & Network Isolation**: Each customer receives a dedicated Virtual Private Cloud with fully separated address space at Layer 2 and Layer 3. - **European Infrastructure**: Own servers in Germany. No US cloud provider. No US Cloud Act. - **Container Image Security**: Automated vulnerability scanning of all container images. - **Supply Chain Security**: Signed artifacts, verified base images, traceable build pipelines. ### Physical Security - **Tier III+ Data Center**: Frankfurt, redundant power and cooling systems. - **24/7 Access Control**: Physical access controlled and logged. - **Environmental Monitoring**: Temperature, humidity, smoke, continuously monitored. ### Data Protection - **Encryption at Rest**: Storage layer and all node disks fully encrypted. - **European Data Sovereignty**: GDPR is built into the architecture: no data processing outside the EU, no US dependencies, no CLOUD Act exposure. - **Data Residency**: Data does not leave Europe. Full control over storage location. ### Access Management - **OIDC-Based Access**: Infrastructure access via OpenID Connect. - **RBAC**: Fine-grained, role-based access control. - **Multi-Factor Authentication**: 2FA/MFA at all levels. FIDO2 hardware keys as standard. - **Audit Logs**: Traceability of security-relevant access and changes across all platform components. ### Monitoring & Response - **24/7 Monitoring**: Continuous monitoring of the entire platform infrastructure with automated alerts. - **Network Visibility & Anomaly Detection**: Network anomaly detection based on flow data. Automated alerts for suspicious traffic patterns. - **Incident Response**: Defined incident response procedures. Direct communication in case of emergency. Post-incident analysis and documentation. ### Compliance & Certifications What enum fulfills and where data center certifications apply. ### Security Contact Do you have security questions or want to report a vulnerability? Our security team is here for you. Email: security@enum.co security.txt: Security.txt ### Responsible Disclosure The security of our platform and our customers' data is our highest priority. We value the work of security researchers and the community who help us identify and fix vulnerabilities. #### Scope **In-Scope** - enum Cloud Platform (*.enum.co, *.enum.cloud) - enum API and Console - enum Kubernetes Engine, enum Object Storage, enum Compute, enum Network, enum VPC, enum Cloud DNS, enum CDN, enum Cloud WAF - Network infrastructure and edge components **Out-of-Scope** - Social engineering, phishing or physical attacks - Denial-of-Service attacks (DoS/DDoS) - Spam or mass registrations - Vulnerabilities in third-party software not operated by enum - Vulnerabilities requiring physical access to devices or infrastructure #### Rules - If you encounter customer data during testing, stop immediately and report the vulnerability. - Do not perform any actions that could affect the availability of our services. - You may only interact with accounts you own or with explicit written permission. - Do not disclose vulnerability details before we have fixed the issue and given you clearance. - We ask that you report vulnerabilities promptly after discovery. - No stunt hacking, no extortion, no leverage. #### Our Promise - We consider good-faith security research to be authorized activity, even if it technically violates our terms of service. - We will acknowledge receipt of your report within 48 hours. - We will keep you updated on the status of the fix. - We will not take legal action against you as long as you comply with this policy. - We compensate reported vulnerabilities. The amount depends on severity and report quality. We will inform you on a case-by-case basis. #### Reporting Please report vulnerabilities via email to: security@enum.co **Please include in your report:** - Description of the vulnerability - Steps to reproduce - Affected systems or endpoints - Potential impact (assessment) - Proof of Concept if available (screenshots, logs, code) If possible, encrypt your email with our PGP key: --- ## About Source: https://enum.co/about # Cloud for Europe. **About enum** enum is a European public cloud platform. Founded in Cologne, operated in Frankfurt. Sovereign infrastructure and technical excellence - for us, that's not a contradiction. ### Services - **Frankfurt, DE**: Data center location. Tier III+. ISO 27001. - **CNCF Silver Member**: Linux Foundation Member. RIPE NCC Member. - **100% European**: No US dependencies. No CLOUD Act. No fine print. ### Why enum exists. European companies face a false choice: US hyperscalers with technical excellence but no data sovereignty. Or European providers with a privacy pitch but products at hoster level. We don't accept that choice. enum delivers both - hyperscaler-level infrastructure and European data sovereignty. Because Europe deserves both. ### Founder Max Heyer, Founder Max Heyer founded enum to give European teams public cloud infrastructure that runs under EU law, in Frankfurt, with no US dependencies. enum brings together enum Kubernetes Engine for Managed Kubernetes, S3-compatible Object Storage, and VPC Networking on one platform. ### What we stand for. - **Direct & Honest**: Straight talk. With customers, within the team, in the docs. If something won't work, we say so. If something takes time, we say how long. No diplomatic packaging. - **Sustainable Work**: Infrastructure that still stands in five years. No quick fixes, no tech debt we pass on to customers. The easy way out is never the right one. - **Responsibility**: We run the stack your product runs on. We take that personally. At 3 AM, your problem is our problem. Ownership, not ticket ping-pong. - **Courage**: We say what we think, even when it's uncomfortable. We challenge an industry that got used to US monopolies. Europe can do better, and we're proving it. - **Sovereignty**: No US dependencies. No CLOUD Act. Your data belongs to you - legally and technically. That's not a marketing claim, that's the architecture. - **Focus**: Less, but done right. No feature bloat, no trying to be everything. Rather three products that deliver than twenty that half-work. --- ## Contact Source: https://enum.co/contact # Talk to Us. Questions about enum, pricing, or enterprise needs? Our team is here to help. ### Location enum GmbH Kaiser-Wilhelm-Ring 3-5 50672 Cologne ### Video call 30 minute meet ### Email Response within 24h ### Lightning-Fast Responses We answer all inquiries within 24 hours. No waiting, no delays - just the support you need when you need it. ### Find us in the heart of Europe enum GmbH Kaiser-Wilhelm-Ring 3-5 50672 Cologne --- ## Privacy Source: https://enum.co/privacy # Privacy We are very pleased about your interest in our company. Data protection is of particular importance for the management of enum GmbH. The use of the internet pages of enum GmbH is possible without any indication of personal data; however, if a data subject wants to use special enterprise services via our website, processing of personal data could become necessary. If the processing of personal data is necessary and there is no statutory basis for such processing, we generally obtain consent from the data subject. The processing of personal data, such as the name, address, e-mail address, or telephone number of a data subject shall always be in line with the General Data Protection Regulation (GDPR), and in accordance with the country-specific data protection regulations applicable to enum GmbH. By means of this data protection declaration, our enterprise would like to inform the general public of the nature, scope, and purpose of the personal data we collect, use and process. Furthermore, data subjects are informed, by means of this data protection declaration, of the rights to which they are entitled. As the controller, enum GmbH has implemented numerous technical and organizational measures to ensure the most complete protection of personal data processed through this website. However, Internet-based data transmissions may in principle have security gaps, so absolute protection may not be guaranteed. For this reason, every data subject is free to transfer personal data to us via alternative means, e.g. by telephone. ### 1. Definitions The data protection declaration of enum GmbH is based on the terms used by the European legislator for the adoption of the General Data Protection Regulation (GDPR). Our data protection declaration should be legible and understandable for the general public, as well as our customers and business partners. To ensure this, we would like to first explain the terminology used. ### 2. Name and Address of the controller Controller for the purposes of the General Data Protection Regulation (GDPR), other data protection laws applicable in Member states of the European Union and other provisions related to data protection is: ### 3. Cookies The Internet pages of enum GmbH use cookies. Cookies are text files that are stored in a computer system via an Internet browser. Many Internet sites and servers use cookies. Many cookies contain a so-called cookie ID. A cookie ID is a unique identifier of the cookie. It consists of a character string through which Internet pages and servers can be assigned to the specific Internet browser in which the cookie was stored. This allows visited Internet sites and servers to differentiate the individual browser of the dats subject from other Internet browsers that contain other cookies. A specific Internet browser can be recognized and identified using the unique cookie ID. Through the use of cookies, enum GmbH can provide the users of this website with more user-friendly services that would not be possible without the cookie setting. By means of a cookie, the information and offers on our website can be optimized with the user in mind. Cookies allow us, as previously mentioned, to recognize our website users. The purpose of this recognition is to make it easier for users to utilize our website. The website user that uses cookies, e.g. does not have to enter access data each time the website is accessed, because this is taken over by the website, and the cookie is thus stored on the user's computer system. Another example is the cookie of a shopping cart in an online shop. The online store remembers the articles that a customer has placed in the virtual shopping cart via a cookie. The data subject may, at any time, prevent the setting of cookies through our website by means of a corresponding setting of the Internet browser used, and may thus permanently deny the setting of cookies. Furthermore, already set cookies may be deleted at any time via an Internet browser or other software programs. This is possible in all popular Internet browsers. If the data subject deactivates the setting of cookies in the Internet browser used, not all functions of our website may be entirely usable. ### 4. Collection of general data and information The website of enum GmbH collects a series of general data and information when a data subject or automated system calls up the website. This general data and information are stored in the server log files. Collected may be (1) the browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system reaches our website (so-called referrers), (4) the sub-websites, (5) the date and time of access to the Internet site, (6) an Internet protocol address (IP address), (7) the Internet service provider of the accessing system, and (8) any other similar data and information that may be used in the event of attacks on our information technology systems. When using these general data and information, enum GmbH does not draw any conclusions about the data subject. Rather, this information is needed to (1) deliver the content of our website correctly, (2) optimize the content of our website as well as its advertisement, (3) ensure the long-term viability of our information technology systems and website technology, and (4) provide law enforcement authorities with the information necessary for criminal prosecution in case of a cyber-attack. Therefore, enum GmbH analyzes anonymously collected data and information statistically, with the aim of increasing the data protection and data security of our enterprise, and to ensure an optimal level of protection for the personal data we process. The anonymous data of the server log files are stored separately from all personal data provided by a data subject. ### 5. Contact possibility via the website The website of enum GmbH contains information that enables a quick electronic contact to our enterprise, as well as direct communication with us, which also includes a general address of the so-called electronic mail (e-mail address). If a data subject contacts the controller by e-mail or via a contact form, the personal data transmitted by the data subject are automatically stored. Such personal data transmitted on a voluntary basis by a data subject to the data controller are stored for the purpose of processing or contacting the data subject. There is no transfer of this personal data to third parties. ### 6. Routine erasure and blocking of personal data The data controller shall process and store the personal data of the data subject only for the period necessary to achieve the purpose of storage, or as far as this is granted by the European legislator or other legislators in laws or regulations to which the controller is subject to. If the storage purpose is not applicable, or if a storage period prescribed by the European legislator or another competent legislator expires, the personal data are routinely blocked or erased in accordance with legal requirements. ### 8. Data protection for applications and the application procedures The data controller shall collect and process the personal data of applicants for the purpose of the processing of the application procedure. The processing may also be carried out electronically. This is the case, in particular, if an applicant submits corresponding application documents by e-mail or by means of a web form on the website to the controller. If the data controller concludes an employment contract with an applicant, the submitted data will be stored for the purpose of processing the employment relationship in compliance with legal requirements. If no employment contract is concluded with the applicant by the controller, the application documents shall be automatically erased two months after notification of the refusal decision, provided that no other legitimate interests of the controller are opposed to the erasure. Other legitimate interest in this relation is, e.g. a burden of proof in a procedure under the General Equal Treatment Act (AGG). ### 9. Legal basis for the processing Art. 6(1) lit. a GDPR serves as the legal basis for processing operations for which we obtain consent for a specific processing purpose. If the processing of personal data is necessary for the performance of a contract to which the data subject is party, as is the case, for example, when processing operations are necessary for the supply of goods or to provide any other service, the processing is based on Article 6(1) lit. b GDPR. The same applies to such processing operations which are necessary for carrying out pre-contractual measures, for example in the case of inquiries concerning our products or services. Is our company subject to a legal obligation by which processing of personal data is required, such as for the fulfillment of tax obligations, the processing is based on Art. 6(1) lit. c GDPR. In rare cases, the processing of personal data may be necessary to protect the vital interests of the data subject or of another natural person. This would be the case, for example, if a visitor were injured in our company and his name, age, health insurance data or other vital information would have to be passed on to a doctor, hospital or other third party. Then the processing would be based on Art. 6(1) lit. d GDPR. Finally, processing operations could be based on Article 6(1) lit. f GDPR. This legal basis is used for processing operations which are not covered by any of the abovementioned legal grounds, if processing is necessary for the purposes of the legitimate interests pursued by our company or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data. Such processing operations are particularly permissible because they have been specifically mentioned by the European legislator. He considered that a legitimate interest could be assumed if the data subject is a client of the controller (Recital 47 Sentence 2 GDPR). ### 10. The legitimate interests pursued by the controller or by a third party Where the processing of personal data is based on Article 6(1) lit. f GDPR our legitimate interest is to carry out our business in favor of the well-being of all our employees and the shareholders. ### 11. Period for which the personal data will be stored The criteria used to determine the period of storage of personal data is the respective statutory retention period. After expiration of that period, the corresponding data is routinely deleted, as long as it is no longer necessary for the fulfillment of the contract or the initiation of a contract. ### 12. Provision of personal data as statutory or contractual requirement; Requirement necessary to enter into a contract; Obligation of the data subject to provide the personal data; possible consequences of failure to provide such data We clarify that the provision of personal data is partly required by law (e.g. tax regulations) or can also result from contractual provisions (e.g. information on the contractual partner). Sometimes it may be necessary to conclude a contract that the data subject provides us with personal data, which must subsequently be processed by us. The data subject is, for example, obliged to provide us with personal data when our company signs a contract with him or her. The non-provision of the personal data would have the consequence that the contract with the data subject could not be concluded. Before personal data is provided by the data subject, the data subject must contact any employee. The employee clarifies to the data subject whether the provision of the personal data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the personal data and the consequences of non-provision of the personal data. ### 13. Existence of automated decision-making As a responsible company, we do not use automatic decision-making or profiling. ### 7. Rights of the data subject --- ## Imprint Source: https://enum.co/imprint # Imprint Information according to § 5 TMG **enum GmbH** Kaiser-Wilhelm-Ring 3-5 50672 Cologne Commercial register: HRB 121362 Register court: Amtsgericht Köln VAT ID: DE451942405 Represented by: Max Heyer, Founder ### Contact E-Mail: mail@enum.co --- ## Network Source: https://enum.co/network **Our Network** # The enum network. Own Autonomous System, direct peering at European Internet Exchanges, edge presence in four European cities. This is what separates a cloud provider from a reseller. ### Built for Resilience from the Ground Up Redundancy is built into the network at every layer. Our network is designed for resilience from the ground up. Multiple independent carriers. Automatic failover at the BGP level. No single point of failure between your application and the internet. When an upstream fails, our network reroutes traffic automatically. No manual intervention, no downtime. - **Multi-Homing & Multi-Path**: Multiple carriers active simultaneously, multiple paths per provider. If one fails, the others take over. Automatically. - **BGP Failover**: Routing decisions in seconds, not hours. Our network reacts before your users notice. - **Redundant Paths**: Every packet has multiple paths to its destination. No single provider, no single cable is a risk. ### Anycast Network. One IP address. Multiple locations. Traffic is automatically routed to the nearest PoP. Our Anycast network distributes DNS queries and content delivery across multiple European locations. Every request is automatically routed to the geographically nearest Point of Presence. The result: Lower latency, higher availability, better performance. Edge PoPs in Amsterdam, Stockholm, and Warsaw launch in Q3 2026. Frankfurt is live today. - **Cloud DNS**: Anycast-based DNS resolution at multiple European locations. Sub-10ms response times for most of Europe. - **CDN**: Content delivery via edge PoPs in Frankfurt, Amsterdam, Stockholm, and Warsaw. Static assets close to your users. - **Automatic Failover**: If a PoP goes down, Anycast routes traffic automatically to the next location. No manual intervention needed. ### European Jurisdiction. End to End. No data processing outside the EU. No CLOUD Act. No compromises. enum is a German company with its own infrastructure in European data centers. Our network operates via its own Autonomous System, registered with RIPE NCC. This is not a retroactive localization option. This is the architecture. For companies under NIS2, DORA, or KRITIS requirements, this means: Every component of your cloud infrastructure is verifiably European. From the server to BGP announcement. - German company - Own AS, own IP ranges from RIPE inventory - NTT Frankfurt: ISO 27001, ISO 9001, EN50600 - No reselling, no US cloud provider **What does it mean that enum operates its own Autonomous System?** enum is registered as AS215998 with RIPE NCC. We control our own IP address ranges and routing decisions. Traffic takes the path we choose, not the path a transit provider forces on us. We can switch carriers without any IP address changing. **Where does enum have network presence?** The primary region is in Frankfurt, Germany, in a Tier III+ datacenter with ISO 27001 and EN50600 certification. Edge PoPs for Cloud DNS and CDN are coming in Q3 2026 in Amsterdam, Stockholm, and Warsaw. Berlin is planned as a full second region. **Is enum's network compliant with NIS2 and DORA requirements?** enum is a German GmbH operating entirely within the EU. No data processing leaves European jurisdiction. No CLOUD Act exposure. Every component, from the server to the BGP announcement, is verifiably European. This makes enum suitable for organizations under NIS2, DORA, or KRITIS obligations. **Can I verify enum's network on PeeringDB?** Yes. AS215998 is publicly listed on PeeringDB. You can verify our peering relationships, IP ranges, and network details there at any time. --- ## Roadmap Source: https://enum.co/roadmap **Roadmap** # What we're building. See what's coming. No marketing fluff, just our engineering priorities. ### 2024-2026: Foundation Building (Shipped) ### Q1 (Shipped) - S3 Versioning (Object Storage) - S3 Lifecycle (Object Storage) - S3 Server-Side Encryption (SSE-C) (Object Storage) - S3 CORS (Object Storage) - S3 Object Lock (Object Storage) - API (Developer Experience) - enumctl (Developer Experience, Preview) - Machine Types (Kubernetes) - Startup Program (Platform) ### Q2 (In Progress) - enumctl (Developer Experience) ### Q3 (Planned) - European Edge Network (Networking) - Cloud DNS (Networking, Preview) - CDN (Networking, Preview) - Cloud WAF (Networking, Preview) - Virtual Private Cloud (Networking, Preview) - Terraform Provider (Developer Experience) - IAM (Platform, Preview) - Console (Platform, Preview) - Container Registry (Platform) - Standalone Cloud Compute (Compute, Preview) ### Q4 (Planned) - CDN (Networking) - Cloud WAF (Networking) - Cloud DNS (Networking) - Virtual Private Cloud (Networking) - IAM (Platform) - Console (Platform) - Standalone Cloud Compute (Compute) - Database as a Service (Platform, Preview) - AI Agent Runtime (Platform, Preview) - ISO 27001 Certification (Compliance) ### 2027: Europe's AI backbone (Planned) - BSI C5 Certification (Compliance) --- ## Changelog Source: https://enum.co/changelog **Changelog** # What's New Stay up to date with the latest updates, features, and improvements to the enum cloud platform. ### Object Storage Sync, enumctl 2026.06.4 (2026-06-25) ## Object Storage - Object storage buckets created directly against the S3 API (for example with `aws s3`) now sync into enum and appear alongside buckets created through enum ## enumctl 2026.06.4 - Check for newer enumctl releases and print a hint on run; `enumctl --version` does an explicit check - `object-storage users` and `object-storage buckets` commands now take positional args instead of flags - Rename the `--display-name` flag to `--name` ## API - Deprecate the `displayName` parameter for creating object storage users in favor of `name` ## SDKs - Node.js SDK: object storage resource status `active` is renamed to `ready` - Node.js SDK: drop the legacy initial access key and the `revoked_at` field from object storage types ### Go SDK (2026-06-08) ## SDKs - Release the Go SDK for the enum API: `go get github.com/enumco/client-go` - Manage organizations, projects, Kubernetes clusters, and object storage from Go ### enumctl 2026.06.1, Object Storage Updates (2026-06-05) ## Object Storage - Project and bucket quotas are soft limits that support can raise within minutes ## enumctl 2026.06.1 - Add commands to list, create, and delete object storage buckets - Add delete for object storage keys and users - Drop the required organization ID from projects list - Add a Nix install option, alongside the existing Homebrew and AUR (Arch Linux) packages ## API and SDKs - Manage object storage buckets from the Node.js SDK - Return bucket status from the API ### Object Storage Buckets (2026-04-28) ## Object Storage - Create, list, and delete object storage buckets through the API, without a separate S3 client ### enumctl 2026.04.5, Object Storage Updates, API Launch (2026-04-14) ## enumctl 2026.04.5 - Add support to manage object storage users and keys - Add support to manage organizations and projects - Fix token refresh during re-authentication - Add homebrew support ## enum Object Storage - Add support for CORS - Add support for object locks - Add support for lifecycle policies - Add support for versioning - Add support for SSE-C ## API - Add support for object storage - Add public docs - Release node.js SDK ### Price Calculator Launch (2026-03-20) ## Platform - New interactive Pricing Calculator to estimate monthly costs before provisioning ### Startup Program Launch (2026-01-10) ## Platform - The enum Startup Program is now open for applications - Eligible startups receive platform credits and dedicated onboarding support - Apply at enum.co/startups --- ## Customers Source: https://enum.co/customers **Customers** # You're in good company. European teams running real production workloads on enum. --- ## Customer: scanmetrix Source: https://enum.co/customers/scanmetrix # Migrated in one week. Stable in production since the migration. scanmetrix runs its facility management platform for 32+ tenants on enum Kubernetes Engine in Frankfurt. Kubernetes, S3, and networking operate under German jurisdiction. ### Stats - **99.95%**: Availability since the migration - **-95%**: Load time for tenant APIs and S3 queries - **< 5 min**: Tenant onboarding (before: hours) - **300+**: S3 buckets, millions of requests per day ### The company scanmetrix is a German SaaS company that builds an ERP platform for facility management and technical service providers. The company has been in the market for more than seven years and works with FM companies, refrigeration and HVAC businesses, cleaning services, and security companies across Germany. The platform covers dispatch planning, maintenance management, contract management, billing with DATEV integration, an offline-capable tablet app for technicians, and AI-assisted maintenance predictions. ### The challenge - With the previous German provider, Kubernetes and S3 availability sat at 97% despite managed Kubernetes. - Networking behaved unpredictably and forced long debugging sessions. - The multi-tenant architecture did not scale cleanly. - Some days brought several incidents, eating into development time. ### Why enum - **Direct access to engineers**: No support loops through sales or first-level teams. scanmetrix talks directly to enum engineers who can debug, decide, and fix the issue. Debugging sessions shrink from days to hours. - **Upstream Kubernetes**: Manifests, Helm Charts, and GitOps pipelines ran without changes. No proprietary APIs, no provider-specific workarounds. Teams that know standard Kubernetes can work in production on enum. - **Kubernetes knowledge from production**: enum has run Kubernetes in production for years, not as a marketing label. The team knows pod disruption budgets, storage classes, and network policies from real operating cases. That matters when something has to be debugged under load. - **Scales across Kubernetes and S3**: Kubernetes workloads and S3 storage scale independently. New tenants mean new namespaces, not rearchitecting. scanmetrix can grow without redesigning the platform at every step. - **Hands-on migration support**: enum worked through the migration directly instead of just handing over access. The move took one week, including S3 data transfer and DNS cutover. The seven-person scanmetrix team could keep building product instead of managing the migration alone. - **S3 as a product, not an add-on**: 300+ buckets and millions of requests per day need more than attached storage. At enum, S3, routing, and latency work together cleanly. Object Storage gets the same care as Kubernetes. - **Billing in euros**: Costs are clear, billed in euros, and tied to actual usage. No currency swings, no hidden line items. For a small team, that is easier to plan than a cloud bill that looks different every month. - **A platform team that thinks with you**: enum thinks through architecture decisions instead of just forwarding tickets. Recommendations come early, not after several escalations. That shortens the path from problem to fix. ### Architecture What runs on enum and how the parts work together. Each tenant runs up to 10 services and multiple S3 buckets. - **enum Kubernetes Engine**: One cluster with 32+ tenant namespaces, clean isolation, and production workloads. - **enum Object Storage (S3)**: 300+ buckets for service reports, photos, and compliance artifacts. - **enum Networking**: Ingress and load balancing. - **ArgoCD**: GitOps deployments for all tenant namespaces. ### Results - 99.95% availability since the migration, after 97% at the previous provider. - Load time for tenant APIs and S3 queries reduced by 95%. - Tenant onboarding from hours to under 5 minutes. - Multi-tenancy simplified: one cluster with clean namespace isolation. - Monitoring expanded into a standardized observability stack together with enum. - The seven-person team builds product instead of infrastructure. - All data stays in Frankfurt, GDPR-native and without US dependencies. ### Self-service without a helpdesk On top of enum, scanmetrix built its own tenant manager and connected it to ArgoCD. Signup, namespace provisioning, and instance booking are automated. scanmetrix customers can sign up in self-service today and book their own instance within minutes, without anyone at scanmetrix touching the process. > At enum, real engineers worked through the migration with us directly. Since the switch, we can sleep through the night again. Infrastructure that simply runs was exactly what we wanted. - Jack Hull, CTO, scanmetrix ### Sovereignty as an enabler scanmetrix is preparing for ISO 27001 certification and uses enum's German infrastructure as its compliance foundation. For scanmetrix, German jurisdiction is not a checkbox. It is a sales argument with customers in regulated industries. ### What's next scanmetrix is adding scanmetrix Cortex, an AI assistant, plus new modules for ESG reporting and predictive maintenance. enum remains the technical base for that work. --- ## Customer: meinMPP Source: https://enum.co/customers/meinmpp # meinMPP runs its platform without an internal DevOps team. meinMPP runs its employee PC program on enum Kubernetes Engine. enum handles operations, from CI/CD to 24/7 on-call, in Frankfurt under German jurisdiction. ### Stats - **< 15 min**: Incident response (down from up to 12h) - **0**: internal DevOps team - **End to end**: operations by enum - **Enterprise**: ready for HR data ### The company meinMPP runs the Employee PC Program (MPP), a state-supported tech benefit for employers. Employees lease private tech of their choice through salary sacrifice, roughly 30% cheaper than buying it outright, including full protection. For employers, the program is free and mostly automated. Employers from startups to enterprise companies offer it to their teams. The product includes a public-facing shop with 2,000+ products, self-managed employee budgets, automated payroll exports, and HR integrations. ### The challenge - Operations sat with an agency and external providers. During incidents, meinMPP sometimes waited up to 12 hours for a response. - Enterprise customers ask for German hosting, clear contracting parties, and solid GDPR paperwork. - The public-facing shop has to absorb traffic peaks when large customers roll out the program across their organizations. - Payroll exports and HR integrations have to be right because mistakes flow straight into payroll. - The team was stuck in incidents instead of building the product and platform. ### Why enum - **Full operation instead of an internal team**: enum handles CI/CD, monitoring, alerting, and 24/7 on-call with an SLA. meinMPP gets the operating model of an internal DevOps team without building one. - **One accountable partner**: Before, the agency, operations, and external providers were split apart. During incidents, that led to finger-pointing and waiting. With enum, the platform, operations, and 24/7 on-call sit with one partner under one SLA. - **Direct access to the engineers who run it**: meinMPP talks directly to the engineers operating the platform, not a first-level queue. That is why response time went from hours to minutes. - **Frankfurt, German jurisdiction**: HR and compliance teams ask about data location, contracting party, and legal jurisdiction. enum gives meinMPP Frankfurt, a German GmbH, and GDPR-native infrastructure. That makes enterprise sales conversations easier. - **Built for payroll-critical workloads**: Payroll exports feed real salary runs. Errors are expensive. enum monitors the platform and catches issues before they reach payroll. - **Fire-and-forget scaling**: Traffic peaks happen when large customers roll out the program across their organizations. For meinMPP, scaling is fire and forget: the team scales the product and software, enum scales the platform and plans capacity ahead of demand. ### Operations: DevOps as a Service enum runs the platform end to end, like an internal DevOps team: - Development environment and CI/CD pipelines - Platform operations on enum Kubernetes Engine - Observability and monitoring - Alerting and 24/7 on-call with SLA - Incident response under 15 minutes - Auto-scaling for traffic peaks during enterprise rollouts - Updates, patching, and security - Backups ### Architecture What runs on enum and how the parts work together. - **enum Kubernetes Engine**: One cluster in Frankfurt for the platform backend and online shop. - **enum Object Storage (S3)**: Product images, customer documents, and artifacts. - **enum Networking**: Ingress and load balancing in Frankfurt. - **GitOps**: Declarative deployments via standard Kubernetes tooling. ### Results - Incident response reduced from up to 12 hours to under 15 minutes. - 24/7 on-call with SLA, operated by enum. - Traffic peaks during enterprise rollouts are absorbed automatically. - Employees order tech through the public-facing shop, whether they work at startups or enterprise companies. - HR teams get automated payroll exports instead of manual follow-up. - All data stays in Frankfurt, under German jurisdiction and without US dependencies. - meinMPP runs the platform without an internal DevOps team. > enum gave us a platform team without us having to hire one. We focus on our product, not Kubernetes. - Dominik Albers, Founder, meinMPP ### Sovereignty as an enabler Enterprise customers want verifiable German hosting. enum provides Frankfurt, German jurisdiction, and GDPR-native infrastructure. For meinMPP, that is not a checkbox. It is a sales argument with HR and compliance teams. ### What's next meinMPP is adding new product categories and HR integrations. enum remains the technical base. --- ## Customer: BasePeak Source: https://enum.co/customers/basepeak # Sovereign Cloud and AI, built on enum from day one. BasePeak runs its sovereign AI platform, BasePeak.AI and BasePeak.WORK, on enum Kubernetes Engine in Frankfurt. From the first commit, under German jurisdiction, for public administration and regulated industries. ### Stats - **Day 1**: Built on enum since the first day. - **100%**: Open-source based stack - **2**: products on one sovereign base - **0**: US dependencies, all data under German jurisdiction ### The company BasePeak is a German startup building sovereign AI infrastructure for organisations that cannot send data to US clouds. Its two products, BasePeak.AI and BasePeak.WORK, form a workspace where people and AI agents collaborate, built on open source and running as SaaS or on-premise. The company was founded by Thorsten Klein, who worked on k3s at Rancher Labs and created k3d. Customers include public administration, such as the city of Dormagen, and regulated enterprises. ### The challenge - Sovereign AI is only as trustworthy as the infrastructure underneath it. A German AI platform on a US-headquartered cloud undermines the promise. - Regulated and public-sector customers require verifiable German hosting, a German contracting party, and no US CLOUD Act exposure. For them it is a sales argument, not a checkbox. - As a startup, BasePeak had no legacy to migrate and no team to spare on operating infrastructure. The platform had to be production-ready from day one. - AI workloads demand predictable compute, storage for large knowledge bases, and low-latency networking between agents, models, and integrations. ### Why enum - **Sovereignty that matches the product**: BasePeak sells sovereign AI. enum provides the sovereign base: Frankfurt, a German GmbH, German and EU law only, no US parent, no CLOUD Act. The infrastructure and the product tell the same story. - **Built greenfield, no migration tax**: Because BasePeak started on enum, there was nothing to migrate. No re-platforming, no data-residency workarounds, no dual-running. The team spent its first weeks building product, not moving it. - **CNCF-conformant upstream Kubernetes**: BasePeak is built on open source and values portability. enum runs CNCF-conformant upstream Kubernetes with standard manifests, Helm, and GitOps, with no proprietary APIs. What runs on enum runs anywhere. - **NVMe storage fast enough to self-host S3**: BasePeak runs its own Garage S3 cluster on enum Kubernetes Engine, on top of enum's NVMe-backed block storage. Performance is great, so the team gets sovereign, self-controlled object storage without giving up speed. - **Direct access to engineers**: As a small team, BasePeak talks directly to the engineers who run the platform. No first-level queue, no ticket loops. Decisions and fixes happen in the same conversation. - **enum for Startups**: BasePeak joined the enum for Startups program, which brings cloud credits and conditions tailored to early-stage European teams. That lowered the barrier to building on sovereign infrastructure from day one. - **Predictable, euro-denominated billing**: For a startup, a cloud bill that swings with currency and hidden line items is a planning problem. enum bills in euros, tied to real usage, so costs are forecastable. ### Architecture What runs on enum and how the parts fit together. - **enum Kubernetes Engine**: Runs BasePeak.AI and the self-hosted Garage S3 cluster in Frankfurt, scaling with complex multi-tenant application deployments. BasePeak.WORK will launch on the same base. - **enum NVMe Block Storage**: NVMe-backed block storage delivering high performance for the Garage S3 cluster and AI workloads. - **Garage (self-hosted S3)**: BasePeak's own S3-compatible storage for knowledge bases, documents, and artifacts, running on enum Kubernetes Engine. - **enum Networking**: Ingress and low-latency routing between agents, models, and integrations. ### Results - A sovereign AI platform live in production, built on enum from the first commit, with no migration and no legacy cloud. - Sovereignty as a sales argument: Frankfurt hosting and German jurisdiction open doors with public administration and regulated enterprises. - A self-hosted Garage S3 cluster on enum Kubernetes Engine, with great NVMe storage performance, grounding AI answers in knowledge bases and artifacts. - An open-source stack on CNCF-conformant upstream Kubernetes, fully portable. - A small team focused on product, with infrastructure operated by a partner that thinks with them. - All data stays in Frankfurt, under German jurisdiction, with no US dependencies. > I worked on k3s at Rancher Labs and created k3d, so I know what good Kubernetes looks like. enum stands out: CNCF-conformant, upstream Kubernetes, done exceptionally well. - Thorsten Klein, Founder, BasePeak ### Sovereignty as an enabler BasePeak's customers, public administration and regulated industries, choose it because data stays under European control. enum provides the foundation: Frankfurt, a German GmbH, and GDPR-native infrastructure with no US CLOUD Act exposure. For BasePeak, sovereignty is not a checkbox. It is the product. ### What's next BasePeak is expanding BasePeak.AI across more public-sector and regulated customers and preparing the launch of BasePeak.WORK, with new agents, integrations, and the BasePeak Exchange for sharing them. enum remains the sovereign base underneath. --- ## Blog Source: https://enum.co/blog **Blog** # The enum blog News, engineering notes, and product updates from the team behind the European public cloud platform. ### Posts - **How to ransomware-proof S3 backups with Object Lock** (2026-04-30) S3 Object Lock turns your bucket into write-once storage. Even with valid credentials, ransomware can't delete what's locked. Here's how it works on enum. --- ## Blog: How to ransomware-proof S3 backups with Object Lock Source: https://enum.co/blog/object-lock-ransomware Published: 2026-04-30 | Author: Max Heyer S3 Object Lock turns your bucket into write-once storage. Even with valid credentials, ransomware can't delete what's locked. Here's how it works on enum. The modern ransomware playbook ends with a step most teams haven't planned for: before encrypting production, the attackers kill your backups. They log into your S3 bucket with credentials pulled from a developer's machine and delete the recovery objects. Or, worse, they overwrite them with garbage, wait for the corruption to replicate to your offsite copy, then trigger the encryption. Your tested restore procedure now restores poison. If your bucket trusts whoever holds the API key to delete or overwrite, your backups aren't backups. They're a liability with a versioning history. That's the problem S3 Object Lock solves. ## The S3 default isn't enough A standard S3 bucket has two delete behaviors. With versioning off, a `DELETE` removes the object permanently. With versioning on, a `DELETE` creates a delete marker. The object is still there, hidden, but anyone with `s3:DeleteObjectVersion` can remove it for good. Both behaviors require nothing more than valid credentials. If an attacker has your access keys, they have your backups. You can mitigate this with separate credentials, scoped IAM policies, MFA delete, separate accounts. All of those help. None of them are sufficient. Your protection still lives at the credential layer, exactly the layer attackers spend their time compromising. Object Lock moves the protection somewhere they can't reach: the storage layer itself. ## What Object Lock does S3 Object Lock implements a **Write-Once-Read-Many** model on top of the standard S3 API. Once an object version is locked, it cannot be deleted or overwritten until its retention period expires. Not by the bucket owner. Not by an admin. Not by anyone. Two mechanisms: **Retention period.** A timestamp on the object version. Until that timestamp passes, the object is immutable. You can extend it. Depending on the mode, you cannot shorten it. **Legal hold.** A binary flag with no expiry. While set, the object can't be deleted. Used for litigation hold, regulatory investigations, anything that needs indefinite immutability. Two prerequisites: 1. **Versioning must be enabled.** Object Lock locks specific object _versions_, not object names. Without versioning, the concept doesn't apply. 2. **Object Lock must be enabled at bucket creation.** You can't retroactively enable it on an existing bucket. Provision your buckets with Object Lock from day one. Migrating later means copying every object to a new bucket, which gets painful fast. ## Governance Mode vs Compliance Mode Object Lock has two modes, and the choice matters more than most teams realize. **Governance Mode.** Objects are locked, but a principal with the `s3:BypassGovernanceRetention` permission can override the lock. Useful for "we want immutability, but we need an emergency escape hatch." **Compliance Mode.** Objects are locked. Period. No principal, including the root account, can delete the object or shorten its retention until the period expires. If you're using Object Lock as ransomware protection, only Compliance Mode counts. Governance Mode protects against operator error. Compliance Mode protects against attackers who fully own your account. The trade-off is real: in Compliance Mode, a fat-fingered retention policy ("oops, 10 years instead of 10 days") costs you storage you can't reclaim until the timer runs out. The right answer for most workloads is 14 to 30 days for routine backups, with longer windows reserved for explicit regulatory requirements. A common failure mode: teams default to Governance Mode "just in case," then never enforce restrictions on the bypass permission. That's worse than no Object Lock at all. It provides the feeling of safety without the protection. ## Setting it up on enum enum's object storage is fully Object Lock compatible. Same API surface as AWS S3, same semantics. Create a bucket with Object Lock enabled: ```bash enumctl storage buckets create backups-prod \ --object-lock \ --region fra ``` Set a default retention configuration so every uploaded object inherits it: ```bash aws s3api put-object-lock-configuration \ --bucket backups-prod \ --endpoint-url https://fra.storage.enum.cloud \ --object-lock-configuration '{ "ObjectLockEnabled": "Enabled", "Rule": { "DefaultRetention": { "Mode": "COMPLIANCE", "Days": 30 } } }' ``` Upload a backup: ```bash aws s3 cp pg-dump-2026-04-30.sql.gz \ s3://backups-prod/postgres/ \ --endpoint-url https://fra.storage.enum.cloud ``` Now try to delete a specific version. `--version-id` is the destructive form: what an attacker would use to permanently remove the object, not just hide it behind a delete marker: ```bash aws s3api delete-object \ --bucket backups-prod \ --key postgres/pg-dump-2026-04-30.sql.gz \ --version-id \ --endpoint-url https://fra.storage.enum.cloud An error occurred (AccessDenied) when calling the DeleteObject operation: Access Denied because object protected by object lock. ``` That's the entire point. The credential is valid. The IAM policy allows the action. The storage layer refuses anyway. Verify the lock status on any object: ```bash aws s3api get-object-retention \ --bucket backups-prod \ --key postgres/pg-dump-2026-04-30.sql.gz \ --version-id \ --endpoint-url https://fra.storage.enum.cloud ``` ```json { "Retention": { "Mode": "COMPLIANCE", "RetainUntilDate": "2026-05-30T14:22:11+00:00" } } ``` For a complete backup workflow, point Restic, pgBackRest, Velero, or whatever you already use at the bucket. They write to S3 normally; the bucket's default retention applies the lock automatically. Your tooling doesn't need to know. ## What Object Lock doesn't do Object Lock is one layer. Not the entire defense. **It doesn't protect what you haven't backed up yet.** If your attacker waits to encrypt production until after a clean snapshot rolls out of your retention window, you're back where you started. Industry medians for ransomware dwell time are still over a week. A 7-day retention is too short. Pick something longer than your worst-case detection time. **It doesn't protect against malicious uploads.** An attacker with write credentials can upload garbage and lock it, leaving you paying for storage you can't delete. Restrict who holds write credentials. Monitor object counts and sizes. Enforce key prefix conventions through bucket policies. **It doesn't replace least-privilege IAM.** Backup credentials should still be scoped narrowly: read-only for restore tooling, append-only for backup writers. Object Lock is a backstop, not the only line. The lock is an enabler. The recovery procedure is the actual product. ## Get started Object Lock is available on enum's object storage in Frankfurt today. Default retention configurations, Compliance Mode, Legal Hold, all supported, S3-API compatible. Full reference in the [docs](https://docs.enum.co). Questions about migrating? [mail@enum.co](mailto:mail@enum.co). ---