Renting a Frankfurt data center from a US hyperscaler changes where your data sits, not who can be compelled to hand it over. The US CLOUD Act follows the provider, not the geography. If the company at the top of the stack is American, so is the legal reach into your stack.
HeySignal took the question seriously and answered it all the way down.
No AWS, no Google Cloud, no Azure, no Cloudflare. Not for the annoying parts either: logs, queues, and caches live on the same European providers. We publish the full subprocessor list, named, at /legal/subprocessors. Read it; it's short.
EDGE Bunny.net · EU points of presence
DATABASES OVHcloud Postgres + Valkey · France + Frankfurt
US CLOUD 0 providers in the pipeline
European courts keep arriving at the same place: data handled by US-controlled providers is exposed to US surveillance law regardless of which region hosts the bytes. Every business running tags through a US-cloud pipeline is carrying that argument on its own compliance budget, usually without having read it.
You will notice competitors get this half right. One markets European bare metal for its core product while its own docs admit a flagship gateway product runs on Google Cloud and, their words, falls under the US Cloud Act. Another is a Delaware corporation offering an EU sub-brand as an opt-in. The pattern is the same: sovereignty as a feature tier.
Here it is the default, because it is the whole company. There is no US-jurisdiction default we quietly steer you toward.
Obviously, delivering an event to Meta means data goes to Meta; that is what you asked for, gated on your visitor's consent. The sovereignty claim covers everything before that moment: capture, verification, storage, processing, and analytics happen on European providers under European jurisdiction. What leaves, leaves because consent and your configuration said so.
We hold no security certifications yet; SOC 2 Type II work is planned for late 2026, and the security page tracks the current posture in plain language: per-field credential encryption at rest with key rotation, tenant isolation enforced at the database layer with row-level security, constant-time secret comparison, no PII in logs. We would rather show you the engineering while the audit paperwork catches up than the other way around.
No. Regions answer "where is the data". Jurisdiction answers "who can be compelled". US providers remain subject to US law wherever the region is.
Bunny.net (edge) and OVHcloud (databases) carry the pipeline. The full named list lives at /legal/subprocessors and changes to it are announced.
Not inside our pipeline. Data leaves European infrastructure only as consented deliveries to the destination platforms you configured.
Not yet, and we say so. SOC 2 Type II is planned for late 2026; the security page details current practice.