Skip to content
eu://sovereignty — how it works

Your data stays in Europe. Under Swedish law.

Somewhere in your pipeline is a buyer whose procurement will ask "under whose law?" — and "EU region" will not be the answer. Here it is: a Swedish company, EU-only storage, Swedish law, and a private database per user that your own tenant cannot read into.

Your user
your application
Singularity Database
EU storage · Swedish law
location ≠ jurisdiction

An EU region is a location. Sovereignty is a jurisdiction.

A region menu tells you where the disks are, not whose courts the operator answers to. The EU's own Cloud Sovereignty Framework, first applied in April 2026, scores jurisdiction and operational control — not just server location.

Criterion "EU region" on a non-EU provider Singularity Database
Where the data sits EU datacentre (selectable) EU only; core datacentre in Linköping
Which law governs The provider's home jurisdiction Swedish law; disputes in Linköping
Who operates it A provider under its home country's obligations CloudBackend AB, a Swedish company
Who can read it Whatever the provider's access model allows Never the tenant, for home://; every access checked against an ACL on the data
four questions, answered in present tense

Where, under which law, by whom, and who can read it.

today

Where is the data?

Within the EU, stored by local cloud service providers. Headquarters and core datacentre in Linköping.

today

Which law applies?

The contract is with CloudBackend AB under Swedish law, with disputes settled in a Swedish court in Linköping.

today

Who operates it?

A Swedish company, on servers it controls in Europe.

today

Who can read it?

Access is authorised on the data by ACL, down to the individual object. The tenant — the SaaS business — cannot read into an identity's private database.

how we deliver: the tenant cannot reach it

Every identity gets a private database the tenant cannot read into.

Separation is a fact of the schema, not a policy you have to implement. tenant:// holds the shared data your app runs on; home:// belongs to the identity, and the tenant has no path into it. Sharing out of it is explicit and recorded in an ACL.

Data is encrypted in transit and at rest. Access is authorised on the data itself, down to the individual object.

tenant://

The shared database: common data, settings, the app itself, published price plans. This is what your SaaS can read.

home://

Every identity's private database. The tenant cannot read into it; the identity shares out of it with an ACL.

for teams outside the EU

Keep your product. Add an EU-sovereign data layer.

  • Data stored in the EU under a Swedish-law contract
  • A private database per user that your tenant cannot read
  • Encrypted in transit and at rest, on EU infrastructure
  • Self-service erasure and data-level access control for their DPA

A description of the platform, not legal advice.

not a wall — a bridge

Sovereignty works in both directions.

European buyers want to keep using American software. What their procurement cannot accept is customer data under a jurisdiction their own law cannot reach. Host the data here; the service stays American, the data stays the user's, in Europe.

Ask us how a US service can offer an EU-sovereign data layer →

stated precisely

What is in the EU, and what isn't.

EU, Swedish law

Your database

Identities, groups, containers, objects, streams, applications, plans, tickets and statistics — stored in the EU, processed by CloudBackend AB.

disclosed vendors

Email, SMS and product analytics

SendGrid, Twilio and Mixpanel are US-based and declared in our terms. They hold contact details and console usage events, never database contents. The console AI uses OpenAI, only when opened. Full list.

Roadmap, stated as roadmap: a policy module for rules on where data is physically stored. Not binding until it ships.

EU only

All data is stored within the EU by local cloud service providers. Not a region choice — the only option.

Identity-based ACL

Every access authenticated and authorised down to the container and object; groups and roles carry ACL rights too.

Encrypted data

Encrypted at rest and in motion, on infrastructure inside the EU.

questions a CTO asks

Straight answers.

Is an "EU region" on a US hyperscaler sovereign?

It is EU data residency. Sovereignty depends on which law the operator answers to. The Singularity Database is operated by a Swedish company under Swedish law, with EU-only storage.

Can CloudBackend read my users' data?

The tenant — your SaaS business — cannot read into an identity's private database; that separation is architectural. As the operator, CloudBackend holds the data encrypted at rest on EU infrastructure and answers to Swedish law for any request to produce it.

What about the US CLOUD Act?

Your database is stored in the EU and processed by a Swedish company under Swedish law. US law applies only to the limited contact and usage information held by our email, SMS and analytics vendors.

Can I run it on my own infrastructure?

The XIOS/3 web system can be run on a local website as an alternative to the hosted service. Ask us about pricing and prerequisites.

How do I handle a right-to-erasure request?

An identity can delete itself from the account panel; administrators can remove identities from the console; objects can be removed or restored with the CLI.

European by construction. Open to everyone.