Skip to content
eu://sovereignty — how it works

Your data stays in Europe. Only your users hold the key.

Somewhere in your pipeline is a buyer whose procurement will ask "under whose law?" — and "EU region" will not be the answer. Here it is: a Swedish company, EU-only storage, Swedish law, a private database per user, and client-side encryption that leaves us nothing to hand over.

Your user
the key stays here
Singularity Database
EU storage · Swedish law
location ≠ jurisdiction

An EU region is a location. Sovereignty is a jurisdiction.

A region menu tells you where the disks are, not whose courts the operator answers to. The EU's own Cloud Sovereignty Framework, first applied in April 2026, scores jurisdiction and operational control — not just server location.

Criterion"EU region" on a non-EU providerSingularity Database
Where the data sitsEU datacentre (selectable)EU only; core datacentre in Linköping
Which law governsThe provider's home jurisdictionSwedish law; disputes in Linköping
Who operates itA provider under its home country's obligationsCloudBackend AB, a Swedish company
Who can read itDepends on key custodyNot us, with client-side encryption; never the tenant, for home://
four questions, answered in present tense

Where, under which law, by whom, and who can read it.

today

Where is the data?

Within the EU, stored by local cloud service providers. Headquarters and core datacentre in Linköping.

today

Which law applies?

The contract is with CloudBackend AB under Swedish law, with disputes settled in a Swedish court in Linköping.

today

Who operates it?

A Swedish company, on servers it controls in Europe.

today

Who can read it?

Access is authorised on the data by ACL; the tenant cannot read a user's private database; with client-side encryption, nobody but the user.

how we deliver: only your users hold the key

Encrypted before it leaves the device, so there is nothing for us to decrypt.

The SDK encrypts inside your application, on the user's device. What travels and what lands on disk in the EU is ciphertext. The key never leaves the user — so no one who asks us can get more than ciphertext.

Optional, per application. Encrypted content is not searchable server-side; keep searchable fields in key/values.

What each party can see
PartyPlain dataCiphertextKey
The user, on their deviceyesyesyes
The tenant (your SaaS)only what the user sharesno
CloudBackend ABnoyes, in the EUno
Anyone asking CloudBackendnociphertext at mostno
for teams outside the EU

Keep your product. Add an EU-sovereign data layer.

  • Data stored in the EU under a Swedish-law contract
  • A private database per user that your tenant cannot read
  • Client-side encryption, so the key stays with the user
  • Self-service erasure and data-level access control for their DPA

A description of the platform, not legal advice.

not a wall — a bridge

Sovereignty works in both directions.

European buyers want to keep using American software. What their procurement cannot accept is customer data under a jurisdiction their own law cannot reach. Host the data here; the service stays American, the data stays the user's, in Europe.

Ask us how a US service can offer an EU-sovereign data layer →

stated precisely

What is in the EU, and what isn't.

EU, Swedish law

Your database

Identities, groups, containers, objects, streams, applications, plans, tickets and statistics — stored in the EU, processed by CloudBackend AB.

disclosed vendors

Email, SMS and product analytics

SendGrid, Twilio and Mixpanel are US-based and declared in our terms. They hold contact details and console usage events, never database contents. The console AI uses OpenAI, only when opened. Full list.

Roadmap, stated as roadmap: a policy module for rules on where data is physically stored. Not binding until it ships.

EU only

All data is stored within the EU by local cloud service providers. Not a region choice — the only option.

Identity-based ACL

Every access authenticated and authorised down to the container and object; groups and roles carry ACL rights too.

Encrypted data

Encrypted at rest and in motion, with optional client-side encryption inside the tunnel.

questions a CTO asks

Straight answers.

Is an "EU region" on a US hyperscaler sovereign?

It is EU data residency. Sovereignty depends on which law the operator answers to. The Singularity Database is operated by a Swedish company under Swedish law, with EU-only storage.

Can CloudBackend read my users' data?

The tenant cannot read into an identity's private database. With client-side encryption, content is encrypted on the device before it is sent; we store ciphertext and do not hold the key.

What about the US CLOUD Act?

Your database is stored in the EU and processed by a Swedish company under Swedish law. US law applies only to the limited contact and usage information held by our email, SMS and analytics vendors.

Can I run it on my own infrastructure?

The XIOS/3 web system can be run on a local website as an alternative to the hosted service. Ask us about pricing and prerequisites.

How do I handle a right-to-erasure request?

An identity can delete itself from the account panel; administrators can remove identities from the console; objects can be removed or restored with the CLI.

European by construction. Open to everyone.