Europa-only Alternative zu AWS.

Amazon Web Services is the original public cloud - and the original Schrems II problem. The same EU regions that make AWS technically usable for European workloads do not change the parent jurisdiction: AWS Inc. is a Delaware corporation, AWS EMEA SARL is a Luxembourg subsidiary fully controlled by it, and the CLOUD Act applies to both. For audited workloads, regulated industries and any business that has had a customer ask "is your provider US-subpoenable?", the honest answer on AWS is yes. Below is the engineering-grade map for getting off it.

United States Ersatz-Stack, ausschließlich EU 14 Dienste zugeordnet
Anbieter
AWS
Hauptsitz
Seattle, WA
Rechtsmacht
United States
Rechtsregime
CLOUD Act, FISA 702, EO 12333

"EU-Region" ist keine Souveränität. Vier Fragen entscheiden.

Data-Residency sagt, wo die Bits liegen. Souveränität sagt, welches Rechtssystem Zugriff erzwingen kann. Die Antwort muss auf allen vier Punkten halten, sonst ist der Stack nicht souverän.

Residenz

Wo sind die Daten physisch gespeichert?

Nicht "in der Cloud": welches Rechenzentrum, in welchem Land, unter welcher Jurisdiktion.

Subprozessoren

Wer ist sonst noch in Ihrem Datenpfad?

Jeder Anbieter, der die Daten berührt: das CDN, das E-Mail-Relay, der Error-Tracker, die Analytics-Pipeline.

Rechtsmacht

Wessen Gesetze können die Offenlegung erzwingen?

Ein Anbieter mit US-Hauptsitz untersteht FISA 702 und dem CLOUD Act, auch wenn die Bits in Frankfurt liegen.

Schlüsselverwahrung

Wer hält tatsächlich die Verschlüsselungsschlüssel?

Wenn der Cloud-Anbieter sowohl die Daten als auch die Schlüssel hält, sind die Daten für ihn lesbar, unabhängig von jedem AVV.

Erfüllt nicht AWS · Azure · GCP · EU-Region

Scheitert an Rechtsmacht und Schlüsselverwahrung.

EU-Daten, US-Mutterkonzern, US-Subprozessoren im Standardpfad, vom Anbieter verwaltete Schlüssel.

Erfüllt Binadit Managed Stack

Besteht in allen vier Punkten.

EU-gehostet auf Infrastruktur mit EU-Hauptsitz. Null US-Subprozessoren im Standardpfad. Kunden- oder EU-KMS-Schlüssel. Namentlich in Ihrer Artikel-28-AVV aufgeführt.

Warum Teams aussteigen AWS

The drivers we hear in scoping calls are consistent: a procurement gate that now demands "no third-country data processor" (NIS2, DORA, public sector), a customer audit (typically B2B enterprise or healthcare) that flagged the AWS relationship, escalating egress and bandwidth costs that look worse every quarter, or a leadership-level concern after the 2024-2025 round of EU-US transfer mechanism uncertainty. The technical lift to leave AWS is rarely the blocker it appears to be. The real friction is choreography: zero-downtime database migrations, DNS cutover, observability continuity. That is where a managed-infrastructure partner saves months.

AWS Dienste und ihre EU-only Äquivalente

Eine Migration ist nicht "eine Box gegen eine andere tauschen". Die Zuordnung unten ist das, was wir für Kunden ausführen, die Folgendes verlassen: AWS auf Grundlage von Schrems II: vollständige EU-Jurisdiktion, kein US-Mutterkonzern im Datenpfad.

EC2 (compute)

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. KVM-VMs auf Debian oder Ubuntu, provisioniert mit Terraform und konfiguriert mit Ansible.
Engineering-Hinweis
Wir dimensionieren die Instanzen anhand Ihres tatsächlichen Lastprofils statt anhand einer Katalog-Stufe, sodass die meisten Migrationen mit weniger, aber besser ausgelasteten Maschinen enden.

S3 (object storage)

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. MinIO oder Ceph RGW, S3-kompatibel.
Engineering-Hinweis
S3-kompatible APIs sind universell; bei den meisten Anwendungen genügt eine einzige Endpoint-Änderung. Bei den meisten EU-Anbietern fallen keine Egress-Gebühren an.

RDS / Aurora (managed DB)

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. PostgreSQL oder MySQL mit Patroni für Failover und pgBackRest für Point-in-Time Recovery.
Engineering-Hinweis
Streaming-Replikation ermöglicht eine Umschaltung ohne Ausfallzeit. Managed EU-PostgreSQL-Preise liegen typischerweise 30-50% unter vergleichbarem RDS.

CloudFront (CDN)

Was wir stattdessen betreiben
Wir implementieren und betreiben ein EU-CDN für Sie: Bunny.net oder KeyCDN, mit Nginx- und Varnish-Caching an Ihrem Origin.
Engineering-Hinweis
Ein CDN ist eine der wenigen Schichten, die wir nicht selbst betreiben. Wir wählen den EU-Anbieter aus, konfigurieren Cache-Header, Purge-Strategie und Origin Shielding und betreiben es als Teil des Managed Service.

Route 53 (DNS)

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. PowerDNS oder Knot, autoritativ, DNSSEC-signiert.
Engineering-Hinweis
Zonen werden als Standard-Zonendateien exportiert und importiert, das ist meist der unspektakulärste Teil einer Migration. Senken Sie die TTLs eine Woche im Voraus.

Lambda (serverless)

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. Knative oder OpenFaaS auf Ihrem Kubernetes-Cluster.
Engineering-Hinweis
Für souveräne Deployments ist self-hosted Knative auf EU-Compute die sauberste Lösung. Die meisten Lambda-Workloads passen in einen kleinen Kubernetes-Cluster.

SES (email)

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. Postfix mit DKIM, SPF und DMARC, sowie Rspamd zum Filtern.
Engineering-Hinweis
Bei transaktionalem Volumen unter 1 Mio./Monat ist ein korrekt konfiguriertes Postfix-Relay operativ einfacher und günstiger als SES.

SQS / SNS

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. RabbitMQ, NATS oder Redis Streams, je nach Zustellgarantien.
Engineering-Hinweis
Managed Message Broker sind im EU-souveränen Raum selten. Self-Managed ist das Standardmuster; wir betreiben es für Kunden.

EKS (managed Kubernetes)

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. Kubernetes auf Debian oder Talos, mit Cilium-Networking und cert-manager für Zertifikate.
Engineering-Hinweis
Managed K8s bei EU-Anbietern bietet für 95 % der Workloads Funktionsparität.

CloudWatch / X-Ray

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. Prometheus, Grafana, Loki und Tempo, verbunden mit OpenTelemetry.
Engineering-Hinweis
Der OpenTelemetry-Standard macht die Migration trivial; der operative Gewinn sind konsolidierte Dashboards und keine Kosten pro Metrik.

IAM

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. Keycloak oder Authentik als Identity Provider, mit OIDC und SAML.
Engineering-Hinweis
Kein 1:1-Ersatz; plattformübergreifende Identität wird mit Vault, OIDC-Providern (Keycloak) und tool-spezifischen Rollen neu aufgebaut.

WAF / Shield

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. Coraza oder ModSecurity mit dem OWASP Core Rule Set, plus CrowdSec für verhaltensbasierte Blockierung.
Engineering-Hinweis
Regeln werden gegen Ihren tatsächlichen Traffic abgestimmt, statt als Standardset ausgeliefert zu werden - das verhindert, dass eine WAF unbemerkt echte Kunden blockiert.

KMS

Was wir stattdessen betreiben
Binadit Private Infrastructure. Vault Transit für Key-Management, mit HSM-gestützten Keys, wo das Compliance-Regime es erfordert.
Engineering-Hinweis
Für HYOK-Szenarien ist ein On-Premises-HSM mit cloud-seitigem BYOK das gängige souveräne Muster.

Secrets Manager / SSM Parameter Store

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. HashiCorp Vault oder Infisical, self-hosted, mit automatischer Lease-Rotation.
Engineering-Hinweis
Vault auf EU-Infrastruktur ist die produktionsreife Antwort. Wir deployen und betreiben sie.

Wie wir migrieren von AWS

Eine typische Mittelstand-Migration läuft in drei Phasen. Die Zahlen unten gehen von einem 6-10-köpfigen Engineering-Team und einem mäßig komplexen Anwendungs-Stack aus.

  1. Weeks 1-2

    Audit & dependency map

    Inventory every AWS service in use, every IAM role, every Lambda, every cross-service call. Tag personal data flows. Output: a remediation plan with risk-ranked findings and an effort estimate per service.

  2. Weeks 3-6

    Soft dependencies & egress prep

    Replace CloudFront, Route 53, SES and CloudWatch first - zero application code changes for most. Move S3 buckets behind S3-compatible EU storage with dual-write during cutover. Pre-stage replicas of RDS in EU.

  3. Weeks 6-14

    Core compute & DB cutover

    Blue-green compute migration with DNS-level traffic shift. Streaming-replication database cutover during a low-traffic window. EKS workloads moved to managed EU K8s or self-managed Talos. Decommission AWS account once verified.

5-year TCO modelling on workloads we have actually migrated: typically 30-55% cheaper on EU sovereign infrastructure for predictable workloads, neutral to slightly higher for highly bursty workloads that benefit from sub-second autoscaling. Egress savings alone are often the difference between a positive and negative ROI.

Does using an AWS EU region (Frankfurt, Ireland, Stockholm) solve the Schrems II problem?
No. The data residency is in the EU but Amazon Web Services Inc. is the controller of the infrastructure under US law. The CLOUD Act allows US authorities to compel disclosure of data held by US-controlled entities anywhere in the world. The EDPB has explicitly flagged this as a Schrems II issue. AWS EMEA SARL is a Luxembourg subsidiary fully owned by AWS Inc.; that ownership chain is what the analysis turns on.
How long does an AWS exit take in practice?
For a mid-market application (10-50 EC2 instances, a couple of RDS databases, S3, CloudFront, SES) with a 6-10 person engineering team and competent operational support: 10-16 weeks elapsed time. With a managed-infrastructure partner driving the choreography (which is most of the actual work), 6-10 weeks.
What about AWS GovCloud or AWS Sovereign Cloud Europe?
AWS GovCloud is for US federal workloads and is not relevant to EU buyers. AWS European Sovereign Cloud (announced 2023, in build-out) is operated by EU-headquartered AWS staff in EU regions, but the parent legal entity remains Amazon Web Services Inc. Whether it is "sovereign enough" depends on your specific compliance regime; for many Schrems II analyses it is not sufficient because the parent jurisdiction is unchanged.
Will we lose features by leaving AWS?
Specific managed services (DynamoDB single-digit-ms, Aurora Serverless v2, Bedrock model access, SageMaker training on H100s) have no clean EU sovereign equivalents. For 90% of mid-market workloads - web applications, APIs, e-commerce, B2B SaaS, analytics on warehouses - the EU sovereign stack covers it. We tell you upfront if your workload sits in the 10% category.
Can we keep some AWS services and migrate the rest?
Yes - a hybrid is sometimes the right answer. The discipline is to keep AWS only for clearly non-personal workloads, and document the boundary in your DPA. We have run hybrids where AWS handles ML training (no personal data, batch-only) and the EU sovereign stack handles all customer-facing infrastructure.
What does a managed exit cost?
Project-based pricing, scoped after the audit. Typical mid-market AWS exit: €25-80k for the project, plus the ongoing managed-infrastructure retainer for the new EU stack. The first-year savings on AWS spend usually exceed the project cost.

Plane deinen Exit von AWS.

30-minütiges Scoping-Gespräch. Wir bilden Ihren Stack auf EU-only Alternativen ab, schätzen den Migrationsaufwand und sagen Ihnen, ob es die richtige Entscheidung ist.