Europees-only alternatief voor Heroku (Salesforce).

Heroku is the original developer-first PaaS, acquired by Salesforce in 2010 and now part of Salesforce.com Inc. Salesforce is a US corporation, Heroku's default region is in the US, and the EU "Common Runtime" lives in AWS Ireland - meaning your Heroku app is on AWS infrastructure with Salesforce as the contractual processor. Both layers are US-jurisdictional. The sovereign alternative is straightforward: a self-hosted PaaS like Coolify or Dokku on EU infrastructure, or a fully-managed equivalent operated by an EU partner.

United States Vervangende stack, uitsluitend EU 11 diensten in kaart gebracht
Leverancier
Heroku (Salesforce)
Hoofdkantoor
San Francisco, CA (Salesforce)
Rechtsmacht
United States
Wettelijk regime
CLOUD Act, FISA 702

"EU-regio" is geen soevereiniteit. Vier vragen bepalen het.

Dataresidentie zegt waar de bits staan. Soevereiniteit zegt welk rechtssysteem toegang kan afdwingen. Het antwoord moet op alle vier standhouden, anders is de stack niet soeverein.

Residency

Waar staat de data fysiek opgeslagen?

Niet "in de cloud": welk datacenter, in welk land, onder welke jurisdictie.

Subprocessoren

Wie zit er nog meer in uw datapad?

Iedere leverancier die data raakt: de CDN, de e-mailrelay, de error-tracker, de analytics-pipeline.

Rechtsmacht

Wiens wetten kunnen openbaarmaking afdwingen?

Een provider met een Amerikaans hoofdkantoor valt onder FISA 702 en de CLOUD Act, ook als de bits in Frankfurt staan.

Sleutelbeheer

Wie heeft daadwerkelijk de encryptiesleutels?

Als de cloudprovider zowel de data als de sleutels beheert, is die data voor hen leesbaar, ongeacht welke verwerkersovereenkomst er ligt.

Voldoet niet AWS · Azure · GCP · EU-regio

Faalt op rechtsmacht en sleutelbeheer.

EU-bits, Amerikaanse moedermaatschappij, US-subprocessoren in het standaardpad, sleutels beheerd door provider.

Voldoet Binadit managed stack

Slaagt op alle vier.

EU-gehost op EU-hoofdkantoor infrastructuur. Nul US-subprocessoren in het standaardpad. Klant- of EU-KMS-sleutels. Bij naam vermeld in uw Artikel 28 DPA.

Waarom teams weggaan Heroku (Salesforce)

Heroku exits we have run come from three triggers: a customer audit (B2B SaaS) flagging the AWS-Ireland-via-Heroku data path as Schrems II-exposed, the discontinuation of free dynos in 2022 forcing a cost reassessment, or a strategic decision to remove the double provider chain (Salesforce → AWS) which complicates DPA management. Heroku's value is the developer experience; open source alternatives like Coolify, Dokku and Caprover reproduce most of that experience on EU infrastructure.

Heroku (Salesforce) diensten en hun EU-only equivalenten

Een migratie is niet "vervang één doos door een andere". De mapping hieronder is wat we draaien voor klanten die weggaan bij Heroku (Salesforce) op grond van Schrems II: volledige EU-jurisdictie, geen Amerikaans moederbedrijf in het datapad.

Dynos (web/worker)

Wat wij in plaats daarvan draaien
Binadit Managed Cloud Platform. Docker images gebouwd in GitLab CI en gedeployed naar Kubernetes, met review environments per branch.
Engineering-notitie
Coolify biedt een vrijwel identieke Heroku DX (git push deploys, one-click apps) op EU-infrastructuur. Facturen liggen doorgaans 60-80% lager dan bij Heroku voor equivalente compute.

Heroku Postgres

Wat wij in plaats daarvan draaien
Binadit Managed Cloud Platform. PostgreSQL of MySQL met Patroni voor failover en pgBackRest voor point-in-time recovery.
Engineering-notitie
Logical replication maakt een overstap zonder downtime mogelijk. Heroku Postgres-backups kunnen worden gedownload als standaard pg_dump en overal worden hersteld.

Heroku Redis

Wat wij in plaats daarvan draaien
Binadit Managed Cloud Platform. Redis of Valkey, met Sentinel voor failover.
Engineering-notitie
Standaard Redis-API; migratie via SLAVEOF of RDB-transfer.

Heroku Connect (Salesforce sync)

Wat wij in plaats daarvan draaien
Binadit DevOps & Support. Integration workers die draaien op uw eigen infrastructuur en rechtstreeks communiceren met de vendor-API.
Engineering-notitie
Voor teams die Salesforce CRM behouden, wordt de synchronisatielaag herbouwd; voor teams die Salesforce vervangen, vervalt deze zorg.

Add-ons marketplace

Wat wij in plaats daarvan draaien
Binadit DevOps & Support. De componenten die u daadwerkelijk gebruikt, uitgerold en beheerd als onderdeel van uw stack.
Engineering-notitie
Het gemak van Heroku-add-ons is het grootste DX-verlies; direct leveranciersbeheer is de prijs voor soevereiniteit.

Pipelines (review apps, CI/CD)

Wat wij in plaats daarvan draaien
Binadit DevOps & Support. Review-omgevingen per branch op Kubernetes, aangemaakt en verwijderd door GitLab CI.
Engineering-notitie
Coolify ondersteunt preview-omgevingen per branch.

Heroku Buildpacks

Wat wij in plaats daarvan draaien
Binadit DevOps & Support. Dockerfiles of Cloud Native Buildpacks, gebouwd in GitLab CI.
Engineering-notitie
De meeste Heroku-apps worden ongewijzigd gedeployed via Cloud Native Buildpacks op Coolify.

Logplex / Logging

Wat wij in plaats daarvan draaien
Binadit Managed Cloud Platform. Loki voor aggregatie, met Grafana voor het bevragen en retention policies per stream.
Engineering-notitie
Loki is het standaardpatroon; verzamelt logs van alle containers.

Heroku CI

Wat wij in plaats daarvan draaien
Binadit DevOps & Support. GitLab CI met runners op uw eigen infrastructuur.
Engineering-notitie
GitLab CI op een self-hosted EU-runner is de vervanging van productiekwaliteit.

Heroku Private Spaces

Wat wij in plaats daarvan draaien
Binadit Private Infrastructure. Volledig geïsoleerde omgeving, dedicated hardware, custom netwerkarchitectuur.
Engineering-notitie
Het concept "Private Spaces" is een VPC onder een andere naam; standaard EU-netwerkinfrastructuur handelt dit af.

SSL / domains

Wat wij in plaats daarvan draaien
Binadit Managed Cloud Platform. cert-manager met Let's Encrypt, automatisch vernieuwd.
Engineering-notitie
Domeinoverdracht is een registrarwijziging; SSL wordt door alle moderne PaaS-alternatieven geautomatiseerd.

Hoe we migreren af van Heroku (Salesforce)

Een typische mid-market migratie loopt in drie fasen. De getallen hieronder gaan uit van een team van 6-10 engineers en een gemiddeld complexe applicatie-stack.

  1. Days 1-3

    PaaS choice + dependency map

    Decide on the EU PaaS (Coolify is our default for Heroku-style DX; Dokku for minimalists; managed offering from Binadit for hands-off teams). Inventory Heroku apps, dynos and add-ons.

  2. Days 4-10

    Database + add-on swap

    Heroku Postgres replicated to EU managed PostgreSQL with logical replication. Each add-on replaced with EU equivalent (one-by-one to control risk). Logging migrated to Loki.

  3. Weeks 2-4

    Application cutover

    Apps redeployed on Coolify with the same buildpacks. DNS cutover with low TTL window. Heroku app archived after a verification period.

5-year TCO on Heroku exits: 60-85% cheaper. Heroku's pricing model (per-dyno, per-add-on, per-database tier) compounds quickly; a self-hosted PaaS on EU infrastructure replaces a typical $500-2000/month Heroku bill for a fraction of that in raw infrastructure, plus our managed fee if you do not want to operate it yourself.

Is Heroku's EU region sufficient for GDPR?
Residency only. Heroku's "Common Runtime" EU region runs in AWS Ireland - that is two layers of US-controlled processors (Salesforce as the immediate contracting party, AWS as the underlying infrastructure). The CLOUD Act analysis applies to both. For Schrems II-strict workloads, Heroku EU is not sufficient.
Will we lose the Heroku DX?
Coolify reproduces git-push deploys, one-click app templates, preview environments per PR, automated SSL, environment variables, and per-branch deploys. The DX is genuinely close. The main loss is the add-on marketplace; you swap that for direct vendor relationships, which is more manageable than Heroku marketing suggests.
What about Heroku Connect for Salesforce sync?
If you're keeping Salesforce CRM, Heroku Connect needs to be rebuilt (REST/Bulk API + queue). If you're also moving off Salesforce - which is increasingly common in Schrems II-driven exits - this concern disappears.
Can we use Coolify ourselves or do we need help?
Many teams self-host Coolify successfully on a single VM. For multi-tenant production scenarios - multi-environment, blue-green, secrets management - a managed-partner setup makes sense. We deploy and operate Coolify clusters for clients.
How long does a Heroku exit take?
For a small workload (1-3 apps, 1 Postgres, a few add-ons): 1-2 weeks. For a multi-app enterprise Heroku setup with Private Spaces and Heroku Connect: 6-10 weeks. Heroku's app surface is intentionally simple, which makes the migration mostly a choreography exercise.
What about the newer Heroku-style platforms?
They reproduce the developer experience well, and if that is all you need they are a reasonable landing. Check two things before you commit: which jurisdiction the platform and its database sit under, and what the exit looks like in two years. A platform that builds from your Dockerfile onto infrastructure you could run yourself is a much shorter conversation later than one with a proprietary build and runtime.

Plan je exit van Heroku (Salesforce).

Gesprek van 30 minuten. We mappen je stack tegen EU-only alternatieven, schatten de migratie-inspanning en zeggen je of het de juiste keuze is.