Hybrid Cloud: Sovereignty Where It Is Needed
Core Benefits
The Proven Balance Between Control and Speed
In many organisations, sovereignty requirements and commercial pressure pull in opposite directions. Running everything in-house ties up capital and staff, while a pure hyperscaler strategy creates legal and technological dependencies. The hybrid model resolves this conflict through allocation: every application and every data set sits where protection requirements, cost constraints and development speed align.
Hybrid Models Extending Into the Classified Domain
Operation on your own premises, where physical and logical access regimes must remain entirely under your responsibility.
- Infrastructure in your own data centre
- Full authority over operation and administration
- Connection to existing protected networks
Consumption as a managed service, where the level of protection is required but staff and floor space are limited.
- Operated by secunet cloud in audited environments
- No need to build your own high-security infrastructure
- Scaling without upfront investment
Critical workloads remain under your authority, operated under German law in German data centres.
ISO 27001, IT-Grundschutz and BSI C5 evidence operations in an auditable form for regulators and auditors.
Unregulated workloads continue to run wherever they are most cost-effective. Teams work with the same Kubernetes and OpenStack interfaces across all environments.
Every Workload in the Right Place
The basis is a protection requirement assessment for each system, supplemented by regulatory obligations, load profile and cost constraints.
- Allocation matrix covering all systems
- Assessment by protection requirement and regulation
- Cost and load profile per environment
- Continuous updating during operation
One Foundation for All Environments
OpenStack provides the shared infrastructure layer for public, dedicated and classified environments.
- Identical APIs across all models
- Transferable automation and operating processes
- No separate operational expertise per environment
- Fully auditable open source stack
Containers Across Environment Boundaries
MetaKube runs Kubernetes clusters under the same model in public, private and hybrid scenarios.
- Certified Kubernetes distribution
- Automated lifecycle management
- Integration into existing CI/CD pipelines
- Portable deployments across models
Secure Connection Between Tiers
The environments are linked through encrypted, controlled transitions.
- VPN services between environments
- Layer 4 and layer 7 load balancing
- Security groups and segmentation
- DDoS protection at infrastructure level
Nachweisfähigkeit über alle Modelle
Regulierte Verfahren erfordern lückenlose Nachvollziehbarkeit, unabhängig vom Betriebsmodell.
- Lückenloses Audit-Logging
- Nachvollziehbarkeit aller Systemzugriffe
- Zertifizierte Betriebsprozesse
- Dokumentierte Datenflüsse zwischen den Ebenen
Phased Transition
Existing systems are migrated without a cut-over date; legacy and new operations run in parallel.
- Analysis of existing system landscapes
- Migration during ongoing operation
- Parallel operation until decommissioning
- Support through managed services
Architecture Model
Three Operating Models, One Technological Foundation
Workloads are allocated by protection requirement, not by provider. Moving between tiers remains an operational task rather than a migration project.
Hybrid Models Extending Into the Classified Domain
Operation on your own premises, where physical and logical access regimes must remain entirely under your responsibility.
- Infrastructure in your own data centre
- Full authority over operation and administration
- Connection to existing protected networks
Consumption as a managed service, where the level of protection is required but staff and floor space are limited.
- Operated by secunet cloud in audited environments
- No need to build your own high-security infrastructure
- Scaling without upfront investment





Application Scenarios

Register and case data reside on dedicated infrastructure under IT-Grundschutz requirements, while citizen portals, form processes and interfaces scale from the public cloud. Peak loads around application deadlines are absorbed without altering the protection requirement of the core data.

Evaluation, analysis and situational awareness services run in a dedicated environment, while classified cases and the digitisation of classified material take place in the SINA Cloud. Controlled transitions keep federal exchange between control centres, state and federal authorities fully auditable.

Systems handling classified material are covered by the SINA Cloud, either on-premises at your own site or as a service. Simulation, evaluation and development pipelines without a classification level continue to use scalable resources, without creating two separate operating worlds.

Treatment and billing data remain on dedicated infrastructure with their own security policies and C5 attestation. Research, analysis and application development operate alongside on a cost-optimised basis using anonymised or synthetic data sets.

Control-adjacent and reportable systems run in a controlled environment with complete audit logging in line with NIS 2 and KRITIS requirements. Portals, customer systems and data analytics remain in the public cloud and are connected through secured transitions.
How is it decided which workload belongs where?
The basis is a protection requirement assessment for each system, supplemented by regulatory obligations, load profile and cost constraints. The result is an allocation matrix that is updated continuously during operation.
Do two separate operating worlds emerge?
No. All models are built on OpenStack and MetaKube. Automation, deployment processes and operational expertise apply across all environments.
Can partner solutions be integrated?
Yes. Standardised interfaces allow combination with partner and third-party solutions without relinquishing control over data sets requiring protection.
Where is the data processed?
Operations take place exclusively at sites in Germany.
Get started with the secure cloud now
Talk to our experts - initial strategic consultation, technical proof of concept, or migration path.
Resources