Hybrid Cloud: Sovereignty Where It Is Needed

Workloads that require protection run under German law and audited compliance, everything else remains freely combinable.
syseleven.de has become secunet.cloud. You are already on our new website. The platform, services and contacts remain the same.

Core Benefits
The Proven Balance Between Control and Speed

In many organisations, sovereignty requirements and commercial pressure pull in opposite directions. Running everything in-house ties up capital and staff, while a pure hyperscaler strategy creates legal and technological dependencies. The hybrid model resolves this conflict through allocation: every application and every data set sits where protection requirements, cost constraints and development speed align.

Hybrid Models Extending Into the Classified Domain

SINA Cloud complements the public and private tiers with cloud infrastructure up to VS-NfD, available in two operating variants.
SINA Cloud On-Premise

Operation on your own premises, where physical and logical access regimes must remain entirely under your responsibility.

  • Infrastructure in your own data centre
  • Full authority over operation and administration
  • Connection to existing protected networks
SINA Cloud as a Service

Consumption as a managed service, where the level of protection is required but staff and floor space are limited.

  • Operated by secunet cloud in audited environments
  • No need to build your own high-security infrastructure
  • Scaling without upfront investment

Critical workloads remain under your authority, operated under German law in German data centres.

ISO 27001, IT-Grundschutz and BSI C5 evidence operations in an auditable form for regulators and auditors.

Unregulated workloads continue to run wherever they are most cost-effective. Teams work with the same Kubernetes and OpenStack interfaces across all environments.

What a Hybrid Architecture Delivers
Workload Allocation


Every Workload in the Right Place
The basis is a protection requirement assessment for each system, supplemented by regulatory obligations, load profile and cost constraints.

  • Allocation matrix covering all systems
  • Assessment by protection requirement and regulation
  • Cost and load profile per environment
  • Continuous updating during operation
Unified Platform


One Foundation for All Environments
OpenStack provides the shared infrastructure layer for public, dedicated and classified environments.

  • Identical APIs across all models
  • Transferable automation and operating processes
  • No separate operational expertise per environment
  • Fully auditable open source stack
Managed Kubernetes


Containers Across Environment Boundaries
MetaKube runs Kubernetes clusters under the same model in public, private and hybrid scenarios.

  • Certified Kubernetes distribution
  • Automated lifecycle management
  • Integration into existing CI/CD pipelines
  • Portable deployments across models
Network Connectivity


Secure Connection Between Tiers

The environments are linked through encrypted, controlled transitions.

  • VPN services between environments
  • Layer 4 and layer 7 load balancing
  • Security groups and segmentation
  • DDoS protection at infrastructure level
Compliance & Audit


Nachweisfähigkeit über alle Modelle

Regulierte Verfahren erfordern lückenlose Nachvollziehbarkeit, unabhängig vom Betriebsmodell.

  • Lückenloses Audit-Logging
  • Nachvollziehbarkeit aller Systemzugriffe
  • Zertifizierte Betriebsprozesse
  • Dokumentierte Datenflüsse zwischen den Ebenen
Migration


Phased Transition

Existing systems are migrated without a cut-over date; legacy and new operations run in parallel.

  • Analysis of existing system landscapes
  • Migration during ongoing operation
  • Parallel operation until decommissioning
  • Support through managed services

Architecture Model
Three Operating Models, One Technological Foundation

Workloads are allocated by protection requirement, not by provider. Moving between tiers remains an operational task rather than a migration project.

Hybrid Models Extending Into the Classified Domain

The SINA Cloud complements the public and private tiers with cloud infrastructure up to VS-NfD, available in two operating variants.
SINA Cloud On-Premise

Operation on your own premises, where physical and logical access regimes must remain entirely under your responsibility.

  • Infrastructure in your own data centre
  • Full authority over operation and administration
  • Connection to existing protected networks
SINA Cloud as a Service

Consumption as a managed service, where the level of protection is required but staff and floor space are limited.

  • Operated by secunet cloud in audited environments
  • No need to build your own high-security infrastructure
  • Scaling without upfront investment
IT-Grundschutz
BSI C5 Type 2
ISO 27001
ISO 27017
ISO 27018

Application Scenarios

The constellations a hybrid architecture is designed for.
Specialist Applications and Register Modernisation

Register and case data reside on dedicated infrastructure under IT-Grundschutz requirements, while citizen portals, form processes and interfaces scale from the public cloud. Peak loads around application deadlines are absorbed without altering the protection requirement of the core data.

Situational Awareness and Inter-Agency Cooperation

Evaluation, analysis and situational awareness services run in a dedicated environment, while classified cases and the digitisation of classified material take place in the SINA Cloud. Controlled transitions keep federal exchange between control centres, state and federal authorities fully auditable.

Separating Standard Operations from Classified Components

Systems handling classified material are covered by the SINA Cloud, either on-premises at your own site or as a service. Simulation, evaluation and development pipelines without a classification level continue to use scalable resources, without creating two separate operating worlds.

Patient Data Separated from Analytical Systems

Treatment and billing data remain on dedicated infrastructure with their own security policies and C5 attestation. Research, analysis and application development operate alongside on a cost-optimised basis using anonymised or synthetic data sets.

Decoupling Operational Control from Ancillary Systems

Control-adjacent and reportable systems run in a controlled environment with complete audit logging in line with NIS 2 and KRITIS requirements. Portals, customer systems and data analytics remain in the public cloud and are connected through secured transitions.

FAQ
Frequently Asked Questions About Hybrid Cloud

The basis is a protection requirement assessment for each system, supplemented by regulatory obligations, load profile and cost constraints. The result is an allocation matrix that is updated continuously during operation.


No. All models are built on OpenStack and MetaKube. Automation, deployment processes and operational expertise apply across all environments.


Yes. Standardised interfaces allow combination with partner and third-party solutions without relinquishing control over data sets requiring protection.


Operations take place exclusively at sites in Germany.


Contact request

Get started with the secure cloud now

Talk to our experts - initial strategic consultation, technical proof of concept, or migration path.
 

I acknowledge that I have the right to object to the processing of my data at any time, with effect for the future. Further information on the processing of your personal data can be found at: https://www.secunet.cloud/en/privacy-policy.