An EU region of an American cloud is not sovereignty.
If you sell digital goods in Europe, the money and the data flow through a commerce layer — processor, merchant of record, cloud — that is almost always American-owned. For a long time the convenience outweighed the cost. That trade has changed.
This page is the deep-dive behind the sovereignty claims on the rest of the site: why the ownership of the rail now matters, what 'sovereign' actually requires, and how lernaura is built so that when your buyer's procurement asks the question, you have a clean answer — without doing anything.
The question every EU buyer will ask
By 2027 the standard procurement question for a commerce vendor will be: if the United States invokes the CLOUD Act against your parent company tomorrow, what happens to my customer data, my settlement balances and my business continuity? Paddle, Lemon Squeezy (now part of Stripe), FastSpring and Cleverbridge all answer the same way — it depends on the warrant.
lernaura's answer is that the question does not apply: we are not subject to US jurisdiction, we do not run on US-owned infrastructure, and our settlement is not routed through US payment networks. That is a structural property, not a contractual promise — and no clause an American vendor offers can override the CLOUD Act or FISA 702.
Why the legal ground moved
The legal basis for processing European data on American clouds has collapsed twice. Schrems I invalidated Safe Harbor in 2015; Schrems II invalidated Privacy Shield in 2020. The current EU–US Data Privacy Framework, agreed in 2023, is already in litigation, and most European privacy lawyers will tell you in private that Schrems III is a matter of when, not whether.
Meanwhile the obligations on the American side are explicit. The CLOUD Act (2018) compels US-headquartered providers to hand over customer data on lawful request, regardless of where it is physically stored. FISA 702, renewed in 2024, gives US intelligence broad latitude over non-US persons' data held by US companies. These are written into law; a vendor's terms of service cannot contract out of them.
What 'sovereign' actually requires
Most 'EU' claims stop at a data-residency region. Real sovereignty is about ownership and jurisdiction, not the physical location of the bytes. Concretely, it requires:
- Hardware owned by an EU entity — not an EU region of a US-owned cloud, which the CLOUD Act still reaches.
- A vendor not subject to US jurisdiction — no US parent, no US headquarters.
- Payments licensed in the EU and settled off US card-network dependency where possible.
- Tax and platform obligations operated under EU registration, by the vendor.
- An audit trail you can put in front of a procurement officer without a footnote.
How lernaura is built for it
Each layer is a deliberate engineering choice, not a marketing label. There is no US-owned link in the chain:
- Database & hardware — Scaleway, a French-owned company operating in French data centres. Not an EU region of an American cloud.
- Payments — Mollie, a Dutch-licensed payment institution under EU regulation.
- Application hosting — Scalingo, a French platform.
- AI inference — Mistral, in France, with contractual no-training terms.
- Tax & reporting — VAT/OSS, IOSS, DAC7 and DSA verification operated by us, under EU registration.
The procurement test
The useful way to evaluate any commerce vendor is the warrant test: if a US court orders your provider's parent to disclose your customers' data tomorrow, what is the honest answer? For every American-owned MoR, the answer turns on the warrant. For lernaura, the question has no purchase, because there is no US entity to serve and no US-owned infrastructure to reach.
We document the chain — entity, hardware, payments licence, tax registration — rather than asserting it, and we're certifying to the standards procurement will ask for (ISO 27001 and SOC 2 Type II, both in preparation). What that means for you: when your buyer's DPO asks the question, the answer is a page you send, not a meeting you schedule.
FAQ
- What exactly is the CLOUD Act problem?
- The US CLOUD Act (2018) compels a US-headquartered provider to hand over customer data on lawful request regardless of where it is stored. So an American MoR or cloud — even with EU data centres — can be compelled to disclose your European customers' data. A vendor with no US entity and no US-owned infrastructure isn't in scope.
- Isn't the Data Privacy Framework enough?
- It's the third such mechanism after Safe Harbor and Privacy Shield, both struck down by the Court of Justice. The DPF is already in litigation. Building on it is building on a foundation that has washed out twice; sovereignty by construction doesn't depend on it surviving.
- I use the EU region of a US cloud — isn't that fine?
- For data residency, partly. For sovereignty, no: the CLOUD Act reaches the data because the cloud provider is a US company, wherever the region sits. EU-owned hardware is the difference that holds up in court.
- How do I prove this to my own buyers and auditors?
- We document the chain — entity, hardware, payments licence, tax registration — rather than asserting it, and we're certifying to the standards procurement will demand (ISO 27001 and SOC 2 Type II, both in preparation). You can hand that to an auditor without caveats.
- Does sovereignty cost more?
- No. The rail is 5% + €0.50, all-in — the same as the American incumbents charge. The sovereignty is built in, not priced in; you don't pay a premium for the EU-owned chain.