Sovereignty Takes Different Forms Across Drupal Hosting
Sovereignty is a visible category in Drupal hosting, but providers apply the term to services with different ownership, jurisdiction, and operational boundaries. Current offers range from customer-selected regions on managed platforms to infrastructure in customer-controlled cloud accounts, government-managed platforms, certified commercial services, and agency-managed self-hosting. The common label does not establish an equivalent level of control.
Public procurement shows why those distinctions matter. On 17 April 2026, the European Commission announced that it had awarded four contracts under which European Union institutions, bodies, offices, and agencies can procure up to EUR 180 million in sovereign cloud services over six years. Its Cloud Sovereignty Framework calculates an overall score from 48 criteria grouped into strategic, legal and jurisdictional, data and artificial intelligence, operational, supply-chain, technological, security and compliance, and environmental categories. The Commission’s 3 June 2026 proposal for a Cloud and AI Development Act would introduce a single European Union-wide assessment framework for cloud and artificial intelligence sovereignty.
Managed Platforms and Regional Control
Among managed Drupal platforms, Acquia provides a baseline for customer-selected regions on provider-operated infrastructure. Acquia Cloud Platform runs on Amazon Web Services and offers supported locations across North America, Europe, Asia Pacific, South America, and the Middle East. Acquia also offers Compliant and Dedicated virtual private cloud options, while its compliance page lists Cloud Platform as FedRAMP Authorized. The customer selects from supported regions and service configurations, while Acquia and Amazon Web Services continue to operate the platform and infrastructure layers.
Pantheon documents a detailed regional boundary for site resources. Its regional documentation says application and database containers, Redis and Apache Solr services, the distributed filesystem, request router, backup workers, and stored backups remain in the region selected when a site is created. The documented regions are the United States, Australia, Canada, and the European Union. Every Pantheon site also uses its global content delivery network, which can cache static assets and anonymous pages at distributed points of presence. Buyers should therefore treat the application region and the edge-delivery footprint as separate controls.
Upsun adds a multi-cloud variation to the managed-platform model. It offers application infrastructure through several underlying cloud providers and presents OVHcloud-backed European deployments as one sovereignty option. Upsun says it manages orchestration, integrated services, and security patches under a single service level. Region and infrastructure-provider choice therefore remain separate from ownership of the platform’s operational layer.
Customer-Controlled Infrastructure and Managed Self-Hosting
amazee.io can move the infrastructure boundary into the customer’s environment. Its Dedicated Cloud service can run in a customer cloud account, on other selected infrastructure, or in an on-premises data centre. The customer controls the underlying infrastructure choice, while amazee.io installs, monitors, patches, and operates its platform. This model increases direct infrastructure control without transferring all operational responsibility to the customer.
DevPanel offers more than one ownership arrangement. Its Community Edition supports Amazon Web Services, Microsoft Azure, DigitalOcean, and Kubernetes deployments inside the customer’s cloud account, with automation for development, test, and production environments, deployments, backups, security, and scaling. DevPanel also advertises a fully managed option in which its professional-services team owns and operates the cloud account and platform operations. Buyers therefore need to confirm which account, data, administrative, and exit controls apply to the contracted model rather than assuming that every DevPanel deployment is customer-owned.
Metadrop offers a bespoke form of managed self-hosting. Its service page describes Drupal deployments on bare metal, private cloud, or public-cloud infrastructure controlled by the client or the agency, with Metadrop designing and managing the stack. The published base architecture combines Apache, PHP-FPM, NGINX, MariaDB, and Redis, with optional Varnish, load balancing, database replication, and content delivery network integration. Because the architecture and responsibilities are scoped per engagement, buyers need to verify infrastructure ownership, privileged access, backup locations, subcontractors, and exit provisions for the proposed deployment.
Government-Managed and Certified Services
GovCMS represents a government-managed model rather than a commercial sovereignty label. The Australian Department of Finance manages the cost-recovered platform for government agencies, using Drupal with technologies including Lagoon, Kubernetes, Docker, and GitLab. Its Software as a Service option includes infrastructure and application maintenance, security updates, monitoring, and an Information Security Registered Assessors Program assessment aligned with the OFFICIAL: Sensitive level. Under its Platform as a Service option, the infrastructure layer is assessed, while the agency remains responsible for Drupal updates, modules, themes, user accounts, and application-level security assessment.
Ironstar represents a certified commercial hosting model. The Australian Government’s Hosting Certification Framework register lists Ironstar Hosting Services’ Government Cloud Service offering under its Certified Strategic Service category. The framework’s service-provider criteria cover matters including ownership and control, monitoring systems, supply-chain risk, remote-support arrangements, and continuing compliance. The listing confirms the status of the named service offering, but buyers still need to establish whether the proposed Drupal architecture and contracted services fall within its certification scope.
Skpr uses a nationally contained managed-platform model for New Zealand. The provider says every Amazon Web Services component underpinning its New Zealand platform, including compute, content delivery, web application firewall, and search, runs within the ap-southeast-6 region. This establishes a documented national residency boundary for the named services while Amazon Web Services supplies the infrastructure and Skpr operates the platform. Buyers still need to assess corporate jurisdiction, privileged access, encryption-key control, support records, contractual dependencies, and migration options.
What Drupal Buyers Need to Test
These models can be compared through connected sets of controls. Data residency covers application data, files, backups, logs, search indexes, content delivery caches, analytics exports, and support records. Infrastructure and operational control cover cloud-account ownership, network boundaries, encryption services, privileged administrators, patching, incident response, and recovery. Legal, supply-chain, and exit control cover provider ownership, subprocessors, foreign-law exposure, data export, software dependencies, and the ability to operate the workload elsewhere.
No model automatically satisfies every sovereignty requirement. A managed regional platform may provide more consistent security, certification, and resilience than a poorly operated customer account. Customer-controlled cloud or on-premises infrastructure can increase direct authority over the environment, but it can also transfer operational responsibility and retain dependencies on external cloud services or remote administrators. Procurement should assess the deployed architecture and contract against defined requirements rather than accepting a provider’s use of the sovereignty label.
The available evidence documents current provider positioning and procurement language, not a measured shift in customer adoption. Current service pages show Drupal hosts making residency, account ownership, national certification, and self-hosting explicit, while European and Australian government frameworks place those controls within procurement and service governance. Historical comparisons, market-share figures, contract data, independent audits, and customer deployment studies would be needed to determine whether provider positioning has changed and which models organisations are selecting at scale.
