Zscaler on STACKIT

Leverage Zero-Trust Security as a Strategic Business Enabler

Glowing digital padlock icon on a dark circuit board background with blue bokeh lights, representing cybersecurity, data encryption, and network security.
YT Zscaler

Never trust. Always verify.

Today, companies must use high-end security to protect themselves against increasingly complex cyber threats. At the same time, they must ensure that their data remains under their own control and within European jurisdiction. Zscaler on STACKIT solves this dilemma. The market-leading zero-trust platform and the Schwarz Group’s sovereign cloud provider offer maximum IT security with 100% data sovereignty in a “fusion of excellence.” Zscaler connects users directly to applications rather than to the network, ensuring maximum cyber resilience with minimal complexity—all within STACKIT’s secure German cloud.

This highly secure architecture is essential, particularly for the uncompromising requirements of strictly regulated and critical industries. Zscaler on STACKIT was developed specifically for this purpose and offers tailored security and full operational flexibility—with a particular focus on the public sector (Public), defense (Defense), healthcare (Health), and financial services (FSI).

The Challenge: The Dilemma Between High-End Security and Digital Sovereignty

For many, preparing critical infrastructure for highly complex attacks using the world’s best security technologies while simultaneously guaranteeing European sovereignty requirements without compromise is a paradox. This necessary balancing act—global innovation on one hand and national legal certainty on the other—often leads to a strategic dilemma, as conventional cloud solutions usually cannot meet all requirements at the same time.

Legal Uncertainty

A constant conflict between U.S. security solutions and the strict regulatory requirements of the GDPR—access by authorities in third countries must be ruled out, but standing still is not a solution.

Geopolitical Dependency

The digital infrastructure and data flows of critical sectors must not be subject to the interests or access of third countries outside the EU.

Use of AI

Modern cyberattacks are becoming increasingly complex, faster, and more automated due to the use of artificial intelligence. The use of public AI tools provides an additional entry point for cybercriminals. Traditional security architectures no longer offer sufficient protection against this.

YOUR BENEFITS WITH ZSCALER ON STACKIT

100% GDPR-compliant

Your data never leaves the German legal jurisdiction. Hosted in STACKIT data centers (regions DE01/DE02), all information is subject exclusively to German data protection laws.

Operational sovereignty

Stay in control. Through the “Unilateral Cut-off” mechanism, we guarantee business continuity and protection against access by third countries—even in times of geopolitical instability.

Technological Excellence

Harness the full power of the Zscaler Zero Trust Exchange™ platform. Faster application access, reduced complexity, and scalable security for your hybrid workforce.

Maximum performance with local data storage

Minimal latency and an outstanding user experience for your employees. You’ll also benefit from German-language support provided by security-vetted experts who understand your regulatory requirements.

Zscaler & STACKIT MB

ZSCALER ON STACKIT – THE IDEAL COMBINATION FOR A SOVEREIGN CLOUD STRATEGY

Zscaler, the long-standing leader in the Gartner® Magic Quadrant™ for Security Service Edge (SSE), and STACKIT, the Schwarz Group’s leading sovereign cloud provider, are joining forces. The result is a highly available security architecture designed specifically to meet the requirements of German enterprises, KRITIS operators, and the public sector.

THE THREE PILLARS OF ZSCALER ON STACKIT

Verified Security: Our Certification

Zscaler on STACKIT meets the strictest national and international compliance and security standards. Its unique selling point is the seamless operation provided by STACKIT, which—through BSI C5 certification—demonstrates the highest level of cloud security, verified by the German Federal Office for Information Security (BSI). This combination of market-leading cloud security and European infrastructure offers you fully verified protection:

BSI C5 conformity
Zscaler Architektur

What does "zero trust" mean?

At Zscaler, zero trust means that the platform does not automatically trust any user or device. Instead of granting users blanket access to the entire corporate network, Zscaler verifies every single request in real time and connects users only to the specific application they need. The rest of the network remains invisible and protected from potential attackers. This consistent approach eliminates the digital attack surface, proactively prevents threats, and secures sensitive data highly effectively.

Tobias Träbing

STACKIT and Zscaler 
Combine Security and 
Sovereignty

“In today’s threat landscape, security and sovereignty should no longer be a contradiction. With Zscaler on STACKIT, we offer exactly what critical infrastructures and regulated markets need today: the world’s leading zero-trust architecture, operated in an uncompromisingly sovereign European cloud. This is a true milestone for our customers’ digital resilience and global innovation.”

Tobias Träbing

Managing Director, Cyber Security • Schwarz Digits Cloud

Get in touch

FAQ: Frequently Asked Questions About Zscaler on STACKIT

What exactly is “Zscaler on STACKIT”? 

“Zscaler on STACKIT” is a joint service offering that combines Zscaler’s market-leading Zero Trust Exchange platform with STACKIT’s European sovereign cloud infrastructure. The solution is specifically tailored to the requirements of highly regulated industries and the public sector.

 

What is the core vision of the STACKIT & Zscaler partnership? 

Sovereignty and Zero Trust united—for a secure, independent digital future for Europe.

 

Which Zscaler services are included in the offering?

The initial scope includes the core “Zscaler for Users” services:

  • Zscaler Internet Access (ZIA): secure internet and SaaS access
  • Zscaler Private Access (ZPA): Zero Trust access to private applications

     

What are the benefits of combining these two solutions?

Market-leading SASE/Zero Trust security, paired with 100% digital sovereignty, top performance through local data centers, and guaranteed GDPR compliance.
The key features are:

  • Zscaler already meets a high standard for digital data sovereignty. Based on European requirements regarding operational independence, this scope has been expanded in collaboration with STACKIT.

The joint offering provides the following features:

  • Data sovereignty: Zscaler services are delivered directly from STACKIT’s EU-operated data centers, ensuring that all data and logs remain within the region. The Zscaler architecture, combined with STACKIT, ensures full GDPR compliance and mitigates the risk of access by third countries (e.g., the U.S. CLOUD Act).

Operational sovereignty: 

  • The service includes the deployment, management, operation, and support of the entire cybersecurity cloud platform, all carried out by STACKIT.

Objective:  

  • The solution is designed to support compliance with complex EU regulations and national assurance schemes.
     

For which companies is this solution particularly suitable?

The solution is particularly suitable for European companies, KRITIS operators, the public sector, and highly regulated industries that are subject to the strictest requirements for sovereignty, resilience, and the protection of classified data, and that do not want to compromise between data protection and cybersecurity.

 

Who operates the solution, and who has access to my data?

The platform is operated on the STACKIT cloud infrastructure of the Schwarz Group, a German company with data centers in Germany and Austria. Operations are carried out by European staff under European jurisdiction. Access by authorities from third countries (e.g., via the U.S. CLOUD Act) is prevented by the architecture and operating model.

 

Who is responsible for operations, support, and incident response?

The service includes end-to-end managed operations: platform operation, patching, monitoring, 24/7 support, and incident response by European staff. Escalation procedures and SLAs are clearly defined in the contract.

Where is my data processed with “Zscaler on STACKIT”?

Exclusively in STACKIT’s highly secure data centers (e.g., in Germany and Austria), operated by the Schwarz Group.

 

How is digital sovereignty specifically ensured?

Sovereignty is guaranteed on four levels:

  • Data sovereignty: Processing and storage exclusively in EU data centers
  • Operational sovereignty: Operations managed by European staff, under EU jurisdiction
  • Technological sovereignty: No dependence on non-EU hyperscalers.
  • Legal sovereignty: Contracts governed by German and EU law; no extraterritorial access
     

How is classified data or data requiring special protection handled?

Through inline DLP, TLS inspection, encryption in transit and at rest, and granular policy controls. Logs and metadata remain entirely within the EU. Optional Bring-Your-Own-Key (BYOK) and Hold-Your-Own-Key (HYOK) models are available.

 

What does Zero Trust mean at Zscaler?

Zero Trust at Zscaler means that the platform does not automatically trust any user or device. Instead of granting users blanket access to the entire corporate network, Zscaler verifies every single request in real time and connects users exclusively to the exact application they need. The rest of the network remains invisible and protected from potential attackers. This consistent approach eliminates the digital attack surface, proactively prevents threats, and secures sensitive data highly effectively.

Make your operations more productive and secure!

Take advantage of the unique combination of Zscaler, the zero-trust market leader, and the data-sovereign STACKIT Cloud to radically minimize risks—
—such as those posed by your workforce’s hybrid work arrangements.