What exactly is “Zscaler on STACKIT”?
“Zscaler on STACKIT” is a joint service offering that combines Zscaler’s market-leading Zero Trust Exchange platform with STACKIT’s European sovereign cloud infrastructure. The solution is specifically tailored to the requirements of highly regulated industries and the public sector.
What is the core vision of the STACKIT & Zscaler partnership?
Sovereignty and Zero Trust united—for a secure, independent digital future for Europe.
Which Zscaler services are included in the offering?
The initial scope includes the core “Zscaler for Users” services:
- Zscaler Internet Access (ZIA): secure internet and SaaS access
- Zscaler Private Access (ZPA): Zero Trust access to private applications
What are the benefits of combining these two solutions?
Market-leading SASE/Zero Trust security, paired with 100% digital sovereignty, top performance through local data centers, and guaranteed GDPR compliance.
The key features are:
- Zscaler already meets a high standard for digital data sovereignty. Based on European requirements regarding operational independence, this scope has been expanded in collaboration with STACKIT.
The joint offering provides the following features:
- Data sovereignty: Zscaler services are delivered directly from STACKIT’s EU-operated data centers, ensuring that all data and logs remain within the region. The Zscaler architecture, combined with STACKIT, ensures full GDPR compliance and mitigates the risk of access by third countries (e.g., the U.S. CLOUD Act).
Operational sovereignty:
- The service includes the deployment, management, operation, and support of the entire cybersecurity cloud platform, all carried out by STACKIT.
Objective:
- The solution is designed to support compliance with complex EU regulations and national assurance schemes.
For which companies is this solution particularly suitable?
The solution is particularly suitable for European companies, KRITIS operators, the public sector, and highly regulated industries that are subject to the strictest requirements for sovereignty, resilience, and the protection of classified data, and that do not want to compromise between data protection and cybersecurity.
Who operates the solution, and who has access to my data?
The platform is operated on the STACKIT cloud infrastructure of the Schwarz Group, a German company with data centers in Germany and Austria. Operations are carried out by European staff under European jurisdiction. Access by authorities from third countries (e.g., via the U.S. CLOUD Act) is prevented by the architecture and operating model.
Who is responsible for operations, support, and incident response?
The service includes end-to-end managed operations: platform operation, patching, monitoring, 24/7 support, and incident response by European staff. Escalation procedures and SLAs are clearly defined in the contract.
Where is my data processed with “Zscaler on STACKIT”?
Exclusively in STACKIT’s highly secure data centers (e.g., in Germany and Austria), operated by the Schwarz Group.
How is digital sovereignty specifically ensured?
Sovereignty is guaranteed on four levels:
- Data sovereignty: Processing and storage exclusively in EU data centers
- Operational sovereignty: Operations managed by European staff, under EU jurisdiction
- Technological sovereignty: No dependence on non-EU hyperscalers.
- Legal sovereignty: Contracts governed by German and EU law; no extraterritorial access
How is classified data or data requiring special protection handled?
Through inline DLP, TLS inspection, encryption in transit and at rest, and granular policy controls. Logs and metadata remain entirely within the EU. Optional Bring-Your-Own-Key (BYOK) and Hold-Your-Own-Key (HYOK) models are available.
What does Zero Trust mean at Zscaler?
Zero Trust at Zscaler means that the platform does not automatically trust any user or device. Instead of granting users blanket access to the entire corporate network, Zscaler verifies every single request in real time and connects users exclusively to the exact application they need. The rest of the network remains invisible and protected from potential attackers. This consistent approach eliminates the digital attack surface, proactively prevents threats, and secures sensitive data highly effectively.