A server in Frankfurt is an address. It is not a security property. Yet startups pronounce "German servers" in the tone normally reserved for encryption. The phrase does useful legal work: it tells a customer which jurisdiction governs the machine. Then the slide deck starts cheating. Geography is made to answer questions about keys, administrator access, backups and code changes. It cannot.
Data residency means placement. Data sovereignty means control. Security means capability: who can decrypt, who can alter, who can conceal. A German server can hold plaintext backups, a permanent master key and an administrator with production access. The flag changes the court. It does not revoke root access.
The category error
Jurisdiction matters. It determines who can compel a company, where a customer can sue and how a seizure unfolds. Latency and resilience have addresses too. None of this is trivial. It is simply not encryption. Calling a local rack "sovereign" while the vendor retains unrestricted decryption power is not a security claim. It is a category error with a sales budget.
A postcode identifies the building. It does not constrain the operator.
Run the uncomfortable comparison. One service runs in China. The customer holds the keys; staff cannot read stored records; privileged access is narrow; releases are authenticated; every sensitive change leaves evidence. The other runs in Frankfurt. Its operators hold the keys, browse production, deploy unreviewed code and explain breaches after the newspaper does. Choose the first system. Immediately. This is not an endorsement of Chinese state power. It is a refusal to pretend that a German postcode repairs a system whose operator can already betray you.
Proof has a shape
A serious security page answers boring questions. Who holds the keys? Can an employee decrypt? What enters the logs? Are backups encrypted? Who approves a release? How does a customer learn about a breach? End-to-end encryption, least privilege, authenticated releases and independent audits are mechanisms. "Sovereign cloud" is vocabulary. Vocabulary cannot deny an administrator access.
Mathematics is valuable because it makes narrow promises and keeps them. NotaVera pins critical integrity rules with SHA-256 build seals. Change the approved bytes and the build fails. The seal does not prove that the code is wise or that the company is virtuous. It proves something smaller and harder: these are the bytes we approved; these are not. A slogan requests trust. A seal exposes drift. 1
That boundary is the point. A hash does not encrypt data. Encryption does not prevent an authorized executive from creating an exception. Every system ends where a person still has discretion. Good architecture reduces that discretion, records what remains and makes the cost of cheating visible.
The founder is in the threat model
Proton is trusted partly because Switzerland changes the legal frame. It is trusted more deeply because its zero-access design limits what Proton can decrypt, its code is public and its claims can be inspected. A Swiss postcode cannot remove a key the company still holds. An architecture can remove the key from the company. 2
Its transparency reporting states the remaining limit plainly: authorities may obtain some account information; encrypted content is data Proton says it cannot decrypt. That is the adult version of a security claim. It names what law can demand and what architecture can surrender. Move that design to a less flattering country and the legal risk changes, but the technical limit survives. Leave it in Switzerland, replace it with plaintext and unrestricted access, and the Alpine branding becomes theatre. 3
Founders prefer to omit themselves from the threat model. They decide whether master keys exist, whether logs hoard plaintext, whether auditors see the ugly parts and whether customers hear about failure before the press does. Integrity is not a value on the careers page. It is the decision to reduce your own power, document the remainder and disclose when it fails.
Use law for law. Use geography for geography. Use cryptography for confidentiality. Use governance for power. If a vendor answers "Where are the servers?" when you asked "Who can decrypt?", they have already told you what they are selling: a flag where proof should be.
- National Institute of Standards and Technology. (2015). FIPS PUB 180-4: Secure Hash Standard (SHS). https://doi.org/10.6028/NIST.FIPS.180-4
- Proton. (2026). "What is zero-access encryption?" Accessed July 14, 2026. https://proton.me/learn/encryption/types-of-encryption/zero-access
- Proton. (2026). "Transparency report." Updated January 6, 2026; accessed July 14, 2026. https://proton.me/legal/transparency