Codebahn

The CLOUD Act and your Git host

“CLOUD Act compliant” is what people search. It is also a misnomer. US providers comply with the CLOUD Act by handing data over. You do not comply your way out of it. You get out of its reach.

Data residency is not data sovereignty

Data residency is where data physically sits. Data sovereignty is whose law governs it. Ticking “EU region” in a US provider’s dashboard changes the datacenter. It does not change the legal entity that controls the data, or which government can compel that entity to produce it.

What the CLOUD Act does

The Clarifying Lawful Overseas Use of Data Act (2018) lets US authorities compel any provider subject to US jurisdiction to produce data in its possession, custody, or control, regardless of where that data is stored. It applies to US-incorporated companies and extends to their subsidiaries. It bypasses the mutual legal assistance treaty (MLAT) process that would otherwise route the request through the courts of the country where the data sits.

This sits in direct tension with GDPR Article 48, which says third-country court judgments requiring data disclosure may only be recognised if based on an international agreement.

The CLOUD Act is the floor, not the ceiling. FISA Section 702 authorises programmatic surveillance of non-US persons via US electronic communication service providers. National security letters add another layer. Each applies independently.

Why “EU region” does not fix it

The jurisdiction follows the company, not the server. A US provider’s “EU region” or “sovereign cloud” product limits operational access but not its legal obligations under US law.

In June 2025, Microsoft France’s director of public and legal affairs was asked before a French Senate inquiry whether he could guarantee that French data would never be transmitted to US authorities without explicit French authorisation. He replied: “No, I cannot guarantee that, but, again, it has never happened before.”

This is not a failing specific to Microsoft. It is structural. Any provider under US jurisdiction faces the same constraint, regardless of what the marketing says about data locality.

What puts you out of reach

The test is straightforward: process data via a non-US entity with no US parent, using sub-processors that are themselves non-US entities and have no control relationship with a US company.

Codebahn meets that bar:

Entity, servers, law. No link in the chain is subject to a US court order.

Indirect exposure can reintroduce the problem. A US-owned integration, a US admin, or a US sub-processor at any layer brings the jurisdiction back. Codebahn’s chain is fully EU with no US entity at any point.

This is what we can say about our side of the stack. Your overall compliance depends on your full stack and your own assessment. This page is information, not legal advice; a formal view means a DPIA or Transfer Impact Assessment with qualified counsel.

SOC 2 or ISO 27001 audit reports today: we are not your vendor yet.

Sovereignty includes leaving

One-click export, standard Forgejo format. No ticket, no wait. Sovereignty that locks you in is not sovereignty; it is a new dependency wearing an EU flag.

How EU hosting works. Data Processing Agreement. Sub-processor list. Security overview. Sovereignty and data residency. Pricing.

Open an account Or email hello@codebahn.net with questions.

This is not legal advice. The law around cross-border data access changes; verify current status with qualified counsel. GitHub is a trademark of GitHub, Inc. Codebahn is not affiliated with or endorsed by Microsoft, GitHub, or any provider referenced on this page.