When the provider has to shut down: jurisdiction risk in password managers
Whoever controls the infrastructure controls availability and access – including for your credentials.
Credentials are the most sensitive category of data in a company: they are the key to every other system. Where this key ring resides – and which legal order governs the provider and the infrastructure – determines who can access it in an emergency and who may shut the service down. This is exactly what digital sovereignty means: control over where data resides, who accesses it and whether a service remains available. With cloud-based services under foreign jurisdiction, that control is not unlimited – it is subject to foreign laws and official orders.
Availability is not guaranteed: a current example
In June 2026, something that sounds abstract became tangible: an export-control order by the US government required the AI provider Anthropic to suspend access to two of its most advanced models for foreign nationals – regardless of whether they were inside or outside the USA. Because users’ nationality could not be checked reliably in real time, the provider proactively switched the affected models off for all customers. Within a few hours, a previously freely available product could no longer be used – regardless of running contracts, paid subscriptions or the users’ physical location.
The case is instructive for one reason: it was not a technical outage, but a regulatory decision. A contractual availability commitment (SLA) does not protect against this – if a provider has to comply with an official order, that order takes precedence over the contractual commitment. For non-critical services, this is an annoyance that can be tolerated. For business-critical infrastructure, it is a risk that belongs in the architecture decision.
Two dimensions of jurisdiction risk
Anyone who entrusts data or services to a provider under a foreign legal order accepts two distinct risks:
- Access: Authorities in the relevant country may, under certain circumstances, force the provider to hand over data – even if the data is physically stored in Europe.
- Availability: Sanctions, export controls or other sovereign orders may require the provider to discontinue a service for certain user groups or regions.
Both risks are independent of the technical quality of the service or the contractual situation. They arise solely from the question of which legal order the provider is subject to.
Why this matters especially for password managers
A password manager is not an ordinary service. It contains the credentials for practically all other systems in a company – from email accounts, servers and cloud services to accounting. Whoever compromises or switches off this central vault indirectly reaches everything else.
That changes the risk assessment: for many applications, the balance may favour the convenience of the cloud. For the vault containing the company’s master keys, however, control over access and availability is paramount. Here, a jurisdiction risk does not affect a single system, but potentially the entire IT environment.
The legal background
Jurisdiction risk with providers under a foreign legal order is not a theoretical construct, but is rooted in specific laws. It is not limited to the USA – comparable rules exist in other states – but three points are particularly relevant for the European market:
- CLOUD Act (USA, 2018): Requires providers of electronic communication or remote computing services under US jurisdiction to disclose data in their possession, custody or control – regardless of whether it is stored inside or outside the USA. A European data center operated by a US provider therefore does not necessarily rule out access.
- Intelligence-service access rules: Powers such as FISA Section 702 concern, under certain conditions, the targeted collection of communications of non-US persons outside the USA via US communication services. The scope and legal status of such powers must be assessed separately for the specific service.
- Third-country transfer under GDPR: Anyone who transfers personal data to providers in third countries or has it processed there must observe Art. 44 ff. GDPR. The EU-US Data Privacy Framework has provided a basis for certified US organisations since 2023, but it does not replace the risk and provider assessment for particularly sensitive data.
These rules do not make cloud services generally impermissible. But they shift control to some extent outside the company – and precisely this control is particularly valuable for credentials.
What digital sovereignty means in concrete terms
Digital sovereignty is easily misunderstood as a political buzzword. In practice, it simply means that the company retains control over the three questions that count in an emergency.
- Location: Where is the data stored, physically and logically?
- Access: Who can access the data – and who can be forced to provide access?
- Availability: Who decides whether the service continues to run?
Sovereignty does not mean avoiding cloud services on principle. It means not giving up control over the answers to these three questions for the most sensitive layer – the credentials.
On-Premises as the architectural answer
The obvious answer to jurisdiction risk is to keep control over the critical layer within the company. An On-Premises password manager keeps the encrypted databases, user management and logs entirely on infrastructure that the company controls itself.
A clear distinction is worthwhile here, because with self-hosting the password-manager provider is always removed as an external point for disclosure or shutdown – the remaining question is solely the infrastructure:
- Own data center: Vault, keys, backups and operation are entirely in your own hands. This is where digital sovereignty goes furthest – there is neither an external password-manager service nor an external infrastructure operator that could be forced to provide access or ordered to shut down.
- Private Cloud or own Azure-Tenant: Here too, no manufacturer operates the password-manager service. However, an infrastructure operator enters the picture – if it is subject to a foreign legal order, its jurisdiction risk must be assessed separately. The provider risk of the password manager disappears; the hosting risk remains.
For maximum control, operation in your own data center is therefore the clearest choice. The data-protection assessment becomes simpler in both cases because no third-country transfer is caused by the password-manager provider – details are available in the article GDPR password manager for businesses.
Sovereignty by operating model compared
Cloud password managers are not insecure per se – for organisations without their own infrastructure and without special sovereignty requirements, they can be an appropriate choice. The question is not “good or bad”, but: who should decide, in an emergency, over access to and availability of the most sensitive data?
| Criterion | SaaS password manager under foreign jurisdiction | On-Premises password manager in self-hosted operation |
|---|---|---|
| Data storage location | On the provider’s infrastructure | In your own data center, in a Private Cloud or in your own Azure-Tenant |
| Access by foreign authorities | Potentially possible via the provider – regardless of storage location | No password-manager provider as a disclosure point; with external hosting, the infrastructure operator must be assessed separately |
| Control over availability | The provider and its legal order determine whether the service runs | Your own IT determines operation and availability; no manufacturer service that could be switched off |
| Third-country transfer (GDPR) | To be assessed depending on provider and group structure | No third-country transfer by the password manager; hosting must be assessed separately |
| Evidence in audits | Depends on the provider’s evidence and commitments | Storage location, access paths and logs can be documented directly |
| Provider dependency | Ongoing subscription; service must remain available | Perpetual licence possible; operation not dependent on a manufacturer service |
In short: where control over access and availability is decisive, self-hosting is the consistent choice – not because cloud is ruled out in principle, but because credentials are the one layer where control should remain with you.
Password Depot: data sovereignty as a principle
The Password Depot Enterprise Server is consistently built for operation in your environment and does not force any external cloud service – data sovereignty remains entirely with you. The manufacturer is also decisive for the sovereignty question: Password Depot is developed by AceBIT GmbH, based in Darmstadt – a German company under German and European law. Developed since 1998, used by more than 100,000 customers.
- Operation in your infrastructure: On-Premises in your own data center, in a Private Cloud at the hosting partner of your choice or in your own Azure-Tenant – the encrypted databases do not leave the area of responsibility you have chosen.
- Manufacturer under EU law: As a German company, AceBIT is not subject to the US CLOUD Act. If you use external infrastructure, its operator must be assessed separately – the choice is yours.
- Verifiable security architecture: AES-256 (algorithm according to FIPS 197) and TLS 1.3, a SySS penetration test for Password Depot 19 (12/2025) with the result “no serious security vulnerabilities identified”, and an ISMS of AceBIT GmbH certified to ISO/IEC 27001:2022 by TÜV NORD CERT.
- Can be operated in line with GDPR: Because the data remains on the infrastructure selected by you in self-hosted operation, the password manager causes no third-country transfer; roles, logging and encryption support the technical and organisational measures under Art. 32 GDPR. Actual compliance also depends on your configuration and processes. All evidence is available in the Trust Center.
This turns the supposed disadvantage of self-hosting into a strategic advantage: Password Depot is the operating model in which no third-party manufacturer service decides over access to your master keys or the availability of your vault.
Conclusion: sovereignty is an architecture decision
Availability and access protection cannot be guaranteed by contract alone if the underlying provider or infrastructure chain is subject to a foreign legal order – the example from June 2026 makes that clear. For most systems, this dependency is acceptable. For the password manager that holds the keys to everything else, it is not. Anyone who wants to retain control over location, access and availability is best advised to make this decision at the architecture level – through self-hosted operation under their own control and with a manufacturer under European law.
Convince yourself in your own environment: test the Enterprise Server free for 30 days, see the solution in a live demo or request a no-obligation quote for your number of users.
Frequently asked questions about digital sovereignty
What does digital sovereignty mean in password management?
It means that the company retains control over three questions: where the credentials reside, who can access them and who decides over the service’s availability. In self-hosted operation in your own data center, all three answers lie with the company itself.
What is the CLOUD Act – and are German companies affected by it?
The CLOUD Act (USA, 2018) requires providers of electronic communication or remote computing services under US jurisdiction to disclose data in their custody or control – regardless of the physical storage location. For German companies, this can become relevant if they use such providers to manage sensitive data, even if the data is located in a European data center.
Does a European data center operated by a US provider protect against access?
Not necessarily. What matters is not only where the data is stored, but also which legal order the provider is subject to. If the provider is subject to US law, a disclosure obligation may also affect data stored outside the USA.
Does this make cloud password managers fundamentally insecure?
No. This is not about the technical security of encryption, but about control over access and availability. For organisations without special sovereignty requirements, cloud solutions can be appropriate. For credentials – the layer that unlocks all other systems – the balance often favours your own control.
How does On-Premises operation protect against jurisdiction risk?
With self-hosted operation, there is no external password-manager service that could be forced to disclose data, and no manufacturer-operated service that a foreign authority could shut down. In your own data center, storage location, access paths and availability are fully under the control of your own IT. With external infrastructure such as a Private Cloud or Azure-Tenant, the infrastructure operator must also be assessed.
Is Password Depot subject to US law?
No. Password Depot is developed by AceBIT GmbH, based in Darmstadt – a German company under German and European law. In On-Premises operation, the encrypted data remains in your own infrastructure or infrastructure selected by you. If external infrastructure is used, its provider must still be assessed separately.
Request a quote for your self-hosted operation
Choose your number of users and maintenance term – you will receive your individual quote for Password Depot Enterprise Server with no obligation and no sales call required.
Request a quote