Sovereignty You Can Audit
A verifiable virtualization layer for cloud providers building sovereign infrastructure. Open source, reproducible, and authorized for BSI VS-NfD classified workloads.
Verifiable by Design
Every cloud offering advertises with “sovereign”, but what actually means it? If you ask how sovereignty is actually implemented at the virtualization layer, most providers point to organizational measures: contracts, jurisdictions, perimeter controls. The Cyberus Hypervisor and CTRL-OS give cloud providers a virtualization foundation whose security claims can be independently checked:
100% Open Source
No black boxes at the isolation boundary and every line of code in the stack is inspectable.
Reproducible Builds
Anyone can rebuild the exact binaries from source and verify that what runs in production matches the published code.
BSI-Authorized Isolation
The approval process required an in-depth technical evaluation of the isolation properties, conducted by the authority itself.
We run what we sell
Every release of our hypervisor and CTRL-OS is tested automatically on physical hardware using Cidoka, our own test platform, before it ships. The same discipline we apply to ourselves, we offer to our customers.
- Every release tested on physical hardware
- Same discipline, internally and externally
- Documented test evidence for your auditors
Contributing to Europe’s Digital Sovereignty

Part of an Ecosystem
Contributor to Apeiro-RA, the EU-funded reference architecture for sovereign cloud infrastructure
Flexible Orchestration
Integration paths for open orchestration layers (Kubernetes, OpenStack, ...)
Compliance-First
Designed for compliance contexts including the EU Cyber Resilience Act
Building a Sovereign Offering?
Talk to our engineers about integrating a verifiable virtualization layer into your platform. We work with providers at the architecture stage, not just at the license stage.
