Summary
- Zscaler’s Zero Trust Exchange is being delivered from German datacentres on Schwarz Digits’ STACKIT cloud.
- The service is available across Europe and aimed particularly at public administration, defence, finance, and healthcare.
- Procurement assessments will need to cover software updates, administrative authority, telemetry, encryption, incident response, and service continuity.
A European-hosted version of Zscaler’s security service edge platform is now available from German datacentres, adding a sovereign operating model to a category of security infrastructure normally delivered through globally managed vendor clouds.
Zscaler and Schwarz Digits are delivering the Zero Trust Exchange platform through STACKIT, the German cloud operation owned by Schwarz Group. The companies said the service is available across Europe and designed particularly for public administration, defence, financial services, healthcare, and other regulated environments.
STACKIT operates the underlying infrastructure from German datacentres, while the joint offering covers deployment, management, operation, and support of the Zscaler platform. Customer data is intended to remain within the European Union, with the service aligned to European legal and operational requirements.
Security service edge platforms occupy an influential position within enterprise architecture because they inspect network traffic, enforce access policy, connect users to private applications, and process security telemetry from distributed environments. The control plane can support consistent policy across a large organisation, although its availability and administrative integrity become dependencies for access to business services.
The German deployment responds to demand for technology services that combine established security capabilities with European infrastructure and data residency. Public bodies and regulated companies have increasingly sought greater control over the jurisdiction, operation, and support of cloud services that handle sensitive traffic and identity information.
Operational control within a shared service
Data location forms one part of that control. The operating model must also define who can approve emergency changes, distribute software updates, access diagnostic information, administer customer environments, and respond when either the application or infrastructure layer is affected by an incident.
The partnership divides technical responsibility between a security platform provider and a cloud operator, creating a service whose resilience depends on the interface between them. A platform defect may require evidence and remediation from Zscaler, while an infrastructure outage or compromise may sit within STACKIT’s area of control. Customers need one incident process capable of working across both layers.
Contracts and operating procedures should identify which company retains security logs, who leads customer notification, how forensic evidence is preserved, and which party can isolate a compromised service. The same documents should explain how administrative access is authenticated, whether support personnel can operate from outside the EU, and where encryption keys and policy data are held.
The deployment forms part of a broader European move towards cloud and security services that can be operated under regional governance without requiring organisations to replace every technology product with a locally developed alternative. Such arrangements retain access to established software while moving infrastructure and parts of the operating model into Europe.
Dependencies on the original software provider remain part of the service. Product engineering, security fixes, release decisions, and major platform changes continue to rely on the company maintaining the application. European hosting can strengthen local operational control without removing the need to assess those software dependencies.
Organisations subject to the Digital Operational Resilience Act, the Network and Information Systems Directive, or sector outsourcing requirements will need to incorporate the service into their concentration-risk and continuity assessments. Testing should cover the failure of identity services, management portals, network connectivity, policy distribution, and support channels rather than considering only the availability of the underlying datacentre.
Exit planning also remains part of resilience. Security policy, logs, configurations, and application connections must be portable enough to support a migration or emergency replacement without prolonged loss of access.
The partnership gives European organisations a new operating option for a security platform that can sit across much of the enterprise network. Its durability will depend on the clarity of administrative control, the integration of incident processes, and the ability to maintain essential access when either partner’s service is disrupted.



