Summary
- Bitdefender will host GravityZone on Aruba’s cloud infrastructure while retaining operational control of the security platform.
- The companies say customer data, configuration information, security events, and telemetry will remain stored and processed inside the European Union.
- The partnership shows European technology providers turning digital sovereignty into decisions about jurisdiction, infrastructure, operations, and data handling.
European technology sovereignty is moving deeper into the security stack, with Bitdefender and Italian cloud provider Aruba combining cybersecurity software and locally controlled infrastructure for organisations that want greater certainty over where operational security data is stored and processed.
Bitdefender will host its GravityZone cybersecurity platform on Aruba’s cloud infrastructure, while Aruba will resell the Romanian company’s wider business-security portfolio across prevention, detection, and response. Bitdefender retains operational control of GravityZone, with Aruba providing the underlying infrastructure.
The companies say customer and configuration data, security events, and telemetry will not be accessed, transferred, or processed outside the European Union. That distinction gives the arrangement a stronger sovereignty claim than simply placing a software service in an EU data centre, although customers will still need to examine the wider technology, support, legal, and supply-chain dependencies behind the service.
GravityZone combines endpoint protection, endpoint detection and response, extended detection and response, cloud security, risk analytics, and compliance functions. Those systems process particularly revealing operational data because their job is to monitor machines, users, identities, applications, and suspicious behaviour across an organisation.
Security data creates its own sovereignty problem
Cybersecurity platforms are often deployed precisely because organisations need broad visibility across their technology estate, which means the platform itself can accumulate information about devices, users, software, network behaviour, vulnerabilities, and incidents. Sending that telemetry to a security service outside an organisation therefore creates another dependency alongside the risks the product is intended to control.
Data location is only one element of that dependency. The European Commission’s own cloud-sovereignty framework assesses providers across legal and jurisdictional control, operational independence, supply chains, technology, security, compliance, and data, reflecting the difficulty of reducing sovereignty to the postcode of a server.
Bitdefender and Aruba are consequently emphasising both location and operational control. Aruba supplies infrastructure in Italy, while Bitdefender says data will remain encrypted and under its exclusive management, creating a division between the operator of the cloud environment and the operator of the cybersecurity platform.
The model fits particularly closely with regulated sectors including financial services, healthcare, public services, energy, manufacturing, and critical infrastructure, where the consequences of losing control over security telemetry can extend beyond an ordinary software outage. NIS2 and DORA have also raised the importance of understanding technology dependencies, access controls, incident processes, and supplier risk rather than treating cloud procurement as a simple question of price and functionality.
European providers are building sovereignty layers
The Italian agreement is part of a wider pattern rather than an isolated localisation exercise. Bitdefender has already announced European sovereignty arrangements involving OVHcloud in France and secunet in Germany, giving it different routes into markets where customers or public bodies may favour regional infrastructure and European-controlled suppliers.
Infrastructure providers are responding to the same demand from the opposite direction. Recent projects such as Microsoft’s extension of Azure infrastructure into Luxembourg have placed greater emphasis on local data residency, while European operators are competing on jurisdiction, control, and independence as well as latency and capacity.
Those approaches are not interchangeable. A local region operated by a global hyperscaler can meet residency requirements without satisfying every definition of technological or jurisdictional sovereignty, while a European-owned service can still rely on non-European processors, software components, and supply chains.
Organisations therefore have to decide which forms of sovereignty are actually required for a particular workload. Security telemetry from a public authority may justify stricter controls than ordinary collaboration software, while a multinational business may place more value on consistent global operations than on maximising local control in every market.
Residency does not remove operational risk
Keeping security information inside Europe does not make a service secure by definition. Customers still depend on configuration, identity management, encryption, vulnerability handling, monitoring, incident response, backups, operational access, and the ability of the two suppliers to manage their shared responsibilities without creating gaps between them.
The division of responsibilities is particularly important in security services because failures can occur at several layers. Aruba is responsible for the underlying cloud infrastructure, Bitdefender controls the security platform, and the customer remains responsible for deploying and configuring the service appropriately across its own environment.
Procurement language around sovereignty is therefore useful only when it can be translated into technical and contractual detail. Buyers need to establish who can access telemetry, where support staff operate, which subcontractors are involved, how encryption keys are managed, what happens during an incident, and whether changing provider later would create another dependency.
Bitdefender and Aruba are nevertheless putting those questions closer to the centre of an ordinary cybersecurity purchase. European sovereignty has spent several years appearing in policy papers and cloud strategies; arrangements such as this one are turning it into the less glamorous architecture of where logs sit, who operates the software above them, which jurisdiction applies, and who has the ability to intervene when something goes wrong.












