What is the CLOUD Act?
The US CLOUD Act (Clarifying Lawful Overseas Use of Data Act, 2018) lets US authorities require providers subject to US jurisdiction to disclose data in their possession, custody or control, wherever in the world that data is stored.
Written by Ugo Balducci. Last updated
What the CLOUD Act means
The Clarifying Lawful Overseas Use of Data Act was enacted in March 2018 as part of the Consolidated Appropriations Act, 2018. Its core provision, 18 U.S.C. § 2713, confirms that a provider subject to US jurisdiction must answer a valid US warrant or order for data in its possession, custody or control, even when the data is stored outside the United States. The Act gives a formal route to challenge an order that conflicts with the law of a country that has an executive agreement with the US. Elsewhere a provider can still raise a conflict of laws, but the starting point is disclosure.
The Act also allows the US to sign executive agreements with other countries for cross-border access to data. Switzerland has no such agreement with the US today. A foreign authority that wants data from a Swiss company normally goes through international legal assistance handled by the Swiss authorities. The US Department of Justice publishes the Act’s text, its executive agreements and its own explanation on its CLOUD Act resources page.
Why it matters when choosing where software runs
The Act follows the company, not the server. A European datacentre operated by a US company, or by a subsidiary of one, can still fall within its reach. Whether a non-US company with ties to the United States is covered depends on the facts, so the useful question is: which companies in my data path answer to US courts?
That list is longer than the main vendor. It includes the hosting provider, the content delivery network, the identity provider, error reporting and any AI API your apps call. Many organisations accept some of that exposure; the point is to decide it knowingly. This is one part of data sovereignty.
How Pilae handles it
Pilae SA is a Swiss company with no US parent, no US subsidiary and no US office, operating under Swiss law. Pilae Cloud runs on dedicated machines in ISO 27001-certified datacentres, and in Swiss and EU regions they are run by European datacentre operators, outside US jurisdiction. You can also run everything on your premises or air-gapped.
We are open about where US companies can still appear. Our public edge and email delivery run on a US-owned network provider, and an external AI model is reached only if you enable it. Every company that processes your data is disclosed to you in the signed DPA with its role. Your apps can answer only on the private mesh, error reporting can be switched off, and AI can run on a model inside your perimeter. The services you exclude are written into your contract. The details are on the jurisdiction page.