#495 Whose cloud is it anyway?
Friday Ship #495 | June 12th, 2026

This week spoke to several region-specific managed service providers who are interested in providing Parabol to their customers in their specific regions.
A few weeks ago, in Friday Ship #487, I wrote that we’d never seen so many inbound requests for private- and self-managed instances of our software. That trend hasn’t slowed down. If anything, the conversations have gotten more specific. Customers aren’t asking whether they can keep their data inside a particular jurisdiction anymore—they’re asking us exactly how, and they’re bringing their lawyers.
It’s worth slowing down to explain why. “Data sovereignty” can sound like a procurement checkbox, but underneath it are two very real questions a defense ministry, a central bank, a hospital network, or a law firm now has to answer: Who can compel access to our knowledge? and What happens when the building it lives in goes dark?
The jurisdiction problem
Most teams assume that if their data sits on a server in their own country, it’s governed by their own country’s laws. That assumption is wrong, and it’s the single most common thing we end up correcting.
The reason is the U.S. CLOUD Act. Passed in 2018, it lets U.S. authorities compel any U.S.-based provider to hand over data in its “possession, custody, or control”—regardless of where in the world that data physically sits. A data center in Frankfurt or Riyadh owned and operated by a U.S. company is still reachable by a U.S. warrant. Residency is where the bytes live. Sovereignty is whose courts can reach them. They are not the same thing, and a flag painted on the side of a building doesn’t change which legal system applies.
This isn’t theoretical hand-wringing. In June 2025, Microsoft’s French subsidiary told a French Senate hearing, under oath, that it could not guarantee data held in France under its “sovereign” offering would be shielded from U.S. authorities. That admission landed hard in Europe, and it’s part of why regulators have stopped treating physical location as sufficient. The EU Data Act, which began applying in September 2025, now requires cloud providers to put technical and legal measures in place to prevent unlawful non-EU government access. For financial institutions, DORA stacks on top of that, with penalties reaching €10 million or 10% of annual turnover. Banks, in particular, are discovering that a GDPR-clean program doesn’t automatically satisfy banking-secrecy and operational-resilience obligations.
The upshot for our customers is simple: for a regulated organization, the only airtight way to keep knowledge under a single legal jurisdiction is to host it on infrastructure that the organization—not a foreign vendor—ultimately controls. That’s true whether the sensitive material is case files at a law firm, patient records at a hospital, or, increasingly, the institutional memory that lives in a knowledge management system. When your retros, decisions, and strategy docs accumulate in Parabol Pages, that corpus is the institution’s reasoning. It deserves the same jurisdictional care as the database it sits beside.
The resilience problem
The second question used to be hypothetical. It isn’t anymore.
This past March, Iran’s Revolutionary Guard used Shahed-136 drones to strike two Amazon data centers in the UAE and one in Bahrain, the first time data centers have been deliberately hit by air strikes in a conflict. Because multiple availability zones went down at once, the usual cloud redundancy model didn’t save anyone. Outages rippled through regional banks—Emirates NBD, First Abu Dhabi Bank, Abu Dhabi Commercial Bank—along with payment platforms and other services that assumed “the cloud” was someone else’s resilience problem. Weeks later, the IRGC publicly named a list of U.S. hyperscalers as “legitimate targets.”
You don’t have to be in the Gulf for the lesson to apply. A growing number of governments and institutions have concluded that concentrating their most sensitive collaboration on a handful of foreign-operated megastructures is a strategic risk—legally and physically. Sovereignty, it turns out, is partly about being able to keep working when someone else’s infrastructure is on fire.
What this means for how we build
None of this changes what Parabol is. It changes where it can run. Our job is to make a self-managed, single-tenant Parabol—including Parabol Pages—as boring to operate as our SaaS, so that an organization choosing sovereignty isn’t also choosing a worse product. A lot of this week’s unglamorous deployment work is exactly that: fewer external dependencies, cleaner configuration, and integrations that work in environments that never phone home.=
Metrics

Metrics were mixed this week, with predictable summer usage patterns starting to take effect. The bright spot was a significant rise in weekly meeting activity.
This week we…
…migrated Hocus Pocus to v4. It’s always a great feeling to make bugs go poof.
…added a feature that highlights similar reflections in a retro. We’re excited to help people group their reflections faster. More on this next week!
…started work on a Sprint Poker AI facilitator. We have ideas on how we can help our users accurately score their issues during estimation meetings.
Next week we’ll
…wrap up an Enterprise trial with a large financial services company and keep plugging away at our work in Cycle 14 .