CloudCondom mascot

CloudCondom / Phantom

EU data sovereignty on US cloud infrastructure

Stay on AWS / GCP / Azure — change nothing in your code — own your keys

“Responsible consumption of US cloud resources”

The Problem

Every EU company on US cloud infrastructure faces an unresolved legal conflict: the CLOUD Act compels US providers to disclose data regardless of where it’s stored, while GDPR prohibits exactly that. Schrems III is expected to invalidate the current EU-US Data Privacy Framework — again.

EU sovereign clouds aren’t ready. Migration costs millions and takes years. Enterprises need a solution today, on the infrastructure they already use.

The Solution

Phantom is a Kubernetes operator that ensures secrets never enter the cloud provider’s infrastructure. A mutating webhook injects a sidecar that fetches secrets from an EU-hosted vault directly into process memory. The provider has nothing to hand over.

One Helm install. Zero code changes. Cryptographic proof of sovereignty.

No migration needed. No application rewrites. Just deploy a Helm chart and your secrets bypass Kubernetes entirely.

Why Not HYOK / Cloud EKM?

Cloud providers offer “Hold Your Own Key” but it doesn’t solve the problem: keys enter provider RAM during use, the provider controls compute, and K8s Secrets are plaintext on read. Phantom ensures secrets never enter provider infrastructure at all.

What Phantom Protects (and What It Doesn’t)

Phantom is a credential sovereignty tool. It’s precise about what it protects.

Protected by Phantom

  • Database passwords, API keys, TLS certs — never in etcd
  • K8s-deployed databases (PostgreSQL, MongoDB, MySQL, CockroachDB) — credentials + TLS certs + LUKS encryption keys from OpenBao. All SQL queries work. Cloud sees only ciphertext.
  • Data in S3/GCS — app encrypts with Phantom-delivered key, cloud stores ciphertext it can’t read
  • Encryption keys for client-side crypto

Not Protectable (by design)

  • Managed DBs (RDS, Cloud SQL) — cloud runs the DB engine, must read data to query it. Use K8s-deployed DBs instead.
  • S3/GCS without client-side encryption — provider can read it
  • Process memory without TEE — use Phantom Hardened for hardware guarantee

Run your database in Kubernetes with Phantom-delivered keys — full SQL, full sovereignty. See the FAQ for detailed protection matrices per database.

Market Opportunity

$23.1B
EU sovereign cloud by 2027
$463B
Confidential computing by 2034
660%
Search surge for EU alternatives
€5.88B
Cumulative GDPR fines

Why Now

  • DORA enforced Jan 2025 — EU financial sector must demonstrate ICT risk management
  • NIS2 broadens cybersecurity to 18 sectors
  • Schrems III expected — DPF governance already undermined (PCLOB quorum removed)
  • AWS EU Sovereign Cloud launched Jan 2026 — validates market, doesn’t solve jurisdiction
  • Denmark ditching Microsoft for sovereignty reasons

Competitive Positioning

No existing product combines: K8s-native + secrets never in etcd + no code changes + hardware attestation + EU sovereignty focus.

Capability CloudCondom Thales Fortanix Anjuna ESO
K8s-nativeYesNoNoPartialYes
Secrets never in etcdYesN/AN/AN/ANo
No code changesYesNoNoPartialYes
Hardware attestationYesNoYesYesNo
EU sovereignty focusPrimarySecondaryNoNoNo

Target Customers

EU enterprises (500–10,000 employees) on managed Kubernetes with regulated workloads.

IndustryPainWTPPriority
Financial servicesVery HighVery High1
Healthcare / pharmaHighHigh2
GovernmentVery HighMedium3
SaaS (EU customers)HighMedium-High4

Business Model

Open-Core

Webhook + sidecar: open-source. Managed EU-hosted OpenBao, SaaS dashboard, compliance reporting: paid.

Pricing

$50–150/node/month. Standard (any instance) and Hardened (TEE required, premium).

B2C Funnel

Open-source consumer deployment (OpenClaw-style) creates adoption funnel: developers who use Phantom personally become advocates inside enterprises.

Revenue Timeline

Month 1–4

MVP: webhook + sidecar + OpenBao integration + circuit breaker + caching

Month 4–5

AMD SEV-SNP attestation on GKE — ready for design partners

Month 5–6

Helm chart, docs, first design partner deployments

Month 6–9

First paying customer

Month 14–20

$1M ARR

Month 24–36

$5M ARR

Assessment Scores

Product-Market Fit
8.5 / 10
Architecture
8.5 / 10
Security
8.0 / 10
Operations
8.0 / 10
Weighted Overall
8.25 / 10

The Ask

3–4
Engineers to build MVP
4–5 months
To design partner ready
GKE first
Single provider focus

BUILD IT — but ship 20% of what’s planned

Phantom only. GKE only. 3 design partners in EU financial services. Independent security audit. Everything else is Phase 2.