The essentials
The CLOUD Act (2018) authorizes US federal authorities to request data from any company with a legal presence in the United States, regardless of where that data is hosted. Supabase, Firebase, and AWS Amplify each offer an EU hosting region — all three remain U.S. companies as the contracting entity. This criterion does not weigh in the same way depending on the project. It remains marginal for an MVP without sensitive data. It becomes a filter to check before even comparing prices, as soon as a DPO, health data or an EU public procurement enter the equation.
What BaaS benchmarks measure — and what they forget
BaaS comparisons are generally organized around four axes: price per use, functional richness, ease of migration, and developer experience. The functional richness covers auth, database, real-time, storage and edge functions. These are legitimate criteria. None of the four answers a simple question: who can legally access your data, and under what authority?
The CLOUD Act — Clarifying Lawful Overseas Use of Data Act — was enacted in March 2018 in the United States. It authorizes federal authorities to force any provider with a legal presence on American soil to produce the data it holds, even stored abroad (18 U.S.C. § 2713). The text directly responds to a dispute where Microsoft refused to transmit to the FBI data stored on a server in Dublin. Congress decided by law rather than waiting for the decision of the Supreme Court, then seized of the case.
This question does not appear on almost any public comparison grid, including on third-party sites dedicated to BaaS. The reason is structural: a comparison site lists features that can be checked — presence of an SDK, free quota, GraphQL support. The jurisdiction of a company is not a functionality that can be activated in an administration panel, so it does not fit into the usual table format. That doesn't make it any less decisive.
The details of the text, its articulation with the GDPR and a complete supplier verification checklist are covered in our guide GDPR compliant and EU sovereign backend. This section is limited to what actually changes in a BaaS comparison.
Checking an EU region only solves half the problem
Checking a European hosting region in an administration panel is not enough to go beyond the scope of the CLOUD Act. The law applies to the company that operates the service, not the physical location of the server — two pieces of information that a provider's pricing page almost never distinguishes.
Supabase, Inc. is the entity identified as data controller in its own privacy policy, with sites hosted primarily from the United States. Firebase is a product of Google LLC, a subsidiary of Alphabet Inc., a company incorporated under American law. AWS Amplify is contractually attached by default to Amazon Web Services, Inc., located in Washington State. All three offer an EU hosting region. The three remain, as a contracting entity, companies under American law.
This is not a judgment on their technical quality — it is an observation on the legal structure of the entity signing the contract with you. An excellent product can remain legally exposed; the two evaluations are independent of each other.
Aurabase SAS is a company incorporated under French law. Its production infrastructure is verified in Germany (Nuremberg, Falkenstein) and in Finland (Helsinki), at Hetzner. EU sovereignty is based on two cumulative conditions: the hosting AND the company that operates it must be under European jurisdiction, without American legal presence in the chain.
When should this criterion weigh into your choice?
The CLOUD Act does not deserve the same weight in all projects. A solo MVP, without an identified European user and without health or HR data, can reasonably treat this criterion as secondary to price and development velocity.
The switch occurs as soon as a signal appears: a DPO or a lawyer involved in the decision, sensitive data within the meaning of Article 9 of the GDPR — health, biometrics, opinions. It is confirmed with a public sector client, or an EU public contract which requires an explicit guarantee of sovereignty. At this point, the legal test should be checked before comparing prices — not after you have already chosen a technical favorite.
This is the typical tipping point for an SME-ETI CTO who arbitrates between internal build, Supabase Cloud, AWS Amplify and a sovereign solution. The trigger is not the size of the company, but the nature of the data processed and the existence of a contact who will have to answer to a customer or a regulator.
Concretely, the criterion is verified at three distinct moments of a BaaS purchasing cycle. Before the shortlist, it serves as a binary filter for projects already identified as sensitive. During technical due diligence, it is verified document by document, alongside the DPA and the security policy. Before signing, it becomes a contractual clause — not just an oral response from a demo salesperson.
A useful clause to negotiate at this stage: the right to terminate without penalty if the supplier's shareholder structure changes. A takeover by an American company changes the answer to the legal question, even if the infrastructure remains technically identical the next day.
The grid to add to your comparison
Here is the grid to add to an existing BaaS comparison, ordered by intensity of exposure rather than alphabetically by supplier.
| Project profile | Weight | Recommended action |
|---|---|---|
| Solo MVP, no sensitive EU data | LOW | First compare price and DX; check the supplier jurisdiction before going into production. |
| B2C SaaS with EU users, standard data | MEDIUM | Demand an up-to-date DPA and standard contractual clauses; an EU region with documented guarantees may be sufficient. |
| Health/HR data, DPO involved | HIGH | Filter to apply before the price: EU hosting AND EU operating company, without American legal presence in the chain. |
| Public sector / EU public procurement | ELIMINATORY | The guarantee of sovereignty must be contractual and verifiable — never a simple marketing statement. |
Add this grid as one more column in your existing comparison spreadsheet, not as a separate document. It must remain visible when you decide between two technically close favorites.
How to check it in 10 minutes by supplier
A first verification does not require legal advice. Two public documents are enough to locate any candidate supplier: its confidentiality policy and the general conditions attached to the contract.
- Look for “data controller” or “data controller” in the privacy policy — that’s the actual legal entity, not the brand name displayed on the site.
- Locate the governing law clause in the general conditions — it indicates the jurisdiction under which the contract, and often the entity, operates.
- Check if a separate EU entity exists for your region (Irish subsidiary, for example) — and whether it changes the answer to the previous question, or just the billing address.
This is the method used to verify the facts cited in this article: Supabase, Inc. Privacy Policy, AWS Terms and Conditions, Google Privacy Policy. Three public documents, none requiring a commercial account to view.
What this criterion does not replace
The CLOUD Act criterion does not exempt you from evaluating the rest of the comparison. Migration cost, maturity of the ecosystem, real quality of the RLS and the developer experience remain determining factors for the velocity of a team. An EU sovereign provider with an immature SDK remains a poor choice for many projects.
There is also a timing argument specific to the choice of a BaaS: the more deeply a team integrates a provider – schema, policies, Edge Functions, webhooks –, the more expensive a subsequent migration is. A legal criterion discovered after six months of production is handled urgently and with an unfavorable balance of power. The same criterion evaluated before signing only costs the time to read two public documents.
American law is not the only lever of exposure. This is not an automatic dead end for an American supplier either: mechanisms such as standard contractual clauses or an adequacy decision can govern a transfer outside the EU, under specific conditions. A real risk analysis (DPIA) remains the only way to decide for a specific case — this grid is used to know when to trigger it, not to replace it.
The CLOUD Act should not be the first criterion for all BaaS comparisons. He should no longer be absent.
For an independent developer without sensitive data, this guide can be read in five minutes and closed. For a CTO who responds to a public call for tenders, it becomes an obligatory point of passage before the slightest commercial demo.
Add a “provider jurisdiction” line next to price and feature richness. Make it weigh before other criteria as soon as the project profile justifies it. Check the response on the vendor's public compliance page, rather than a sales promise.
For the complete GDPR/CLOUD Act framework and a detailed supplier checklist, see our guide dedicated to GDPR compliance and EU sovereignty. For a complete technical and legal comparison with Supabase, see Aurabase vs Supabase.