It’s not paranoia when they really are out to get you; so many countries are looking outside the US for digital sovereignty approaches for their IT stack. Red Hat’s answer to this need, Red Hat Confirmed Sovereign Support, is out today. 

Over the past year, numerous governments and companies outside the US have decided they can’t trust American tech companies. Can you blame them? So, digital sovereignty, especially in the European Union (EU), is becoming a vital IT goal. US-based companies, like Red Hat, understand which way the wind is blowing, so they’re supporting their own digital sovereignty solution: Red Hat Confirmed Sovereign Support (RHCSS).

RHCSS builds on Red Hat’s broader digital sovereignty initiative introduced last year, which was designed to ensure critical European IT operations remain under EU control. It wasn’t enough. 

Red Hat is pushing its digital sovereignty story with the general availability of RHCSS. This is a premium, in‑region support model designed for a world where traditional “follow‑the‑sun” operations increasingly look like a regulatory liability rather than a feature.

What does that mean? Brian Gracely, Red Hat’s senior director of portfolio strategy, explained in a briefing. “Digital sovereignty is being driven by AI, and how do customers make sure that they are putting the right controls around the AI that they may try to deploy. And then obviously, there are geopolitical headlines that are taking place day in and day out, and there’s a lot of uncertainty about what might be going on today, tomorrow, and into the future. And so,” he added, “digital sovereignty really sort of is the Venn diagram of those two things coming together.

Gracely said customers are asking a simple question with complicated implications: “How do we make sure that we have great control over their environments, great control over their ability to deliver services to their business, to their customers, to their constituents in public sector environments?”

Red Hat’s answer is a three‑pillar model of digital sovereignty.

  • Technology – “The first, obviously, is technology,” Gracely said. “We want to make sure that our customers have complete control over the technology that they choose to use, that they choose to operate, but long term and over the life cycle of it, that they have complete control, now and into the future. -“
  • Support – “The second piece of that is completely around support,” he continued, “making sure that, as they need support for the technology, and especially as they are in environments in which they designate that they need to be within a certain law, certain jurisdiction, we want to make sure that we can provide them support that is both in the right location, but also stays within that jurisdiction.”
  • Location – “Finally, the third piece is location,” Gracely said. “They have to make sure that they are within the right country, the right jurisdiction, and that’s not just their data, but it’s the physical locality of where they operate, where support happens, where communication happens for things like passing along logs or telemetry data or any of those sorts of things.”

That all sounds good, but what exactly does it mean? RHCSS is the operationalization of the support and location pillars. Service is generally available in the European Union and the United States, with other regions planned. Yes, even Americans aren’t so trusting of hyperscalers these days. 

Gracely described it this way: “What this is, is really, as customers in different geographic locations come to us and they say, ‘Look, we operate in Europe, we operate in Asia, we operate in environments that need to be confined or protected. We need to make sure that the people who will be providing support to us are in the correct location. They’ve been vetted, but secondarily, we want to make sure that no communication happens outside of that region.”

“So we need to make sure that logs, telemetry, any sort of communication that’s talking about that, remains within that [region],” he said. “And that’s ultimately what RHCSS offers. We make sure that, within the region, within the location that you identify, that we can provide that support, that the people who are gonna be working on it have been vetted, and are, you know, locally validated.”

Under the hood, Red Hat has split support operations into distinct paths:

  • Customer diagnostics (logs, sosreports, configuration bundles) are routed to and stored within an isolated regional boundary.
  • Case metadata continues to live in Red Hat’s global ticketing infrastructure, but access is restricted via role‑based access control so that only verified in‑region staff can see details tied to sovereign environments.

The hard problem, of course, is escalation. Red Hat’s answer is a mirror‑case workflow: the primary case and full diagnostics never leave the region, but an in‑region engineer can create a stripped‑down secondary case to bring in global specialists without exposing sensitive data.

Red Hat concedes that manual redaction isn’t enough at scale. To reduce the risk of leakage, Gracely explained, “All of the diagnostics and all the data that’s passed along stays within that space, and then we’re providing some additional capabilities that we call the SOS Clean AI project, and that ensures that all of the data is going to be scrubbed, to make sure that no information could potentially be lost or leaked after the communication takes place.” In other words, “We make sure that no geography, no customer information, no names, [no] location is going to be able to leak out of the system.” 

From Red Hat’s engineering description, this scrubbing isn’t just regex and good intentions. The company is integrating AI‑driven obfuscation into the workflow, running region‑local models that process logs inside the same jurisdiction as the workloads. Those models are refined using human‑verified snippets, creating a closed training loop that stays within the boundary.

Beyond tools, Red Hat is stressing human controls. Confirmed Sovereign Support cases are handled by senior engineers who are legally authorized to work in‑region and subject to background checks and security training. Direct access to customer environments is governed by least‑privilege, with explicit customer authorization and auditable, localized IAM as the gate.

Gracely underlined that the company is not quietly falling back to the old support model once the sales slide is done: “We’re not going to sort of work with them locally, but then pass it back to a central location, say, in the United States, just because of how we’re set up,” he said. “We want to make sure that we can be local with our customers, and RHCSS provides that capability.”

In short, as Chris Wright, Red Hat’s CTO and senior vice president, Global Engineering, said in a statement, “Digital sovereignty means keeping control over your own technology destiny, from data location to software and operations. Navigating the EU’s stringent regulatory and compliance frameworks demands an open-source-driven, transparent, auditable foundation and a local operational support model. Red Hat Confirmed Sovereign Support offers exactly that: a fully EU-anchored support experience, run by EU citizens for EU organizations backed by the trust of our open hybrid cloud portfolio.”

Can you trust Red Hat? The company’s heart may be in the right place, but under the US CLOUD Act, US authorities can force American cloud companies to provide access not just to US-based data but data stored outside the States as well. 

Gracely assures nervous customers that  “We can deliver those sovereign services and customers can feel very comfortable that who they’re working with, where they’re working on it, and what the support model looks like is extremely well understood and aligns to these emerging laws and regulations and jurisdictions that are happening because of both AI and the geopolitics.”

Others may not be so sure. For them, completely European-based approaches, such as SUSE‘s digital sovereignty approach, are preferred. As Andreas Prins, SUSE’s leader of the global initiative on digital sovereignty, said, SUSE’s “overall goal is to provide a 100% auditable IT stack based on an open source platform that protects data from being subject to foreign regulations.