Reducing the Complexity of Data Localization | The Last Great Cloud Transformation EP3
As organizations accelerate their cloud journey, many are losing visibility into and control over their IT environments. That’s a problem not only for securing apps and data, but also for complying with a growing number of government regulations. In particular, governments around the world are implementing data sovereignty and localization regulations such as GDPR in the EU, CCPA in California and many others regionally that define exactly where data must be processed and stored. Global organizations often have to comply with multiple regulations, while simultaneously trying to manage and protect their increasingly complicated environments.
How can organizations keep moving forward in the cloud, and also adhere to numerous data sovereignty and data localization laws? They need a new kind of cloud — one that transforms the network, restoring visibility and control for their complex environments. A connectivity cloud delivers that transformation. By integrating enterprise networks and the Internet, organizations regain control over their environments. They can comply with laws by setting precise rules for where data is processed and stored. And they can securely route data to the right places without the performance penalties of using distant core data centers. With the connectivity cloud, data sovereignty and localization laws do not have to be obstacles on the cloud journey.
Transcript
Hey everyone, it's Alan Shimmel for Techstrong, and you are watching the Last Great Cloud transformation. This is a, for those who you are not familiar, this is a biweekly show that we do in partnership with our friends from CloudFlare. And we're talking about what's going on.
You know, the cloud has been around, well, it burst on the scene around 2005, 2006 actually. So it's been almost 20 years. And you know what?
Over that 20 years, a lot of organizations have moved at least some of their infrastructure to the cloud. There's a good chunk of people who haven't yet, and they may never, there's a good chunk of people who are still planning to, but you know, the initial move to the cloud was sort of these hyperscale, kind of core cloud data centers, if you will. And they're great, and they're big, and they take a lot of energy and they throw off a lot of heat.
And we're hearing all these things about them, you know, now, especially with AI and GPUs. But we're also seeing gen two, gen three, even GEM four migrations in the cloud, where, hey, it's not just putting it in the, in the one big hyperscaler data center, or even on their network. It's hybrid cloud.
It's multi-cloud, it's cloud on the edge data located on endpoints in space, underwater in ice, you know, and everywhere in between. So that presents its own series of challenges, and that's the kind, that's what we explore here on this show. Um, I'm gonna go into today's topic in a second, but I first wanna introduce you to our panel for today.
First of all, joining us, I, he's actually up in Canada looking at his background today. Um, he is pretty well known security space, has a lot of experience in, in the kind of things I've just been talking about, as well as currently serving on, uh, some csa, uh, panels on SBO and dbo and other security related frontiers, our friend Chris Blas. Hey, Chris, how are you?
Loving life. Good to see you, Alan. Good to see everyone.
Nice to have you here. Um, joining Chris and I, uh, she's with, been with us before, if you've been watching this series, Emily Hancock of CloudFlare and Emily, if you, I, I couldn't do the whole bio I gave there for Chris, so why not, if you don't, why, why don't you introduce yourself to the audience? Sure.
Yeah. Uh, it's great to be here. Again, I'm the Chief Privacy Officer at CloudFlare.
I also manage our legal product privacy and IP team and our privacy operations team. And I've been with CloudFlare a little over six years now. Fantastic.
And, and that's a job. Yeah. Um, God bless you.
Uh, next up my co-host, and he's the CTO here at, uh, tech Strong as well as CTA at future, our sister company that we're merging with. My friend Mitchell. Ashley.
Hey, Mitch, great to have you here. Always good to be talking about security with friends, and let have a great time. All righty.
So let's jump into it today, guys. Let me, I'm gonna read you from the abstract, and, uh, we will, we'll jump from there, but, you know, how can organizations keep moving forward in the cloud while at the same time adhering to numerous, and I do underline the word numerous data sovereignty and data localization laws. They need a new kind of cloud, one that transforms the network, restoring visibility and control for their complex environments.
Um, beyond that, though, let's dive into this, right? People, we are so concerned about supply chains. We're so concerned about where our data is being stored or we're starting to be really concerned.
And there are, and when I say there are numerous data sovereignty and local data localization laws, we're dealing at the federal level of the US state level, EU level nation states throughout. I mean, what's a poor company to do? I mean, you know, a single entity.
How, how the heck do you navigate this? What, you know, I I could see paralysis by analysis setting in Emily, you, you know, your chief privacy officer at CloudFlare. CloudFlare carries a good chunk of the internet over, its, over its wires, over its network.
How do you, how, what's the answer here? What, what comfort do you, can you give our audience? Yeah.
Well, I, I can give, I can give some comfort, um, but I will commiserate with the audience because it is an increasingly complex world out there. Um, we're seeing data sovereignty and localization, not just from data protection laws. And you mentioned like GDPR, um, there's laws in a bunch of countries, Japan, South Korea, to name a, a couple, um, that regulate the processing of personal data of their citizens outside of their countries.
And they don't always pro prohibit it, but a lot of times what they say is, if you're going to take that personal data outside of the com the country, you need to, you know, clear these hurdles or, or do these things or put these contractual provisions in place. So there's that. Then there's a whole slew of industry specific procurement requirements that may require things to be stored locally.
India banking regulations, for example, require some of that banking information to stay in India. And then we've got some certifications. Um, one of the big ones that's on the horizon, it's not there yet, but is the EUCS in Europe, which would say that if you're providing, uh, support, uh, critical infrastructure types of, um, services, or you're supporting critical infrastructure, some of that data has to be localized.
And, and then there's other countries, smattering of which, um, you know, Russia, for example, have localization laws where they want data to stay local so their government can access that for whatever purposes they may want. Um, so yeah, there's a, a really complex, um, situation going on. And so what you have to look at when you're moving to the cloud, because there is this concern of, well, what is the cloud?
It's, you know, with, it's the cloud, it's, it's, where is it? What, what does that mean? Um, you know, when it's on-prem, I know that it's kind of in my server in the basement or next door or wherever the servers are.
So when it's in the cloud, you need to be looking for providers that can help you store things in jurisdictions, if that's the requirement, or that can process data in certain jurisdictions, if that's the requirement. A lot of it is really dependent on what requirements you think you have to meet. And then you have to look for the cloud provider who can check those boxes based on the services they provide.
Yeah. Panel. Chris, Mitch, any, I, I have thoughts on this, but I'll let you guys go first.
Mitch, you gotta learn to take the mute off. Okay. Uh, oftentimes I'm, I'm kind of both sides of this fence.
One, have as a provider, but also having been a provider, but also as the, uh, service or of data, if you will. And it seems like one of the things that you can look towards, and I know that, um, full disclosure, techstrong is a customer of cloud flares. Um, but there are, there are resources that, uh, working with companies can provide.
Like for example, the EU has their US data privacy framework. Now, security people were very used to frameworks, right? Process.
Here's how you document what you need to do and what you have to report on. Um, but that's, that's also I think a comforting factor is you don't have to go unwind all this stuff yourself. You have folks like Emily providers that you can work with.
I don't mean that as just a commercial for cloud flare, but that's who we rely on one of the companies. And, uh, so that way you, you know, they're not there for legal advice, but they're there to help point you to the resources that you can use to try to unwind these things and figure out what you need to do in your situation. And I can think of, you know, two examples of this.
ccls, I mentioned the show before, been public, uh, public knowledge working with, uh, Columbia and South Carolina, the, the nation, Columbia, you know, on long-term, uh, infrastructure plans and this level of, of visibility into cloud infrastructure. You know, saying that as you move forward at a certain point in ot, as we accept now in the operational technology world, people understand cloud is part of it. But this was about six years ago.
We didn't, you know, to have exactly these sit down conversations where, as you said, Emily, where you, you get the stakeholders together and say, you need to le localize inside my jurisdiction inside my country, this stuff, or, you know, cloud all you want, we're not doing it. And at that point, they weren't. Now they aren't.
And, you know, and, and current, you know, this is how timely, this is where we are right now. So in the Department of Homeland Security, there's a bunch of tiger teams working on supply chain issues, and we're just finishing a two month, uh, tiger team right now, uh, looking at ISACs as SBO and distributors. So information sharing and analysis centers, you know, that, that share threat intelligence already and have the last, you know, 10, 20 years, uh, doing the same sort of things with SBOs and what some of the things both of you is, some, uh, particularly Emily said, had me thinking about this as recently as today, working through how an ISAC can be there for the discovery of an SBO m but not actually for the access or transport.
The other two phases of sharing because of localization and liability and all those sorts of things. And just today, I, as far as I know, having the best of the first conversations about how we, you know, a year and two from now, how we work on the conversations where maybe, you know, and ISAC specifically does want to hold some of those SBOs because of conditions anyways, without going into all that. So yeah, my whole obsession with change over time leads to the kinds of things you said, Mitch, that about now I'd expect companies about like, like CloudFare to be offering about this sort of service.
'cause that's where we are. And if you need it, it's probably available. And if it's not, you know, the VC world is waiting, start a company, now's the time.
Yeah. I, I, I'll, I'll add something in here. Emily, you, you, you touched on it.
Chris and Mitch are both, you know, there are some jurisdictions, I think, um, you mentioned Russia, uh, that said, Hey, I want my data or data relating to my citizens kept in my sovereign cloud so that I can access it if I want to. There's the flip side of that, which is I want my citizens' data kept in my country's sovereign cloud, because if it's not in my sovereign cloud, I don't have access to it in some other country will access my citizens' data. And, and this is a market I I, I don't remember if CloudFlare was in, but I know some of the hyperscalers were certainly doing it, saying, Hey, we will, we won't crumble, right?
From a government subpoena, right? I think it might have been Apple was involved in this too, right? We're not gonna turn, we're not gonna give them access to your iPhone.
We're not gonna give them access to your data. Now, you know, once you start getting into areas of localization like this, I don't know how a, a CloudFlare or an Apple or an Amazon or any of these folks are gonna withstand a full on government press here and, and the power of the courts and the full, you know, faith, full faith and credit of the United States of America, right? Telling me, you gotta turn this over.
I mean, what I mean, Emily, this is, this is kind of your, you know, you live this day to day, what do you do? Yeah, well, you're, you're now getting into the history of the cloud act a little bit, um, which is a law. So the, the very first big case on this was, uh, when Microsoft said, no, we're not going to turn it over data because it's actually stored in Europe.
And, um, long story short, that led to a cloud act. And so governments are supposed to have these information sharing agreements put into place so they can share this national security information or law enforcement information. We're not there yet.
The governments are, are still kind of fighting all that out. In the meantime, um, this is a little bit of what we started seeing before the US EU data privacy framework was implemented. The courts in Europe, uh, the, the, uh, CJ EU specifically was saying, we're not sure that there can be any appropriate protections for EU data as long as it's held by a US company, even if it's held in the eu.
We've started to see the tide turn on that a little bit. There's been some smaller courts in, I think there's a smaller Germany for example, that said, um, just because the US government might be able to get data does not necessarily mean they will. Because if you look to the agreements that these providers have in place, um, those agreements with their customers mean that they won't turn over data.
For example, um, cloudless signs a data processing addendum with all of our customers. And in that data processing addendum, we specifically say that if there's a conflict of law that that exists, um, between what the US government might try to get from, uh, get, if they wanted to get data about one of our customers and our customers data was related to people who are not US citizens. We specifically say that if there's that kind of conflict of law, we will push back.
And we have a, um, transparency report that has warrant canaries that are kind of these promises of things that we've never done for, you know, in response to government requests. Um, so we maintain those and, and that's the kind of thing that you would wanna look for from a cloud provider, is look at their record on those kinds of issues and what kind of government requests they've gotten, because all of the big companies have these transparency reports now, and you want to make sure that you're looking for that, and that's how you can balance this, this concern. The other thing that's really important is the data privacy framework.
Part of the reason that it got implemented was because the Biden administration packed an executive order that really reframed how the US government surveillance agencies, um, and could, could exercise powers under the Foreign Intelligence Surveillance Act. And those powers were what, um, have been an issue in all the rems, uh, jurist in the REMS debates. So, um, but, but I think going back to the providers, you wanna look at those that have the privacy guarantees, that have the commitments to push back on government requests and then maintain those commitments.
Agreed. And that sounds really reasonable to me, you know, to get, you know, ba you know, as I said a minute ago, I would expect folks like you to be doing about those things about now. And I think you hit on a lot of the key points.
You, this, you know, to be clear, the rules and legislation aren't done yet, you know, in any one country, you know, the US, Canada, or, uh, internationally, but we keep moving down in that direction. So I would agree that you want, you know, as your concerns justify this, having someone, you know, the, uh, the, what was the term policy canaries, I love those, right? Uh, the War and canaries, war, war and Canaries, right?
Yeah. You know, to somebody pay attention to this. 'cause if you follow down the path, you know, the Department of Energy and uh, and uh, DHS are pushing, uh, uh, cyber informed engineering.
And one of the key terms in there is radical transparency. And I like those, those words. Exactly.
And I don't like the, the, the forces lining up behind that because we need to have this conversation. Radical transparency does not mean that everybody gets everything just like it did with vulnerabilities and threat intelligence. And now supply chain, it doesn't mean that everybody gets everything.
It means that you get the information you need in a time you can actually use it. So your time to transparency window doesn't collapse before you can do something with it. And today, yeah, I would like someone, uh, a corporation with all the motivations to stay in business and not get sued and so forth, to have taken those steps and have those, uh, those warrant canaries, you know, waiting on policy trips because no individual individuals and even well-resourced enterprises can't keep track of all that themselves yet.
You know, I, I think one of, one of the dual complexities of this, and I'm particularly interested in your perspective about this, Emily, is that there's the regulatory compliance side of this, which is always moving, you know, changing, evolving new things, popping up, things, taking a long time to get put in place. So there's a, a bit of uncertainty about it, but at the same time, we're deploying applications and data and infrastructure across the cloud, you know, at the edge in the core, wherever it might be. And, and that's, that's become more of a fluid thing.
It used to be that infrastructure was, I set it up and then we leave it and we run it for a while and I might change it. And there's a real specific procedure. Now you've got infrastructures code and APIs into the cloud and into, into your software infrastructure.
Um, I I, is there any guidance that we can provide people on as you create more of a dynamic environment, um, how to help you understand where you may need to reexamine your compliance when it comes to privacy and localization? Well, well, I mean, that's, that's a, that's a very big question. So I don't wanna give a lot of, I might add you're, you're allowed to ask you.
I'm like, I need to ask you about This question. Yeah, well, I mean, yeah, so like, that's one of the, you know, that's one of the advantages potentially of, um, of going with sort of a bigger company because for example, we've developed this global network, so we had to look at all the laws of all the countries where we have data centers and where we're operating. And so we've done that work.
Um, and if you don't have the bandwidth to, to do your own 200 country survey or, or whatever, um, to figure out what the applicable laws are, you know, we're global, so we're respecting the global laws and regulations, and we've developed these tools that help you figure out if you need to localize. Um, and, and so, you know, the idea is that you shouldn't have to trade off your fears about not being able to comply when you move to the cloud, when you go from an on-prem solution to the cloud. Um, and, and so, you know, our whole goal is, and I imagine the other hyperscalers too, our whole goal though is to have the benefit of this global network with the per performance, reduce latency, all these built in security features, all this kind of stuff, while you still can figure out how to comply with the regulations, we have a data localization service, for example, that allows you to restrict where data is inspected, um, where you keep your keys.
So if you wanna keep your, your encryption keys out of a particular country, for example, uh, we can do that. And then, um, we have some limited availability now, but we also have some ability to store logs in particular jurisdictions. And right now, that part is a little bit more limited to the EU and the us, but we're, we're building that capability out.
And, um, you know, so, so I think if you are trying to expand and you're trying to move to the cloud, you wanna just, again, look for, uh, you know, a cloud provider that also has, has, has thought about these things, but also has done this certification work. So for example, um, we've certified to ISO 2 7 7 0 1, which maps to the GDPR, um, and we have an EU cloud code of conduct certification and, and some others that show that we have looked at some of these particulars jurisdictions and have kind of checked the box to say, yes, we're, we're compliant in these areas. And, and I think that's the kind of thing you would wanna look for.
You can't do all that legal work yourself. Okay. Very good.
Very helpful. I, I think another reason why you wanna, and this, this actually is a, I guess one of the advantages of going with a cloud flare, flare like thing is this is such a, a liquid situation. It's far from static.
And so portability, right? And that used to be one of the hallmarks, one of the foundational things of being in the cloud is elasticity and portability, right? I, today, it's here tomorrow, I wanna move it there.
It's fine. And you know, I I I think that meal may not be something cloud flare can assist with. Emily, I'd love for you to weigh in, but we need, I mean, for organizations out there dealing with this issue, gotta recognize that whatever solution works for you today may not in fact work for you tomorrow or next week.
And we need Plan Bs and Cs on, on, in terms of portability to, to adapt to whatever the, you know, the latest and greatest are, uh, in terms in terms of regulations and compliance. So, uh, again, I'll throw it to Emily and Chris, Emily and Chris, I mean, Emily specifically CloudFlare, how, how do you guys help with that? And then Chris, what are you hearing on that issue, you know, through your contacts?
Yeah, sorry. So in terms of, I mean, if portability, if you wanna leave CloudFlare, which we hope we don't do, right? Um, we don't lock people in and there's not a lot that we store.
So right now there's, we have a couple storage products. Um, so it, you're able to move your data. We don't own it.
Chris, how do you facilitate people who have to move their data or around, Well, I'm just going to pile in here and praise of vendors, right? And Cloudflare's here, and you know, Emily has really good answers. So there's nothing I, I, I would, uh, see that would make me think that that's not a good choice.
But it reminds me of, uh, uh, 90 19 92, the first firewall, you know, standing there in a booth all by myself. This two young folks came up with a great question, and it's like, Ooh, I know the answer to this one. I'm really proud of myself.
Then the second one, and they came up the third time and I said something that, that has lasted to this day. And it's true. Look, what you're really buying is a relationship with a bunch of people who should anything go wrong will live on anger and caffeine until it's fixed, right?
See what, you know, the value of working with, with good vendors who are reputable and manage to keep their customers is that by definition, they're worrying about this stuff all the time. And I love, you know, geeking into the individual answer on how we do things, you privacy and localization, but unless you wanna do that stuff for a living, at a certain point, you're gonna have to have appropriate trust in someone else, right? And there are, outside of the very large enterprises, very large enterprises, there's not a lot of this you're gonna be implementing yourself and by definition, right?
Unless you are, you know, that cloud provider, you know? So you need to be appropriately aware of your policy environment, what legal risk do I have? If you don't have good lawyers, get them, um, get good technical people who can question the, the answers of, of vendors and providers and so forth, and, and ask the kind of questions that come up on shows like this.
But, you know, this is, and this is where, where my radical transparency obsession comes in. I, I think today you can do business with good vendors and, and suppliers and vice versa. But the contracts and the actual vehicles we use to protect IP, for example, are almost just a wave in a, uh, you know, we're just, we're hoping our employees understand them.
I think we get better and better at, at automating these sort of things so we can get the kind of visibility, so in this case, the vice president of it at a, at an enterprise can say to the, the, the C-suite and the, and the board, yes, in fact, we've done our diligence, we've got the right providers and I can see what's going on. Fair. You know, when it comes to portability too, Alan, is, there's portability within the cloud within the service provider or providers that you use, right?
And that's, it can be portability of the workload as well as portability of data. Though data is much more difficult, consequential to move. We get into localization issues and things like that.
But even within, you know, one network, one network provider, moving those workloads around to the edge, you know, edge workers that are doing different parts based on traffic that might be coming in, or security issues that are happening in the network, I think more and more we're moving to you. It isn't set it on flexible and it'll allow automatically move all over by itself. But you're getting to a point where you could make parts of your application more portable, say to the edge or different locations at the edge, uh, versus things that need to run in a certain location or at the core.
And that's part of the architecture design of our applications. And that's where this portability cloud starts to overlap into software architecture, infrastructure design, things like that. They, there aren't hard lines separating the two anymore because so much of The cloud is programmable.
That's exactly what I was getting at. But as part of that portability, do I run afoul of these sovereignty laws, right? Because you're going, I, I happen to know you're going to Barcelona next week for a conference.
What, what does that mean for my data? I mean, you know, yeah, I, I keep it stored here in the US right now as per our, you know, policy. But what are you going to take with you over there?
Or what are you, are you going to use, uh, let's say I'm on CloudFlare or some other network. Am I gonna temporarily have data on the edge over there and and what does that mean? Yeah, I mean, that, that's, that's kind of the, the benefit really in the cloud in some ways, right?
So your data is, if it, it's being processed at the edge, if you're using CloudFlare, your data is being processed at the edge of the network and um, you know, the sovereignty is, it's kind of funny. It can mean kind of a couple different things. And, and one of the things is you want that data to be processed as close as possible to where the person is, whose data is being processed.
Um, but the benefit of the global network is that if there's DDoS attack or some other kind of congestion on the network, you can route that data to where it needs to go. So what we've done with our data localization suite, for example, is, um, if you are a European citizen and you're traveling within Europe, um, your data will still only be inspected in Europe if that's turned on. Now, if you go outside and you're still trying to access a customer, that customer's website is based in Germany, but you're a German person who now has gone to the United States for vacation and you're trying to access your German bank account and the German bank is behind CloudFlare and they have data localization suite turned on, you might experience a little latency because that bank has chosen that they still want their data inspected in the EU as opposed to in the United States.
Um, but as far as I can tell, the European data protection regulators aren't too worried about the scenario of their, their people going on vacation and, and accessing from outside, but it's really more when they're inside the EU and accessing the eu. But that's, that's Europe in its own its own glory. Um, so different jurisdictions may have slightly different rules, but generally that traveling, what you really want is you wanna make sure that your customers, wherever they are in the world, can get their stuff or can access their stuff wherever it's stored as quickly as possible.
And that's the beauty of, of processing, um, at the edge closest to where the individual is located. My answer was gonna be, I was gonna ask to borrow your phone and your laptop when I go to Barcelona, Allen. So Of course it's your problem.
Um, I think I left on there, but I mean, look, this is, this is real world and here's my other kind of fear in many ways. Our world today, on the geopolitical front between wars and competitions and, and nationalist movements and sovereignty laws and all this stuff is getting more and more fragmented, more and more complex, more and more fraught with, with craziness, for lack of a better word. There's gotta be a better way.
How do, I mean, Chris, you work with the federal space at the federal level in the US I know is big on alliances and you know, at least with their friends on, on trying to get these things done. I believe, you know, you represent CloudFlare here, chief Privacy officer, is it pie in the sky? And, and you know, naivety to think that we can come to some sort of global kinda rules around this that'll make life easier.
Chris, you're raising your hat, Right? Yeah. So take everything we talked about right now, and this is the state of the world we're in, and we got here, you know, in, in many ways, you know, recent history last three years, five, seven, you know, I to talk about decades and for everything we talked about, I, I've got one word for you, starlink.
Alright? You know now, so you're not inside that ju you're orbiting the planet rats. What do I do there?
Well, and, and as an interesting step beyond that, you know, Gwen Shotwell, who's COO at, uh, SpaceX, um, is or was anyways, uh, also CEO of a company called Orbit's Edge. So imagine Starling satellites in tens of thousands that aren't just routers, they're server. So we actually get that, you know, everything we're dealing with, with data centers and clouds and sovereignty and jurisdictions.
Now imagine those data centers are opening the earth at 17,000 miles an hour and it's distributed across end space. And as with all things, either we get into this future and the, you know, society collapses and we all go back to, you know, eating, you know, dear, or we work it out. And I'm pretty sure, you know, the kinds of things, policy visibility and processing, the ability to say, my data is here and I know this to a usable level of the word no and is subject to these policies that I don't have to hire a bunch of, you know, uh, interns to look up, but are are known all the time as that's accessed.
I think that sort of thing is inevitable and it is in the, in the, the working lifetimes of everyone here. You're an optimist, Emily, are you as optimistic? Um, well I don't think we're gonna get to a place where we're all, you know, back to, you know, hunting and gathering and, and shooting deer for dinner.
It's not, I think, I think we're, we're maybe away from that, hopefully. Um, I mean, it is, it is tough though because we do see a lot of governments who are really pushing for keeping their data local because they view it as a national security concern, right? They, they want it, want it in a, in an on-prem data center.
And yet we saw when Russia invaded Ukraine, that that actually is a really risky proposition too, because Ukraine had to suddenly put all its stuff on the cloud because they were worried that the Russians would take over the data center where the data was. So there's real benefits to having things in the cloud. There's also real security and cyber intelligence benefits when, for CloudFlare, for example, we're looking at traffic, you know, we, we sit in front of about 20% of the internet and we're looking at global traffic, we're looking at cyber threats, DDoS attacks, you know, bots, all the things, all the bad things that can happen.
And we are figuring out how to adapt and evolve to that and protect our customers. And you can't do that if you're only looking at the risks that come from France or the risks that come from Germany or that come from Chile or, or whatever. So you have to have that global visibility, you have to have that interconnectedness.
And I think we have seen a little movement, I let EUCS certification I was talking about, there was a storm contingent, um, led by France that was saying, no, no, no, this data has to be processed locally. And we've actually seen the Europeans move away from that slightly. I don't think that means that countries are going to just drop these sovereignty requirements altogether, but I think there is a real recognition that as providers like us and others are developing, um, you know, ways to program how the network works for you as our customer, as we continue to evolve, that you're going to be able to fine tune, fine grained control what's happening to your data on our network while taking advantage of the global network and, and all the advantages, um, for cybersecurity that, that brings.
So, and I, and I think the cybersecurity officials are really recognizing that some of the data protection officials are maybe a little slower to agree. And then you've gotta deal with the, the geopolitics of, you know, countries trying to compete just economically and trying to boost their own economies. And one way to boost your own economy is to insist on a sovereign cloud that is, is gonna have data centers.
So you've got a lot of competing tensions there, but I mean, we hope we can rise above that as, as the cloud that offers a lot of different, um, ways for our customers to kind of program what they need to meet their specific, specific legal obligations. Yeah, I'm really glad Ggl, glad to hear you say that because you know, in security we talk about compliance, but we also talk about guardrails, which is sort of the automation of adjusting those rules based on the context of the situation. Um, and that seems to be what we, what we need because that situ, 'cause we're in a fluid environment, it's gonna mean this, today it's gonna be have stronger or less, less strength than in its enforcement tomorrow.
And so you need a way of being able to work in an environment where when those things change, I don't have to lift everything up and go decide how to re-architect it somewhere else. I've got a way of, okay, that won't move there anymore because that's not meeting those conditions any longer. So those kind of guardrails sound extremely useful to me.
Well, I mean, you think about it, you know, my, on the international Space station right now, we have Americans and Russians and other nationalities creating and using data that I think is, is a, you know, a litmus or a little canary or something about the future. We're moving into, you know, as we establish spaces on the moon and more, more things in orbit, and you know, if you think starlink and Orbit's edge is hard to process in this context, figure it out. And we will have control of our data and there will be nation states and corporations with enormous stakes in it and that that will know where their data is and who's touching it.
So sovereignty, to your point, Emily, you know, may not always just mean literally on this two dimensional space inside my boundaries, but inside my sovereign space, and I know it at the nation state level, we will get there Always the optimist. Chris, I think let's try to end it on a high note though, Emily, first of all, thank you for coming on this edition of the last great Cloud transformation. My pleasure.
Thanks for having me. Yeah, no, and you know what, thank you for CloudFlare to CloudFlare convey our thanks because quite frankly, there are only a handful of companies that have the scale to deal with these global, uh, regulations that we're all having to deal with now and, and, and increasingly slow. So, so it's good to see that someone's actually thinking about this and, and doing something.
Chris is always my friend, thank you for coming on. Keep up all that you do that a lot of it goes unsaid or unrecognized, but we'll recognize it here. Thank you.
And Mitchell, what, I'll give you the last word. You know, I was just thinking about, um, I remember reading the book about globalization and the concepts of, you know, e everybody working in a global economies, and this is what it looks like, what globalization really looks like. There's a lot of lot to it as you get into the devil's in the details and, um, you know, partnering with the right people can make all the difference for sure.
As someone who's had to operate those things, it, it makes a meaningful difference. Great. All right.
We hope you've enjoyed this edition of our last great Cloud transformation show here in partnership with, as I said, with our friends at CloudFlare. We'll be on in another, I guess, uh, two weeks after this with another one. And we actually have another live event, which I really, if you like, talking about these kinds of things, these live events give you a chance to weigh in and ask questions.
So please join us for that. But until then, this is Alan Shimel. Have a great day everyone.
Thanks for joining in.

