Skip to content
Long side of a windowless technical building made of light precast concrete parts under an overcast sky: a steel door and a roller shutter in the facade, on the roof a row of identical dry coolers behind a louvre blind, in front of it an empty asphalt driveway.

The platform runs in five data centres in Germany and Finland

We are responsible for the network, systems and access to our racks ourselves. We did not build the data centres where our systems are located — we select them: based on energy efficiency, legal framework and connectivity. They are located in Frankfurt am Main (twice), Berlin, Munich and Helsinki.For each location, we show what is verifiable: the assessment according to EN 50600, the annual average PUE, the contractual power supply and the certificates. Where a figure is calculated and not measured, the reservation is stated next to the number. What is written here is also written in our operations manuals.

The PUE is measured at the location and updated monthly. The class according to EN 50600 comes from the report of the auditing body; it assesses the construction, not the operations.

Inventory 08/2026

Locations
5
Frankfurt am Main (twice), Berlin, Munich and Helsinki — all in operation
Assessed according to EN 50600
5 of 5
The European standard for the construction of data centres. The class indicates the extent to which supply and cooling are duplicated.
Best PUE
1.08
PUE is the total power consumption divided by the consumption of the IT alone. 1.00 would be the theoretical optimum.
Availability class VK4
4
Highest class of the standard. It requires two completely separate supply paths, each of which carries the full load on its own.

Key figures across all locations

Average PUE
1.116Annual average across all five locations. For every kilowatt of IT load, 116 watts are therefore used for cooling, losses and lighting.
Power density
42kW per rackMaximum value for direct water cooling. This requires a supply air temperature of 24 °C according to ASHRAE class A1.
Fuel reserve
72hMinimum reserve at full load that we require at every location. Also required are a backup power system in N+1 design and a subsequent delivery within six hours of request.

The five locations in detail

Each card states the annual average PUE, the latency from Frankfurt, the contractual power supply, the connection to our backbone, the utilisation and the certificates of the location. The price factor indicates how the list price shifts compared to the reference location Frankfurt.

fra1Germany

Location Rhein-Main I

🇩🇪Frankfurt am Main, Germany

In operation
PUE (annual average)
1.14
latency from Frankfurt
3 ms
power procurement, contractual
100% renewable, with guarantees of origin
Procurement via guarantees of origin, not a physical specification. We list grid emissions separately at /nachhaltigkeit.
connection to the backbone
Metro Rhine-Main · Ring Germany
Used capacity71 %

Proportion of used capacity to the available capacity of this location.

Certificates

  • ISO 27001
  • ISO 50001
  • BSI C5:2020
  • EN 50600 VK4
  • TÜV Rheinland

50.110° N · 8.680° O

Price factor 1.00 ×

fra2Germany

Location Rhein-Main II

🇩🇪Frankfurt am Main, Germany

In operation
PUE (annual average)
1.09
latency from Frankfurt
3 ms
power procurement, contractual
100% renewable, supplemented by on-site photovoltaics
Procurement via guarantees of origin, not a physical specification. We list grid emissions separately at /nachhaltigkeit.
connection to the backbone
Metro Rhine-Main · Ring Germany
Used capacity44 %

Proportion of used capacity to the available capacity of this location.

Certificates

  • ISO 27001
  • ISO 50001
  • BSI C5:2020
  • EN 50600 VK4

50.050° N · 8.750° O

Price factor 1.00 ×

ber1Germany

Location Spree

🇩🇪Berlin, Germany

In operation
PUE (annual average)
1.16
latency from Frankfurt
6 ms
power procurement, contractual
100% renewable, focus on wind power
Procurement via guarantees of origin, not a physical specification. We list grid emissions separately at /nachhaltigkeit.
connection to the backbone
Ring Germany · Ring Baltic Sea
Used capacity58 %

Proportion of used capacity to the available capacity of this location.

Certificates

  • ISO 27001
  • BSI C5:2020
  • EN 50600 VK3

52.520° N · 13.400° O

Price factor 1.00 ×

muc1Germany

Location Isar

🇩🇪Munich, Germany

In operation
PUE (annual average)
1.11
latency from Frankfurt
5 ms
power procurement, contractual
100% renewable, geothermal cooling
Procurement via guarantees of origin, not a physical specification. We list grid emissions separately at /nachhaltigkeit.
connection to the backbone
Ring Germany
Used capacity82 %

New orders at this location on request only.

Certificates

  • ISO 27001
  • ISO 50001
  • BSI C5:2020
  • EN 50600 VK4
  • Suitable for critical infrastructure

48.140° N · 11.580° O

Price factor 1.00 ×

hel1Finland

Location Uusimaa

🇫🇮Helsinki, Finland

In operation
PUE (annual average)
1.08
latency from Frankfurt
21 ms
power procurement, contractual
100% renewable, focus on hydro and wind power
Procurement via guarantees of origin, not a physical specification. We list grid emissions separately at /nachhaltigkeit.
connection to the backbone
Ring Baltic Sea
Used capacity36 %

Proportion of used capacity to the available capacity of this location.

Certificates

  • ISO 27001
  • ISO 50001
  • BSI C5:2020
  • EN 50600 VK4

60.170° N · 24.940° O

Price factor 0.94 ×

Four details per location

A location can be compared using four details: place, redundancy class of the building according to EN 50600, annual average PUE and certificates. The PUE is measured at the location over the year; class and certificates come from the reports of the auditing bodies. Where a value does not come from ongoing operations, the reservation is stated on the number and not in a footnote.

Location data in comparison — as of 08/2026
LocationRedundancy class (EN 50600)PUECertificates
Frankfurt am Mainfra1 · GermanyEN 50600 VK41.14ISO 27001 · ISO 50001 · BSI C5:2020 · TÜV Rheinland
Frankfurt am Mainfra2 · GermanyEN 50600 VK41.09ISO 27001 · ISO 50001 · BSI C5:2020
Berlinber1 · GermanyEN 50600 VK31.16ISO 27001 · BSI C5:2020
Munichmuc1 · GermanyEN 50600 VK41.11ISO 27001 · ISO 50001 · BSI C5:2020 · KRITIS-compliant
Helsinkihel1 · FinlandEN 50600 VK41.08ISO 27001 · ISO 50001 · BSI C5:2020

What a location must fulfil

We did not build the data centres where the platform runs, and we do not operate them. What is written here is therefore not a certificate of performance, but a list of conditions: if a location does not meet them, we will not consider it.

All locations are audited against the same framework — EN 50600, the European standard for data centre construction. What differs is the availability class: VK4 in Frankfurt am Main (twice), Munich and Helsinki, VK3 in Berlin.

Location requirement

Building services. They are a requirement, not something we provide ourselves — audited before a location is selected and then for as long as we use it.

  • Fire compartments, early detection and extinguishing concept
  • Power feed, UPS and backup power system
  • Cooling, supply air temperature and water consumption
  • Premises, reception and security airlocks to the IT area
  • Building management system and a 24/7 staffed control room

In our hands

What we manage ourselves and can therefore guarantee — regardless of which building it is in.

  • Our systems: servers, storage, hypervisor, firmware
  • Our network: backbone, peerings, DDoS protection, AS204812
  • Our hardware up to verifiable erasure
  • Access to our racks: authorisation and logging
  • Our operations: monitoring, maintenance windows, reporting channels, deadlines

Behind the classes are two design levels. N+1 means: there is one more device available than operations require — if one fails, the rest carry the load. 2N means: the system exists twice in its entirety, on separate paths, and each side carries the full load alone. N+1 survives a failure, 2N additionally survives maintenance on an entire side. 2N is required from the low-voltage distribution onwards, and at least N+1 for the systems before it.

Entrance to a technical building made of light precast concrete: a recessed opening with a wide door made of brushed steel and glass, behind it a bright, empty vestibule with an unadorned counter. The concrete wall next to it is smooth and unlettered.
The building envelope is part of the security concept, not the architecture: windowless and made of exposed concrete, so that nothing behind it can be reached from the outside. Two separate medium-voltage connections from different substations are required; if both fail, the fuel supply must last for 72 hours at full load.
Vertical view of a raised floor with two perforated tiles removed and placed next to it: underneath, galvanised supports on the screed and two separate routes — black power cables in one, light data cables in the other, both bundled and combed straight.
Under the raised floor, power and data must run on separate routes; above it, the same floor guides the cold supply air, and the perforated tiles lie exactly in front of the racks they supply. A hood lies over the cold aisles, separating cold supply air from warm exhaust air. A supply air temperature of 24 °C ± 1 K is required; a rack can thus carry up to 42 kW, provided it is directly water-cooled.
Row of identical grey control cabinets on a wall, each with the same closed door, the same handle and the same ventilation louvre in the base. Above the row is a galvanised cable tray, from which heavy insulated cables branch off into each cabinet in the same curve; in front of it is clear working space.
The battery must last for eleven minutes at full load. That sounds short but is plenty: the diesel generators take over after 12 to 18 seconds. The battery does not bridge the power failure, but only the start-up — and the route above then carries the power onwards on two separate paths.

Location requirement

Fire compartments and fire suppression

We require an IT area divided into fire compartments of no more than 800 m², separated by F90 walls — 90 minutes fire-resistant — and fire doors with hold-open devices. Early detection must use aspirating smoke detectors with two-stage alarms: pre-alarm at 0.03%/m obscuration, main alarm at 0.12%/m. Extinguishing is done with nitrogen, not water: the oxygen concentration drops to 15 vol%. This smothers the fire without destroying the hardware. We do not choose a location without this concept.

Compartment size
max. 800 m²
Separation
F90, T90 doors with hold-open device
Early detection
Aspirating smoke detectors, 2 stages
Extinguishing agent
Nitrogen, target value 15 vol% O₂
Flooding time
≤ 60 s per compartment
Testing interval
Quarterly, full test annually

Location requirement

Power supply, N+1 and A/B separated

A location is only considered if it is supplied via two separate medium-voltage connections from different substations. Transformers, UPS systems — the battery-backed uninterruptible power supply — and distribution boards must be designed at least N+1. From the low-voltage distribution onwards, we require two completely separate paths A and B up to the power strip in the rack; they must not touch at any point. Our servers with two power supply units then survive the failure of an entire path without interruption.

Power feed
2 × 20 kV, different substations
Transformers
N+1 per compartment
Paths in the rack
A and B, physically separated
UPS topology
Double conversion, online
UPS autonomy
11 min at full load

Location requirement

Backup power system and fuel supply

If the power feed fails, the UPS bridges the start-up of the diesel generators. We require a switchover process that remains well within the battery autonomy; in our existing portfolio, it is between 12 and 18 seconds depending on the location. The generators must be designed N+1 — one can fail without load being shed —, and the fuel supply must last at least 72 hours at full load.

Power per generator
2.5 MW
Design
N+1 per location
Startup time to load transfer
12 – 18 s
Fuel capacity
min. 72 h at full load
Resupply
Framework agreement, ≤ 6 h from request
Test run
Monthly without load, annually with load transfer

Location requirement

Cooling concept

The basis must be indirect free cooling: outside air cools a closed water circuit via dry coolers. Mechanical cooling only runs when the outside temperature no longer allows it — in Frankfurt am Main an annual average of 680 hours, in Berlin 1,290, in Munich 610 and in Helsinki 190. Also required are a closed cold aisle containment on the IT space and a supply air temperature of 24 °C according to ASHRAE class A1.

Primary method
Indirect free cooling, adiabatically supported
Chillers
N+1
Supply air temperature
24 °C ± 1 K
Containment
Cold aisle, closed
Power density
up to 42 kW per rack (direct liquid cooling)
Special features
muc1: geothermal energy · hel1: longest free cooling time

Requirement and our own contribution

Routes into the building — and our network behind it

We require two separate entry points for fibre optics on opposite sides of the building and at least two meet-me rooms — the rooms where third-party network operators hand over their lines —, with separate routing up to that point. From the handover point, it is our network: we operate the edge routers and connect each rack with two uplinks to two different leaf switches — the switches to which the servers are directly connected. The fact that the two switches are located in different fire compartments is another requirement for the location.

Building entry points
2, on opposite sides
Meet-me rooms
at least 2
Internal routing
Separate up to the handover point

What we control

Rack connection
2 × 25 GbE, separate switches
Backbone connection
2 × 400 GbE per edge router
Internal topology
Leaf-spine, non-blocking up to 1:1.2
Time source
GNSS + PTP, 2 references per location

Requirement and our own contribution

Monitoring: building and systems separated

Building management systems, fire alarm systems and access control systems must converge in networks that have no route into the customer network; a control room staffed around the clock is required. Our own monitoring is separate from this: we measure each of our racks ourselves, alert our on-call service and report faults to the affected accounts. What the building reports does not replace our monitoring — it is in addition to it.

Control room
Staffed around the clock
Video surveillance
Inside and outside, 90 days storage
Alarm routes
Redundant via landline, mobile, satellite
Disaster recovery drill
Twice a year, with report
Network separation
Operations technology without route to customer network

What we control

Sensors per rack
Temperature, humidity, power, door contact
Power measurement
Per rack and path, in our panel
Opening log
Per rack, with timestamp and identity
Reporting channel
Affected accounts individually, maintenance window in advance
Access door at the end of a concrete corridor: a grey steel leaf in a steel frame with visible hinges, handle set and overhead door closer. Next to it at hand height is an unadorned reader with a single green dot; the corridor is empty and continuously lit.

Five steps to the rack

There are five separate controls between the street and the server. Four of these are building security and therefore a condition for the location: if one is missing, we do not deploy systems there. None of the five can be bypassed by tailgating — the anti-tailgating system checks weight and contour and only opens for one person per authorisation.

The fifth step is ours. We decide who is allowed to open one of our racks, and every opening is logged with a timestamp and identity. Customer visits are possible at any location, but require registration at least 24 hours in advance with name and ID details. Escort by our staff is continuous, even in the customer's colocation cage.

Biometrics: we require palm vein recognition. The feature is not left on surfaces like a fingerprint, and the reference data must remain locally at the location.

  1. Location requirement

    Premises

    Required are a fence with anti-climb protection, fence detection and video surveillance with motion analysis. Deliveries must go through a separate entrance with a mantrap gate; the outer gate closes before the inner one opens.

    Fence detection · video analysis · mantrap gate for delivery traffic

  2. Location requirement

    Reception

    A reception staffed around the clock is required: presentation of official photo ID, comparison with the registered visitor list, issuance of a temporary badge. Without prior registration 24 hours in advance, there is no access — not even for our own employees who do not work regularly at this location.

    ID check · 24 h prior registration · temporary visitor badge

  3. Location requirement

    Security interlock

    A mantrap with weight and contour check is required. It opens only for exactly one person per clearance; tailgating is mechanically impossible. If the measured weight deviates from the expected weight, the mantrap remains locked and the control room is alerted.

    Weight and contour check · single clearance · alert on deviation

  4. Location requirement

    White space

    Access to the IT area must only be possible with a card and biometric feature. We require palm vein recognition: this feature is not left on surfaces like a fingerprint. The reference data must be stored exclusively locally at the location and must not converge centrally.

    Card + palm vein · reference data local only · four-eyes principle for external companies

  5. In our hands

    Rack or cage

    This is where building security ends and ours begins. The rack is additionally locked mechanically or electronically; who is allowed to open it is on a list that we maintain, and each clearance is granted individually. Electronic locks log every opening with timestamp and identity; the log can be viewed in the customer panel. Colocation cages have their own access list, which the customer maintains themselves.

    Electronic rack lock · opening log in panel · own access list

Our own network under AS204812

The network is the part that belongs entirely to us. Since 2019, ENTRONYX CLOUD has been using dark fibre instead of transit capacity — dark fibre means: the cable is laid, we provide the light on it ourselves. This is more expensive to purchase. In return, the latency between locations is predictable, and a capacity expansion is a matter of transponders — the transmitting and receiving modules on the fibre — instead of contract negotiations.

Total capacity
11.2Tbit/sSum of the three rings, calculated per direction
Direct peerings
94At the internet exchanges of the countries where the platform runs; open peering policy
Transit contracts
4Deliberately redundant, no provider over 40% share
Switchover time
< 50msIn the event of a fibre break, via pre-calculated backup paths
Restriction: Applies to rings with completely separate routes. Where both directions share a cable duct — the ring table names the location with its length —, an excavator can hit them both at the same time.
Ring topology of the backbone — as of 08/2026
RingSectionsLengthCapacity per direction (Tbit/s)Redundancy
Metro Rhine-Mainfra1 ↔ fra2 (4 ways)34 km6.4Four independent paths, no shared route
Ring Germanyfra1 → ber1 → muc1 → fra21,720 km3.2Separate routes except for 6 km in the Fulda area, closed via the Metro Rhine-Main
Ring Baltic Seaber1 ↔ hel1 (2 ways)1,180 km1.6Two submarine cables with separate landing points, without shared section

Peering instead of transit where possible

72% of our traffic leaves the network via direct peerings at the internet exchanges of the countries where the platform runs — primarily DE-CIX in Frankfurt, BCIX in Berlin and FICIX in Helsinki. We use transit for the rest and as a fallback. We answer peering requests within five working days; our policy is open and without requirements on the traffic ratio.

Separate routes, not just separate fibres

Two paths are only considered redundant by us if they lie on separate routes. Where this is not consistently possible, both directions share a cable duct for a short distance. The ring table names this point with its length, and it is included in the availability calculation.

DDoS filtering in our own network

Detection runs via flow analysis on all edge routers — the continuous analysis of who exchanges how much traffic with whom. Filtering is handled by a distributed scrubbing capacity of 1.2 Tbit/s: filter nodes that sift out attack traffic and let the rest through. Attacks below 40 Gbit/s are discarded directly at the edge without diversion; larger attacks are routed via the filter nodes, which means 8 to 14 ms additional latency.

See where your systems will be located

An accompanied visit to where your systems are or will be located is possible for existing and prospective customer accounts — with 24 hours' advance notice and ID check at reception. For colocation from half a rack, please speak directly to sales: we check every request individually and state the deadline for provisioning in the quote.

Locations
5
According to EN 50600
5 of 5
Best PUE
1.08
Steps to the rack
5