Sovereign Cloud Solutions: Google Distributed Cloud air-gapped for the Highest Security Requirements
The Sovereign Cloud from Hyperscaler
Regulated companies in the core industries of increased security needs - such as Public, Health, Financial Services, Insurance, and Defense - are facing the major challenge of having to operate their sovereign IT in a secure, future-oriented, and scalable manner. Google Cloud is the first and so far only hyperscaler to offer a state-of-the-art solution: the "Google Distributed Cloud (GDC) air-gapped". GDC air-gapped is a technological construct with dedicated hardware that organizations can operate completely autonomously and isolated from the Internet - air-gapped, without any Internet connection. Google Cloud thus meets the highest security requirements that organizations can set with regard to a truly sovereign cloud.
The core of GDC air-gapped is that Google Cloud delivers the corresponding hardware and software to customers or national managed GDC service providers that have been specially qualified by Google Cloud. GDC air-gapped is then completely removed from the hyperscaler's access. This means that no connection to Google Cloud or the public internet is ever required to manage infrastructure, services, APIs, or tools.
Google Cloud itself has no access to either the software or the GDC air-gapped servers. At Arvato Systems, we position ourselves as a managed GDC provider that looks after and manages this highly secure Sovereign Cloud either in our own data center or on the customer's premises.
Cloud Challenges: Operational and Technological Sovereignty
From the hyperscaler Google Cloud's perspective, the question of sovereignty has different facets - such as data sovereignty, operational sovereignty, and software and technology sovereignty. Especially when it comes to control over the technology used and its operation, this has naturally been difficult to get to grips with in the context of a cloud model. The fact that the cloud provider itself is responsible for controlling and operating the technology was an important factor in the triumph of cloud computing. But GDC air-gapped makes this problem disappear because Google Cloud does away with any access. Instead, the customer or their managed GDC service provider is given direct control, which also extends to all hardware. Apart from Google Cloud, no other hyperscaler to date provides functioning hardware as the basis for a genuine sovereign cloud. GDS air-gapped includes everything that is necessary to provide, operate, scale, and protect a privately managed cloud: from the server hardware and software to the local control level and all operational tools.
Secure and Confident, but Cloud-Native at the Same Time
The offer of a highly secure GDC with Air Gap is interesting not least because it is much more than just an Infrastructure-as-a-Service (IaaS) stack. This is because GDC air-gapped is cloud-native and thus makes open source technologies such as Kubernetes accessible. In addition, GDC opens up access to numerous Platform-as-a-Service (PaaS) services in the context of Google Cloud, and the valuable possibilities of the Vertex AI platform are also available. Last but not least: GDC gives organizations access to an air-gapped marketplace where Google's build partners offer localized, GDC-certified software packages that can be executed in the isolated environment of the user companies. Here too, software installed via the Distributed Cloud Marketplace must be executed and managed by the user company or its Managed GDC Service Provider under its own responsibility. Neither Google Cloud nor the build partners have any access to this.
With the Sovereign Cloud to Sovereign AI
It is the principle of GDC air-gapped: organizations can use the modern cloud technology of a hyperscaler without having to compromise on their own sovereignty. The AI capabilities of Google Cloud are also available: whether translation API, speech-to-text, optical character recognition (OCR) or the Document AI Suite. Google highlights three offline use cases in particular in the context of GDC air-gapped: AI-based translation of audio and video, AI-based analysis of audio and video content and the use of Google's Large Language Models for conversational search.
AI-based translation
With GDC, the latest Google Cloud technologies in the field of OCR (Optical Character Recognition) and speech recognition become accessible offline: in the form of a completely separate environment for the translation of text, whether it is in images, PDFs or audio files. This eliminates the need for manual transcriptions and translations.
AI-based video analysis
GDC is also a ready-to-use end-to-end video analytics platform with AI-powered natural language search. Its intelligent video capture supports both batch uploads and real-time streams. The offline analytics solution has a fully automated workflow management system that orchestrates the entire lifecycle of the solution.
Generative AI for searching in local data
GDC air-gapped offers a search package that leverages the capabilities of Google's own Large Language Models (LLM) to provide users with a conversational search of their local data - in other words, a search based on natural language. The Gemma family of lightweight, open LLMs is built on the same technology that powers Google Gemini AI.
Arvato Systems as Your Partner for GDC air-gapped
Arvato Systems is pursuing a clear strategy of positioning itself as a leading provider of sovereign IT. Other specialized offerings for sovereign IT include the Delos Cloud, which we operate for the public sector in Germany. We offer all our customers a unique end-to-end portfolio for sovereign IT, including our own data centers. Now we also cover GDC air-gapped. In future, Arvato Systems will be one of only two managed GDC service providers in Germany. Google Cloud is currently setting standards with its Google Distributed Cloud with Air Gap. It is the first isolated private cloud offering already available that is based on the cloud-native technology of a hyperscaler and includes all the necessary hardware in addition to the software. From a security and cost perspective, GDC air-gapped is state of the art. Nevertheless, it can make sense for strictly regulated organizations to implement their own sovereign cloud in this way - one that is completely isolated and highly secure, but which also gives them access to the technology of a hyperscaler.
As a managed service provider, Arvato Systems has the expertise to advise you on all aspects of sovereign IT and GDC air-gapped.
Frequently Asked Questions About Google Cloud air-gapped
-
What is the Google Distributed Cloud air-gapped?
The Google Distributed Cloud air-gapped is an isolated cloud environment consisting of the necessary hardware and software: a state-of-the-art solution for a sovereign cloud. GDC air-gapped enables organizations to operate their own cloud completely sovereign and manage cloud-native applications and data without ever having any connection to Google Cloud, the Internet or other networks. This makes GDC air-gapped ideal for organizations with the highest security requirements and strictest compliance regulations.
-
What are the advantages of using an air-gapped cloud solution?
Companies benefit from the flexibility of using the cloud technologies of a hyperscaler - those of Google Cloud - while still complying with the strictest security requirements. The advantages of such a sovereign cloud with Air Gap are maximum security, complete data control, support for compliance requirements and the ability to operate critical applications and data in a completely isolated environment.
-
For which industries is the Google Distributed Cloud air-gapped suitable?
This solution is particularly suitable for highly regulated industries where data protection and security are of paramount importance, such as the financial services sector, healthcare, defense, public administration and critical infrastructures.
-
How does the cloud solution with Air Gap differ from traditional cloud services?
In contrast to traditional cloud services, which require a constant internet connection, GDC air-gapped is physically completely isolated from other networks. This is because Google Cloud provides the customer with a complete technological package consisting of dedicated hardware and the necessary cloud software. This gives the customer a sovereign cloud that is completely under their own control. This minimizes the risk of cyberattacks and unauthorized access to sensitive data.
-
How do I implement the Google Distributed Cloud air-gapped in my company?
The implementation requires careful planning and ideally also the support of a special Google Cloud partner: a German Managed GDC Service Provider. Companies with high security requirements should analyze their specific needs and compliance requirements in order to develop a tailor-made solution together with their Managed GDC Service Provider that optimally meets their security needs and their requirements for using the benefits of Google Cloud technology.

Arvato Systems is your ideal partner for the implementation of the Google Distributed Cloud air-gapped. As a leading Sovereign IT provider, we offer a unique end-to-end portfolio that covers all aspects of the Sovereign Cloud. Our expertise as a managed service provider enables us to provide you with comprehensive advice on all aspects of sovereign IT and GDC air-gapped. With our support, you can implement a highly secure, isolated cloud solution that also gives you access to the innovative technology of a hyperscaler.