RabbitMQ Sovereignty: Beyond "Hosted in Switzerland"
Major managed message broker services (Amazon MQ, CloudAMQP on US-owned infrastructure) run under US law. Your message queues, event streams, and application communications are accessible under the CLOUD Act without Swiss judicial process.
Running RabbitMQ on Swiss infrastructure solves the data residency question. However, sovereignty is more than where data is stored. The EU Cloud Sovereignty Framework defines eight dimensions that determine whether your provider is truly sovereign.
RabbitMQ and the license question
The RabbitMQ server is licensed under the Mozilla Public License 2.0 (MPL-2.0). MPL-2.0 is a copyleft license that applies per file, not per project, so the obligation covers the MPL-2.0 files themselves and not your application code that talks to the broker. There is no GPL-style requirement to open-source your application, and no SSPL or BSL-style clause restricting who may offer RabbitMQ as a service. That last point is what makes any managed RabbitMQ offering possible, ours included.
The upstream repository also ships an Apache-2.0 license file covering some components, so MPL-2.0 describes the server rather than every file in the tree.
What the license does not settle
RabbitMQ is a Broadcom property. The upstream repository carries "Copyright (c) 2007-2026 Broadcom", Broadcom publishes commercial editions alongside the open-source server, and at least one protocol feature (AMQP 1.0 over WebSocket) is listed as supported in VMware Tanzu RabbitMQ rather than in the open-source build. Which open-source releases receive community support is set by Broadcom's Community Support Eligibility Policy.
None of that changes the license on code already published. MPL-2.0 grants are irrevocable, so any version you deploy today stays under those terms permanently and a fork remains possible. What it does mean is that the roadmap, the boundary between the open-source and commercial editions, and the support window are decided by a US-domiciled vendor.
For a sovereignty assessment: the license risk is low, the vendor-governance risk is real, and the second is the one to watch. A page that told you RabbitMQ carries no vendor risk at all would be selling you something.
What an operator can affect is the other half. VSHN runs the open-source server on infrastructure you choose, under Swiss law, with no Broadcom subscription in the path. The same terms apply whether you deploy via Managed Server or self-service through Servala.
RabbitMQ sovereignty compared
| Dimension | Amazon MQ | CloudAMQP | VSHN Managed RabbitMQ |
|---|---|---|---|
| Ownership | Amazon (USA) | 84codes AB (Sweden) | VSHN AG (Switzerland) |
| Governing law | US law | Swedish law | Swiss law |
| CLOUD Act | Exposed | Not directly exposed (runs on US hyperscalers) | Not exposed |
| Data location | AWS EU regions | AWS/GCP/Azure EU regions | Switzerland (Cloudscale or your choice) |
| Source code | Uses RabbitMQ, proprietary service layer | Open source (uses RabbitMQ) | Open source (MPL-2.0) |
| Staff access from abroad | Support staff worldwide, including USA and India | 84codes staff in Sweden, USA, New Zealand and remote | VSHN Canada for night-time scheduled work; none with the Swiss-only option |
| Certifications | SOC 2, ISO 27001 | SOC 2 | ISO 27001, ISAE 3402 Type II |
VSHN sovereignty self-assessment
We applied the EU's Cloud Sovereignty Framework (v1.2.1, October 2025) to our own services. This framework was used to score providers in the EU's EUR 180M sovereign cloud tender in April 2026. Three pure-European providers achieved SEAL-3, while a consortium involving Google Cloud scored only SEAL-2.
This is a self-assessment, not a formal SEAL certification. We publish it for transparency so customers can evaluate our sovereignty profile using the same structured criteria the EU uses.
| # | Dimension | Weight | Assessment | Evidence |
|---|---|---|---|---|
| SOV-1 | Strategic | 15% | Strong | Swiss AG, no foreign parent, all shareholders Swiss citizens (Commercial Register) |
| SOV-2 | Legal | 10% | Strong | Swiss law (GTC), no CLOUD Act, EU adequacy decision |
| SOV-3 | Data & AI | 10% | Strong | Swiss DCs by default. Sovereign key management via Managed OpenBao + Swiss HSM |
| SOV-4 | Operational | 15% | Strong | Swiss 24/7 ops, Swiss-only support option. All services on vanilla Kubernetes |
| SOV-5 | Supply Chain | 20% | Strong | Infrastructure-agnostic: customer chooses provider. Open-source software |
| SOV-6 | Technology | 15% | Strong | 100% open source. VSHN contributes to K8up (CNCF Sandbox) and maintains Project Syn |
| SOV-7 | Security | 10% | Strong | ISO 27001, ISAE 3402 Type II, Swiss SOC. FINMA-regulated customers |
| SOV-8 | Environmental | 5% | Moderate | DC operators: Green Datacenter AG (ISO 22301/27001/27701), Exoscale sustainability. VSHN CSR policy |
Overall: SEAL-3 equivalent. This is the same level achieved by the winners of the EU's own sovereignty tender. No bidder in the EU's own tender reached SEAL-4: it requires complete EU control with no critical non-EU dependencies, and every cloud provider depends on hardware made in Asia and the US and on open-source projects governed by US-based foundations such as the Linux Foundation and CNCF. These structural gaps are shared by every cloud provider.
Try Swiss infrastructure: Servala (managed services, free trial), Exoscale (Swiss IaaS). Want help choosing? Contact us.
Get a sovereignty assessment for your messaging infrastructure
Running Amazon MQ or CloudAMQP and concerned about jurisdictional risk? We assess your sovereignty profile against the EU framework and plan a migration to Swiss-hosted RabbitMQ.