RabbitMQ Sovereignty: Beyond "Hosted in Switzerland"

Major managed message broker services (Amazon MQ, CloudAMQP on US-owned infrastructure) run under US law. Your message queues, event streams, and application communications are accessible under the CLOUD Act without Swiss judicial process.

Running RabbitMQ on Swiss infrastructure solves the data residency question. However, sovereignty is more than where data is stored. The EU Cloud Sovereignty Framework defines eight dimensions that determine whether your provider is truly sovereign.

RabbitMQ and the license question

The RabbitMQ server is licensed under the Mozilla Public License 2.0 (MPL-2.0). MPL-2.0 is a copyleft license that applies per file, not per project, so the obligation covers the MPL-2.0 files themselves and not your application code that talks to the broker. There is no GPL-style requirement to open-source your application, and no SSPL or BSL-style clause restricting who may offer RabbitMQ as a service. That last point is what makes any managed RabbitMQ offering possible, ours included.

The upstream repository also ships an Apache-2.0 license file covering some components, so MPL-2.0 describes the server rather than every file in the tree.

What the license does not settle

RabbitMQ is a Broadcom property. The upstream repository carries "Copyright (c) 2007-2026 Broadcom", Broadcom publishes commercial editions alongside the open-source server, and at least one protocol feature (AMQP 1.0 over WebSocket) is listed as supported in VMware Tanzu RabbitMQ rather than in the open-source build. Which open-source releases receive community support is set by Broadcom's Community Support Eligibility Policy.

None of that changes the license on code already published. MPL-2.0 grants are irrevocable, so any version you deploy today stays under those terms permanently and a fork remains possible. What it does mean is that the roadmap, the boundary between the open-source and commercial editions, and the support window are decided by a US-domiciled vendor.

For a sovereignty assessment: the license risk is low, the vendor-governance risk is real, and the second is the one to watch. A page that told you RabbitMQ carries no vendor risk at all would be selling you something.

What an operator can affect is the other half. VSHN runs the open-source server on infrastructure you choose, under Swiss law, with no Broadcom subscription in the path. The same terms apply whether you deploy via Managed Server or self-service through Servala.

Contact Us

RabbitMQ sovereignty compared

Dimension Amazon MQ CloudAMQP VSHN Managed RabbitMQ
Ownership Amazon (USA) 84codes AB (Sweden) VSHN AG (Switzerland)
Governing law US law Swedish law Swiss law
CLOUD Act Exposed Not directly exposed (runs on US hyperscalers) Not exposed
Data location AWS EU regions AWS/GCP/Azure EU regions Switzerland (Cloudscale or your choice)
Source code Uses RabbitMQ, proprietary service layer Open source (uses RabbitMQ) Open source (MPL-2.0)
Staff access from abroad Support staff worldwide, including USA and India 84codes staff in Sweden, USA, New Zealand and remote VSHN Canada for night-time scheduled work; none with the Swiss-only option
Certifications SOC 2, ISO 27001 SOC 2 ISO 27001, ISAE 3402 Type II

VSHN sovereignty self-assessment

We applied the EU's Cloud Sovereignty Framework (v1.2.1, October 2025) to our own services. This framework was used to score providers in the EU's EUR 180M sovereign cloud tender in April 2026. Three pure-European providers achieved SEAL-3, while a consortium involving Google Cloud scored only SEAL-2.

This is a self-assessment, not a formal SEAL certification. We publish it for transparency so customers can evaluate our sovereignty profile using the same structured criteria the EU uses.

# Dimension Weight Assessment Evidence
SOV-1 Strategic 15% Strong Swiss AG, no foreign parent, all shareholders Swiss citizens (Commercial Register)
SOV-2 Legal 10% Strong Swiss law (GTC), no CLOUD Act, EU adequacy decision
SOV-3 Data & AI 10% Strong Swiss DCs by default. Sovereign key management via Managed OpenBao + Swiss HSM
SOV-4 Operational 15% Strong Swiss 24/7 ops, Swiss-only support option. All services on vanilla Kubernetes
SOV-5 Supply Chain 20% Strong Infrastructure-agnostic: customer chooses provider. Open-source software
SOV-6 Technology 15% Strong 100% open source. VSHN contributes to K8up (CNCF Sandbox) and maintains Project Syn
SOV-7 Security 10% Strong ISO 27001, ISAE 3402 Type II, Swiss SOC. FINMA-regulated customers
SOV-8 Environmental 5% Moderate DC operators: Green Datacenter AG (ISO 22301/27001/27701), Exoscale sustainability. VSHN CSR policy

Overall: SEAL-3 equivalent. This is the same level achieved by the winners of the EU's own sovereignty tender. No bidder in the EU's own tender reached SEAL-4: it requires complete EU control with no critical non-EU dependencies, and every cloud provider depends on hardware made in Asia and the US and on open-source projects governed by US-based foundations such as the Linux Foundation and CNCF. These structural gaps are shared by every cloud provider.

Try Swiss infrastructure: Servala (managed services, free trial), Exoscale (Swiss IaaS). Want help choosing? Contact us.

Get a sovereignty assessment for your messaging infrastructure

Running Amazon MQ or CloudAMQP and concerned about jurisdictional risk? We assess your sovereignty profile against the EU framework and plan a migration to Swiss-hosted RabbitMQ.

Contact us

Need managed RabbitMQ? Order on Servala at servala.com/service/rabbitmq/ for self-service provisioning, or contact us for a free consultation. Need messaging architecture help? We connect you with the right consulting partner.

Book a free call

Or ask your question