Resources · Cloud Providers & SCM

12 clouds. 8 SCMs. 13 container registries.

Wherever your code lives, wherever your images live, wherever your workloads run — Safeguard plugs in. SCM connectors for every major hosted and self-hosted Git platform, container registry support across every cloud, and deployment shapes from shared cloud to sovereign air-gapped.

Cloud-agnostic by design.
No lock-in. Bring your existing cloud — or run sovereign on bare metal.
Source Control (SCM)

8 SCM providers, hosted and self-hosted.

ProviderAuthenticationStatus
GitHubOAuth2 / PATGA
GitLabPAT (Bearer)GA
BitbucketApp PasswordGA
Azure DevOpsHTTP Basic (PAT)GA
Oracle DevOpsOCI API KeyGA
Generic Git (any Git-compatible server)Token / SSHGA
Gitea (self-hosted)PAT or username/passwordRoadmap
AWS CodeCommitAWS credentialsRoadmap
Container Registries

13 container registries across every cloud.

RegistryAuthenticationStatus
Docker HubJWT (username/password)GA
AWS ECR (Elastic Container Registry)AWS SDK (Access Key + Secret)GA
Azure ACR (Container Registry)Basic / Service PrincipalGA
GCP GCR (Container Registry)Service Account JSONGA
Oracle OCIR (Cloud Infrastructure Registry)Tenancy + Auth TokenGA
Harbor (open-source registry)Basic / Robot tokensGA
Generic OCI-compatible registryBasic / BearerGA
Quay.io / Red Hat QuayRobot accounts / OAuth2Beta
JFrog ArtifactoryAPI Key / username:passwordBeta
Sonatype Nexus RepositoryUsername/password or tokenBeta
GitHub Container Registry (ghcr.io)GitHub PATBeta
GitLab Container RegistryGitLab PAT / Deploy TokenBeta
Google Artifact Registry (GCP AR)Service Account JSONBeta
Cloud Providers

12 cloud surfaces. From shared cloud to sovereign.

Amazon Web Services

AWS

Services: ECR, ECS, Lambda, EKS, S3, IAM, CodeCommit, Secrets Manager

Deployment: Shared cloud · Dedicated cluster · VPC-isolated

Microsoft Azure

Azure

Services: ACR, AKS, Azure Functions, Azure DevOps, Key Vault, Entra ID

Deployment: Shared cloud · Dedicated cluster · VPC-isolated

Google Cloud Platform

GCP

Services: GCR, GAR, GKE, Cloud Run, Cloud Build, Secret Manager, Workload Identity

Deployment: Shared cloud · Dedicated cluster · VPC-isolated

Oracle Cloud Infrastructure

OCI

Services: OCIR, OKE, OCI DevOps, OCI Vault, Identity & Access Management

Deployment: Dedicated cluster · VPC-isolated · Sovereign

Yotta Cloud (India)

Yotta

Services: Compute, GPU, Storage, Networking — India data-residency

Deployment: Dedicated cluster · VPC-isolated · Sovereign

IBM Cloud

IBM

Services: ICR, IKS, Code Engine, Secrets Manager, Cloud IAM

Deployment: Dedicated cluster · VPC-isolated

DigitalOcean

DO

Services: Container Registry, DOKS, Spaces, App Platform

Deployment: Shared cloud · Dedicated cluster

On-premises Kubernetes

K8s

Services: Any CNCF-conformant K8s + OCI registry of your choice

Deployment: Dedicated cluster · VPC-isolated · Sovereign · Air-gapped

VMware vSphere / Tanzu

VMW

Services: TKG, Harbor, vSphere with Tanzu, Tanzu Application Platform

Deployment: Dedicated · VPC-isolated · Sovereign · Air-gapped

OpenStack (community + commercial)

OSt

Services: Magnum, Swift, Heat, Keystone

Deployment: Dedicated · Sovereign · Air-gapped

Bare-metal + custom infra

Bare

Services: K8s / Nomad / Docker Swarm with OCI registry of your choice

Deployment: Sovereign · Air-gapped

Sovereign / national clouds

Sov

Services: Per-country sovereign cloud providers (NCA-aligned KSA, Bhasai/MeghRaj India, Gaia-X EU)

Deployment: Sovereign · Air-gapped

Preferred per region

Recommended cloud per region.

Recommendations based on data residency, regulator alignment, sovereign requirements, and observed customer patterns. Safeguard runs on whichever you pick.

RegionPreferred (primary)Alternate optionsSovereign / local
North America (US / Canada)AWS (us-east-1, us-west-2)Azure East US 2, GCP us-central1AWS GovCloud · Azure Gov · GCP for Government
European UnionAWS (eu-west-1 Dublin, eu-central-1 Frankfurt)Azure West Europe, GCP europe-west3OVHcloud · Scaleway · STACKIT · T-Systems · S3NS (FR)
United KingdomAWS London (eu-west-2)Azure UK South, GCP europe-west2UKCloud · Crown Hosting
IndiaAWS Mumbai (ap-south-1)Azure Pune / Chennai, GCP MumbaiMeghRaj / NIC · MeitY-empanelled providers · CtrlS · NxtGen · Yotta
Middle East — KSAOracle Jeddah · AWS Bahrain (me-south-1)Azure Saudi (preview), GCP Doha (me-central1)NCA-licensed local providers · STC Cloud · stc-pay infra
Middle East — UAEAzure UAE North · AWS UAE (me-central-1)Oracle Abu Dhabi, GCP DohaG42 · Khazna · Mubadala
Middle East — other GCCAWS Bahrain · Azure Qatar CentralOracle Jeddah / DubaiLocal NCA / NIA / CITC-licensed providers
Australia & NZAWS Sydney (ap-southeast-2)Azure Australia East, GCP australia-southeast1Vault Cloud · AUCloud · Sliced Tech
APAC — Singapore / SEAAWS Singapore (ap-southeast-1)Azure Southeast Asia, GCP asia-southeast1ST Engineering · Singtel · IM8-aligned providers
APAC — JapanAWS Tokyo (ap-northeast-1)Azure Japan East, GCP asia-northeast1KDDI · NTT Com · Fujitsu Cloud
APAC — KoreaAWS Seoul (ap-northeast-2)Azure Korea Central, GCP asia-northeast3KT Cloud · Naver Cloud · NHN Cloud
Latin AmericaAWS São Paulo (sa-east-1)Azure Brazil South, GCP southamerica-east1Locaweb · Ascenty (regional carriers)
AfricaAWS Cape Town (af-south-1)Azure South Africa North, GCP johannesburgLiquid C2 · Teraco · State Information Technology Agency (SITA, ZA)

"Preferred" reflects customer-success patterns and data-residency optimisation — not a vendor mandate. Safeguard remains cloud-agnostic; you choose, we run there. Sovereign tier always runs on customer-controlled infrastructure.

What "supported" means here.

SCM: first-class connector with OAuth/PAT setup, webhook auto-config, repo discovery, branch policy, and PR-comment write-back. "GA" means production-ready; "Roadmap" means planned with a published quarter.

Container registry: authenticated pull + manifest read + tag enumeration + SBOM ingest. "GA" means in production; "Beta" means functional but under hardening.

Cloud: the platform runs on or against any of the listed clouds. Deployment shape (shared / dedicated / VPC-isolated / sovereign / air-gapped) determines which Griffin variant is available.

Missing your cloud or SCM? The Generic Git + Generic OCI connectors cover most edge cases. For anything else, talk to the integrations team — first-class connectors are a 4–8 week add given the existing framework.

Need a specific cloud or SCM?

Talk to the integrations team — integrations@safeguard.sh.