TELEMAXX GmbH
Germany · www.telemaxx.de · 12 vendors
TelemaxX Telekommunikation GmbH operates five high-security data centers and a fiber optic network in the Karlsruhe Technology Region. The company specializes in providing customized solutions for data center space, server housing, managed services, IT services, and telecommunications services to business clients.
Resilience scores
- Digital Sovereignty: 17
- Digital Resilience: 8
- Financial Resilience: 7
Technology vendors
- Ghost — Technology — Singapore
- Meta Platforms, Inc. — Technology — United States
- Netlify, Inc. — Technology — United States
- and 10 more
Services catalogue
2 services in catalogue across 1 category; runs on 12 sub-vendors.
- DNS Hosting
- Web Hosting
Insights
Last updated 2026-08-19 · revision 2
12 direct vendors, 219 subvendors
Direct vendors by controlling owner country (sample)
- Australia: 1
- Germany: 1
- Singapore: 1
Subvendors by controlling owner country (sample)
- France: 10
- Norway: 1
- Italy: 2
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
TelemaxX exhibits strong migration readiness due to its modern and diverse internal technology stack, including OpenStack, Kubernetes, Infrastructure as Code (IaC), VMware, and Proxmox VE. The company itself offers various cloud services (OpenCloud, VPC, VMware Cloud), demonstrating inherent expertise in cloud environments and migration pathways. Their 'IT-Infrastruktur Consulting' services explicitly include cloud migration planning and hybrid data center architecture, indicating a clear understanding of migration processes. TelemaxX's exceptionally strong data residency posture (100% Germany-based, GDPR-compliant, 'sovereign' cloud) simplifies migration for customers with strict data sovereignty requirements. Furthermore, direct connections to major hyperscalers (AWS, Azure, Google Cloud via DirectCLOUD and Microsoft Azure Peering Service) facilitate hybrid and multi-cloud migration strategies. The primary challenge for migration readiness stems from the ambiguity around vendor relationships; while 'Vendor Geographic Diversity' is noted, the 'Total Vendors: 0' and 'Vendor Lock-in Risk: Unknown' make it difficult to assess potential dependencies or complexities in migrating away from specific technologies or services. The 'Assessment Required' status for critical regulations like NIS2, TKG, and EnEfG introduces potential compliance hurdles and additional overhead that would need to be addressed during a significant migration effort. Lastly, the absence of financial stability data (revenue concentration, growth history) prevents an assessment of the company's capacity to fund or absorb the costs associated with a large-scale migration.
Compliance
10 in-scope frameworks identified; showing 3.
SOC 2 (source) — Assessment Required
SOC 2 is a US-origin framework (AICPA) primarily relevant for cloud service providers and managed service providers serving US-based clients or US-regulated industries. TelemaxX operates cloud services (OpenCloud, VPC, VMware Cloud), managed services, and colocation — all service types for which SOC 2 is commonly expected by enterprise clients, particularly those with US operations or US regulatory requirements. Risk is Medium because: (1) TelemaxX holds ISAE 3402 Type 2 certification, which is the European/international equivalent of SOC 1 (controls over financial reporting), not SOC 2 (security, availability, confidentiality); (2) TelemaxX's ISO 27001:2024 certification covers information security management, partially overlapping with SOC 2 Trust Service Criteria; (3) No SOC 2 report has been identified; (4) For TelemaxX's primarily German/EU customer base, SOC 2 is less critical than ISAE 3402 and ISO 27001, but international enterprise clients may request it. The absence of SOC 2 could be a commercial risk rather than a regulatory compliance risk.
Evidence: https://www.telemaxx.de/services/rechenzentrum/datacenter/zertifizierungen, https://www.telemaxx.de/fileadmin/docs/cert/2024-DE-ISO_27001-TelemaxX.pdf
TKG — Assessment Required
The German Telecommunications Act (TKG 2021, implementing the European Electronic Communications Code / EECC) is directly applicable to TelemaxX as a provider of public telecommunications networks and services. TelemaxX operates: a 2,400+ km fibre-optic backbone network, public internet access services (Business Internet), IP telephony (SIP Account, SIP Trunk, Cloud Telephony), and carrier/interconnection services. These activities squarely fall within TKG scope. Risk is High because: (1) TKG imposes significant obligations including network security requirements (§165 TKG), lawful interception (§170 TKG), emergency call obligations, number portability, and regulatory reporting to the Bundesnetzagentur (BNetzA); (2) TKG §165 requires telecommunications providers to implement technical and organisational measures to protect network integrity and security — with mandatory notification to BNetzA for significant security incidents; (3) Non-compliance can result in fines up to €1M or 3% of annual turnover; (4) The BNetzA actively enforces TKG requirements; (5) No public disclosure of TKG compliance status or BNetzA registration has been found, though registration is legally mandatory for public network operators.
Evidence: https://www.telemaxx.de/services/telekommunikation, https://www.telemaxx.de/services/telekommunikation/glasfaserinfrastruktur, https://www.telemaxx.de/services/telekommunikation/ip-telefonie, https://www.telemaxx.de/loesungen/perspektiven/nis2, https://www.gesetze-im-internet.de/tkg_2021/
BDSG — Compliant
The BDSG supplements and implements GDPR in Germany, adding specific national provisions for employee data processing, data processing by public authorities, and specific sectoral rules. As a German company, TelemaxX is subject to BDSG in addition to GDPR. Risk is Low because: (1) TelemaxX's demonstrated GDPR compliance posture (ISO 27001, ISAE 3402, DSGVO-konform marketing) inherently covers BDSG requirements; (2) BDSG primarily adds specificity to GDPR rather than creating entirely new obligations for private sector companies; (3) The company's published Datenschutzerklärung addresses both GDPR and BDSG obligations; (4) The LfDI Baden-Württemberg (state data protection authority) is the competent supervisory authority, and no enforcement actions against TelemaxX have been identified.
Evidence: https://www.telemaxx.de/datenschutz, https://www.telemaxx.de/services/rechenzentrum/datacenter/zertifizierungen, https://www.gesetze-im-internet.de/bdsg_2018/
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 7/10
TelemaxX demonstrates strong qualitative financial resilience despite the absence of retrievable primary financial figures in this research pass. Its ownership by nine regional municipal utilities plus one municipality (Stadtwerke consortium in Baden-Württemberg) provides an exceptionally stable, patient capital base that rarely demands short-term dividends and is willing to fund long-cycle data center capex. This quasi-public ownership also confers implicit creditworthiness support, which is unusual for a mid-sized private operator. The business model is inherently resilient: colocation, managed services, telecom lines and cloud are largely subscription/contract-based, providing predictable recurring cash flow. The company's own fiber network (~2,400+ km) and four operational data centers (with a fifth opened in 2018 and sixth planned) represent a substantial physical asset moat versus pure resellers. Certifications (ISO 27001, ISAE 3402 Type 2, ISO 14001, EMAS, fair.digital) position the company well for regulated German customers in finance, healthcare, and public sector. However, the score is moderated by scale disadvantages versus hyperscalers (AWS, Azure, Google) and large European colocation players (Equinix, Digital Realty), regional geographic concentration in the Karlsruhe area (all DCs within similar geography creating systemic risk), and heavy capex intensity from ongoing DC construction. Post-2022 energy costs directly hit gross margins as DC power is a significant OpEx component. Firm financial metrics could not be verified from primary filings in this pass.
Key strengths: Stable quasi-public ownership by nine regional municipal utilities plus one municipality, Recurring subscription/contract-based revenue model (colocation, managed services, cloud, telecom), Own fiber network of ~2,400+ km and four operational data centers, Strong certifications (ISO 27001, ISAE 3402 Type 2, ISO 14001, EMAS, fair.digital), Diversified customer base across finance, logistics, retail, healthcare, public sector, automotive, 25-year track record of continuous DC footprint expansion (IPC 1 through planned IPC 6), DE-CIX Enabled Site status providing strategic interconnection value, Data sovereignty positioning as DSGVO-compliant German alternative to hyperscalers
Risk factors: Small scale versus hyperscalers (AWS, Azure, Google) and large European colocation players (Equinix, Digital Realty/Interxion, NTT), Regional geographic concentration - all four DCs within Karlsruhe/TechnologieRegion creating systemic regional risk, High capex intensity from new DC construction (IPC 5, IPC 6) requiring heavy investment with long payback periods, Energy cost exposure post-2022 directly impacting gross margin as DC power is significant OpEx, Ownership structure with nine shareholders can slow strategic decision-making, Increasing regulatory compliance burden (NIS2 directive, EnEfG energy-efficiency regulation, DSGVO), No disclosed hyperscaler partnership beyond DE-CIX/DirectCloud interconnects, Pricing pressure on colocation and cloud services from larger competitors
Revenue by geography
- Germany: 100%
Revenue by product/service
- Cloud: 0%
- Interconnection: 0%
- Managed services: 0%
- Telecommunications: 0%
- Data center / colocation: 0%
Workforce by country
- Germany: 145
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.