privacyIDEA is a modular open source authentication server that adds multi-factor authentication to logins, VPNs, SSH and web portals. It supports one-time passwords, FIDO2 and WebAuthn, smartcards, push, SMS, email and SSH keys, and reads users from LDAP, Active Directory, SQL databases and other sources. Administrators manage tokens and policies through a web interface and a REST API. The server is written in Python with the Flask framework and runs on Linux, on your own infrastructure.
The server is licensed under the AGPL-3.0 and its code is developed openly on GitHub. NetKnights GmbH, based in Kassel, Germany, offers the privacyIDEA Enterprise Edition with support, which according to the vendor can be deployed on premises or hosted. Because the community edition is self-hosted, user and token data stays in the environment you operate, so its location and jurisdiction are under your control. A European organisation can therefore run it in its own datacentre or an EU cloud while keeping access to the source code.