🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

3DS Outscale

France · IaaS · https://www.outscale.com

Sovereignty score77.2%
Global (unweighted)76.3%
Overall SEAL
SEAL-3 Digital Resilience
SOV-1 Strategic Sovereignty89.6SEAL-4
SOV-2 Legal & Jurisdictional Sovereignty91.6SEAL-4
SOV-3 Data & AI Sovereignty80.0SEAL-3
SOV-4 Operational Sovereignty79.0SEAL-3
SOV-5 Supply Chain Sovereignty67.9SEAL-3
SOV-6 Technology Sovereignty55.0SEAL-3
SOV-7 Security & Compliance Sovereignty78.5SEAL-3
SOV-8 Environmental Sustainability68.8SEAL-3

SOV-1 · Strategic Sovereignty 89.6% · SEAL-4 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity (French-law entity, brand of Dassault Systemes SE, no non-EU parent) -> opt4 (entirely within EU) (src: https://www.3ds.com/newsroom/press-releases/outscale-first-cloud-qualified-secnumcloud-32).
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4highOwned by Dassault Systemes, a large French/EU industrial software group; takeover/transfer to a non-EU sovereign entity is very unlikely (opt5).
SOV-1.3Control over roadmap4. Full influence of EU actors125/125SEAL-4mediumEU-controlled roadmap with own R&D (TINA OS) and EU governance participation (GAIA-X founder, ANSSI ecosystem) -> opt4 full influence of EU actors.
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4highFunded by French parent Dassault Systemes; no material reliance on non-EU capital (opt5).
SOV-1.5EU economic contribution4. Majority in the EU94/125SEAL-4mediumOperations, engineering, data centers and jobs predominantly in France/EU; majority of economic contribution is in the EU (opt4).
SOV-1.6Participation in EU strategic programs4. Strong participation94/125SEAL-4highFounding member of GAIA-X and active in EU sovereign-cloud / SecNumCloud initiatives; strong participation (opt4).
SOV-1.7Alignment with EU industrial strategies3. Measured achievement and dedicated governance83/125SEAL-4mediumSovereign-cloud strategy with measured achievements (first SecNumCloud 3.2 qualification) and dedicated governance aligned with EU digital-sovereignty strategy (opt3).
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4mediumown_stack: vertically integrated EU provider with self-developed TINA OS orchestrator, EU ops and documented continuity; foreign chips are residual hardware only -> opt5 full autonomy & continuity.

SOV-2 · Legal & Jurisdictional Sovereignty 91.6% · SEAL-4 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highSovereign SecNumCloud offer contracted exclusively under French/EU law -> opt3 (4) (src: https://en.outscale.com/our-certifications/).
SOV-2.2Extraterritorial laws exposure5. Verified legal immunity, non-EU laws unenforceable167/167SEAL-4highimmunity: SecNumCloud 3.2 (key rule c) + pure-FR entity with no non-EU nexus; explicitly protected against extraterritorial law -> opt5 verified legal immunity (4) (src: https://www.3ds.com/newsroom/press-releases/outscale-first-cloud-qualified-secnumcloud-32).
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4highNo foreign_parent + immunity: French-law entity not subject to US CLOUD Act/FISA, commits to reject/challenge non-EU compelled access -> opt5 requests always rejected (4) (src: https://www.3ds.com/newsroom/press-releases/outscale-first-cloud-qualified-secnumcloud-32).
SOV-2.4Export control restrictions5. Part of offer shielded from restrictions towards EU MSs/intl orgs167/167SEAL-4mediumEU SecNumCloud sovereign offer shielded from non-EU export-control restrictions toward EU member states and international organisations; foreign chips treated as residual hardware only (consistent with the cluster's SecNumCloud peers) -> opt5 (4) (src: https://en.outscale.com/our-certifications/).
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4mediumCore IP (TINA OS orchestrator and platform software) developed/mastered in France; some embedded firmware/chip IP originates outside EU -> opt4 mostly within EU.
SOV-2.6IP holder jurisdiction4. EU law with exceptions125/167SEAL-4mediumPlatform IP held by the French entity/Dassault Systemes under EU law, with some third-party embedded components under non-EU law -> opt4 EU law with exceptions (4).

SOV-3 · Data & AI Sovereignty 80.0% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys4. Customer primary control but provider can read data150/200SEAL-3lowCustomer-managed encryption/key management offered, but default IaaS means provider retains technical read ability absent dedicated HSM/HYOK -> opt4 customer primary control, provider can read (3).
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3lowCustomer-accessible access logs and usage console; full real-time independent auditability not clearly evidenced -> opt4 full customer-controlled, not real-time (3).
SOV-3.3Secure deletion & proof of erasure4. Deletion technically verified with access logs150/200SEAL-3mediumSecNumCloud 3.2 mandates secure-deletion procedures with logged/traceable erasure operations -> opt4 deletion technically verified with access logs (3); full independent cryptographic proof not published, so not opt5.
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4mediumeu_exclusive: the scoped SecNumCloud sovereign offer stores and processes exclusively in EU/France with no third-country fallback (the non-EU regions are a separate product) -> opt5 exclusively EU (4) (src: https://en.outscale.com/our-certifications/).
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3mediumEU-led sovereign AI (LLMaaS, OKS) running in the SecNumCloud environment, but compute relies on NVIDIA GPUs (foreign accelerators) -> opt4 EU-led AI, foreign accelerators (3).

SOV-4 · Operational Sovereignty 79.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumAWS EC2/OpenStack-compatible APIs, documented data export and formal migration/reversibility services for a sovereign IaaS -> opt4 (4).
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4higheu_ops: entire stack operated and maintained by Outscale's France/EU teams with its own orchestrator; no non-EU ops dependency -> opt5 (4).
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumEngineering and operations skills concentrated in France/EU; all-EU staff for the sovereign offer, clearances not universally evidenced -> opt4 (3).
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3high24/7 support delivered from France and Europe for the sovereign offer; all support staff in EU -> opt4 (3).
SOV-4.5Documentation & knowledge transfer4. EU-only primary repositories125/167SEAL-4mediumDocumentation and knowledge are EU-primary for the French sovereign provider; EU-only primary repositories -> opt4 (4).
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3lowSelf-developed orchestrator and EU ops allow sourcing alternatives or internalising functions if a non-EU hardware supplier withdraws -> opt4 ability to source alternatives (3).

SOV-5 · Supply Chain Sovereignty 67.9% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)3. Transparent with exceptions72/143SEAL-3lowHardware components sourced from non-EU vendors but provenance is transparent to certified/audit processes with exceptions under SecNumCloud -> opt3 transparent with exceptions (3).
SOV-5.2Manufacturing location3. Mixed sourcing, EU audit rights72/143SEAL-3lowServers built on foreign-designed silicon, integrated/operated by Outscale; mixed sourcing with EU audit rights under SecNumCloud -> opt3 (3).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/microcode in CPUs/GPUs/NICs originates from non-EU vendors (Intel/AMD/NVIDIA) with only partial disclosure -> opt2 (seal 4 by rubric, no cap).
SOV-5.4Origin of software5. Exclusively designed/maintained by EU teams143/143SEAL-4highNo foreign_core: TINA OS cloud operating system/orchestrator is exclusively developed and maintained by Outscale's EU teams (from open-source components) -> opt5 exclusively EU-maintained (4).
SOV-5.5Software build/release jurisdiction5. EU control + EU policy gates143/143SEAL-4mediumSoftware built and released under EU control by the French team in a SecNumCloud-qualified environment with EU policy gates -> opt5 (4).
SOV-5.6Single point of dependency4. Few non-EU in non-critical services, documented107/143SEAL-3mediumCritical platform software is EU-controlled (own orchestrator); remaining non-EU vendors are chip/hardware suppliers in non-critical-software role, documented -> opt4 few non-EU non-critical, documented (3).
SOV-5.7Supply chain transparency4. Most suppliers auditable107/143SEAL-3lowSecNumCloud 3.2 imposes supplier auditability; most suppliers auditable through the qualification, full hardware-vendor transparency not fully published -> opt4 most suppliers auditable (3).

SOV-6 · Technology Sovereignty 55.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumStandards-based AWS-EC2 and OpenStack-compatible APIs with broad tooling compatibility and documented portability -> opt4 (3).
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumOpen standards (EC2-compatible API, OpenStack interoperability, Kubernetes) adopted across most core services as policy -> opt4 (3).
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3lowTINA OS built from open-source elements with EU contributions, but the orchestrator is centrally governed -> opt3 open source, centralised governance (3); no foreign_core cap.
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3mediumPublic documentation, open bug-bounty (YesWeHack) and architecture insight; not fully customer-extensible -> opt3 some public insight (3).
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3mediumHPC/AI on EU-hosted infrastructure but compute stack relies on foreign accelerators (NVIDIA GPUs) and foreign CPUs -> opt2 EU-hosted, foreign stack (3).

SOV-7 · Security & Compliance Sovereignty 78.5% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumCert->EAL mapping: SecNumCloud 3.2 ~ EAL3-equivalent -> opt4 EAL3 (3) (src: https://en.outscale.com/our-certifications/).
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)5. Fully compliant to all, independently audited143/143SEAL-4highSecNumCloud 3.2, ISO 27001/27017/27018, HDS, SOC 2 Type 2 (Deloitte), CISPE, TISAX, GDPR/NIS2 alignment -> opt5 fully compliant, independently audited (4).
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3mediumSecurity operations and incident handling run end-to-end by France/EU teams under SecNumCloud requirements -> opt4 entire lifecycle by EU teams (3).
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3mediumCustomers get direct access to monitoring/logs stored in the EU under SecNumCloud; immutable tamper-proof logging not explicitly evidenced -> opt4 full direct access, EU-stored (3).
SOV-7.5Disclosure of incidents4. Partial compliance, monitored flow, SLAs107/143SEAL-3mediumGDPR/NIS2-aligned incident disclosure with monitored flow and SLAs under SecNumCloud; full real-time CSIRT sharing not specifically documented -> opt4 (3).
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4mediumMaintenance performed by Outscale's own teams on its own orchestrator with notice and testing; high autonomy for an IaaS -> opt3 moderate autonomy (4).
SOV-7.7Auditability5. Full independent audit by any entity143/143SEAL-4mediumaudit_rights: SecNumCloud 3.2 sovereign offer implies full audit rights for the contracting authority and independent EU bodies -> opt5 full independent audit (4).

SOV-8 · Environmental Sustainability 68.8% · SEAL-3 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowFrench sovereign data centers run at high efficiency with an environmental roadmap (ISO 50001); a published PUE below 1.3 is not confirmed, so PUE<1.5 + roadmap is the conservative match -> opt3 (4).
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowDocumented sustainable-development and circular hardware-lifecycle practices aligned with Dassault Systemes group; no EU-certified lifecycle claim -> opt3 documented program (3).
SOV-8.3Environmental impact reporting4. Detailed EU methodology188/250SEAL-3mediumSovereign Carbon Footprint service (Cockpit + API) measures per-customer cloud emissions with a defined methodology, backed by Dassault Systemes CSRD-grade group reporting -> opt4 detailed EU methodology (3); not opt5 (no independent EU audit of the cloud-specific figures published).
SOV-8.4Energy supplies5. Only green EU energy supplies250/250SEAL-4mediumFrench data centers supplied with 100% renewable energy -> opt5 only green EU energy supplies (4) (src: https://en.outscale.com/our-certifications/).