🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Alwaysdata

France · PaaS · https://www.alwaysdata.com

Sovereignty score62.3%
Global (unweighted)61.1%
Overall SEAL
SEAL-0 No Sovereignty
SOV-1 Strategic Sovereignty74.0SEAL-2
SOV-2 Legal & Jurisdictional Sovereignty87.4SEAL-2
SOV-3 Data & AI Sovereignty55.0SEAL-1
SOV-4 Operational Sovereignty70.9SEAL-3
SOV-5 Supply Chain Sovereignty50.1SEAL-1
SOV-6 Technology Sovereignty65.0SEAL-3
SOV-7 Security & Compliance Sovereignty36.0SEAL-1
SOV-8 Environmental Sustainability50.1SEAL-0

SOV-1 · Strategic Sovereignty 74.0% · SEAL-2 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4highALWAYSDATA SARL is incorporated in Paris (91 rue du Faubourg Saint-Honore, 75008), a wholly French private company founded in 2006 with no non-EU parent (src: https://www.alwaysdata.com/en/).
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4mediumSmall founder-run French SARL with no external/non-EU investors disclosed; takeover by a non-EU sovereign entity appears very unlikely, though a small private firm could in principle be acquired.
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2lowAs a small provider, roadmap is set internally; customers can influence via support/community channels but there is no formal EU governance body.
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4mediumSelf-funded/bootstrapped French SARL (capital EUR 200k) with no disclosed non-EU capital; funding is effectively entirely EU-based.
SOV-1.5EU economic contribution5. Fully in the EU125/125SEAL-4mediumAll staff, infrastructure and revenue base are in France; economic contribution is fully within the EU.
SOV-1.6Participation in EU strategic programs2. Limited participation31/125SEAL-4lowMarkets itself as 'the European Cloud' and hosts public-sector/academic clients (Academic Cloud), but no evidence of formal participation in Gaia-X or IPCEI-CIS; limited participation at most.
SOV-1.7Alignment with EU industrial strategies2. Existing action plan42/125SEAL-4lowPositions explicitly as a sovereign European host with an OSS and decarbonised-energy posture (an action plan), but no measured achievement or dedicated sovereignty governance is published.
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4lowown_stack (owns its servers/storage/network AS60362, all-OSS stack, in-house tooling on EU colocation, documented ability to internalise/source alternatives) -> SOV-1.8 opt5 'Full autonomy and continuity'; only residual non-EU dependency is commodity chips/hardware.

SOV-2 · Legal & Jurisdictional Sovereignty 87.4% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highA French SARL operating solely in France; the service is governed exclusively by EU/French law with no non-EU jurisdictional nexus (src: https://www.alwaysdata.com/en/).
SOV-2.2Extraterritorial laws exposure4. Legal structures shielding from foreign law125/167SEAL-2mediumeu_entity with structural separation but immunity NOT certified (no SecNumCloud 3.2 / EUCS-High) -> SOV-2.2 opt4 'Legal structures shielding from foreign law' (seal 2); this is the SEAL-2 ceiling on the legal axis.
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumNo foreign_parent (pure-FR, no US/CN nexus) and no compelled-access pathway; foreign demands go via EU MLAT and would be rejected -> SOV-2.3 opt5 (seal 4).
SOV-2.4Export control restrictions4. Part of offer shielded from restrictions towards EU MSs125/167SEAL-3lowPure-FR provider serving EU with no foreign-controlled tech subject to export restrictions; the offer is shielded from restrictions toward EU Member States -> SOV-2.4 opt4 (seal 3).
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4mediumCore platform IP (admin interface in Django, orchestration, tooling) is developed in-house in France; underlying components are third-party open source, so IP origin is mostly within the EU.
SOV-2.6IP holder jurisdiction5. Fully under EU law167/167SEAL-4mediumAlwaysdata's own IP is held by the French SARL under French/EU law; the OSS it uses is permissively licensed and not subject to a controlling non-EU IP holder.

SOV-3 · Data & AI Sovereignty 55.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys2. Primarily provider, not exclusively50/200SEAL-1lowManaged PaaS where the provider operates the platform and can technically access stored data; no customer-held-key/hold-your-own-key offering is advertised, so control is primarily provider-side.
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowProvides access/activity logs through the admin panel but these are vendor-controlled and not positioned as real-time independently-auditable oversight.
SOV-3.3Secure deletion & proof of erasure2. Manual confirmation only50/200SEAL-1lowData is deleted on account closure per policy but there is no published cryptographic proof-of-erasure or independent verification; manual confirmation at best.
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4higheu_exclusive: production (Equinix) and backups (Digital Realty/Interxion) all in the Paris region, exclusively France, no third-country fallback -> SOV-3.4 opt5 (seal 4) (src: https://blog.alwaysdata.com/2021/03/18/handling-the-disaster-as-a-cloud-provider/).
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3lowNo in-scope AI service offered -> no foreign-AI dependency; per key judgment call (absence of AI), SOV-3.5 opt4 (seal 3). Customers may self-host OSS models but that is not a provider AI service.

SOV-4 · Operational Sovereignty 70.9% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumOpen-source-based PaaS with standard languages, MariaDB/PostgreSQL and standard export tooling (SSH/SFTP/dumps), giving documented standard data-export and portability with no proprietary lock-in.
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4mediumEntire stack is operated by the small French team; there are no non-EU operations teams involved in running the service.
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumStaff are based in France (100% remote within the country); all engineering/support skills sit in the EU, though there is no stated security-clearance regime.
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3mediumSupport is provided directly by the French team ('100% human' service with a DPO) entirely within the EU.
SOV-4.5Documentation & knowledge transfer3. EU primary with non-EU fallback84/167SEAL-4lowDocumentation and knowledge base are maintained in France/EU (French and English); EU is the primary repository with no evidence of non-EU dependency.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3lowKey suppliers are colocation (Equinix/Interxion) and commodity hardware; because it owns its equipment and runs OSS, it could source alternative facilities/suppliers and internalise functions if needed.

SOV-5 · Supply Chain Sovereignty 50.1% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowPublishes architecture details (paired switches/routers from two manufacturers, RAID1 SSDs) but does not provide a full component bill of materials, so disclosure of physical-component origin is only partial.
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1mediumServers and network gear are standard commodity hardware manufactured abroad (foreign chips/boards); manufacturing is of foreign origin with only partial disclosure.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/microcode on the commodity servers, switches and storage is foreign and proprietary with no full provenance disclosure; partial at best.
SOV-5.4Origin of software5. Exclusively designed/maintained by EU teams143/143SEAL-4mediumNOT foreign_core: platform is exclusively OSS + in-house Django tooling maintained by the EU team, no licensed Google/MS/AWS core -> SOV-5.4 opt5 (seal 4), no SEAL-2 software ceiling.
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3lowSoftware is developed and released by the French team on EU-controlled infrastructure (their own GitHub-published projects and admin platform); EU control and execution, without an evidenced formal EU policy-gate regime.
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2mediumDepends on a few non-EU-headquartered but EU-located critical facilities (Equinix, Digital Realty/Interxion datacentres) and foreign hardware vendors; these are documented critical dependencies.
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowPrimary suppliers (Equinix, Interxion) are large certified colocation operators subject to audit, but the full hardware supply chain is not represented as fully auditable; critical suppliers auditable.

SOV-6 · Technology Sovereignty 65.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumBuilt on standard open protocols (SSH, SFTP, HTTP, standard SQL, WebDAV) with broad language/runtime compatibility, making it standards-based and broadly interoperable.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumCore services run on open standards and open-source engines across the stack, reflecting a de facto policy of open standards for most core services.
SOV-6.3Open source availability5. Fully open-source, independent/EU governance200/200SEAL-4highThe infrastructure relies exclusively on open source (OS, HTTP, databases, mail, AV), the admin UI uses Django, and the company publishes its own code under open-source licences on GitHub.
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3mediumPublishes a public architecture/help corpus and blog describing the platform's design; some meaningful public insight, though not customer-extensible source.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowNo in-scope HPC offering -> no imported black-box HPC dependency; per key 'no in-scope HPC' maps to SOV-6.5 opt2 (seal 3).

SOV-7 · Security & Compliance Sovereignty 36.0% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)1. EAL0 / none0/143SEAL-1mediumNo certifications held (no SecNumCloud / EUCS / C5 / ENS / ISO 27001 / EAL) -> EAL0/none -> SOV-7.1 opt1 (seal 1). A genuine SEAL-1 floor: no cert to map to EAL3-equivalent. Unlike the SecNumCloud-IaaS members of the cluster, Alwaysdata has no SecNumCloud basis, so per directive it is not inflated.
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)3. Moderate compliance72/143SEAL-4lowGDPR-aware with a named DPO and EU-only hosting, but no independently audited NIS2/DORA compliance or published certifications, indicating moderate compliance.
SOV-7.3EU-based SOC & incident handling2. Hybrid EU/non-EU36/143SEAL-1lowNo dedicated 24/7 SOC is advertised; security/incident handling is done by the small French team, best characterised as a hybrid/limited EU capability rather than a full EU SOC lifecycle.
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1lowCustomers get a monitoring/admin portal with logs and metrics, but not full immutable tamper-proof EU-stored security logging guarantees; basic monitoring portal.
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2lowAs an EU provider it is bound by GDPR/NIS2 breach-notification duties; disclosure is moderate and regulation-aligned without an evidenced real-time CSIRT-sharing SLA.
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowOperates its own infrastructure and OSS stack, giving moderate maintenance autonomy (it schedules and tests its own updates, subject to upstream vendor firmware/zero-day constraints).
SOV-7.7Auditability2. Limited independent access36/143SEAL-1lowNo audit_rights: no certification bodies, no contractual full-audit regime advertised; per key, audits only via (absent) certification bodies -> SOV-7.7 opt2 (seal 1). SEAL-1 floor.

SOV-8 · Environmental Sustainability 50.1% · SEAL-0 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowHosts in Equinix/Interxion Tier-grade Paris datacentres that typically run modern PUE around 1.3-1.5 with efficiency roadmaps, but Alwaysdata publishes no specific PUE figure (src: https://www.alwaysdata.com/en/green-it/).
SOV-8.2Hardware reuse & recycling2. Basic circular practices63/250SEAL-0lowDemand-based 'minimum stock' ordering and long-lived hardware are basic circular practices, but no documented hardware reuse/recycling program is published (confirmed on the environment page) -> SOV-8.2 opt2 'Basic circular practices' (seal 0). This is the overall SEAL-0 gate (src: https://www.alwaysdata.com/en/green-it/).
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2mediumCalculates annual emissions to fund offset projects (offsetting 200% of GHG emissions) and publishes green documentation, amounting to an annual environmental report (src: https://www.alwaysdata.com/en/green-it/).
SOV-8.4Energy supplies4. Only EU energy supplies (high renewable)188/250SEAL-4mediumAll infrastructure is in France, explicitly chosen for 'the most decarbonised energy in Europe', so energy is EU-sourced with a high renewable/low-carbon (nuclear+renewables) mix (src: https://www.alwaysdata.com/en/green-it/).