🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Anexia

Austria · IaaS/PaaS · https://www.anexia.com

Sovereignty score64.8%
Global (unweighted)63.2%
Overall SEAL
SEAL-1 Jurisdictional Sovereignty
SOV-1 Strategic Sovereignty86.5SEAL-2
SOV-2 Legal & Jurisdictional Sovereignty83.3SEAL-2
SOV-3 Data & AI Sovereignty65.0SEAL-1
SOV-4 Operational Sovereignty70.9SEAL-3
SOV-5 Supply Chain Sovereignty46.6SEAL-1
SOV-6 Technology Sovereignty40.0SEAL-2
SOV-7 Security & Compliance Sovereignty57.2SEAL-1
SOV-8 Environmental Sustainability56.3SEAL-2

SOV-1 · Strategic Sovereignty 86.5% · SEAL-2 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity (Austrian Anexia Holding GmbH, 100% founder-owned by Alexander Windbichler, HQ Klagenfurt, no non-EU parent) -> SOV-1.1 opt4 (entirely within EU). (src: https://anexia.com/en/company/about-anexia)
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4highFounder Alexander Windbichler remains 100% owner and CEO; privately held with no external/non-EU investors, making a takeover by a non-EU sovereign entity very unlikely.
SOV-1.3Control over roadmap4. Full influence of EU actors125/125SEAL-4highEU-controlled with own in-house R&D: Anexia develops the Engine platform and KVM stack in-house and the EU owner/management hold full roadmap authority -> opt4 (full EU influence).
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4highPrivately, founder-owned Austrian company financed without external/non-EU capital; funding is entirely EU-based (self-financed PV park, EU credit standing).
SOV-1.5EU economic contribution4. Majority in the EU94/125SEAL-4mediumRoughly 400 staff and HQ/main operations in Austria mean the majority of economic value and employment is in the EU, though it serves clients globally and has a US office.
SOV-1.6Participation in EU strategic programs4. Strong participation94/125SEAL-4highCEO holds a seat on the CISPE board and Anexia is active in the CISPE Sovereign Cloud Committee and Gaia-X trust-label efforts, indicating strong participation in EU strategic programs.
SOV-1.7Alignment with EU industrial strategies3. Measured achievement and dedicated governance83/125SEAL-4mediumPublic sovereignty positioning, CISPE governance role, ISO programs and own PV park show measured achievement and dedicated governance aligned with EU industrial strategy, though without a hyperscale-level investment program.
SOV-1.8Resilience to cut-off4. Ability to source alternatives or internalise key functions94/125SEAL-2mediumown_stack-leaning: EU provider running its own KVM/Engine software in Austrian DCs; not dependent on a foreign parent and removed the VMware core, but residual non-EU hardware vendors mean ability to source alternatives/internalise rather than full autonomy -> opt4 (seal 2).

SOV-2 · Legal & Jurisdictional Sovereignty 83.3% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highAustrian/EU legal entities; the offering is governed exclusively by EU/Austrian law -> opt3 (exclusively EU law). (src: https://anexia.com/en/software-development/working-with-anexia/privacy-and-security)
SOV-2.2Extraterritorial laws exposure4. Legal structures shielding from foreign law125/167SEAL-2mediumeu_entity with structural separation but NO certified immunity (no SecNumCloud/EUCS-High) and a non-EU operational nexus (NYC office, 100+ DC locations in 70 countries) -> legal structures shielding from foreign law, opt4 (seal 2); not verified statutory immunity. (src: https://anexia.com/en/company/about-anexia)
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumNo foreign_parent: pure-EU entity; Anexia publicly asserts only the European legal system applies and the CLOUD Act has no power over its services, so it would reject non-EU compelled-access requests as lacking legal basis -> opt5 (requests always rejected). (src: https://anexia.com/blog/en/how-cloud-computing-from-europe-secures-your-digital-sovereignty/)
SOV-2.4Export control restrictions3. Share of revenues >50% in the EU84/167SEAL-2lowEU-headquartered with majority of revenue from European customers and no indication of export restrictions toward EU member states; specific shielding mechanisms toward intl orgs not documented -> opt3.
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4mediumCore IP is the self-developed Anexia Engine and KVM-based platform 'made in Austria'; management/orchestration software IP is mostly EU-origin, though underlying hardware IP is non-EU -> opt4 (mostly within EU).
SOV-2.6IP holder jurisdiction5. Fully under EU law167/167SEAL-4mediumAnexia's own software IP is held by its Austrian entities under EU law; the proprietary platform IP sits fully under EU jurisdiction -> opt5.

SOV-3 · Data & AI Sovereignty 65.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys4. Customer primary control but provider can read data150/200SEAL-3lowAs IaaS/managed-hosting, customers can manage their own encryption within VMs (customer primary control), but as operator Anexia retains administrative access and can read data; exclusive HYOK is not the documented default -> opt4.
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowInfrastructure is auditable and monitored, but real-time independently auditable customer access logs are not documented; logs are largely vendor-controlled -> opt3 (seal 2).
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowGDPR/ISO 27001 processes imply policy-based deletion with internal validation, but no published independent proof-of-erasure mechanism -> opt3 (seal 1).
SOV-3.4Data location strictly in EU/EEA4. EU by default, tightly controlled exceptions150/200SEAL-1mediumNot eu_exclusive: 'protected in Europe' with Austrian DCs and EU residency, but a global 100+ location network in 70 countries and NYC office mean EU by default with tightly controlled exceptions, not a hard EU-only no-fallback guarantee -> opt4 (seal 1). [SEAL gate] (src: https://anexia.com/en/global-cloud)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3lowNo flagship in-scope proprietary AI service, so no foreign-AI model dependency; per key, absence of in-scope AI -> opt4 (seal 3).

SOV-4 · Operational Sovereignty 70.9% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumKVM/Engine virtual data centers use standard documented export/import and documented APIs; standard documented export methods available -> opt3 (seal 4).
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4higheu_ops: entire stack operated by Anexia's own Austrian/EU teams with 24/7 support from Klagenfurt; no foreign team required -> opt5 (fully EU-managed stack).
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumWorkforce of ~400 predominantly EU-based (Austria/Germany); engineering/ops skills are EU staff; no published security-clearance requirement -> opt4 (all EU staff, seal 3).
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3medium24/7 support delivered from Klagenfurt by EU staff; all support EU-based, without documented formal security clearances -> opt4 (all EU support, seal 3).
SOV-4.5Documentation & knowledge transfer3. EU primary with non-EU fallback84/167SEAL-4lowDocumentation/knowledge maintained by EU teams in the EU; given a global footprint and US office, EU-primary with possible non-EU fallback -> opt3 (seal 4).
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3lowAnexia owns its software and runs its own KVM platform; could re-source non-critical hardware suppliers and internalise over time -> opt4 (ability to source alternatives/internalise, seal 3).

SOV-5 · Supply Chain Sovereignty 46.6% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowServer hardware from standard global OEMs; no detailed published bill of materials for physical components -> opt2 (partial disclosure).
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1mediumServers, CPUs and network gear manufactured outside the EU by global vendors; integrated by Anexia but foreign origin with at best partial disclosure -> opt2.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/BIOS on commodity servers is proprietary to foreign hardware vendors; provenance at best partially disclosed -> opt2.
SOV-5.4Origin of software4. Large majority maintained by EU teams107/143SEAL-3mediumNo foreign_core: Anexia migrated 12,000 VMs off VMware to a homebrew KVM/open-source platform (Engine + Netcup KVM) by 2024, so the large majority of core platform software is now EU-maintained; residual OS/firmware foreign -> opt4 (seal 3).
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3mediumAnexia's own platform/KVM software is controlled and built by its Austrian engineering teams -> EU control and EU execution, opt4 (seal 3).
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2mediumAfter dropping VMware, remaining non-EU critical dependency is mainly foreign hardware within an otherwise EU-controlled, documented stack -> opt3 (few non-EU in critical services, documented, seal 2).
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowISO 27001 and DPA subprocessor lists make critical suppliers auditable, but not all suppliers down the chain -> opt3 (critical suppliers auditable, seal 2).

SOV-6 · Technology Sovereignty 40.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces3. Mixed (partial openness)100/200SEAL-2mediumStandard KVM/IaaS interfaces and the Engine's documented APIs provide partial openness; interoperable with common tooling but not fully open-by-default -> opt3 (seal 2).
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2lowUse of common virtualization (KVM) and networking standards implies partial core adoption of open standards, without a published open-standards-by-policy commitment -> opt3 (seal 2).
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2mediumThe Anexia Engine core is proprietary/vendor-controlled (client libs/Terraform provider are open, core is not); source-available-strict tier -> opt2 (seal 2).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowAnexia publishes architecture/technical insight (Engine architecture blogs, KVM migration writeups, CSA STAR self-assessment, ISO scope) giving some public insight -> opt3 (seal 3).
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowNo EU-designed processor program; any HPC capacity would be EU-hosted in Austrian DCs on a foreign hardware/software stack -> opt2 (EU-hosted foreign stack / no in-scope HPC, seal 3).

SOV-7 · Security & Compliance Sovereignty 57.2% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)2. EAL136/143SEAL-1mediumCerts are ISO 27001/27701 + CSA STAR Level 1 (no C5/ENS/EAL/SecNumCloud); per key ISO-27001-only maps to ~EAL1 -> opt2 (seal 1). [SEAL gate] (src: https://anexia.com/en/company/about-anexia/certification)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumIndependently audited ISO 27001/27701 plus CSA STAR and GDPR compliance show partial-to-broad compliance with EU regulation, but no explicit NIS2/DORA attestation -> opt4.
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3lowSecurity operations and 24/7 monitoring run by EU teams from Klagenfurt with EU threat intel; formal ENISA/CSIRT sharing not documented -> opt4 (entire lifecycle EU teams, seal 3).
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3lowCustomers get monitoring/log access via the Engine portal with logs stored in EU data centers; immutable tamper-proof logging not specifically documented -> opt4 (full access, EU-stored, seal 3).
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2mediumAs an EU/Austrian provider Anexia discloses incidents under GDPR and aligns with NIS2, matching moderate GDPR/NIS2-aligned disclosure -> opt3 (seal 2).
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowAnexia controls its own KVM platform and maintenance scheduling with customer notice/testing windows -> moderate maintenance autonomy, opt3 (seal 4).
SOV-7.7Auditability3. Partial independent control72/143SEAL-1lowNo certified audit_rights: independent audits occur via TUV Nord (ISO) and CSA STAR self-assessment (partial independent control), but customers cannot have any entity perform a full independent audit -> opt3 (seal 1). [SEAL gate] (src: https://anexia.com/en/company/about-anexia/certification)

SOV-8 · Environmental Sustainability 56.3% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowModern redundant DCs with efficiency investment but no specific verified PUE published; conservative managed PUE below ~1.5 with sustainability roadmap -> opt3 (seal 4). (src: https://anexia.com/blog/en/pv-park-renewable-energy-for-sustainable-data-center-infrastructure/)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowISO 14001 environmental management implies a documented hardware lifecycle/recycling program, but no EU-certified circular-economy lifecycle published -> opt3 (documented program, seal 3). (src: https://anexia.com/en/company/about-anexia/certification)
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2lowISO 14001 certification since 2022 with annual TUV Nord audits implies regular environmental reporting; no detailed EU-methodology or fully EU-audited GHG report published -> opt3 (annual report, seal 2). (src: https://anexia.com/en/company/about-anexia/certification)
SOV-8.4Energy supplies4. Only EU energy supplies (high renewable)188/250SEAL-4mediumOperates its own Austrian PV park (1.16 ha, Jaidhof) supplying clean energy directly to its DCs and emphasises traceable renewable energy -> opt4 (only EU energy supplies, high renewable). (src: https://anexia.com/blog/en/pv-park-renewable-energy-for-sustainable-data-center-infrastructure/)