🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Aruba Cloud

Italy · IaaS/PaaS · https://www.arubacloud.com

Sovereignty score76.3%
Global (unweighted)75.4%
Overall SEAL
SEAL-3 Digital Resilience
SOV-1 Strategic Sovereignty88.5SEAL-3
SOV-2 Legal & Jurisdictional Sovereignty95.8SEAL-4
SOV-3 Data & AI Sovereignty80.0SEAL-3
SOV-4 Operational Sovereignty79.0SEAL-3
SOV-5 Supply Chain Sovereignty57.2SEAL-3
SOV-6 Technology Sovereignty55.0SEAL-3
SOV-7 Security & Compliance Sovereignty78.5SEAL-3
SOV-8 Environmental Sustainability68.8SEAL-3

SOV-1 · Strategic Sovereignty 88.5% · SEAL-3 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity (Aruba S.p.A. is a privately held independent Italian company, HQ Ponte San Pietro (BG), no non-EU parent) -> entity entirely within EU, opt4. (src: https://www.arubacloud.com/data-sovereignty-aruba-cloud/)
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4mediumFounder/family-controlled private Italian company with no external non-EU investors and a sovereign-cloud mission; takeover by a non-EU sovereign entity very unlikely -> opt5.
SOV-1.3Control over roadmap3. Governance bodies exist with EU actors participation83/125SEAL-3mediumGaia-X day-1 member and SECA sovereign-API co-founder, so EU governance bodies with EU-actor participation influence roadmap/interoperability; final product roadmap company-controlled -> opt3.
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4mediumPrivately funded from own operations and EU capital; no evidence of non-EU funding -> entirely EU-based funding, opt5.
SOV-1.5EU economic contribution5. Fully in the EU125/125SEAL-4highOperations, data centres, hydroelectric plants, staff and revenue concentrated in Italy/EU; economic contribution essentially fully in the EU -> opt5.
SOV-1.6Participation in EU strategic programs4. Strong participation94/125SEAL-4highGaia-X day-1 member and one of only two European Gaia-X Digital Clearing House nodes, co-founder of the SECA Sovereign European Cloud API -> strong participation in EU strategic programs, opt4.
SOV-1.7Alignment with EU industrial strategies3. Measured achievement and dedicated governance83/125SEAL-4mediumClear sovereign-cloud positioning with measured achievements (ACN QC3/AI3, CISPE, Gaia-X) and dedicated governance -> measured achievement and dedicated governance, opt3.
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4mediumown_stack: vertically integrated EU operator owning its data centres and power generation, EU-maintained OpenStack core with documented portability; foreign chips/licensed components are residual only -> full autonomy & continuity, opt5.

SOV-2 · Legal & Jurisdictional Sovereignty 95.8% · SEAL-4 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highSubject exclusively to European law, all data and administrative management in Italy/EU -> contract under EU law only, opt3. (src: https://www.arubacloud.com/data-sovereignty-aruba-cloud/)
SOV-2.2Extraterritorial laws exposure5. Verified legal immunity, non-EU laws unenforceable167/167SEAL-4highimmunity (pure-IT entity, no non-EU parent/nexus + ACN QC3 highest-grade sovereign qualification for strategic national-security PA data, SecNumCloud-equivalent); non-EU laws unenforceable -> verified legal immunity, opt5. (src: https://www.acn.gov.it/portale/en/w/in-56)
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4highNo foreign_parent and no non-EU corporate footprint, infrastructure outside CLOUD Act/FISA reach; access requests have no legal pathway and would be rejected -> requests always rejected, opt5. (src: https://www.acn.gov.it/portale/en/w/in-56)
SOV-2.4Export control restrictions5. Part of offer shielded from restrictions towards EU MSs/intl orgs167/167SEAL-4mediumEU-only operator, essentially all revenue in the EU, offer designed for EU public administration; no non-EU export-control restrictions toward EU MSs or international orgs -> opt5.
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4mediumPlatform IP (OpenStack-based stack, DC and management software) developed in-house in Italy; underlying components mixed but controlling IP mostly EU -> mostly within EU, opt4.
SOV-2.6IP holder jurisdiction5. Fully under EU law167/167SEAL-4mediumProprietary IP held by the Italian company fully under EU jurisdiction -> fully under EU law, opt5.

SOV-3 · Data & AI Sovereignty 80.0% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys4. Customer primary control but provider can read data150/200SEAL-3mediumQC3 offer documents customer-managed encryption keys (BYOK); customer has primary control though provider can read data -> opt4.
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3mediumQC3 offer provides comprehensive customer-accessible activity/access logs in EU DCs (full customer-controlled visibility), though not documented as real-time independently auditable -> full customer-controlled visibility, opt4.
SOV-3.3Secure deletion & proof of erasure4. Deletion technically verified with access logs150/200SEAL-3mediumUnder ACN QC3 (strategic PA data) + ISO 27001-family controls and comprehensive logging/CERT, deletion is technically verified with access logs -> deletion technically verified with logs, opt4.
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4higheu_exclusive: all data stored/processed in Italy and other EU countries (own DCs IT + CZ, EU partner infra), no third-country fallback -> exclusively EU, opt5. (src: https://www.arubacloud.com/data-sovereignty-aruba-cloud/)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3mediumPrivate AI / GPU offering runs in EU DCs with EU-controlled pipelines and no data leaving the perimeter but relies on foreign (NVIDIA) accelerators -> EU-led AI on foreign accelerators, opt4.

SOV-4 · Operational Sovereignty 79.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4highBuilt on OpenStack/VMware standards to reduce lock-in, with documented export and formal migration services -> formal migration services available, opt4.
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4mediumeu_ops: entire stack operated by Aruba's own Italian/EU teams from EU data centres; no critical operations by non-EU teams -> entire stack managed by fully EU-based team, opt5.
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumEngineering/operations staff Italy/EU based, no non-EU staffing; broad security clearances not claimed -> all EU staff, opt4.
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3mediumSupport provided by Italian/EU-based specialists, all support staff EU-based; no documented security-cleared tier -> all support staff in EU, opt4.
SOV-4.5Documentation & knowledge transfer4. EU-only primary repositories125/167SEAL-4mediumDocumentation/knowledge management within Italy/EU; primary repositories EU-based with no non-EU exposure -> EU-only primary repositories, opt4.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3mediumMost suppliers EU-based and Aruba owns core facilities/power; for hardware it could source alternatives or internalise -> ability to source alternatives, opt4.

SOV-5 · Supply Chain Sovereignty 57.2% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)3. Transparent with exceptions72/143SEAL-3lowServer hardware foreign-sourced (x86/NVIDIA) but as ISO-certified operator Aruba provides component transparency to customers/auditors with exceptions; provenance not EU-certified -> transparent with exceptions, opt3.
SOV-5.2Manufacturing location3. Mixed sourcing, EU audit rights72/143SEAL-3mediumHardware is foreign-designed/mixed-sourced but deployed, integrated and operated in Aruba's own EU data centres under ISO-audited supply-chain controls (EU audit rights), matching the uniform key for EU sovereign providers -> mixed sourcing, EU audit rights, opt3.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/embedded code in foreign-built hardware (BIOS, NIC, GPU) largely vendor black-box; only partial disclosure -> partial disclosure, opt2.
SOV-5.4Origin of software3. Core/essential parts maintained by EU teams72/143SEAL-3mediumCore cloud orchestration is OpenStack-based and maintained/customised by Aruba's EU teams plus own Cloud Panel/API; VMware is a licensed commercial component, not the whole platform (not foreign_core) -> core/essential parts maintained by EU teams, opt3.
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3mediumSoftware build and release for Aruba's own platform controlled and executed by its Italian/EU engineering org -> EU control & execution, opt4.
SOV-5.6Single point of dependency4. Few non-EU in non-critical services, documented107/143SEAL-3mediumForeign chips/GPUs and VMware licensing are documented, substitutable non-critical-at-platform-level inputs (own_stack: Aruba owns DCs/power and the EU-maintained core), matching the uniform key for EU sovereign providers -> few non-EU non-critical, documented, opt4.
SOV-5.7Supply chain transparency4. Most suppliers auditable107/143SEAL-3mediumRunning its own EU DCs with ISO 27001 / CISPE supplier audits, most suppliers are auditable beyond just the critical few -> most suppliers auditable, opt4.

SOV-6 · Technology Sovereignty 55.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3highStandards-based on OpenStack/VMware with open APIs and SECA standardisation; broadly compatible and portable but not fully open-by-default across all services -> standards-based and broadly compatible, opt4.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumOpenStack and broad standards adoption plus active SECA open-API standardisation -> policy for most core services, opt4.
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3mediumCore platform built on open-source OpenStack but governance of Aruba's deployment is centralised within the company (not foreign_core) -> open source, centralised governance, opt3.
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3mediumPublishes documentation and architecture insight and contributes to open initiatives (Gaia-X, SECA) -> some public insight, opt3.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowGPU/HPC capability EU-hosted but built on a foreign (NVIDIA) accelerator stack; no EU-designed HPC silicon -> EU-hosted, foreign stack, opt2 (seal 3).

SOV-7 · Security & Compliance Sovereignty 78.5% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumACN QC3/AI3 (highest Italian sovereign qualification for strategic PA data) mapped to SecNumCloud-grade ~ EAL3-equivalent per key -> opt4 (EAL3). (src: https://www.acn.gov.it/portale/en/w/in-56)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)5. Fully compliant to all, independently audited143/143SEAL-4highIndependently audited ISO 27001/27017/27018/27035, CISPE Code of Conduct, ACN QC3/AI3, and DORA/NIS2/GDPR compliance -> fully compliant, independently audited, opt5.
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3mediumSecurity operations and incident handling run by Aruba's EU-based CERT/teams supporting NIS2/DORA; full lifecycle in EU, formal ENISA sharing not explicitly claimed -> entire lifecycle by EU teams, opt4.
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3mediumCustomers get direct access to monitoring/logs stored in EU DCs under ISO 27001 controls; immutable tamper-proof guarantees not documented -> full direct access, logs stored in EU, opt4.
SOV-7.5Disclosure of incidents4. Partial compliance, monitored flow, SLAs107/143SEAL-3mediumIncident disclosure GDPR/NIS2-aligned with SLAs and monitored notification flow; real-time CSIRT integration not explicitly evidenced -> partial compliance, monitored flow, SLAs, opt4.
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4mediumAs operator of its own stack, Aruba schedules maintenance with customer notice and testing windows, retaining moderate autonomy except vendor zero-day patches -> moderate autonomy, opt3.
SOV-7.7Auditability5. Full independent audit by any entity143/143SEAL-4mediumaudit_rights: ACN QC3 sovereign offer for strategic PA data implies tender-grade full audit rights for the contracting authority and independent EU bodies -> full independent audit, opt5.

SOV-8 · Environmental Sustainability 68.8% · SEAL-3 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4mediumGreen-by-design DCs with geothermal/free cooling targeting low PUE with improvement roadmap; no verified sub-1.3 figure published -> PUE<1.5 + roadmap, opt3. (src: https://www.datacenter.it/en/aruba-ecosustainability/energy-production)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowFollows the Climate Neutral Data Centre Pact with documented sustainability/lifecycle practices -> documented program, opt3.
SOV-8.3Environmental impact reporting4. Detailed EU methodology188/250SEAL-3mediumPublishes detailed sustainability reporting under EU methodology (energy, efficiency, renewable self-production) and adheres to the Climate Neutral Data Centre Pact -> detailed EU methodology, opt4.
SOV-8.4Energy supplies5. Only green EU energy supplies250/250SEAL-4highCampus uses only renewable energy, self-produced from owned hydroelectric plants plus solar, supplemented by grid with Guarantee of Origin -> only green EU energy, opt5. (src: https://www.datacenter.it/en/aruba-ecosustainability/energy-production)