🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Centron

Germany · IaaS · https://www.centron.de

Sovereignty score67.9%
Global (unweighted)68.3%
Overall SEAL
SEAL-1 Jurisdictional Sovereignty
SOV-1 Strategic Sovereignty70.9SEAL-2
SOV-2 Legal & Jurisdictional Sovereignty87.4SEAL-2
SOV-3 Data & AI Sovereignty65.0SEAL-1
SOV-4 Operational Sovereignty79.0SEAL-3
SOV-5 Supply Chain Sovereignty50.1SEAL-1
SOV-6 Technology Sovereignty55.0SEAL-3
SOV-7 Security & Compliance Sovereignty64.2SEAL-1
SOV-8 Environmental Sustainability75.0SEAL-2

SOV-1 · Strategic Sovereignty 70.9% · SEAL-2 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4highcentron GmbH is incorporated in Hallstadt (Amtsgericht Bamberg HRB 3986), Germany, an EU member state, with all legal control entirely within the EU. (src: https://www.centron.de/en/iso-27001-certification/)
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4mediumPrivately held, founder-owned German GmbH run since 1999 by its founders/owners Monika and Wilhelm Seucan (succession within the family, with Dominik Seucan as CEO from 2025); no external/VC capital or public listing make a non-EU takeover very unlikely.
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2lowRoadmap is set internally by the owner-managers with customer feedback via support and account channels; no structural EU-actor co-governance body is documented.
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4mediumSelf-funded, profitable founder-owned German company with no external or non-EU investors; financing is entirely EU-based.
SOV-1.5EU economic contribution4. Majority in the EU94/125SEAL-4mediumWorkforce, HQ, R&D and owned data centres (Hallstadt, Nuremberg, Coburg, Frankfurt) are in Germany; only a single Zurich facility lies outside the EU, so the large majority of economic activity is in the EU.
SOV-1.6Participation in EU strategic programs2. Limited participation31/125SEAL-4lowMember of eco / EuroCloud and positioned as a German sovereign-cloud provider, but no documented active role in Gaia-X working groups or IPCEI-CIS; participation is limited at best.
SOV-1.7Alignment with EU industrial strategies2. Existing action plan42/125SEAL-4lowMarkets a 'made in Germany / GDPR-compliant European cloud' sovereignty proposition aligned with EU industrial goals, amounting to an action plan rather than measured, governed achievement.
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4mediumown_stack (vertically integrated EU provider: owned German data centres, EU staff, self-operated OpenStack/Ceph/K8s; foreign chips are residual hardware only, with continuity/exit possible) -> SOV-1.8 opt5 'Full autonomy and continuity'.

SOV-2 · Legal & Jurisdictional Sovereignty 87.4% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highAs a German GmbH with an EU-only corporate structure and primary data centres in Germany, the service is governed exclusively under EU/German law. (src: https://www.centron.de/en/iso-27001-certification/)
SOV-2.2Extraterritorial laws exposure4. Legal structures shielding from foreign law125/167SEAL-2mediumeu_entity with structural separation but NO certified immunity (no SecNumCloud 3.2 / EUCS-High held) -> SOV-2.2 opt4 'Legal structures shielding from foreign law' (seal-2 ceiling). The purely German structure shields from the US CLOUD Act but immunity is not certified. (src: https://www.centron.de/en/iso-27001-certification/)
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4highNo foreign_parent (purely German/EU ownership, no US/CN nexus able to compel access) -> not subject to CLOUD Act/FISA/PRC law; requests have no legal basis and are rejected -> SOV-2.3 opt5 (seal 4). (src: https://www.centron.de/en/iso-27001-certification/)
SOV-2.4Export control restrictions4. Part of offer shielded from restrictions towards EU MSs125/167SEAL-3mediumEU sovereign offer with no export-control restrictions toward EU member states; part of the offer is shielded from restrictions toward EU MSs -> SOV-2.4 opt4 (seal 3).
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4mediumOperational and platform IP (OpenStack integration, management software, data-centre design) is developed in the EU; physical hardware/chip IP (Intel, AMD, NVIDIA) is foreign, so IP is mostly but not fully EU-origin.
SOV-2.6IP holder jurisdiction5. Fully under EU law167/167SEAL-4highThe IP-holding entity is the German centron GmbH, fully under EU law.

SOV-3 · Data & AI Sovereignty 65.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys4. Customer primary control but provider can read data150/200SEAL-3lowThe OpenStack/Ceph platform supports S3 server-side encryption with customer-provided keys via Barbican; absent default confidential-compute/HSM, the provider operating the infrastructure could technically read unencrypted data.
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowAccess and usage logs exist within the managed platform and audit evidence is provided under ISO 27001/BSI scope, but oversight is vendor-controlled and not real-time independently auditable.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowDeletion follows documented ISO 27001/BSI IT-Grundschutz policy and is validated internally, but without per-request independently verified cryptographic proof of erasure to the customer.
SOV-3.4Data location strictly in EU/EEA4. EU by default, tightly controlled exceptions150/200SEAL-1mediumNOT eu_exclusive: data is EU by default but a Swiss (third-country) data centre exists as a controlled exception, with no contractual no-third-country-fallback guarantee -> SOV-3.4 opt4 'EU by default, tightly controlled exceptions' (seal-1 ceiling). (src: https://www.centron.de/en/datacenter-en/)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3mediumAI offering is GPU IaaS (NVIDIA A4000 / RTX 6000 Ada) on which customers run their own open-source/auditable models EU-hosted (EU-led/EU-hosted AI); no black-box managed AI, only the accelerators are foreign -> opt4 'EU-led AI, foreign accelerators' (consistent with the cluster's open-model-on-foreign-GPU providers).

SOV-4 · Operational Sovereignty 79.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumStandards-based export via S3-compatible object storage, Kubernetes, container images and standard Linux VMs avoids proprietary lock-in and supports formal migration off-platform.
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4mediumeu_ops (entire stack operated by centron's own German teams from German data centres, no foreign operational dependency) -> SOV-4.2 opt5 'Entire stack managed by fully EU-based team' (seal 4).
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumEngineering, operations and apprenticeship/training are concentrated in Germany; staff are EU-based with no documented security clearances.
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3medium24/7 support is delivered by centron's own staff based in Germany; no documented security clearances for support personnel.
SOV-4.5Documentation & knowledge transfer4. EU-only primary repositories125/167SEAL-4lowDocumentation and knowledge repositories are maintained in-house in Germany, primarily EU-only.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3lowCore suppliers/facilities are EU-based and the platform is self-operated; centron can source alternative hardware suppliers or internalise functions, with foreign chip vendors being the residual dependency.

SOV-5 · Supply Chain Sovereignty 50.1% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1mediumServer components rely on foreign chips/parts (Intel, AMD, NVIDIA); component origin is only partially disclosed.
SOV-5.2Manufacturing location3. Mixed sourcing, EU audit rights72/143SEAL-3lowHardware is integrated and operated in Germany on mixed/foreign-origin components with EU audit rights via the certified data centre, but built on foreign chip and board designs.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/microcode in CPUs, GPUs, NICs and BMCs comes from foreign vendors with only partial provenance disclosure.
SOV-5.4Origin of software4. Large majority maintained by EU teams107/143SEAL-3mediumNOT foreign_core (no licensed Google/MS/AWS core): platform is open-source OpenStack/Ceph/Kubernetes integrated and maintained by centron's EU teams -> SOV-5.4 opt4 'Large majority maintained by EU teams' (seal 3, not capped at 2).
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3mediumPlatform integration, build and release are under EU control and execution from Germany.
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2mediumA few non-EU dependencies are critical (chip vendors Intel/AMD/NVIDIA with no EU substitute) within an otherwise EU-controlled and documented stack.
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowCritical suppliers are auditable through the ISO 27001/BSI IT-Grundschutz data-centre scope -> SOV-5.7 opt3 'Critical suppliers auditable' (seal 2); full transparency (chip vendors) is not demonstrated.

SOV-6 · Technology Sovereignty 55.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumStandards-based, broadly compatible interfaces: OpenStack APIs, S3-compatible object storage, Kubernetes and container/VM portability.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumCore services are built on open standards (OpenStack, S3 API, Kubernetes, KVM, standard Linux images) as a deliberate policy across most core offerings.
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3mediumThe platform is based on open-source components (OpenStack, Ceph, Kubernetes) with upstream community governance, but centron's own integration/control layer is centrally governed and not itself published.
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowSome public architecture insight is provided via product documentation and the open-source base stack, though centron's specific integration remains largely internal.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3mediumGPU/HPC offering is EU-hosted in German data centres but runs an entirely foreign accelerator stack (NVIDIA).

SOV-7 · Security & Compliance Sovereignty 64.2% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)3. EAL272/143SEAL-2mediumCerts held: ISO 27001 on the basis of BSI IT-Grundschutz + Trusted Cloud (no C5, SecNumCloud or EUCS). Per the cert->EAL map this ISO 27001 + structured national-baseline (IT-Grundschutz) ISMS maps to ~EAL2 -> SOV-7.1 opt3 (seal 2). (src: https://www.centron.de/en/iso-27001-certification/)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumGDPR-compliant with DPAs, ISO/IEC 27001 and BSI IT-Grundschutz certified data centre (BSI-IGZ-0555-2023) plus Trusted Cloud (IaaS); broad compliance to most EU regimes though full independently-audited DORA/NIS2 coverage is not documented.
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3mediumSecurity operations and incident response are handled by centron's own German teams; no documented ENISA/CSIRT real-time sharing membership.
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3lowCustomers get access to their own monitoring/logs with infrastructure logs stored in EU data centres; no claim of immutable tamper-proof customer logging.
SOV-7.5Disclosure of incidents4. Partial compliance, monitored flow, SLAs107/143SEAL-3lowAs a GDPR processor and certified DC operator it follows monitored breach-disclosure flows with SLAs; not documented as full real-time CSIRT sharing.
SOV-7.6Maintenance autonomy4. High autonomy (deploy independently, no checks)107/143SEAL-4lowcentron controls its own maintenance on its self-operated OpenStack stack and can deploy patches independently without third-party vendor scheduling.
SOV-7.7Auditability2. Limited independent access36/143SEAL-1mediumNO tender-grade audit_rights: assurance is only via the provider's own ISO 27001 / BSI IT-Grundschutz certification bodies, not a full independent audit by any entity -> SOV-7.7 opt2 (seal-1 ceiling).

SOV-8 · Environmental Sustainability 75.0% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)5. PUE < 1.2, EU verified250/250SEAL-4highReported PUE of 1.08 for the Hallstadt data centre, comfortably below 1.2, achieved via direct free cooling (~95% compressor-free outside-air operation) in a German EU-located certified facility. (src: https://www.centron.de/en/datacenter-en/)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowISO 14001-certified environmental management with documented efficiency/hardware practices, amounting to a documented program rather than an EU-certified circular lifecycle.
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2lowPublishes sustainability/efficiency figures (e.g. PUE 1.08, cooling-energy reductions) at roughly annual level under ISO 14001, not an independently EU-audited methodology.
SOV-8.4Energy supplies5. Only green EU energy supplies250/250SEAL-4highThe data centre is operated entirely on 100% renewable (green) electricity sourced in Germany/EU. (src: https://www.centron.de/en/datacenter-en/)