🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Cleura

Sweden · IaaS/PaaS · https://cleura.com

Sovereignty score70.1%
Global (unweighted)69.3%
Overall SEAL
SEAL-1 Jurisdictional Sovereignty
SOV-1 Strategic Sovereignty73.0SEAL-3
SOV-2 Legal & Jurisdictional Sovereignty87.4SEAL-2
SOV-3 Data & AI Sovereignty75.0SEAL-1
SOV-4 Operational Sovereignty79.0SEAL-3
SOV-5 Supply Chain Sovereignty46.6SEAL-1
SOV-6 Technology Sovereignty70.0SEAL-3
SOV-7 Security & Compliance Sovereignty60.7SEAL-1
SOV-8 Environmental Sustainability62.5SEAL-2

SOV-1 · Strategic Sovereignty 73.0% · SEAL-3 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity: Cleura AB is incorporated and headquartered in Karlskrona, Sweden (reg. 556630-7806), operating as an Iver company; legal entity control entirely within the EU -> opt4. (src: https://cleura.com/resources/trust-center/certifications/)
SOV-1.2Change of control risk3. Somewhat likely takeover/transfer to non-EU sovereign entity63/125SEAL-4mediumforeign_parent (UK): ultimate owner is ICG plc, a UK-listed asset manager that acquired Iver from EQT in 2021; PE/fund ownership makes a future trade sale to a non-EU buyer somewhat likely -> opt3 (existing choice kept, all seal-4).
SOV-1.3Control over roadmap3. Governance bodies exist with EU actors participation83/125SEAL-3lowEU-controlled provider running OpenStack with its own R&D and EU governance; customers influence via Open Infrastructure Foundation community/governance bodies with EU-actor participation -> opt3.
SOV-1.4Financial independence from non-EU capital3. Balanced mix of EU and non-EU funding63/125SEAL-4mediumforeign_parent (UK): operating company is Swedish but its capital backer is ICG plc (UK, non-EU/EEA), so financing is a balanced mix of EU operations and non-EU capital -> opt3 (existing choice kept, all seal-4).
SOV-1.5EU economic contribution5. Fully in the EU125/125SEAL-4highAll operations, data centres (Sweden, Germany), staff and subprocessors are EU-based; economic contribution fully within the EU -> opt5 (existing choice kept, all seal-4).
SOV-1.6Participation in EU strategic programs3. Active participant in strategic projects63/125SEAL-4mediumActive in the European sovereign-cloud ecosystem and a Gold member of the Open Infrastructure Foundation (OpenStack), an active participant in strategic open-infrastructure projects -> opt3 (existing choice kept, all seal-4).
SOV-1.7Alignment with EU industrial strategies3. Measured achievement and dedicated governance83/125SEAL-4mediumGoverned strategy ('committed to a data-sovereign Europe') with measurable certifications and product lines aligned to EU digital-sovereignty goals -> opt3 (existing choice kept, all seal-4).
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4mediumown_stack: open-source OpenStack core maintained by EU teams on EU DCs lets Cleura source alternatives and internalise key functions; residual non-EU dependency is only commodity hardware/chips -> full autonomy & continuity opt5 (seal 4).

SOV-2 · Legal & Jurisdictional Sovereignty 87.4% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highContracting entity is Swedish; Compliant Cloud operates exclusively under EU/EEA member-state law, not subject to US extraterritorial surveillance -> opt3 (seal 4). (src: https://cleura.com/compliant-cloud/)
SOV-2.2Extraterritorial laws exposure4. Legal structures shielding from foreign law125/167SEAL-2mediumimmunity not certified: pure-EU operating structure marketed as shielded from US extraterritorial laws, but a UK parent (ICG) exists and NO SecNumCloud/EUCS-High is held, so legal structures shield (opt4, seal 2) rather than verified immunity.
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumNo foreign_parent under US CLOUD Act/FISA or PRC law (UK financial owner has no equivalent compelled-cloud-access statute); wholly EU-jurisdiction provider with no US/CN parent able to compel access, requests rejected -> opt5 (seal 4). (src: https://cleura.com/compliant-cloud/)
SOV-2.4Export control restrictions5. Part of offer shielded from restrictions towards EU MSs/intl orgs167/167SEAL-4lowPure-EU provider, large majority of revenue in the EU, no non-EU technology gating its offer; the EU/EEA-exclusive open-source offer is shielded from foreign export-control restrictions toward EU MSs and international orgs -> key 2.4 opt5 (seal 4), consistent with the Nordic OpenStack peers. (src: https://cleura.com/compliant-cloud/)
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4mediumCore platform IP is OpenStack-based and maintained by Cleura's EU teams; bulk of controlled software IP is EU-originated though open-source upstream is global -> opt4 (existing choice kept, all seal-4).
SOV-2.6IP holder jurisdiction4. EU law with exceptions125/167SEAL-4mediumIP and operating entity sit under EU (Swedish) law; upstream open-source licences originate partly outside the EU, so EU law applies with exceptions -> opt4.

SOV-3 · Data & AI Sovereignty 75.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys4. Customer primary control but provider can read data150/200SEAL-3mediumOpenStack Barbican KMS and S3 SSE-C give customers primary key control; without a documented HYOK/confidential-computing guarantee the provider could read data, so customer-primary not exclusive -> opt4.
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3lowOpenStack/Cleura provides customer-accessible activity/access logging with EU-stored logs (full customer-controlled visibility) but independent real-time auditability is not evidenced -> opt4.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowISO 27001-governed deletion with internal validation per policy; no public guarantee of independently verified proof-of-erasure -> opt3 (seal 1).
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4higheu_exclusive: data centres exclusively Sweden and Germany, all documented subprocessors EU/EEA, no third-country fallback -> opt5 (seal 4). (src: https://cleura.com/resources/getting-started-with-cleura-cloud/regions-services-sub-processors/)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3mediumCleura AI runs inference entirely in EU data centres on open/auditable models with data-sovereignty guarantees but relies on foreign (Nvidia) accelerators -> EU-led AI on foreign accelerators opt4.

SOV-4 · Operational Sovereignty 79.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumStandards-based OpenStack APIs plus documented data export and formal migration services on portable open infrastructure -> opt4 (seal 4).
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4higheu_ops: entire stack operated by EU-based teams (Cleura/Iver Sverige) with all subprocessors in the EU; no critical operation delivered by non-EU teams -> opt5 (seal 4).
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumeu_ops: Swedish company with EU-based engineering/operations staff and no documented routine offshore escalation (security clearances not broadly claimed) -> all-EU staff opt4 (seal 3).
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3mediumeu_ops: support delivered by EU-based teams within the Iver group, no non-EU escalation, formal clearances not claimed -> all support staff in EU opt4 (seal 3).
SOV-4.5Documentation & knowledge transfer4. EU-only primary repositories125/167SEAL-4lowDocumentation/knowledge maintained by the EU-based company on EU infrastructure; primary repositories EU-based with no documented non-EU dependency -> EU-only primary repositories opt4 (seal 4).
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3mediumown_stack: subprocessors (Iver, Interxion/Digital Realty EU entities, 23 Technologies) all EU and the open-source stack lets Cleura source alternatives or internalise if a supplier failed -> opt4 (seal 3).

SOV-5 · Supply Chain Sovereignty 46.6% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowHardware/component provenance not publicly detailed; servers and chips are foreign-sourced (global x86/Nvidia) with only partial disclosure -> opt2 (seal 1).
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1lowServer hardware and chips manufactured outside the EU (foreign OEMs/fabs) with limited disclosure of the manufacturing chain -> opt2 (seal 1).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/microcode on commodity servers and accelerators originates from foreign vendors and is not fully disclosed; partial provenance only -> opt2 (existing choice kept, all seal-4).
SOV-5.4Origin of software4. Large majority maintained by EU teams107/143SEAL-3mediumNot foreign_core: platform is open-source OpenStack (not licensed Google/MS tech); large majority of deployed/operated software is maintained by Cleura's EU teams -> opt4 (seal 3).
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3mediumSoftware build/release controlled and executed by Cleura's EU engineering organisation; no documented formal EU policy gates beyond ISO controls -> EU control & execution opt4 (seal 3).
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2mediumResidual non-EU hardware/chip vendors (and US-owned colo operators Interxion/Digital Realty) remain single points in the critical supply path, documented but unavoidable -> key few-non-EU-in-critical-services -> opt3 (seal 2), consistent with the Nordic OpenStack peers that share the same foreign-chip dependency. (src: https://cleura.com/resources/getting-started-with-cleura-cloud/regions-services-sub-processors/)
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowCritical subprocessors named and auditable under ISO 27001/DPA terms, but full upstream hardware supply-chain transparency is limited -> critical suppliers auditable opt3 (seal 2).

SOV-6 · Technology Sovereignty 70.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces5. Open-by-default with portability200/200SEAL-4highBuilt on OpenStack with open, standards-based APIs and strong portability; open-by-default at the IaaS interface layer -> opt5 (seal 4).
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumOpenStack and S3-compatible interfaces mean open standards applied as policy across most core services with documented public APIs -> opt4 (seal 3).
SOV-6.3Open source availability4. Open source, significant EU contributions, restricted governance150/200SEAL-4highNot foreign_core: core platform is open-source OpenStack; Cleura is a Gold OIF member with significant EU contributions under foundation (centralised but open) governance -> opt4 (seal 4).
SOV-6.4Service architecture transparency4. Large corpus of public insight150/200SEAL-3mediumExtensive public documentation, open-source architecture and published regions/subprocessors provide a large corpus of public insight -> opt4 (seal 3).
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowAny HPC/GPU capability (Cleura AI) is EU-hosted but runs on a foreign accelerator stack (Nvidia), not EU-designed silicon -> EU-hosted foreign stack opt2 (seal 3).

SOV-7 · Security & Compliance Sovereignty 60.7% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)2. EAL136/143SEAL-1highcerts: Cleura holds ISO 27001:2022 only (plus ISO 9001/14001); NO SecNumCloud, EUCS, C5, ENS-High or Common Criteria EAL. Per key 'ISO 27001 only -> opt2' -> EAL1-equiv opt2 (seal 1). GATES SEAL. (src: https://cleura.com/resources/trust-center/certifications/)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4highSupports GDPR, NIS2 and DORA compliance and is independently ISO 27001:2022 certified (partial-to-strong across most EU regulations, not one audited cert covering all) -> opt4 (existing choice kept, all seal-4).
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3loweu_ops: security operations and incident handling run by EU-based teams in an EU-only operation (full lifecycle EU); explicit ENISA/CSIRT sharing not documented -> opt4 (seal 3).
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3lowCustomers get direct access to logging/monitoring with logs stored in EU DCs via OpenStack; immutable tamper-proof logging not specifically claimed -> full direct access, EU-stored opt4 (seal 3).
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2mediumIncident disclosure aligned with GDPR/NIS2 obligations as an EU provider; no documented real-time CSIRT sharing with SLAs beyond regulatory baseline -> moderate opt3 (seal 2).
SOV-7.6Maintenance autonomy4. High autonomy (deploy independently, no checks)107/143SEAL-4mediumown_stack: self-operated OpenStack gives high maintenance autonomy to schedule and deploy patches independently without a foreign vendor's release cycle -> opt4 (seal 4).
SOV-7.7Auditability3. Partial independent control72/143SEAL-1lowaudit_rights not certified: independent assurance is via ISO 27001 audits plus DPA customer audit rights (partial independent control), no SecNumCloud-grade contractual full audit by the contracting authority or any independent EU body -> key 7.7 (audits via cert bodies + DPA) -> opt3 (seal 1), consistent with the non-audit-rights Nordic peers. (src: https://cleura.com/resources/trust-center/certifications/)

SOV-8 · Environmental Sustainability 62.5% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowModern EU data centres (Interxion/Digital Realty, Cleura facilities) imply PUE well under 1.5 with a sustainability roadmap; no specific PUE figure published -> PUE<1.5 + roadmap opt3 (seal 4). (src: https://cleura.com/resources/trust-center/certifications/)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowISO 14001-certified environmental management implies a documented hardware lifecycle/reuse program; no formal EU-certified circular-economy scheme evidenced -> documented program opt3 (seal 3).
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2mediumISO 14001 certification and EcoVadis sustainability recognition indicate regular environmental reporting, but not a detailed EU-methodology or EU-audited carbon report -> annual report opt3 (seal 2).
SOV-8.4Energy supplies5. Only green EU energy supplies250/250SEAL-4highCleura states its data centres run exclusively on 100% renewable (green) energy sourced within the EU -> only green EU energy supplies opt5 (existing choice kept, all seal-4). (src: https://cleura.com/resources/trust-center/certifications/)