🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Clever Cloud

France · PaaS · https://www.clever-cloud.com

Sovereignty score80.4%
Global (unweighted)78.9%
Overall SEAL
SEAL-3 Digital Resilience
SOV-1 Strategic Sovereignty89.6SEAL-4
SOV-2 Legal & Jurisdictional Sovereignty95.8SEAL-4
SOV-3 Data & AI Sovereignty80.0SEAL-3
SOV-4 Operational Sovereignty79.0SEAL-3
SOV-5 Supply Chain Sovereignty60.7SEAL-3
SOV-6 Technology Sovereignty75.0SEAL-3
SOV-7 Security & Compliance Sovereignty82.0SEAL-3
SOV-8 Environmental Sustainability68.9SEAL-3

SOV-1 · Strategic Sovereignty 89.6% · SEAL-4 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity: Clever Cloud SAS is incorporated and headquartered in Nantes, France, with wholly European capital and no US subsidiary; legal entity control entirely within the EU -> opt4 (src: https://clever.cloud/solutions/compliance/).
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4mediumBootstrapped/self-funded with European-only capital and founder control; sovereign positioning makes a non-EU takeover very unlikely.
SOV-1.3Control over roadmap4. Full influence of EU actors125/125SEAL-4mediumIndependent EU-controlled SME: EU actors (French founders/owners and customers) have full influence over the roadmap, set internally with no foreign-vendor constraints -> opt4.
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4highBootstrapped/self-financed, capital wholly owned by Europeans; no non-EU venture funding.
SOV-1.5EU economic contribution5. Fully in the EU125/125SEAL-4highOperations, employment, R&D and revenue concentrated in France/EU; economic contribution essentially fully in the EU.
SOV-1.6Participation in EU strategic programs3. Active participant in strategic projects63/125SEAL-4mediumSelected provider under the EC Cloud III sovereign-cloud framework (with Post Telecom/OVHcloud) and active in the EU sovereign-cloud ecosystem; active participant but not the sole pillar of a megaproject -> opt3.
SOV-1.7Alignment with EU industrial strategies3. Measured achievement and dedicated governance83/125SEAL-4mediumClear sovereignty strategy with concrete commitments (EU-only sovereign offer, SecNumCloud pursuit, open-source program): measured achievement and dedicated governance -> opt3.
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4mediumown_stack: EU-maintained core software (Sozu, control plane, orchestration) on own infra + EU-sovereign IaaS partners (OVH, Scaleway, Outscale, Cloud Temple); no non-EU vendor whose withdrawal halts service (only residual foreign chips) -> full autonomy & continuity opt5.

SOV-2 · Legal & Jurisdictional Sovereignty 95.8% · SEAL-4 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highFrench company, EU head office, no US subsidiary; contracts and operations exclusively under EU (French) law -> opt3 (src: https://clever.cloud/solutions/compliance/).
SOV-2.2Extraterritorial laws exposure5. Verified legal immunity, non-EU laws unenforceable167/167SEAL-4mediumimmunity: pure-FR entity with no non-EU parent/nexus, plus the scoped sovereign offer runs on Cloud Temple SecNumCloud-qualified infrastructure; provider explicitly guarantees immunity to extra-European laws -> verified legal immunity opt5 (src: https://www.cloud-temple.com/en/press-releases/combining-paas-and-very-high-security-clever-cloud-solutions-available-in-the-secnumcloud-environment-from-cloud-temple/).
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumimmunity, no foreign_parent: not subject to US CLOUD Act/FISA, no US nexus and no lawful basis to comply; commits to reject foreign-authority access requests -> requests always rejected opt5 (src: https://clever.cloud/solutions/compliance/).
SOV-2.4Export control restrictions5. Part of offer shielded from restrictions towards EU MSs/intl orgs167/167SEAL-4lowEU-based provider not subject to non-EU export-control regimes; sovereign offer shielded from restrictions toward EU Member States and international organisations -> opt5.
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4mediumCore platform software (Rust-based Sozu reverse proxy, Biscuit, orchestration/control plane) developed in-house in France; IP mostly within the EU though built on global open-source components -> opt4.
SOV-2.6IP holder jurisdiction5. Fully under EU law167/167SEAL-4mediumSelf-developed IP held by the French company under EU law; the proprietary stack is fully under EU jurisdiction -> opt5.

SOV-3 · Data & AI Sovereignty 80.0% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys4. Customer primary control but provider can read data150/200SEAL-3lowScoped SecNumCloud sovereign offer provides customer-managed/BYOK encryption keys with customer primary control; provider can still read data operationally -> opt4 (seal 3).
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3lowSecNumCloud-grade offer gives full customer-controlled visibility of access logs and data flows (audit-mandated), though not necessarily real-time -> opt4 (seal 3).
SOV-3.3Secure deletion & proof of erasure4. Deletion technically verified with access logs150/200SEAL-3lowSecNumCloud/HDS processes provide deletion technically verified with access logs (logged, traceable erasure) rather than policy-only -> opt4 (seal 3).
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4mediumeu_exclusive (scoped sovereign offer): data stored and processed exclusively in EU/France across its own and EU-sovereign partner regions, HDS confirms no health data leaves the EEA, no third-country fallback in the sovereign offer -> opt5 (src: https://www.cloud-temple.com/en/press-releases/combining-paas-and-very-high-security-clever-cloud-solutions-available-in-the-secnumcloud-environment-from-cloud-temple/).
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3mediumScoped sovereign offer (Cloud Temple SecNumCloud PaaS zone) has no in-scope AI service - Clever AI is a separate general-platform feature outside the sovereign offer, so no foreign-AI dependency -> opt4 per key judgment-call #2 (seal 3).

SOV-4 · Operational Sovereignty 79.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumStandards-based PaaS with documented data export, git-based deployment and open APIs; formal migration assistance available -> opt4.
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4mediumeu_ops: entire stack operated by the France-based team in Nantes with no offshore operations dependency -> opt5.
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumEngineering and operations staff are EU-based (Nantes); no documented security clearances -> all EU staff opt4.
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3mediumSupport delivered by the France-based team (French/English); all support staff in the EU, no documented clearance requirement -> opt4.
SOV-4.5Documentation & knowledge transfer4. EU-only primary repositories125/167SEAL-4lowDocumentation and engineering knowledge produced and held by the EU team; primary repositories EU-only -> opt4.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3lowInfrastructure partners are EU-sovereign providers (OVH, Scaleway, Outscale, Cloud Temple) and software is largely self-built, so alternatives can be sourced or functions internalised; residual hardware supply constraint -> opt4.

SOV-5 · Supply Chain Sovereignty 60.7% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)3. Transparent with exceptions72/143SEAL-3lowHardware sourced from documented EU-sovereign IaaS partners (OVH, Scaleway, Outscale, Cloud Temple) whose component provenance is transparent with exceptions for foreign silicon -> opt3 (seal 3).
SOV-5.2Manufacturing location3. Mixed sourcing, EU audit rights72/143SEAL-3lowUnderlying hardware is foreign-designed but operated through EU-sovereign partners under SecNumCloud audit rights (mixed sourcing, EU audit rights) -> opt3 (seal 3).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/embedded code in CPUs, NICs and storage is vendor-supplied with limited transparency; partial disclosure only.
SOV-5.4Origin of software4. Large majority maintained by EU teams107/143SEAL-3mediumno foreign_core: platform software (orchestration, Sozu reverse proxy, control plane) designed and maintained in-house by the EU team and largely open-sourced; large majority EU-maintained -> opt4.
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3mediumSoftware controlled and built by the France-based engineering team: EU control & execution of the build/release pipeline, without documented EU-policy security gates -> opt4.
SOV-5.6Single point of dependency4. Few non-EU in non-critical services, documented107/143SEAL-3lowCritical services (software + EU-sovereign IaaS) carry no non-EU vendor dependency; remaining non-EU dependency is residual non-critical hardware/chips, documented -> opt4 (seal 3).
SOV-5.7Supply chain transparency4. Most suppliers auditable107/143SEAL-3lowUnder the SecNumCloud audit regime (via Cloud Temple) plus ISO 27001, most suppliers are auditable end-to-end -> opt4 (seal 3).

SOV-6 · Technology Sovereignty 75.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces5. Open-by-default with portability200/200SEAL-4mediumOpen-by-default: standard git/Docker deployment, open APIs and CLI, broad runtime compatibility and documented portability -> opt5.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumRelies on open standards (HTTP, OCI/containers, standard language runtimes, S3-compatible storage, Redis/Valkey protocols) across most core services -> policy for most core services opt4.
SOV-6.3Open source availability5. Fully open-source, independent/EU governance200/200SEAL-4highno foreign_core: core components (Sozu reverse proxy, Biscuit) fully open-source under EU/independent governance on GitHub, with an explicit open-source program -> opt5.
SOV-6.4Service architecture transparency4. Large corpus of public insight150/200SEAL-3mediumSubstantial public engineering content, open-source code and documentation provide a large corpus of insight into the architecture -> opt4.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowAny HPC/GPU compute is EU-hosted but runs on a foreign hardware/software accelerator stack (NVIDIA), no EU-designed HPC silicon -> EU-hosted foreign stack opt2 (seal 3).

SOV-7 · Security & Compliance Sovereignty 82.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumScoped sovereign offer runs on Cloud Temple SecNumCloud-qualified infrastructure; SecNumCloud 3.2 maps to EAL3 per the key -> opt4 (seal 3) (src: https://www.cloud-temple.com/en/press-releases/combining-paas-and-very-high-security-clever-cloud-solutions-available-in-the-secnumcloud-environment-from-cloud-temple/).
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumGDPR-compliant, ISO 27001:2022 and HDS certified, DORA support process, positioned for NIS2; partial-to-strong compliance across most EU regulations, not yet independently certified against the full set -> opt4.
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3lowSecurity incident handling run end-to-end by the EU-based team in France with EU threat intel; no documented ENISA/CSIRT formal sharing membership for the top tier -> opt4.
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3lowCustomers get direct access to application logs and monitoring with data stored in EU; tamper-proof immutable logging not specifically documented -> full direct access, EU-stored opt4.
SOV-7.5Disclosure of incidents4. Partial compliance, monitored flow, SLAs107/143SEAL-3lowIncident disclosure under NIS2/DORA with monitored notification flow and SLAs; not full real-time CSIRT sharing -> opt4 (seal 3).
SOV-7.6Maintenance autonomy5. Full autonomy (deploy independently, with checks)143/143SEAL-4lowAs operator of its own self-built stack, Clever Cloud has full autonomy to deploy maintenance and patches independently with its own checks -> opt5.
SOV-7.7Auditability5. Full independent audit by any entity143/143SEAL-4mediumaudit_rights: the scoped SecNumCloud-grade sovereign offer (via Cloud Temple) implies full audit rights for the contracting authority and independent EU bodies -> full independent audit opt5 (src: https://www.cloud-temple.com/en/press-releases/combining-paas-and-very-high-security-clever-cloud-solutions-available-in-the-secnumcloud-environment-from-cloud-temple/).

SOV-8 · Environmental Sustainability 68.9% · SEAL-3 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)4. PUE < 1.3188/250SEAL-4mediumReports PUE below 1.3 (sub-1.2 cited for some DCs) and emphasises efficiency; not stated as independently EU-verified across all DCs, so PUE<1.3 -> opt4 (seal 4) (src: https://clever.cloud/cloud-and-green-it/).
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3mediumDocumented practice of running servers to end of useful life to extend hardware lifespan: a documented program rather than a certified circular-economy lifecycle -> opt3 (src: https://clever.cloud/cloud-and-green-it/).
SOV-8.3Environmental impact reporting4. Detailed EU methodology188/250SEAL-3lowPublishes detailed energy-efficiency/green-IT figures (PUE, low-carbon sourcing) following an EU methodology, short of full third-party audit -> detailed EU methodology opt4 (seal 3) (src: https://clever.cloud/cloud-and-green-it/).
SOV-8.4Energy supplies4. Only EU energy supplies (high renewable)188/250SEAL-4mediumInfrastructure in France/EU on a highly low-carbon (nuclear/renewable) grid plus carbon-neutral partner DCs: only EU energy supplies, high renewable share -> opt4 (src: https://clever.cloud/cloud-and-green-it/).