🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Cloud Temple

France · IaaS/PaaS · https://www.cloud-temple.com

Sovereignty score75.3%
Global (unweighted)73.7%
Overall SEAL
SEAL-3 Digital Resilience
SOV-1 Strategic Sovereignty88.5SEAL-3
SOV-2 Legal & Jurisdictional Sovereignty83.4SEAL-3
SOV-3 Data & AI Sovereignty85.0SEAL-3
SOV-4 Operational Sovereignty79.0SEAL-3
SOV-5 Supply Chain Sovereignty57.2SEAL-3
SOV-6 Technology Sovereignty55.0SEAL-3
SOV-7 Security & Compliance Sovereignty78.5SEAL-3
SOV-8 Environmental Sustainability62.6SEAL-3

SOV-1 · Strategic Sovereignty 88.5% · SEAL-3 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity (French company, HQ Puteaux, subsidiary of Euronext-listed Neurones SA, no non-EU parent) -> opt4. SecNumCloud 3.2 requires EU HQ and EU-majority capital (src: https://www.cloud-temple.com/en/press-releases/secure-temple-cloud-temples-iaas-offering-is-secnumcloud-qualified/).
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4highOwned by French listed Neurones; SecNumCloud 3.2 caps extra-EU capital at 24% and bars foreign control, so takeover by a non-EU sovereign entity is very unlikely while qualified.
SOV-1.3Control over roadmap3. Governance bodies exist with EU actors participation83/125SEAL-3mediumEU-controlled provider; participates in Gaia-X and the CANUT public-sector framework giving EU actors governance channels -> opt3 (no formal customer roadmap-control body evidenced).
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4highFunded by French parent Neurones and EU revenues; SecNumCloud 3.2 requires EU-majority capital (extra-EU <24%), so funding is essentially entirely EU-based.
SOV-1.5EU economic contribution5. Fully in the EU125/125SEAL-4highAll data centres, ~300 staff, revenue (EUR 52M 2024) and operations in France; economic contribution fully in the EU.
SOV-1.6Participation in EU strategic programs4. Strong participation94/125SEAL-4highGaia-X member (first European player certified Gaia-X Label Level 3) and winner of the French public-sector CANUT trusted-cloud framework; strong participation in EU/national sovereignty programs.
SOV-1.7Alignment with EU industrial strategies3. Measured achievement and dedicated governance83/125SEAL-4mediumExplicit sovereignty strategy with measured achievements (SecNumCloud 3.2 across IaaS/PaaS/bare metal/object storage, Gaia-X L3) and dedicated governance.
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4mediumown_stack (software stack developed entirely in-house: OpenIaaS XEN-fork hypervisor, native S3/object storage, K8s; three France DCs) + SecNumCloud-mandated reversibility/exit plan -> vertically integrated EU provider with full autonomy & continuity -> opt5 (residual commodity x86 hardware only).

SOV-2 · Legal & Jurisdictional Sovereignty 83.4% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highFrench legal entity governed exclusively by French/EU law; SecNumCloud 3.2 requires an EU entity not subject to non-EU jurisdiction -> opt3.
SOV-2.2Extraterritorial laws exposure5. Verified legal immunity, non-EU laws unenforceable167/167SEAL-4highimmunity (ANSSI SecNumCloud 3.2 designed to make CLOUD Act/FISA 702/EO 12333 unenforceable via EU-only ownership, jurisdiction and operations) -> opt5 verified legal immunity (src: https://www.cloud-temple.com/en/press-releases/cloud-temple-first-in-france-to-obtain-secnumcloud-qualification-for-a-paas-offering/).
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4highimmunity, no foreign_parent (SecNumCloud-qualified French provider, no non-EU parent): not subject to compelled access and would reject such requests -> opt5 (src: https://www.cloud-temple.com/en/press-releases/secure-temple-cloud-temples-iaas-offering-is-secnumcloud-qualified/).
SOV-2.4Export control restrictions5. Part of offer shielded from restrictions towards EU MSs/intl orgs167/167SEAL-4mediumEU-owned SecNumCloud sovereign offer for EU/French public and regulated sectors; shielded from non-EU export-control restrictions toward EU MSs and intl orgs -> opt5.
SOV-2.5Origin of IP3. Mixed within/outside the EU84/167SEAL-4mediumPlatform IP mixed: in-house open-source IaaS (OpenIaaS/XEN) EU-developed, but PaaS (Red Hat OpenShift) and AI (IBM watsonx) IP originate outside the EU -> opt3.
SOV-2.6IP holder jurisdiction3. Mixed law, some EU84/167SEAL-3mediumOwn software held under French law, but licensed components (Red Hat/IBM, VMware) held by US-jurisdiction IP holders -> mixed law, some EU -> opt3.

SOV-3 · Data & AI Sovereignty 85.0% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys5. Customer exclusive control - provider cannot read data200/200SEAL-4highSovereign KMS with HSM hardware root of trust inside the SecNumCloud enclave enabling customer-exclusive key control so the provider cannot read data -> opt5.
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3mediumSecNumCloud mandates customer-accessible access/audit logging stored in the enclave; full customer-controlled visibility, real-time independent auditability not explicitly evidenced -> opt4.
SOV-3.3Secure deletion & proof of erasure4. Deletion technically verified with access logs150/200SEAL-3mediumSecNumCloud 3.2 requires verifiable secure deletion with access logging; technically verified, independent third-party erasure proof not specifically documented -> opt4.
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4higheu_exclusive (all processed data hosted in three certified French data centres, no third-country fallback, as required by the SecNumCloud sovereign offer) -> opt5 (src: https://www.cloud-temple.com/en/press-releases/secure-temple-cloud-temples-iaas-offering-is-secnumcloud-qualified/).
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3mediumIn-scope AI runs in the SecNumCloud sovereign enclave on NVIDIA GPUs and, via watsonx.ai, serves EU-origin/open-weight models (notably Mistral) under EU jurisdiction -> EU-led AI on foreign accelerators -> opt4 (seal 3), consistent with the cluster's SecNumCloud peers (src: https://www.cloud-temple.com/en/press-releases/cloud-temple-offers-secure-ia-on-a-secnumcloud-qualified-sovereign-cloud-with-watsonx-dibm/).

SOV-4 · Operational Sovereignty 79.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumStandards-based open-source IaaS/PaaS (XEN/OpenIaaS, K8s/OpenShift, S3) with documented export/migration services; positioned as a sovereign migration target -> opt4.
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4higheu_ops (SecNumCloud 3.2 requires the entire stack operated by EU-based teams under EU jurisdiction; operations managed by a fully France-based team) -> opt5.
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumAll staff based in France; SecNumCloud requires EU staffing with vetting; no explicit claim of full security clearance for 100% of personnel -> opt4.
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3mediumSupport delivered by France-based teams under SecNumCloud EU-operations requirements, no non-EU escalation; formal clearances for all support staff not documented -> opt4.
SOV-4.5Documentation & knowledge transfer4. EU-only primary repositories125/167SEAL-4mediumSecNumCloud sovereign French provider: documentation/knowledge held within EU/France, EU-only primary repositories with no evident non-EU exposure -> opt4.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3mediumSubcontractors EU-based per SecNumCloud; in-house open-source IaaS reduces lock-in giving ability to source alternatives or internalise -> opt4 (continuity).

SOV-5 · Supply Chain Sovereignty 57.2% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)3. Transparent with exceptions72/143SEAL-3lowOperates from certified French data centres with supply transparent under SecNumCloud audit, but underlying server hardware is foreign with exceptions -> transparent with exceptions -> opt3.
SOV-5.2Manufacturing location3. Mixed sourcing, EU audit rights72/143SEAL-3lowServers on foreign-designed commodity x86 (Cisco UCS/Dell/IBM/Juniper) integrated under SecNumCloud EU audit rights -> mixed sourcing, EU audit rights -> opt3.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/microcode on commodity servers from foreign OEMs/chip vendors with only partial disclosure; SecNumCloud audits give some visibility but full firmware provenance not published -> opt2.
SOV-5.4Origin of software3. Core/essential parts maintained by EU teams72/143SEAL-3mediumCore IaaS software (OpenIaaS XEN-fork, orchestration, S3) maintained by EU teams; PaaS/AI add-ons (OpenShift, watsonx) foreign-origin but not the core -> core/essential parts EU-maintained -> opt3 (no foreign_core for the IaaS core).
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3lowCloud Temple controls and executes builds/releases of its own platform in France under SecNumCloud governance -> EU control & execution -> opt4.
SOV-5.6Single point of dependency4. Few non-EU in non-critical services, documented107/143SEAL-3mediumown_stack core IaaS: remaining non-EU dependencies are residual commodity hardware (documented, non-critical to continuity) -> few non-EU non-critical, documented -> opt4.
SOV-5.7Supply chain transparency4. Most suppliers auditable107/143SEAL-3mediumSecNumCloud 3.2 supply-chain requirements make most suppliers auditable; ANSSI audits the provider and critical subcontractors -> opt4.

SOV-6 · Technology Sovereignty 55.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumStandards-based, broadly compatible technologies (Kubernetes/OpenShift, S3-compatible storage, XEN/OpenStack) with documented APIs and portability -> opt4.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumAdopts open standards (S3, Kubernetes, SQL via managed MariaDB/PostgreSQL/Kafka) as a policy across most core services -> opt4.
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3mediumCore IaaS built on open-source software (OpenIaaS/XEN, Kubernetes, PostgreSQL, MariaDB, Kafka); open source with centralised/vendor governance rather than independent EU governance -> opt3 (EU-maintained core, not foreign_core).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3mediumPublic documentation and architecture insight for its sovereign offerings plus deep audit access under SecNumCloud/Gaia-X -> some public insight -> opt3.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowNo EU-sovereign in-scope HPC; AI acceleration uses EU-hosted foreign (NVIDIA) stack within the French enclave -> EU-hosted foreign stack -> opt2 (seal 3).

SOV-7 · Security & Compliance Sovereignty 78.5% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumSecNumCloud 3.2 (plus C5, ISO 27001, HDS) maps to EAL3-equivalent assurance per the key -> opt4 EAL3 (seal 3) (src: https://www.cloud-temple.com/en/press-releases/cloud-temple-first-in-france-to-obtain-secnumcloud-qualification-for-a-paas-offering/).
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)5. Fully compliant to all, independently audited143/143SEAL-4highANSSI SecNumCloud 3.2 (IaaS/PaaS), ISO 27001, HDS, C5 and Gaia-X L3, all independently audited; full GDPR alignment and strong NIS2/DORA readiness -> opt5.
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3mediumSecNumCloud-required EU-operated security with France-based SOC/incident handling and EU threat intel; full lifecycle by EU teams (explicit ENISA sharing not documented) -> opt4.
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3mediumCustomers get direct access to security logs stored in the French enclave under SecNumCloud; full access, EU-stored (tamper-proof immutability not explicitly claimed) -> opt4.
SOV-7.5Disclosure of incidents4. Partial compliance, monitored flow, SLAs107/143SEAL-3mediumSecNumCloud/GDPR/NIS2 require monitored incident disclosure with defined SLAs and national CSIRT notification; real-time sharing not explicitly stated -> opt4.
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4mediumOperates its own sovereign platform with notice-and-testing maintenance windows under SecNumCloud change-management -> moderate autonomy -> opt3 (seal 4).
SOV-7.7Auditability5. Full independent audit by any entity143/143SEAL-4mediumaudit_rights: the SecNumCloud-qualified sovereign offer affords full audit rights to the contracting authority and independent EU bodies -> opt5 full independent audit.

SOV-8 · Environmental Sustainability 62.6% · SEAL-3 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowModern certified French data centres with efficiency/carbon commitments; PUE <1.5 with a roadmap is a reasonable estimate, no provider-specific figure published -> opt3 (seal 4).
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowCSR commitments and certified data centres with circular practices; a documented hardware reuse/recycling program is evidenced -> opt3 documented program (seal 3).
SOV-8.3Environmental impact reporting4. Detailed EU methodology188/250SEAL-3lowBacked by Neurones (CSRD-reporting Euronext-listed group) with a detailed EU sustainability methodology and stated carbon trajectory -> detailed EU methodology -> opt4 (seal 3).
SOV-8.4Energy supplies4. Only EU energy supplies (high renewable)188/250SEAL-4mediumData centres on the low-carbon French grid (heavily nuclear/renewable, ~50 g CO2/kWh); only EU energy supplies with high low-carbon content -> opt4.