🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

CloudSigma

Switzerland · IaaS · https://www.cloudsigma.com

Sovereignty score41.8%
Global (unweighted)42.7%
Overall SEAL
SEAL-1 Jurisdictional Sovereignty
SOV-1 Strategic Sovereignty36.6SEAL-1
SOV-2 Legal & Jurisdictional Sovereignty41.8SEAL-1
SOV-3 Data & AI Sovereignty65.0SEAL-1
SOV-4 Operational Sovereignty37.6SEAL-1
SOV-5 Supply Chain Sovereignty32.4SEAL-1
SOV-6 Technology Sovereignty45.0SEAL-2
SOV-7 Security & Compliance Sovereignty39.6SEAL-1
SOV-8 Environmental Sustainability43.8SEAL-1

SOV-1 · Strategic Sovereignty 36.6% · SEAL-1 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control2. Mostly outside the EU42/125SEAL-1highCloudSigma AG is incorporated and controlled in Switzerland (Zurich/Zug), a third country, not EU/EEA. No EU parent; entity control sits mostly outside the EU -> opt2 (seal 1; uniform across the Swiss cluster). (src: https://www.cloudsigma.com)
SOV-1.2Change of control risk4. Unlikely takeover/transfer to non-EU sovereign entity94/125SEAL-4lowSmall, independent, founder-led Swiss company with minimal external capital; no signs of imminent acquisition by a non-EU sovereign entity, though small firms remain acquirable. Kept at existing all-seal-4 choice.
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2lowNo formal governance bodies with EU-actor participation; roadmap influence is limited to customer/partner feedback channels typical of a small commercial IaaS provider -> opt2.
SOV-1.4Financial independence from non-EU capital3. Balanced mix of EU and non-EU funding63/125SEAL-4lowPrivately held Swiss company with limited disclosed funding (small rounds plus an EU grant). Capital is Swiss/mixed rather than clearly majority EU-based. Kept at existing all-seal-4 choice.
SOV-1.5EU economic contribution2. Some31/125SEAL-4lowSwiss-headquartered with some EU data centers and customers, but the bulk of corporate value and the global footprint (US/APAC/ME) sit outside the EU. Kept at existing all-seal-4 choice.
SOV-1.6Participation in EU strategic programs2. Limited participation31/125SEAL-4mediumHistoric limited participation in EU-fostered Helix Nebula / HNSciCloud science-cloud initiatives; no Gaia-X or IPCEI-CIS membership. Kept at existing all-seal-4 choice.
SOV-1.7Alignment with EU industrial strategies1. No evidence exists0/125SEAL-4lowNo published action plan or governance demonstrating alignment with EU industrial strategies; markets globally as a neutral CaaS provider. Kept at existing all-seal-4 choice.
SOV-1.8Resilience to cut-off3. Can continue temporarily per contractual agreement63/125SEAL-2lowSelf-operated KVM platform on leased/colo data centers; not own_stack (depends on non-EU colocation, e.g. Equinix, and foreign hardware). Under contract a deployment could continue temporarily -> opt3 (key 1.8).

SOV-2 · Legal & Jurisdictional Sovereignty 41.8% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction2. Mixed EU/non-EU84/167SEAL-1highPrimary jurisdiction is Switzerland (a third country); contracts governed by Swiss law, but CloudSigma also operates EU data centers (Frankfurt, Dublin) and serves EU customers under GDPR -> mixed EU/non-EU, opt2 (seal 1). Normalised to opt2 for consistency with the rest of the Swiss cluster (mixed, both opt1/opt2 are seal 1). (src: https://www.cloudsigma.com)
SOV-2.2Extraterritorial laws exposure2. Mitigation clauses, exposure remains42/167SEAL-1mediumNo immunity: Switzerland is not EU and CloudSigma holds no SecNumCloud/EUCS-High; unlike the Swiss-only peers it also operates US/APAC/ME data centers, exposing parts of the offer to foreign law -> only mitigation clauses, exposure remains, opt2 (seal 1). Real footprint differentiator vs Swiss-only peers (opt4). (src: https://blog.cloudsigma.com/cloud-locations/)
SOV-2.3Data access pathways for non-EU authorities4. Requests disputed, sometimes accepted with notification125/167SEAL-1lowNo foreign_parent for the Swiss entity, but unlike the Swiss-only peers CloudSigma operates US/APAC/ME data centers, so US-located deployments could be compelled by US authorities under the CLOUD Act -> requests disputed, not always rejected, opt4 (seal 1). The genuine US-DC exposure is the differentiator that keeps it below the opt5 (seal 4) reached by the pure-Swiss-hosting peers. (src: https://blog.cloudsigma.com/cloud-locations/)
SOV-2.4Export control restrictions3. Share of revenues >50% in the EU84/167SEAL-2lowNo known export-control restrictions toward EU member states; a meaningful share of revenue is European, but the company is global and Swiss-based rather than EU-shielded -> opt3.
SOV-2.5Origin of IP3. Mixed within/outside the EU84/167SEAL-4lowCore IP is Swiss-developed on open-source (KVM/Linux) with mixed international components; not predominantly EU-origin, but not fully foreign. Kept at existing all-seal-4 choice.
SOV-2.6IP holder jurisdiction1. Non-EU law, single country0/167SEAL-3mediumProprietary platform IP is held by the Swiss parent under Swiss (non-EU, single-country) law -> opt1 per key 2.6.

SOV-3 · Data & AI Sovereignty 65.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys5. Customer exclusive control - provider cannot read data200/200SEAL-4highCustomers perform boot-level/full-disk encryption holding their own keys; CloudSigma states it has no access inside VMs or drives, so the provider cannot read encrypted customer data -> opt5 (seal 4). Genuine customer-held-key differentiator preserved (not flattened). (src: https://www.cloudsigma.com)
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowISO 27001 / SOC 2 controls imply audit and access logging, but logs are vendor-controlled and not advertised as real-time independently auditable customer feeds -> opt3.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowDeletion handled per internal ISO 27001 policy; no published independently verified proof-of-erasure; customer-held keys help but provider erasure is policy-based -> opt3 per key 3.3.
SOV-3.4Data location strictly in EU/EEA3. Mainly EU, some third-country use with safeguards100/200SEAL-1mediumNot eu_exclusive: default global footprint includes many third countries (US, APAC, ME), but CloudSigma DOES offer real EU member-state data centers (Frankfurt, Dublin) so a customer can obtain EU residency -> mainly-EU-with-safeguards, opt3 (seal 1). The presence of genuine EU-DC options keeps it above the Swiss-only peers (opt2 seal 0, no EU region at all). (src: https://blog.cloudsigma.com/cloud-locations/)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3lowPure IaaS with no in-scope sovereign AI service; no foreign-AI dependency in the offer -> opt4 (seal-3) per key 3.5 (no in-scope AI).

SOV-4 · Operational Sovereignty 37.6% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumOpen KVM-based VMs, standard images, documented APIs/data export plus stated migration support give formal portability away from the platform -> opt4.
SOV-4.2Ability to operate without foreign dependencies2. Ops partially sourced within EU42/167SEAL-1lowNot eu_ops: small global team (~50 across 4 continents); operations partially sourced within the EU (Sofia tech team) but not predominantly EU-based -> opt2 per key 4.2.
SOV-4.3Skill availability in the EU2. Mixed, majority outside EU42/167SEAL-1lowStaff spread across Europe, North America and Asia; skills are mixed with no demonstrated EU majority given the global footprint -> opt2 per key 4.3.
SOV-4.4Support channels2. Mixed, majority outside EU42/167SEAL-2low24/7 global support delivered by a small internationally distributed team; not majority EU-based -> opt2 per key 4.4.
SOV-4.5Documentation & knowledge transfer2. EU optional, not enforced42/167SEAL-2lowDocumentation and knowledge live in global/cloud repositories with no stated EU-only residency; EU handling is optional, not enforced -> opt2 per key 4.5.
SOV-4.6Subcontractor & supplier jurisdiction3. Continue temporarily per contractual agreement84/167SEAL-3lowRelies on third-party colocation (e.g. Equinix) and hardware vendors; under contractual arrangements service could continue temporarily, though supplier base is largely non-EU -> opt3.

SOV-5 · Supply Chain Sovereignty 32.4% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowStandard x86 server hardware of foreign origin; component provenance only partially disclosed, no EU-certified supply chain -> opt2.
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1lowServers and chips manufactured abroad (US/Asia); provider does not design or build its own hardware and discloses little manufacturing detail -> opt2.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/BIOS on commodity servers comes from foreign OEMs with at most partial disclosure; no EU-certified firmware provenance. Kept at existing all-seal-4 choice.
SOV-5.4Origin of software3. Core/essential parts maintained by EU teams72/143SEAL-3mediumNo foreign_core: the cloud platform is built and maintained by CloudSigma's own (Swiss-led) teams on open-source KVM/Linux, not licensed Google/MS tech. Core/essential parts maintained by the provider's teams -> opt3 per key 5.4.
SOV-5.5Software build/release jurisdiction2. EU control, non-EU execution36/143SEAL-1lowRelease process controlled by the Swiss company (non-EU) with engineering distributed internationally; control and execution are not EU-based -> opt2 per key 5.5.
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2lowCritical dependencies on non-EU colocation and hardware vendors exist and are documented to some extent (named facility partners) -> opt3 (few non-EU in critical services, documented).
SOV-5.7Supply chain transparency2. Some suppliers auditable36/143SEAL-1lowSome suppliers (named data-center/colocation partners) are identifiable, but no comprehensive auditable supply-chain transparency program -> opt2.

SOV-6 · Technology Sovereignty 45.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumStandards-based KVM virtualization, standard OS images and documented APIs make the platform broadly compatible and avoid heavy proprietary lock-in -> opt4.
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2lowAdopts open standards for core compute/storage (KVM, standard images, common protocols) but without a published comprehensive open-standards policy across all services -> opt3.
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2lowBuilt on open-source KVM/Linux, but CloudSigma's own platform/orchestration software is proprietary and not openly published or community-governed -> opt2 per key 6.3.
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowSome public architectural insight via blog/docs and ISO 27001/SOC 2 audit access, but no deep customer-contributable transparency -> opt3.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowNo EU-sovereign HPC offering; treated as no in-scope HPC -> opt2 (seal-3) per key 6.5.

SOV-7 · Security & Compliance Sovereignty 39.6% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)3. EAL272/143SEAL-2mediumNo SecNumCloud/EUCS-High/C5/Common Criteria EAL; holds ISO 27001 + ISO 27017/27018 + SOC 2 Type II. Per key, ISO 27001 + SOC 2 maps to EAL2 -> opt3 (seal 2). (Below the C5-holding peers Exoscale/Safe-Swiss at opt4.) (src: https://blog.cloudsigma.com/soc-2-customer-data-management-certified-cloud/)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)3. Moderate compliance72/143SEAL-4mediumISO 27001 and SOC 2 Type II certified and GDPR-relevant as a Swiss adequate jurisdiction, showing moderate adherence; no full audited NIS2/DORA compliance. Kept at existing all-seal-4 choice.
SOV-7.3EU-based SOC & incident handling2. Hybrid EU/non-EU36/143SEAL-1lowSecurity operations and incident handling run by a small globally distributed team, implying a hybrid EU/non-EU SOC rather than an EU-confined lifecycle -> opt2.
SOV-7.4Control over security monitoring/logging2. Customers receive periodic reports36/143SEAL-1lowCustomers get reporting and ISO/SOC-aligned controls, but security monitoring/logging is largely provider-controlled with periodic reporting rather than full customer-owned EU-resident logs -> opt2.
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2lowOperating under ISO 27001 and serving EU customers implies GDPR/NIS2-aligned breach disclosure, but no published real-time CSIRT/ENISA sharing -> opt3 per key 7.5.
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowOperating its own KVM platform gives moderate maintenance autonomy with versioned, auditable releases and customer notice, subject to underlying vendor patches -> opt3 per key 7.6.
SOV-7.7Auditability2. Limited independent access36/143SEAL-1lowNo audit_rights: independent assurance is via ISO 27001 / SOC 2 auditors with limited scope; no full independent audit by the contracting authority or any independent EU body -> opt2 (capped seal-1 per key 7.7).

SOV-8 · Environmental Sustainability 43.8% · SEAL-1 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowHosts in modern Tier III Equinix colocation facilities (the same premium-facility class as Exoscale), which run efficient PUE with sustainability roadmaps; no standalone published figure, so PUE<1.5+roadmap is the consistent estimate -> opt3 (seal 4). Normalised to the colo-tenant peers (Exoscale/Safe-Swiss/Nine) using the same facility class. (src: https://blog.cloudsigma.com/cloud-locations/)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowAs a colocation tenant in professionally managed Equinix facilities, hardware lifecycle/recycling is covered by the operators' documented circular-economy programs (same basis credited to the other colo-tenant peers Exoscale/Safe-Swiss/Nine) -> documented program, opt3 (seal 3). Normalised for consistency: no real differentiator vs the peers using the same facility operators. (src: https://blog.cloudsigma.com/cloud-locations/)
SOV-8.3Environmental impact reporting2. Basic reporting63/250SEAL-1lowNo detailed environmental/sustainability report published by CloudSigma itself; at most basic reporting inherited from data-center partners -> opt2 per key 8.3.
SOV-8.4Energy supplies3. Mix of EU and non-EU supplies125/250SEAL-4lowGlobal footprint draws on a mix of EU and non-EU energy supplies depending on the colocation site; not exclusively EU or fully green-traceable. Kept at existing all-seal-4 choice.