🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Elastx

Sweden · IaaS/PaaS · https://elastx.se

Sovereignty score67.5%
Global (unweighted)66.7%
Overall SEAL
SEAL-1 Jurisdictional Sovereignty
SOV-1 Strategic Sovereignty75.0SEAL-3
SOV-2 Legal & Jurisdictional Sovereignty83.4SEAL-3
SOV-3 Data & AI Sovereignty70.0SEAL-1
SOV-4 Operational Sovereignty75.0SEAL-3
SOV-5 Supply Chain Sovereignty46.6SEAL-1
SOV-6 Technology Sovereignty60.0SEAL-3
SOV-7 Security & Compliance Sovereignty60.7SEAL-1
SOV-8 Environmental Sustainability62.5SEAL-2

SOV-1 · Strategic Sovereignty 75.0% · SEAL-3 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4highElastx AB is a Swedish company incorporated in Stockholm, majority-owned (53%) by Swedish investment firm Sobro; states no ownership ties outside Sweden. Entirely within the EU. (src: https://elastx.se/en/overview)
SOV-1.2Change of control risk4. Unlikely takeover/transfer to non-EU sovereign entity94/125SEAL-4mediumPrivately held by Swedish owner Sobro (Swedish unlisted-company investor); no indication of imminent non-EU takeover, but as a small (~20 staff) private firm a future sale is not impossible, so 'unlikely' rather than 'very unlikely'.
SOV-1.3Control over roadmap3. Governance bodies exist with EU actors participation83/125SEAL-3loweu_entity (pure-SE, EU-controlled roadmap with own internal R&D on OpenStack) -> SOV-1.3 opt3; EU governance with some external (upstream) influence, no foreign-set roadmap.
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4mediumFunding comes from Swedish owner Sobro and the Swedish business; no evidence of non-EU capital, so effectively entirely EU-based funding.
SOV-1.5EU economic contribution5. Fully in the EU125/125SEAL-4highAll operations, data centers, and staff are in Sweden; economic contribution is fully within the EU.
SOV-1.6Participation in EU strategic programs2. Limited participation31/125SEAL-4lowActive in the OpenInfra/OpenStack community but no evidence of participation in EU strategic programs such as Gaia-X or IPCEI-CIS; limited participation at best.
SOV-1.7Alignment with EU industrial strategies2. Existing action plan42/125SEAL-4lowMarkets full Swedish digital sovereignty and uses pure open source, indicating an action plan aligned with EU digital-autonomy goals, but no measured governance evidence published.
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4mediumown_stack (owns/operates all infra, all-Swedish staff, pure open-source OpenStack/Kubernetes; only residual non-EU chips) + documented continuity -> SOV-1.8 opt5 Full autonomy & continuity.

SOV-2 · Legal & Jurisdictional Sovereignty 83.4% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highA wholly Swedish-incorporated company operating only in Sweden; subject exclusively to Swedish/EU law. (src: https://elastx.se/en/security)
SOV-2.2Extraterritorial laws exposure5. Verified legal immunity, non-EU laws unenforceable167/167SEAL-4mediumimmunity (pure-SE entity, no non-EU parent/subsidiary/operational nexus a foreign authority could compel) -> SOV-2.2 opt5 verified legal immunity.
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumNo foreign_parent + immunity (pure-SE, not subject to CLOUD Act/FISA/PRC law) -> SOV-2.3 opt5 requests always rejected. (src: https://elastx.se/en/security)
SOV-2.4Export control restrictions5. Part of offer shielded from restrictions towards EU MSs/intl orgs167/167SEAL-4lowNo non-EU technology under export-control gating its offer; a fully Swedish open-source stack is shielded from foreign export restrictions toward EU Member States and international orgs. (src: https://elastx.se/en/security)
SOV-2.5Origin of IP3. Mixed within/outside the EU84/167SEAL-4mediumCore platform IP is open-source OpenStack (globally developed, much from outside the EU) integrated and operated by Elastx in Sweden; mixed within/outside the EU.
SOV-2.6IP holder jurisdiction3. Mixed law, some EU84/167SEAL-3lowOpen-source software is governed under mixed licenses/foundations (OpenInfra is US-based) while Elastx's own integrations fall under EU law; mixed law with some EU.

SOV-3 · Data & AI Sovereignty 70.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys4. Customer primary control but provider can read data150/200SEAL-3mediumOffers encryption at rest with an HSM cluster and OpenStack Barbican for customer-managed secrets; customers can control keys, but as operator Elastx retains technical ability to access data.
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowLogging/monitoring is available on the platform and vendor-operated; no evidence of independently auditable real-time customer oversight.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowStorage is encrypted at rest and managed per policy, but no published proof-of-erasure or independent verification mechanism; internal validation per policy.
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4higheu_exclusive (stored AND processed only in two Swedish regions/three AZs, no third-country fallback) -> SOV-3.4 opt5 exclusively EU. (src: https://elastx.se/en/security)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3lowNo managed black-box AI service: GPUs offered in IaaS/CaaS on foreign (NVIDIA) chips with an auditable open-source stack; customers run their own models, so no foreign-AI lock-in -> key judgment-call (no in-scope foreign AI dependency / EU-led AI on foreign accelerators) -> SOV-3.5 opt4 (seal 3), consistent with the OpenStack Nordic peers. (src: https://elastx.se/en/openstack)

SOV-4 · Operational Sovereignty 75.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumBuilt on standard OpenStack/Kubernetes APIs with documented data-export methods, enabling portability; no evidence of formal turnkey migration services.
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4higheu_ops + own_stack (entire open-source stack operated by an all-Swedish team, no foreign operational dependency) -> SOV-4.2 opt5 fully EU stack+team.
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3higheu_ops: all staff Swedish citizens with annual background checks but no formal security clearance -> per key EU staff -> SOV-4.3 opt4 (clearance would be opt5).
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3highSupport is kept in Sweden with all-Swedish staff; background checks suggest vetting though not formal security clearances, so all support staff in EU.
SOV-4.5Documentation & knowledge transfer4. EU-only primary repositories125/167SEAL-4mediumOperations and documentation are kept in Sweden with an all-Swedish team; EU-only primary repositories are the natural arrangement, though end-to-end EU-only is not explicitly certified.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3lowown_stack: owns/manages all infra on open-source software, can source alternatives/internalise if a subcontractor were lost -> SOV-4.6 opt4 continuity via alternatives.

SOV-5 · Supply Chain Sovereignty 46.6% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowServer/hardware physical components (CPUs, storage) are foreign-sourced from global OEMs; no detailed bill-of-materials provenance published, so partial disclosure.
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1lowHardware is manufactured outside the EU by global vendors; only partial disclosure of sourcing, foreign manufacturing origin.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/embedded code on servers and chips comes from foreign OEMs with no published provenance; partial disclosure at best.
SOV-5.4Origin of software4. Large majority maintained by EU teams107/143SEAL-3mediumNo foreign_core (core is pure unmodified open-source OpenStack/Kubernetes, not licensed Google/MS); the large majority of deployed/operated software is integrated and maintained by Elastx's EU team -> SOV-5.4 opt4 'Large majority maintained by EU teams' (seal 3), consistent with the other pure-OpenStack Nordic peers. (src: https://elastx.se/en/openstack)
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3mediumElastx deploys and operates its own platform from Sweden with a Swedish team; build/release control and execution are EU-based, though without published formal policy gates.
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2lowHardware OEMs and chip vendors are non-EU single points in the critical supply chain; documented as standard server hardware, so few non-EU dependencies in critical services.
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowCritical infrastructure suppliers are identifiable/auditable for ISO 27001 purposes, but full upstream supply-chain auditability is not demonstrated.

SOV-6 · Technology Sovereignty 60.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces5. Open-by-default with portability200/200SEAL-4highBuilt on pure, unmodified OpenStack and Kubernetes with open APIs; open-by-default with strong portability and no proprietary lock-in layers.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3highCore services use open standards (OpenStack, Kubernetes, S3-compatible object storage); a clear policy of open standards across most core services.
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3mediumNo foreign_core; fully open-source (OpenStack/Kubernetes) but upstream governance centralised in non-EU foundations -> SOV-6.3 opt3 open source, centralised governance.
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3mediumArchitecture is documented publicly and based on well-known open-source components, giving meaningful public insight into the service design.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowEU-hosted GPU capability in Sweden running a foreign (NVIDIA) stack; no EU-designed HPC -> per key EU-hosted foreign stack/no in-scope HPC maps to opt2 (seal 3).

SOV-7 · Security & Compliance Sovereignty 60.7% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)2. EAL136/143SEAL-1highHolds ISO 27001/27017/27018 only; no SecNumCloud/EUCS/C5/ENS/Common Criteria EAL -> per key ISO-only maps to opt2 (EAL1-equiv, seal 1). This caps the SEAL. (src: https://elastx.se/en/security)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumDemonstrates GDPR compliance and ISO 27001/27017/27018/14001 certification (independently audited); as a Swedish CSP it falls under NIS2/DORA scope, but full audited compliance to all three is not explicitly evidenced, so partial compliance to most.
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3mediumAll platforms are monitored 24x7 with all-Swedish staff and data/support kept in Sweden; the full incident lifecycle is handled by EU teams, though formal ENISA/CSIRT sharing is not documented.
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3lowLogs are stored in Swedish data centers and monitoring access is provided to customers; full direct access with EU log storage, but no claim of immutable tamper-proof logging.
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2mediumAs a GDPR/NIS2-bound Swedish CSP, incident disclosure is aligned with EU breach-notification requirements; no evidence of real-time CSIRT integration.
SOV-7.6Maintenance autonomy4. High autonomy (deploy independently, no checks)107/143SEAL-4mediumOwns and operates the full open-source stack with a Swedish team, giving high autonomy to deploy maintenance independently without third-party vendor scheduling.
SOV-7.7Auditability3. Partial independent control72/143SEAL-1lowNo audit_rights cert (lacks SecNumCloud/EUCS-High); audits only via ISO certification bodies, no contractual full audit by contracting authority + independent EU bodies -> SOV-7.7 opt3 (seal 1). Caps the SEAL.

SOV-8 · Environmental Sustainability 62.5% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowModern Swedish data centers optimised for energy efficiency on renewable power with ISO 14001, implying PUE under ~1.5 with an efficiency roadmap, though no specific PUE figure is published. (src: https://elastx.se/en/security)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowISO 14001 environmental management implies a documented hardware lifecycle/recycling program, but no detailed circular-economy or EU-certified lifecycle evidence published.
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2lowISO 14001 certification entails environmental reporting; an annual-report level of environmental disclosure is implied, but no detailed EU-methodology or audited footprint figures published.
SOV-8.4Energy supplies5. Only green EU energy supplies250/250SEAL-4highData centers are powered exclusively by green/renewable energy in Sweden (high-renewable grid), i.e. only green EU energy supplies. (src: https://elastx.se/en/security)