🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Exoscale

Switzerland · IaaS/PaaS · https://www.exoscale.com

Sovereignty score57.5%
Global (unweighted)57.9%
Overall SEAL
SEAL-1 Jurisdictional Sovereignty
SOV-1 Strategic Sovereignty47.1SEAL-1
SOV-2 Legal & Jurisdictional Sovereignty62.6SEAL-1
SOV-3 Data & AI Sovereignty65.0SEAL-1
SOV-4 Operational Sovereignty62.6SEAL-3
SOV-5 Supply Chain Sovereignty46.6SEAL-1
SOV-6 Technology Sovereignty55.0SEAL-3
SOV-7 Security & Compliance Sovereignty67.8SEAL-1
SOV-8 Environmental Sustainability56.3SEAL-2

SOV-1 · Strategic Sovereignty 47.1% · SEAL-1 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control2. Mostly outside the EU42/125SEAL-1higheu_entity FALSE: primary entity Akenes SA is incorporated in Lausanne, Switzerland (third country, not EU/EEA); intermediate owner A1 Digital is Austrian (EU) but the operating entity sits outside the EU -> mostly outside EU, opt2 (seal 1). (src: https://www.exoscale.com/about-us/)
SOV-1.2Change of control risk2. Likely takeover/transfer to non-EU sovereign entity31/125SEAL-4mediumUltimate parent Telekom Austria is controlled (56.55%) by Mexico's America Movil, a non-EU sovereign-market entity; Exoscale has already changed hands once (2017). Further transfer of this asset to a non-EU controller is plausible given the ownership chain.
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2lowRoadmap set by Exoscale/A1 management; EU-actor influence limited to customer feedback/changelog channels, no formal EU governance body -> opt2 (seal 2).
SOV-1.4Financial independence from non-EU capital3. Balanced mix of EU and non-EU funding63/125SEAL-4mediumFunding/capital comes through A1 Telekom Austria Group, which mixes EU (ABAG, Austrian state, ~28%) with significant non-EU control (America Movil, Mexico, ~57%), giving a balanced-to-mixed EU/non-EU capital base.
SOV-1.5EU economic contribution4. Majority in the EU94/125SEAL-4mediumOperations, employment, data centres and revenue are concentrated in Europe (CH, AT, DE, BG, HR), so the majority of economic contribution is in/around the EU, though HQ and some value sit in Switzerland.
SOV-1.6Participation in EU strategic programs3. Active participant in strategic projects63/125SEAL-4highActive participant: Gaia-X day-one member (via A1) contributing to working groups, and selected on the GEANT OCRE 2024 framework for European research and education procurement.
SOV-1.7Alignment with EU industrial strategies2. Existing action plan42/125SEAL-4lowPublic positioning and marketing align with EU digital-sovereignty goals (European alternative to US hyperscalers) and there is an action plan, but no measured achievement or dedicated sovereignty governance is evidenced.
SOV-1.8Resilience to cut-off4. Ability to source alternatives or internalise key functions94/125SEAL-2lowown_stack partial: runs its own platform on leased EU/CH colocation and could source alternatives/internalise, but a real non-EU operational dependency remains (Swiss base, foreign hardware) -> opt4 'source alternatives/internalise' (seal 2), not full autonomy.

SOV-2 · Legal & Jurisdictional Sovereignty 62.6% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction2. Mixed EU/non-EU84/167SEAL-1highContracts governed by Swiss law (canton Vaud), a third-country jurisdiction; EU zones (Vienna AT, Frankfurt/Munich DE, Sofia BG) bring GDPR/member-state law into play -> mixed EU/non-EU, not exclusively EU, opt2 (seal 1). (src: https://www.exoscale.com/terms/)
SOV-2.2Extraterritorial laws exposure4. Legal structures shielding from foreign law125/167SEAL-2mediumimmunity FALSE (no SecNumCloud/EUCS-High; Swiss entity with non-EU Mexican ultimate parent). Swiss incorporation does place it outside the US CLOUD Act/FISA/PRC, giving legal structures shielding from foreign law -> opt4 (seal 2), but not verified immunity. (src: https://www.exoscale.com/about-us/)
SOV-2.3Data access pathways for non-EU authorities4. Requests disputed, sometimes accepted with notification125/167SEAL-1mediumforeign_parent TRUE: ultimate control via A1 Telekom Austria is majority-held by America Movil (Mexico, ~51-58%), a non-EU parent reachable by foreign law. It is genuinely exempt from US CLOUD Act/FISA/PRC (no US/PRC nexus) and disputes/refuses requests, but the non-EU ownership chain blocks the absolute opt5 'always rejected' -> opt4 'requests disputed' (seal 1). DECISIVE SEAL-1 gate. Distinct from the pure-Swiss-no-foreign-parent peers (Infomaniak/Safe-Swiss/Nine = opt5): Exoscale has a non-EU ultimate parent. (src: https://ventures.swisscom.com/a1-digital-acquires-swiss-cloud-provider-exoscale/)
SOV-2.4Export control restrictions3. Share of revenues >50% in the EU84/167SEAL-2low>50% revenue in the EU/European market and no known export-control restrictions toward EU MS, but no part of the offer is formally shielded from restrictions -> opt3 (seal 2).
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4mediumCore platform IP is developed by Exoscale's European (Lausanne-based) engineering teams, with upstream open-source dependencies; IP is mostly within the EU/EEA-adjacent European sphere.
SOV-2.6IP holder jurisdiction3. Mixed law, some EU84/167SEAL-3mediumIP held by Akenes SA under Swiss (non-EU) law, but with EU-based intermediate ownership and EU operations -> mixed law, some EU, opt3 (seal 3).

SOV-3 · Data & AI Sovereignty 65.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys4. Customer primary control but provider can read data150/200SEAL-3mediumCustomer BYOK encryption supported, but as IaaS the provider technically retains access to unencrypted data unless the customer encrypts client-side -> customer primary control, provider retains capability, opt4 (seal 3).
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3mediumCustomers get audit logs, IAM and activity visibility through the portal/API, giving full customer-controlled visibility, though not advertised as real-time independently auditable streaming.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowDeletion is handled per documented internal policy and shared-responsibility model under ISO 27001 controls, but no independent cryptographic proof-of-erasure certificate is offered.
SOV-3.4Data location strictly in EU/EEA4. EU by default, tightly controlled exceptions150/200SEAL-1higheu_exclusive FALSE: data stays in the customer-selected zone with no automatic fallback, but the default footprint includes Switzerland (a third country) alongside EU member-state zones AT/DE/BG/HR -> EU-by-default w/ tightly controlled non-EU exceptions, opt4 (seal 1). Not exclusively EU/EEA. Real EU-DC footprint (multiple EU member-state zones) distinguishes it from Swiss-only peers (Infomaniak/Safe-Swiss/Nine = opt2 seal 0). (src: https://community.exoscale.com/platform/dc-zones/)
SOV-3.5AI services sovereignty3. Mixed: auditable/open-source AI, foreign chips100/200SEAL-2lowGPU offering relies on foreign accelerator chips (Nvidia) running open/auditable model stacks rather than EU-origin silicon or black-box models -> mixed, opt3 (seal 2).

SOV-4 · Operational Sovereignty 62.6% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4highOpen standards-based API, CLI, Terraform/Pulumi support, CNCF-certified Kubernetes (SKS) and documented data export enable formal portability and migration with low lock-in.
SOV-4.2Ability to operate without foreign dependencies4. Ops predominantly EU-based teams125/167SEAL-3mediumeu_ops: engineering and platform ops run by Exoscale's European (Swiss/EU) teams, predominantly EU-based staff with limited non-EU dependency beyond hardware -> opt4 (seal 3).
SOV-4.3Skill availability in the EU3. Majority EU, escalation abroad84/167SEAL-3loweu_ops: staff concentrated in Europe (Lausanne HQ, A1 Group), majority EU/European with escalation kept in Europe; no EU-citizen-only staffing or clearances -> opt3 majority EU (seal 3).
SOV-4.4Support channels3. Majority in EU, non-EU escalations84/167SEAL-3loweu_ops: support delivered by European-based customer-success engineers, majority in Europe with non-EU escalations possible; no EU-only staffing with clearances -> opt3 (seal 3).
SOV-4.5Documentation & knowledge transfer3. EU primary with non-EU fallback84/167SEAL-4lowDocumentation/knowledge live primarily in European-managed repositories and community docs with European teams -> EU-primary with possible non-EU fallback, opt3 (seal 4).
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3lowCritical subcontractors are EU/European colocation operators (e.g. Equinix); provider could source alternatives or internalise if a supplier withdrew -> opt4 (seal 3).

SOV-5 · Supply Chain Sovereignty 46.6% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowAs an IaaS operator on colocated infrastructure, only partial disclosure of physical component provenance; server hardware origin not publicly detailed -> opt2 (seal 1).
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1lowUnderlying server/network hardware is foreign-manufactured (global OEMs) with at best partial disclosure; not built or designed by EU teams -> opt2 (seal 1).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/embedded code in commodity servers and network gear is from foreign vendors with only partial disclosure; no EU-certified provenance.
SOV-5.4Origin of software4. Large majority maintained by EU teams107/143SEAL-3mediumforeign_core FALSE: the Exoscale platform software is designed and maintained by its own European engineering teams atop open source; does NOT run Google/MS/AWS under the hood -> large majority EU-maintained, opt4 (seal 3). No foreign_core cap.
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3mediumSoftware build/release controlled and executed by Exoscale's European engineering org; no evidence of formal EU policy gates beyond standard controls -> EU control & execution, opt4 (seal 3).
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2lowA few non-EU dependencies in critical services (foreign-made server/chip hardware, some global tooling), documented via the shared-responsibility/compliance model -> few non-EU critical, opt3 (seal 2).
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowCritical suppliers (colocation/DC operators) are auditable and covered in the compliance program, but full end-to-end supply-chain auditability is not claimed -> critical suppliers auditable, opt3 (seal 2).

SOV-6 · Technology Sovereignty 55.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3highStandards-based and broadly compatible: open REST API, S3-compatible object storage, CNCF-conformant Kubernetes, Terraform/Pulumi providers enabling broad interoperability.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumOpen standards (S3 API, upstream Kubernetes, OpenAPI) are adopted across most core services as a deliberate policy of staying close to upstream open ecosystems.
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3mediumforeign_core FALSE: Exoscale builds on and contributes to open source and ships open clients/providers; core control-plane is proprietary with centralised governance -> open source, centralised governance, opt3 (seal 3). No foreign_core cap.
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowSubstantial public insight via community docs, API specs, engineering blog posts and a published shared-responsibility model -> some public insight, opt3 (seal 3).
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowAny HPC/GPU capability is EU/CH-hosted but runs on a foreign hardware/software stack (Nvidia, standard stack); no EU-designed silicon -> EU-hosted foreign stack, opt2 (seal 3).

SOV-7 · Security & Compliance Sovereignty 67.8% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumcerts: BSI C5 + ISO 27001:2022/27017/27018 + SOC 2 Type II + TISAX + CSA STAR. Per key, BSI C5 is a high-assurance national cloud certification mapping to EAL3 -> opt4 (seal 3). C5 confirmed on Exoscale's own compliance page. (src: https://www.exoscale.com/compliance/)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4highDemonstrated GDPR and Swiss FADP compliance with a DPA, ISO 27001:2022, 27017/27018, SOC 2, TISAX and mappings to NIS2/DORA-relevant controls; partial-to-strong compliance across the EU regulatory set, though not a single all-encompassing independently audited attestation to every regime.
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3lowSecurity operations and incident handling run by Exoscale's European teams with European threat context; no formal ENISA/CSIRT sharing membership -> entire lifecycle by EU teams, opt4 (seal 3).
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3lowCustomers have direct access to monitoring and audit logs via portal/API, logs stored in EU/CH zones; not advertised as immutable tamper-proof -> full direct access, logs stored in EU, opt4 (seal 3).
SOV-7.5Disclosure of incidents4. Partial compliance, monitored flow, SLAs107/143SEAL-3mediumIncident disclosure follows GDPR/NIS2-aligned obligations with monitored notification flows and contractual SLAs, no real-time CSIRT sharing -> partial compliance, monitored flow, SLAs, opt4 (seal 3).
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowMaintenance operated by Exoscale with customer notice/windows; customers retain moderate autonomy over their own workloads with testing, except emergency patching -> moderate autonomy, opt3 (seal 4).
SOV-7.7Auditability3. Partial independent control72/143SEAL-1lowaudit_rights partial: independent audits performed by accredited certification bodies, compliance evidence shared under NDA; no contractual full audit by the contracting authority or any independent EU body -> partial independent control, opt3 (seal 1).

SOV-8 · Environmental Sustainability 56.3% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowModern Equinix/partner facilities selected for efficiency, plausibly PUE <1.5 with improvement roadmaps; no specific verified figure published -> opt3 PUE<1.5+roadmap (seal 4). (src: https://www.exoscale.com/sustainability/)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowHardware lifecycle/recycling addressed via a documented program within A1 Group ESG practices and partner DC operators, no EU-certified lifecycle claim -> documented program, opt3 (seal 3).
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2mediumSince 2021 Exoscale contributes to A1 Group's annual ESG report (energy, waste, travel); structured annual reporting but no standalone EU-audited methodology -> annual report, opt3 (seal 2).
SOV-8.4Energy supplies4. Only EU energy supplies (high renewable)188/250SEAL-4highEnergy is European-sourced and predominantly renewable: 100% renewable in CH, DE and AT zones, 91% in Croatia and 75% in Bulgaria, with green energy certificates available; only-EU/European supplies with a high renewable share. (src: https://www.exoscale.com/sustainability/)