🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Fly.io

United States · IaaS/PaaS · https://fly.io

Sovereignty score24.4%
Global (unweighted)22.7%
Overall SEAL
SEAL-0 No Sovereignty
SOV-1 Strategic Sovereignty16.7SEAL-0
SOV-2 Legal & Jurisdictional Sovereignty12.6SEAL-1
SOV-3 Data & AI Sovereignty25.0SEAL-0
SOV-4 Operational Sovereignty16.8SEAL-0
SOV-5 Supply Chain Sovereignty21.6SEAL-1
SOV-6 Technology Sovereignty50.0SEAL-0
SOV-7 Security & Compliance Sovereignty32.4SEAL-1
SOV-8 Environmental Sustainability6.3SEAL-0

SOV-1 · Strategic Sovereignty 16.7% · SEAL-0 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control1. Entirely outside the EU0/125SEAL-1highforeign_parent (US Delaware corp, Chicago HQ, no EU entity) -> entity entirely outside the EU -> SOV-1.1 opt1 (src: https://fly.io/legal/).
SOV-1.2Change of control risk4. Unlikely takeover/transfer to non-EU sovereign entity94/125SEAL-4lowPrivately held US company; a takeover transferring it to an EU sovereign entity is unlikely given US VC ownership; existing all-SEAL-4 factor choice kept.
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2mediumRoadmap set internally by the US company; customers give feedback via community forum/public channels only; no EU governance body -> SOV-1.3 opt2.
SOV-1.4Financial independence from non-EU capital1. Almost entirely relying on non-EU funding0/125SEAL-4highFunded almost entirely by US venture capital (a16z, Intel Capital, Dell Tech Capital, Accel, Bessemer); no material EU funding; all-SEAL-4 factor choice kept.
SOV-1.5EU economic contribution1. Minimal0/125SEAL-4mediumUS company with globally distributed remote team; economic activity overwhelmingly outside the EU; all-SEAL-4 factor choice kept.
SOV-1.6Participation in EU strategic programs1. No clear participation0/125SEAL-4highNo participation in EU strategic programs (Gaia-X, IPCEI-CIS); all-SEAL-4 factor choice kept.
SOV-1.7Alignment with EU industrial strategies1. No evidence exists0/125SEAL-4mediumNo evidence of alignment with EU industrial strategies; US commercial vendor; all-SEAL-4 factor choice kept.
SOV-1.8Resilience to cut-off2. Service would stop, with delay for customer reaction31/125SEAL-0lowNo own_stack continuity: a US political cut-off/sanction would stop the platform; customers can migrate (standard containers) with reaction delay, not continuity -> SOV-1.8 opt2 (seal 0).

SOV-2 · Legal & Jurisdictional Sovereignty 12.6% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction1. Non-EU only0/167SEAL-1highPrimary jurisdiction is US law (Delaware incorporation, US courts); not governed by EU law -> SOV-2.1 opt1 (src: https://fly.io/legal/).
SOV-2.2Extraterritorial laws exposure2. Mitigation clauses, exposure remains42/167SEAL-1highconsistency (cluster norm 2.2=opt2): US company exposed to US extraterritorial law (CLOUD Act, FISA 702); GDPR DPA/SCC + EU-US DPF mitigation clauses exist but residual exposure remains -> opt2 (seal 1) (src: https://fly.io/legal/data-privacy-framework/).
SOV-2.3Data access pathways for non-EU authorities2. Can compel access without notification, specific cases42/167SEAL-1highforeign_parent (US CLOUD Act/FISA) -> Fly.io can be compelled to disclose data, without notification under gag orders in specific cases -> SOV-2.3 opt2 (seal 1).
SOV-2.4Export control restrictions2. Restrictions towards EU citizens or international orgs42/167SEAL-1lowUS export-control regime could restrict service to certain EU persons/entities; no EU-shielded scoped offer -> SOV-2.4 opt2.
SOV-2.5Origin of IP1. Entirely outside the EU0/167SEAL-4highCore IP (fly-proxy, Machines orchestration, flyctl) developed by the US company entirely outside the EU; all-SEAL-4 factor; choice kept (opt1).
SOV-2.6IP holder jurisdiction1. Non-EU law, single country0/167SEAL-3highIP held by a single US legal entity (Fly.io Inc.) under Delaware law -> SOV-2.6 opt1.

SOV-3 · Data & AI Sovereignty 25.0% · SEAL-0 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys1. Provider only0/200SEAL-0highVolumes use AES-XTS/LUKS with keys managed entirely by Fly.io; no customer-managed key option, provider can read plaintext -> SOV-3.1 opt1 (seal 0).
SOV-3.2Transparent data flows & access logs2. Basic incomplete logs50/200SEAL-1lowObservability tooling exists but no independent real-time customer-controlled audit of provider data access; vendor-controlled, incomplete -> SOV-3.2 opt2.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowconsistency (cluster norm 3.3=opt3): volume/data deletion follows documented internal policy/DPA commitments with no independently verified cryptographic proof-of-erasure -> opt3 (internal validation per policy, seal 1).
SOV-3.4Data location strictly in EU/EEA2. Partly EU, significant third-country reliance50/200SEAL-0mediumNo eu_exclusive: EU regions exist but the platform is US-operated with global default behavior and no contractual no-third-country guarantee; significant third-country reliance -> SOV-3.4 opt2 (seal 0) (src: https://fly.io/docs/reference/regions/).
SOV-3.5AI services sovereignty2. Mostly non-EU: licensed AI, chip dependency50/200SEAL-2mediumAI offering is GPU machines on foreign (Nvidia) accelerators running customer-chosen models; no EU-origin AI stack; licensed/chip dependency -> SOV-3.5 opt2.

SOV-4 · Operational Sovereignty 16.8% · SEAL-0 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumWorkloads are standard OCI containers/Firecracker microVMs with documented export and standard tooling -> standard documented data export -> SOV-4.1 opt3.
SOV-4.2Ability to operate without foreign dependencies1. Critical ops delivered by non-EU teams0/167SEAL-1highNo eu_ops: critical operations run by a US-HQ globally distributed, predominantly non-EU team -> SOV-4.2 opt1.
SOV-4.3Skill availability in the EU2. Mixed, majority outside EU42/167SEAL-1mediumRemote-first global workforce on US pay schedule; skills mixed but majority outside the EU (heavy North America) -> SOV-4.3 opt2.
SOV-4.4Support channels1. Global, majority outside EU0/167SEAL-1mediumSmall remote support team staffed for North America and APAC timezones, i.e. majority outside the EU -> SOV-4.4 opt1.
SOV-4.5Documentation & knowledge transfer1. Global/non-EU exposure0/167SEAL-0lowDocumentation/internal knowledge maintained globally with no EU-residency requirement; global/non-EU exposure -> SOV-4.5 opt1.
SOV-4.6Subcontractor & supplier jurisdiction2. Service would stop with delay42/167SEAL-2lowRelies on non-EU suppliers (US payment/build partners, Nvidia hardware); a disruption would stop parts of the service with delay, no continuity guarantee -> SOV-4.6 opt2.

SOV-5 · Supply Chain Sovereignty 21.6% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowFly.io runs its own bare-metal servers but provides only partial public disclosure of physical component provenance -> SOV-5.1 opt2.
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1mediumServer hardware and GPUs (Nvidia A100/L40S/A10) are foreign-manufactured (US/Asia) with partial disclosure; nothing EU-built -> SOV-5.2 opt2.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/embedded code on foreign hardware (BIOS, GPU firmware, NICs) only partially disclosed; all-SEAL-4 factor; choice kept (opt2).
SOV-5.4Origin of software2. Foreign origin, partial disclosure36/143SEAL-2mediumPlatform software is self-developed by the US company (not foreign_core/licensed Google-MS), with open-source components (Firecracker, WireGuard, Linux/LUKS) giving partial transparency, but core maintenance is non-EU -> SOV-5.4 opt2 (seal 2).
SOV-5.5Software build/release jurisdiction1. Non-EU control & execution0/143SEAL-1mediumSoftware built and released under US control and executed by non-EU engineering; no EU control or EU policy gates -> SOV-5.5 opt1.
SOV-5.6Single point of dependency2. Mostly non-EU, undocumented36/143SEAL-1lowDepends on non-EU vendors for critical inputs (Nvidia GPUs, US build/payment partners, US corporate control) with limited documentation of EU alternatives -> SOV-5.6 opt2.
SOV-5.7Supply chain transparency2. Some suppliers auditable36/143SEAL-1lowSome suppliers/components publicly described, but no comprehensive auditable supply-chain transparency program -> SOV-5.7 opt2.

SOV-6 · Technology Sovereignty 50.0% · SEAL-0 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumStandards-based and broadly compatible (OCI containers, standard Linux, public Machines REST API, WireGuard) -> SOV-6.1 opt4.
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2mediumCore services adopt open standards (OCI images, HTTP, WireGuard, TLS) but adoption is partial, not a comprehensive policy -> SOV-6.2 opt3.
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3mediumKey technology is open source (Firecracker, flyctl, WireGuard) but the orchestration platform is vendor-controlled under centralized governance -> open source, centralised governance -> SOV-6.3 opt3 (seal 3). Not foreign_core, so no opt2 cap.
SOV-6.4Service architecture transparency4. Large corpus of public insight150/200SEAL-3highLarge corpus of public architecture insight (detailed blog posts, public docs on fly-proxy, Firecracker, networking) -> SOV-6.4 opt4.
SOV-6.5HPC sovereignty1. Imported black-box HPC0/200SEAL-0lowGPU/HPC relies on imported black-box Nvidia accelerators; no EU HPC design or fabrication; GPU product being deprecated -> SOV-6.5 opt1 (seal 0).

SOV-7 · Security & Compliance Sovereignty 32.4% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)2. EAL136/143SEAL-1highcerts: SOC 2 Type 2 only (no ISO 27001/SecNumCloud/EUCS/C5/ENS/Common Criteria EAL); per key SOC 2 without ISO 27001 maps to opt2 (EAL1-equiv, seal 1) (src: https://fly.io/docs/security/security-at-fly-io/).
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)3. Moderate compliance72/143SEAL-4mediumOffers a GDPR DPA and participates in EU-US DPF (moderate compliance) but no NIS2/DORA certification or independent EU audit; all-SEAL-4 factor; choice kept (opt3).
SOV-7.3EU-based SOC & incident handling1. SOC/IR outside EU0/143SEAL-1mediumSecurity operations and incident handling run by the US-HQ global team, not an EU-based SOC -> SOV-7.3 opt1.
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1lowconsistency (cluster norm 7.4=opt3): customers get an application logging/metrics monitoring portal but not full independent control of provider-side security monitoring with EU log residency -> opt3 (basic monitoring portal, seal 1).
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2lowIncident disclosure follows GDPR/DPA breach-notification (moderate, NIS2-aligned) without real-time CSIRT sharing -> SOV-7.5 opt3.
SOV-7.6Maintenance autonomy2. Limited autonomy (vendor schedules)36/143SEAL-1lowCustomers control their own app deployments but platform/host maintenance is vendor-scheduled with limited customer autonomy over the underlying stack -> SOV-7.6 opt2.
SOV-7.7Auditability2. Limited independent access36/143SEAL-1mediumNo audit_rights: independent assurance limited to SOC 2 reports shared under NDA; no provision for full independent audit by any entity -> SOV-7.7 opt2 (seal 1).

SOV-8 · Environmental Sustainability 6.3% · SEAL-0 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)1. PUE unmanaged/high0/250SEAL-1lowFly.io runs its own servers in colocation but publishes no PUE figures or energy-efficiency roadmap -> SOV-8.1 opt1.
SOV-8.2Hardware reuse & recycling2. Basic circular practices63/250SEAL-0lowNo documented hardware reuse/recycling program; at most basic circular practices implied by reusing bare-metal servers, no EU-aligned policy -> SOV-8.2 opt2 (seal 0).
SOV-8.3Environmental impact reporting1. No reporting0/250SEAL-1lowNo published environmental-impact or sustainability report identified -> SOV-8.3 opt1.
SOV-8.4Energy supplies1. Non traceable0/250SEAL-4lowEnergy sources not disclosed; relies on third-party colocation power with no traceable EU/green commitment; all-SEAL-4 factor; choice kept (opt1).