🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Fuga Cloud

Netherlands · IaaS · https://fuga.cloud

Sovereignty score64.7%
Global (unweighted)61.1%
Overall SEAL
SEAL-1 Jurisdictional Sovereignty
SOV-1 Strategic Sovereignty82.3SEAL-4
SOV-2 Legal & Jurisdictional Sovereignty71.0SEAL-2
SOV-3 Data & AI Sovereignty65.0SEAL-1
SOV-4 Operational Sovereignty70.9SEAL-3
SOV-5 Supply Chain Sovereignty43.1SEAL-1
SOV-6 Technology Sovereignty65.0SEAL-3
SOV-7 Security & Compliance Sovereignty53.6SEAL-1
SOV-8 Environmental Sustainability37.6SEAL-1

SOV-1 · Strategic Sovereignty 82.3% · SEAL-4 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity (100% Dutch-owned Cyso Group, Alkmaar NL, no non-EU parent) -> SOV-1.1 opt4 (entirely within EU). (src: https://cyso.com/en/about-cyso/)
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4mediumPrivately held founder/owner-run Dutch hosting company since 1997 with no external non-EU capital; non-EU takeover very unlikely (existing all-SEAL-4 choice kept).
SOV-1.3Control over roadmap4. Full influence of EU actors125/125SEAL-4mediumeu_entity running open-governance OpenStack; EU customers and EU operator fully drive the roadmap -> SOV-1.3 opt4 (full EU influence).
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4mediumBootstrapped/self-funded Dutch company with no disclosed non-EU investors; funding effectively entirely EU-based (existing all-SEAL-4 choice kept).
SOV-1.5EU economic contribution5. Fully in the EU125/125SEAL-4highAll staff, infrastructure and revenue in NL/EU; economic contribution fully in the EU (existing all-SEAL-4 choice kept).
SOV-1.6Participation in EU strategic programs2. Limited participation31/125SEAL-4lowAligns with Gaia-X/EU sovereignty messaging but no evidence of named IPCEI-CIS participation; limited participation (existing all-SEAL-4 choice kept).
SOV-1.7Alignment with EU industrial strategies2. Existing action plan42/125SEAL-4lowMarkets EU digital sovereignty / Gaia-X posture (action plan) but no measured achievement or dedicated governance (existing all-SEAL-4 choice kept).
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4mediumown_stack: open-source OpenStack on Cyso's own NL/DE infrastructure with continuity depending on no non-EU vendor (foreign chips residual hardware only); same own-stack profile as Leafcloud/TransIP/Greenhost -> Full autonomy and continuity, opt5 (judgment call per key #1, normalised across the pure-EU Benelux own-stack providers). (src: https://cyso.com/en/about-cyso/)

SOV-2 · Legal & Jurisdictional Sovereignty 71.0% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4higheu_entity operating only in NL/DE data centres, governed exclusively by EU (Dutch/German) law -> SOV-2.1 opt3 (exclusively EU law). (src: https://cyso.cloud/trust-centre)
SOV-2.2Extraterritorial laws exposure4. Legal structures shielding from foreign law125/167SEAL-2mediumeu_entity with structural separation (pure-EU, no non-EU parent) but immunity NOT certified (no SecNumCloud/EUCS-High) -> SOV-2.2 opt4 'legal structures shielding' (seal 2), not certified opt5.
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumNo foreign_parent: not subject to US CLOUD Act/FISA/PRC compelled access and no legal basis to honour foreign orders -> SOV-2.3 opt5 (requests always rejected). (src: https://cyso.cloud/trust-centre)
SOV-2.4Export control restrictions3. Share of revenues >50% in the EU84/167SEAL-2lowEU-only provider with revenues overwhelmingly in the EU and no foreign-state export-control leverage, but no specifically documented shielding mechanism for the offer -> share of revenues >50% in EU, opt3. Normalised to match the other pure-EU Benelux providers (no documented export-control shielding).
SOV-2.5Origin of IP3. Mixed within/outside the EU84/167SEAL-4mediumCore platform is open-source OpenStack (globally developed) integrated/operated by EU teams; IP origin mixed within/outside EU -> SOV-2.5 opt3 (existing all-SEAL-4 choice kept).
SOV-2.6IP holder jurisdiction3. Mixed law, some EU84/167SEAL-3lowOpenStack IP governed under non-EU OpenInfra/Apache framework while Cyso code is EU-held; mixed law with some EU -> SOV-2.6 opt3.

SOV-3 · Data & AI Sovereignty 65.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys3. Shared - provider has override keys100/200SEAL-2lowStandard OpenStack IaaS: encryption is provider-operated but customers can layer their own keys/encryption, so control is shared with provider override rather than provider-only; no customer-exclusive HYOK -> SOV-3.1 opt3 (shared). Normalised to the common OpenStack-IaaS key-control posture across the pure-EU Benelux providers.
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowOpenStack provides usage/access logs available to customers but not real-time independently auditable; logs exist, largely vendor-controlled -> SOV-3.2 opt3.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowISO 27001/NEN 7510 imply deletion policies with internal validation but no published cryptographic proof-of-erasure -> SOV-3.3 opt3 (policy-only).
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4higheu_exclusive: data stored and replicated exclusively on Fuga/Cyso infra in Amsterdam and Frankfurt (EU/EEA), no third-country fallback -> SOV-3.4 opt5. (src: https://cyso.cloud/trust-centre)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3lowNo in-scope AI service (no foreign-AI dependency); per key, absence -> SOV-3.5 opt4 (seal 3).

SOV-4 · Operational Sovereignty 70.9% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4highStandard OpenStack with open APIs and S3-compatible storage plus documented export methods -> SOV-4.1 opt3 (documented data export).
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4mediumeu_ops: entire stack operated by Cyso's Dutch team in NL/DE with no non-EU operational dependency -> SOV-4.2 opt5 (fully EU team).
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumSmall Dutch company; all engineering/operations skills EU-based, no documented formal clearances -> SOV-4.3 opt4 (all EU staff).
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3mediumSupport delivered from the Netherlands by the Cyso team; all support staff EU-based, no advertised clearances -> SOV-4.4 opt4 (all support in EU).
SOV-4.5Documentation & knowledge transfer3. EU primary with non-EU fallback84/167SEAL-4lowDocumentation maintained in EU (docs.cyso.cloud) but uses common SaaS/CDN tooling with possible non-EU fallback -> SOV-4.5 opt3 (EU primary with fallback).
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3lowReliant on EU data-centre/transit suppliers plus open-source OpenStack; vanilla OSS + EU ops means it could source alternatives/internalise if a supplier failed -> SOV-4.6 opt4.

SOV-5 · Supply Chain Sovereignty 43.1% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowCommodity server hardware with no published bill-of-materials/provenance; only partial disclosure -> SOV-5.1 opt2.
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1lowServers are foreign-designed x86 commodity hardware manufactured abroad, no EU manufacturing; foreign origin, partial disclosure -> SOV-5.2 opt2.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/BIOS/microcode on commodity servers is vendor-proprietary and foreign; partial disclosure -> SOV-5.3 opt2 (existing all-SEAL-4 choice kept).
SOV-5.4Origin of software3. Core/essential parts maintained by EU teams72/143SEAL-3mediumNo foreign_core: core platform is open-source OpenStack with essential integration/operation maintained by Cyso's EU team running close-to-vanilla releases -> SOV-5.4 opt3 (core maintained by EU teams).
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3lowCyso controls and executes the build/integration/release of its own platform from the EU (upstream OpenStack is open-source consumed, not a controlling vendor), as for the other pure-EU OpenStack operators in the cluster -> EU control & execution, SOV-5.5 opt4 (seal 3). Normalised to Leafcloud/TransIP/Greenhost.
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2lowDepends on foreign-made hardware vendors for critical compute, documented and substitutable; few non-EU in critical services -> SOV-5.6 opt3 (seal 2).
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowOpen-source OpenStack fully auditable and ISO 27001 implies supplier controls, but full upstream hardware supply chain not all independently auditable; critical suppliers auditable -> SOV-5.7 opt3.

SOV-6 · Technology Sovereignty 65.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces5. Open-by-default with portability200/200SEAL-4highOpenStack and S3-compatible APIs are open by default with strong portability and no proprietary lock-in -> SOV-6.1 opt5 (open-by-default).
SOV-6.2Open standards compliance5. Policy for all core services200/200SEAL-4highOpenStack adheres to the '4 Opens' across all core services -> SOV-6.2 opt5 (policy for all core).
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3highPlatform is fully open-source OpenStack but upstream governance is centralised in the non-EU OpenInfra Foundation -> SOV-6.3 opt3 (open source, centralised governance).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3mediumRunning vanilla open-source OpenStack with public documentation gives substantial public insight into the architecture -> SOV-6.4 opt3 (some public insight).
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowNo dedicated in-scope HPC offering; any high-performance compute is EU-hosted on a foreign hardware/accelerator stack -> SOV-6.5 opt2 (seal 3).

SOV-7 · Security & Compliance Sovereignty 53.6% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)2. EAL136/143SEAL-1highCerts held are ISO 20000 + ISO 27001 + NEN 7510 only (no SecNumCloud/EUCS/C5/SOC2/Common Criteria EAL); per key ISO 27001 only -> SOV-7.1 opt2 'EAL1' (seal 1). GATING CAP. (src: https://docs.cyso.cloud/faq/security-privacy/does-fuga-cloud-have-certifications/)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumGDPR-compliant and ISO 27001/NEN 7510 certified EU provider; partial compliance to most relevant regulations (GDPR/NIS2/DORA) -> SOV-7.2 opt4 (existing all-SEAL-4 choice kept).
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3loweu_ops: security monitoring, incident handling and internal security officer all in NL/EU; full incident lifecycle by EU teams, no documented ENISA sharing -> SOV-7.3 opt4 (EU lifecycle).
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1lowOpenStack provides customer monitoring/logging via portal/CLI but not full immutable tamper-proof access; basic-to-moderate monitoring -> SOV-7.4 opt3.
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2lowEU/Dutch provider following GDPR/NIS2-aligned breach-notification obligations; moderate compliance -> SOV-7.5 opt3.
SOV-7.6Maintenance autonomy4. High autonomy (deploy independently, no checks)107/143SEAL-4lowOperating its own OpenStack platform, Cyso can deploy patches/maintenance independently on its own schedule; high autonomy -> SOV-7.6 opt4.
SOV-7.7Auditability2. Limited independent access36/143SEAL-1lowNo audit_rights: ISO 27001/NEN 7510 give cert-body assurance only; customers cannot perform unrestricted independent audits (no SecNumCloud/tender-grade audit clause) -> SOV-7.7 opt2 (seal 1). GATING CAP. (src: https://docs.cyso.cloud/faq/security-privacy/does-fuga-cloud-have-certifications/)

SOV-8 · Environmental Sustainability 37.6% · SEAL-1 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)2. PUE < 363/250SEAL-1lowNo published PUE; TIER 3 DCs in Amsterdam/Frankfurt but no disclosed PUE figure or efficiency roadmap; conservatively PUE < 3 -> SOV-8.1 opt2.
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowCSR statement references hardware lifecycle management (decommissioned hardware repurposed/donated) and circular intent; documented program but not EU-certified -> SOV-8.2 opt3.
SOV-8.3Environmental impact reporting2. Basic reporting63/250SEAL-1lowSustainability mentioned (Green-IT, CO2-neutral fleet, CSR) but no detailed annual environmental impact report published; basic reporting -> SOV-8.3 opt2.
SOV-8.4Energy supplies3. Mix of EU and non-EU supplies125/250SEAL-4lowData centres in NL and DE on EU grids but no specific green/renewable energy sourcing documented; conservatively a mix of EU energy supplies -> SOV-8.4 opt3 (existing all-SEAL-4 choice kept).