🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Gcore

Luxembourg · IaaS/PaaS · https://gcore.com

Sovereignty score40.7%
Global (unweighted)40.3%
Overall SEAL
SEAL-0 No Sovereignty
SOV-1 Strategic Sovereignty41.8SEAL-2
SOV-2 Legal & Jurisdictional Sovereignty58.5SEAL-1
SOV-3 Data & AI Sovereignty40.0SEAL-1
SOV-4 Operational Sovereignty33.5SEAL-1
SOV-5 Supply Chain Sovereignty32.4SEAL-1
SOV-6 Technology Sovereignty45.0SEAL-2
SOV-7 Security & Compliance Sovereignty39.6SEAL-1
SOV-8 Environmental Sustainability31.4SEAL-0

SOV-1 · Strategic Sovereignty 41.8% · SEAL-2 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control3. Mostly within the EU83/125SEAL-3higheu_entity (parent G-Core Labs S.A. incorporated/HQ in Contern, Luxembourg) but large non-EU operational footprint (Cyprus, Serbia, Georgia, Uzbekistan, South Korea) -> control mostly but not entirely within the EU -> SOV-1.1 opt3. (src: https://fedil.lu/en/members/13336c49-7d74-ed11-81aa-6045bd87097c/)
SOV-1.2Change of control risk3. Somewhat likely takeover/transfer to non-EU sovereign entity63/125SEAL-4mediumPrivately held, VC-backed (2024 Series A led by Wargaming, Constructor Capital, Han River, Northern Data) with global non-EU investors -> somewhat-likely takeover/transfer risk -> opt3 (all SOV-1.2 options seal 4).
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2lowNo published governance bodies giving EU actors a roadmap vote; influence limited to customer feedback channels -> SOV-1.3 opt2 (kept at existing all-seal choice).
SOV-1.4Financial independence from non-EU capital2. Mostly relying on non-EU funding31/125SEAL-4highSole funding round (USD 60M Series A 2024) led by non-EU capital (Wargaming, Constructor Capital, Han River, Northern Data) -> mostly non-EU funding -> opt2 (all SOV-1.4 options seal 4).
SOV-1.5EU economic contribution3. Balanced EU/non-EU63/125SEAL-4lowEU HQ/offices contribute to the EU economy but large share of staff, PoPs and revenue generated outside the EU -> roughly balanced EU/non-EU contribution -> opt3 (kept).
SOV-1.6Participation in EU strategic programs2. Limited participation31/125SEAL-4lowNo evidence of Gaia-X membership or IPCEI-CIS participation; involvement in EU strategic programs limited at best -> opt2 (kept).
SOV-1.7Alignment with EU industrial strategies2. Existing action plan42/125SEAL-4lowMarkets 'sovereign cloud' and EU AI offerings (action plan) but no measured governance or dedicated sovereignty program evidenced -> opt2 (kept).
SOV-1.8Resilience to cut-off3. Can continue temporarily per contractual agreement63/125SEAL-2lowown_stack only partial: owns its network and Tier III/IV facilities so service can continue temporarily, but deep critical dependency on non-EU chips (NVIDIA, Graphcore) and global colocation breaks full autonomy -> 'continue temporarily' opt3 (seal 2).

SOV-2 · Legal & Jurisdictional Sovereignty 58.5% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction2. Mixed EU/non-EU84/167SEAL-1mediumEU parent under Luxembourg law but global subsidiaries/operations span non-EU jurisdictions (Cyprus, Georgia, Uzbekistan, Serbia, South Korea) -> mixed EU/non-EU law -> SOV-2.1 opt2 (seal 1). (src: https://fedil.lu/en/members/13336c49-7d74-ed11-81aa-6045bd87097c/)
SOV-2.2Extraterritorial laws exposure3. EU subsidiary with contractual protections84/167SEAL-1mediumNo immunity: no SecNumCloud/EUCS-High, and extensive non-EU operational nexus (Georgia, Uzbekistan, Serbia, S. Korea) is compellable. EU-incorporated parent gives GDPR-aligned contractual protections only -> 'EU subsidiary with contractual protections' opt3 (seal 1). (src: https://gcore.com/secure-infrastructure)
SOV-2.3Data access pathways for non-EU authorities4. Requests disputed, sometimes accepted with notification125/167SEAL-1lowNo foreign_parent (independent EU-incorporated, not US/PRC-owned) so not capped by CLOUD Act/FISA; but global subsidiaries (Georgia, Uzbekistan, Cyprus) can face local legal requests and no commit to always-reject -> 'requests disputed, sometimes accepted with notification' opt4 (seal 1). (src: https://gcore.com/secure-infrastructure)
SOV-2.4Export control restrictions3. Share of revenues >50% in the EU84/167SEAL-2lowNo export restrictions evident toward EU member states and substantial European revenue, but no scoped offer formally shielded from restrictions -> 'share of revenues >50% in EU' opt3 (seal 2).
SOV-2.5Origin of IP3. Mixed within/outside the EU84/167SEAL-4lowCore CDN/cloud software developed in-house by EU/CIS engineering, but AI-accelerator IP and key hardware originate outside the EU -> mixed within/outside-EU IP origin -> opt3 (kept; all SOV-2.5 seal 4).
SOV-2.6IP holder jurisdiction4. EU law with exceptions125/167SEAL-4lowSoftware IP held by the Luxembourg parent under EU law, with some foreign-developed/licensed components -> 'EU law with exceptions' opt4.

SOV-3 · Data & AI Sovereignty 40.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys2. Primarily provider, not exclusively50/200SEAL-1lowStandard provider-managed encryption (AES 128/256); no documented customer-exclusive HYOK/BYOK preventing provider access -> 'primarily provider, not exclusively' opt2.
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowLogging/IDS/access controls with monitoring portal, but logs vendor-controlled and not independently real-time auditable -> 'logs exist but not real-time / vendor-controlled' opt3.
SOV-3.3Secure deletion & proof of erasure2. Manual confirmation only50/200SEAL-1lowGDPR deletion supported but no published verifiable proof-of-erasure; effectively manual confirmation -> opt2.
SOV-3.4Data location strictly in EU/EEA3. Mainly EU, some third-country use with safeguards100/200SEAL-1mediumNot eu_exclusive: EU training regions exist but default network is global by design (180+ PoPs / 50+ cloud locations, six continents) with no contractually EU-exclusive scoped offer -> 'mainly EU, some third-country use with safeguards' opt3 (seal 1). (src: https://gcore.com/infrastructure)
SOV-3.5AI services sovereignty3. Mixed: auditable/open-source AI, foreign chips100/200SEAL-2mediumAI supports open-source/auditable models and EU training regions but runs on foreign accelerators (NVIDIA GPUs, Graphcore IPUs) -> 'mixed: auditable/open-source AI, foreign chips' opt3 (seal 2).

SOV-4 · Operational Sovereignty 33.5% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumStandards-based cloud APIs, S3-compatible storage and documented export methods -> 'standard documented data export methods' opt3 (seal 4).
SOV-4.2Ability to operate without foreign dependencies2. Ops partially sourced within EU42/167SEAL-1mediumNot eu_ops: engineering/operations spread across EU and non-EU hubs (Lithuania, Poland alongside Georgia, Uzbekistan, Cyprus, Serbia, Korea) -> ops only partially EU-sourced -> opt2 (seal 1).
SOV-4.3Skill availability in the EU2. Mixed, majority outside EU42/167SEAL-1medium600+ staff distributed globally with major engineering hubs outside the EU (Tbilisi, Tashkent, Belgrade, Nicosia, Seoul) -> mixed, majority likely outside EU -> opt2 (seal 1).
SOV-4.4Support channels2. Mixed, majority outside EU42/167SEAL-2lowGlobal 24/7 support with staff across non-EU offices -> mixed, majority outside EU -> opt2 (seal 2).
SOV-4.5Documentation & knowledge transfer2. EU optional, not enforced42/167SEAL-2lowDocumentation/knowledge maintained across a global organisation; no EU-only repository or enforced knowledge transfer -> 'EU optional, not enforced' opt2 (seal 2).
SOV-4.6Subcontractor & supplier jurisdiction3. Continue temporarily per contractual agreement84/167SEAL-3lowRelies on third-party colocation and chip suppliers; Tier III/IV facilities and multi-day autonomy suggest temporary continuity under contract if a supplier were cut off -> opt3 (seal 3).

SOV-5 · Supply Chain Sovereignty 32.4% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowHardware (NVIDIA, Graphcore, x86 servers, Equinix/Intel) is foreign-origin with only partial provenance disclosure -> 'partial disclosure' opt2.
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1lowServers/accelerators manufactured outside the EU (US/Asia foundries/OEMs) with limited disclosure -> 'foreign origin, partial disclosure' opt2.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/embedded code from foreign OEMs with partial disclosure -> opt2 (kept; all SOV-5.3 seal 4).
SOV-5.4Origin of software3. Core/essential parts maintained by EU teams72/143SEAL-3lowNo foreign_core: core CDN/cloud/edge platform software developed and maintained in-house by EU/CIS teams (not licensed Google/MS/AWS), with foreign third-party components layered in -> 'core/essential parts maintained by EU teams' opt3 (seal 3).
SOV-5.5Software build/release jurisdiction3. Non-EU control, EU execution72/143SEAL-3lowBuild/release controlled by the company but engineering execution distributed across EU and non-EU teams -> 'non-EU control, EU execution' / EU presence -> opt3 (seal 3).
SOV-5.6Single point of dependency2. Mostly non-EU, undocumented36/143SEAL-1lowCritical dependencies on non-EU chip vendors (NVIDIA, Graphcore) and global colocation, mostly non-EU and not fully documented -> 'mostly non-EU, undocumented' opt2.
SOV-5.7Supply chain transparency2. Some suppliers auditable36/143SEAL-1lowSome suppliers/facilities documented (Tier III/IV, named partners) but full supply chain not comprehensively customer-auditable -> 'some suppliers auditable' opt2.

SOV-6 · Technology Sovereignty 45.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumStandards-based, S3-compatible and OpenStack-style APIs supporting interoperability without heavy lock-in -> 'standards-based and broadly compatible' opt4.
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2lowAdopts common open standards (S3, OpenStack, standard networking/streaming) for core services but no published open-standards-for-all policy -> 'partial core adoption' opt3.
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2lowCore cloud/CDN stack is predominantly proprietary/vendor-controlled though some OSS use/contribution; no foreign_core but source largely closed -> 'source available for review, strict rights' opt2 (seal 2).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowPublic documentation, technical blogs and architecture overviews give some public insight -> 'some public insight' opt3.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3mediumHPC/AI compute is EU-hostable but runs entirely on a foreign hardware/software stack (NVIDIA, Graphcore IPUs) -> 'EU-hosted, foreign stack' opt2 (seal 3).

SOV-7 · Security & Compliance Sovereignty 39.6% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)2. EAL136/143SEAL-1highHolds ISO/IEC 27001 + PCI DSS (+ GDPR), but no SecNumCloud/EUCS/C5/ENS or Common Criteria EAL; per key ISO-27001-grade maps to ~EAL1 -> opt2 (seal 1). Consistent with Anexia's ISO-27001->opt2 mapping; not EAL0/none since an accredited ISMS certification exists. (src: https://gcore.com/secure-infrastructure)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)3. Moderate compliance72/143SEAL-4mediumISO 27001 and PCI DSS held plus GDPR compliance, indicating moderate adherence; no independently-audited full NIS2/DORA evidence -> 'moderate compliance' opt3 (kept; all SOV-7.2 seal 4).
SOV-7.3EU-based SOC & incident handling2. Hybrid EU/non-EU36/143SEAL-1lowSecurity operations run by a global team with hubs inside and outside the EU -> hybrid EU/non-EU SOC -> opt2 (seal 1).
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1lowMonitoring portal, 2FA and API token controls, but no full customer-controlled EU-resident immutable logging evidenced -> 'basic monitoring portal' opt3 (seal 1).
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2lowEU-based GDPR provider following GDPR/NIS2-aligned breach disclosure -> 'moderate (GDPR/NIS2-aligned)' opt3 (seal 2).
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowOperates its own infrastructure/software with moderate maintenance autonomy (notice + testing windows), subject to vendor firmware/chip updates -> opt3 (seal 4).
SOV-7.7Auditability2. Limited independent access36/143SEAL-1lowNo audit_rights: access limited to certification audits (ISO 27001/PCI QSA); no full independent audit by any entity -> 'limited independent access' opt2 (seal 1). (src: https://gcore.com/secure-infrastructure)

SOV-8 · Environmental Sustainability 31.4% · SEAL-0 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)2. PUE < 363/250SEAL-1lowTier III/IV colocation generally efficient but no verified fleet-wide PUE published; no sub-1.5 commitment -> 'PUE < 3' opt2 (seal 1). (src: https://gcore.com/infrastructure)
SOV-8.2Hardware reuse & recycling2. Basic circular practices63/250SEAL-0lowNo detailed hardware reuse/recycling program published; assumed basic circular practices via colocation partners -> 'basic circular practices' opt2 (seal 0).
SOV-8.3Environmental impact reporting2. Basic reporting63/250SEAL-1lowNo comprehensive annual environmental report with EU methodology; only basic environmental messaging -> 'basic reporting' opt2 (seal 1).
SOV-8.4Energy supplies3. Mix of EU and non-EU supplies125/250SEAL-4lowOperating across six continents in third-party data centres; energy supply is a mix of EU and non-EU sources, no verified all-green/all-EU commitment -> opt3 (kept; all SOV-8.4 seal 4).