🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Gigas

Spain · IaaS/PaaS · https://gigas.com

Sovereignty score62.1%
Global (unweighted)60.8%
Overall SEAL
SEAL-1 Jurisdictional Sovereignty
SOV-1 Strategic Sovereignty69.9SEAL-2
SOV-2 Legal & Jurisdictional Sovereignty83.3SEAL-2
SOV-3 Data & AI Sovereignty65.0SEAL-1
SOV-4 Operational Sovereignty62.6SEAL-3
SOV-5 Supply Chain Sovereignty50.2SEAL-2
SOV-6 Technology Sovereignty40.0SEAL-2
SOV-7 Security & Compliance Sovereignty71.4SEAL-2
SOV-8 Environmental Sustainability43.8SEAL-1

SOV-1 · Strategic Sovereignty 69.9% · SEAL-2 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity: Gigas Hosting, S.A. is a Spanish company (Madrid/Alcobendas) listed on BME Growth (ticker GIGA), controlling entity entirely within the EU with no non-EU parent -> opt4. (src: https://en.wikipedia.org/wiki/Gigas_(company))
SOV-1.2Change of control risk4. Unlikely takeover/transfer to non-EU sovereign entity94/125SEAL-4mediumSmall-cap publicly listed Spanish company with distributed ownership and founder/management involvement; non-EU takeover conceivable for a micro-cap free-float but not currently signalled -> unlikely (opt4).
SOV-1.3Control over roadmap4. Full influence of EU actors125/125SEAL-4mediumEU-owned autonomous company controlling its own roadmap (proprietary Gyper virtualization, Biblion AI); EU actors have full influence -> opt4.
SOV-1.4Financial independence from non-EU capital4. Majority of funding is EU-based94/125SEAL-4mediumEarly funding from EU VCs (Cabiedes & Partners, Bonsai Venture Capital, Caixa Capital Risc) and now BME Growth listing; majority EU-based funding, free-float allows some non-EU shareholding -> opt4.
SOV-1.5EU economic contribution4. Majority in the EU94/125SEAL-4mediumHQ, listing and core engineering in Spain, but material non-EU operations (Miami datacenter, offices/DCs in Chile, Colombia, Peru); economic contribution majority-EU rather than fully EU -> opt4.
SOV-1.6Participation in EU strategic programs2. Limited participation31/125SEAL-4mediumMember of Gaia-X and CISPE indicating participation in EU sovereignty initiatives, but no lead role in flagship programs like IPCEI-CIS; limited participation -> opt2.
SOV-1.7Alignment with EU industrial strategies2. Existing action plan42/125SEAL-4mediumPositions itself as a sovereign cloud aligned with EU data-sovereignty goals (Gaia-X, CISPE) with an action plan around data residency, but lacks measured achievement with dedicated sovereignty governance at scale -> opt2 (existing action plan).
SOV-1.8Resilience to cut-off4. Ability to source alternatives or internalise key functions94/125SEAL-2lowown_stack partial: EU operator running its own KVM-based Gyper stack on leased/colocated DCs could source alternatives or internalise if cut off, but not full autonomy given foreign hardware/chip dependency and no documented vertically-integrated continuity plan -> opt4 (seal 2).

SOV-2 · Legal & Jurisdictional Sovereignty 83.3% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4mediumSpanish company; EU-hosted services governed exclusively by Spanish/EU law (its US/LatAm footprint is contractually separate from the EU offering) -> opt3 (exclusively EU law). (src: https://gigas.com/en/seguridad.html)
SOV-2.2Extraterritorial laws exposure4. Legal structures shielding from foreign law125/167SEAL-2mediumeu_entity with EU control and no US/non-EU parent shields from extraterritorial regimes, but Gigas has non-EU subsidiaries/operations (Miami DC, LatAm) compellable as an operational nexus and holds NO SecNumCloud/EUCS-High, so immunity is structural-not-certified -> opt4 'Legal structures shielding' (seal 2 ceiling), consistent with the Spanish-provider basis. (src: https://gigas.com/en/seguridad.html)
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumNo non-EU parent and EU-hosted data under Spanish law; not subject to US CLOUD Act/FISA/PRC compelled access for the EU offering, requests would be rejected -> opt5 (no foreign_parent).
SOV-2.4Export control restrictions3. Share of revenues >50% in the EU84/167SEAL-2lowEU-controlled software/ops with no non-EU vendor able to impose export controls against EU MSs; conservatively scored mid given the multi-continent footprint -> opt3 (>50% EU revenue).
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4mediumCore platform IP (Gyper KVM-based virtualization, Biblion AI, control plane) developed in-house in Spain; integrates third-party open source and foreign hardware IP -> mostly within the EU (opt4).
SOV-2.6IP holder jurisdiction5. Fully under EU law167/167SEAL-4mediumIP holder is Gigas Hosting, S.A., a Spanish entity; its own software IP is held fully under EU law -> opt5.

SOV-3 · Data & AI Sovereignty 65.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys3. Shared - provider has override keys100/200SEAL-2lowIaaS/PaaS with provider-managed encryption and no published HYOK/confidential-computing; the provider retains administrative access and override keys, consistent with the other Spanish IaaS providers -> shared control with provider override (opt3). (src: https://gigas.com/en/seguridad.html)
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowAccess logs/monitoring consistent with ISO 27001 and SOC 2 Type II, but real-time independent customer auditability not documented; logs exist but vendor-controlled -> opt3.
SOV-3.3Secure deletion & proof of erasure4. Deletion technically verified with access logs150/200SEAL-3lowENS-High plus ISO 27001/27018 mandate verified media-sanitisation controls with access logging, so deletion is technically verified with logs (uniform sovereign-operator basis, consistent with the cluster) -> opt4. (src: https://gigas.com/en/seguridad.html)
SOV-3.4Data location strictly in EU/EEA4. EU by default, tightly controlled exceptions150/200SEAL-1mediumGENUINE differentiator vs EU-only Spanish peers: the product spans EU DCs (Spain, Portugal, Ireland) AND third-country DCs (Miami, Chile, Colombia, Peru) with no contractual EU-only no-third-country-fallback guarantee; EU-by-default with controlled exceptions -> opt4 (seal 1, gating cap). (src: https://gigas.com/en/)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3mediumBiblion is a sovereign GenAI offering run in Gigas's private EU cloud (RAG over LLMs, data kept on Gigas infra); EU-led/operated AI on foreign accelerators and foreign-origin base models -> opt4 (EU-led AI, foreign accelerators).

SOV-4 · Operational Sovereignty 62.6% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumStandards-based IaaS/PaaS with documented data export; positions as a VMware/hyperscaler migration target with formal migration support -> opt4.
SOV-4.2Ability to operate without foreign dependencies4. Ops predominantly EU-based teams125/167SEAL-3mediumeu_ops partial: operations run predominantly by Gigas's own teams, but support/ops span EU and LatAm offices, so the stack is predominantly but not exclusively EU-team-managed -> opt4 (predominantly EU, seal 3).
SOV-4.3Skill availability in the EU3. Majority EU, escalation abroad84/167SEAL-3mediumEngineering anchored in Spain/EU but significant teams in LatAm (Colombia, Chile, Peru); majority EU with escalation abroad -> opt3.
SOV-4.4Support channels3. Majority in EU, non-EU escalations84/167SEAL-3medium24/7 support in Spanish, Portuguese and English from offices across its regions including LatAm; majority in EU for European customers with non-EU escalation -> opt3.
SOV-4.5Documentation & knowledge transfer3. EU primary with non-EU fallback84/167SEAL-4lowDocumentation maintained in-house by Gigas, but given LatAm operations EU-primary with non-EU fallback is the realistic posture -> opt3 (seal 4).
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3lowControls its own virtualization and core operations; for non-critical foreign supplier dependencies (hardware/colocation) could source alternatives or internalise, ensuring continuity -> opt4 (seal 3).

SOV-5 · Supply Chain Sovereignty 50.2% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)3. Transparent with exceptions72/143SEAL-3lowServer hardware/GPUs are foreign-made, but as an ISO 27001 / ENS-High certified operator Gigas provides component transparency to customers/auditors with exceptions (uniform sovereign-operator basis, consistent with the cluster); provenance not EU-certified -> transparent with exceptions (opt3).
SOV-5.2Manufacturing location3. Mixed sourcing, EU audit rights72/143SEAL-3mediumHardware is foreign-designed/mixed-sourced but integrated and operated under ISO 27001 / ENS-High audited supply-chain controls (EU audit rights), matching the uniform key for EU sovereign providers -> mixed sourcing, EU audit rights (opt3).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowEmbedded firmware (BIOS, BMC, NIC/GPU) from foreign OEMs with partial provenance disclosure typical of commodity hardware -> opt2 (seal 4 factor).
SOV-5.4Origin of software3. Core/essential parts maintained by EU teams72/143SEAL-3mediumNo foreign_core: core/essential platform software (Gyper KVM-based virtualization, control plane, Biblion) built and maintained by Gigas EU teams on open source; foreign components exist but core is EU-maintained -> opt3 (seal 3).
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3lowBuild and release of the proprietary Gyper/control-plane software controlled and executed by Gigas's Spain-based engineering; EU control and EU execution -> opt4.
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2mediumMain single point of non-EU dependency is foreign chip/hardware vendors (Intel/AMD/NVIDIA) and some non-EU colocation in critical compute; documented but unavoidable for the segment -> opt3 (few non-EU critical, seal 2).
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowCritical suppliers (datacentre/colocation, hardware) identifiable and auditable under ISO 27001 supplier governance, but full end-to-end supply-chain audit rights not published -> opt3 (critical only, seal 2).

SOV-6 · Technology Sovereignty 40.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces3. Mixed (partial openness)100/200SEAL-2mediumProprietary KVM-based Gyper platform with standard cloud/VPS APIs offers partial openness/compatibility but is not open-by-default, consistent with the other Spanish IaaS providers' proprietary-stack-with-standard-APIs posture -> mixed partial openness (opt3).
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2lowOpen standards (KVM, standard cloud/storage protocols) adopted at the core, but no published open-standards policy across all services; partial core adoption -> opt3.
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2mediumGyper virtualization is proprietary (KVM-based) and not open-sourced; platform largely closed/vendor-controlled with open-source underpinnings, source not openly available -> opt2 (seal 2).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowPublic documentation and product/architecture information via site and support; some public insight into service architecture -> opt3.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowAny GPU/HPC compute for AI (Biblion) is EU-hosted but runs on a fully foreign accelerator stack (NVIDIA/AMD); EU-hosted, foreign stack -> opt2 (seal 3).

SOV-7 · Security & Compliance Sovereignty 71.4% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumHolds ENS Alto (High) (obtained Feb 2026) plus ISO 27001/27018, PCI-DSS L1 and SOC 1/2 Type II; per key, ENS-High is a high-assurance national cloud certification mapping to EAL3 (opt4), consistent with the other ENS-High Spanish providers -> opt4 (EAL3, seal 3). (src: https://gigas.com/blog/es/empresas-ens-alto-gigas-blinda-su-estrategia-cloud/)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4highHolds ISO 27001, ISO 27018, ENS High, PCI-DSS Level 1 and SOC 1/2 Type II, adheres to CISPE code, states GDPR compliance; partial compliance to most EU regulations, no explicit independently audited DORA/NIS2 attestation -> opt4. (src: https://gigas.com/en/seguridad.html)
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3lowSecurity operations and incident handling run by Gigas's own teams under ISO 27001/SOC 2 with EU-anchored operations; EU-team-led lifecycle, though formal ENISA/CSIRT real-time sharing and clearances not documented -> opt4 (seal 3).
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3lowCustomers have direct access to monitoring/logs via the management portal with EU-hosted logging for EU services (ENS-High mandates security-log access/traceability); immutable tamper-proof logging not explicitly documented -> full direct access, logs stored in EU (opt4), consistent with the cluster.
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2mediumOperates under GDPR-aligned incident-disclosure obligations as an EU/ENS-certified provider; moderate GDPR/NIS2-aligned disclosure -> opt3 (seal 2).
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowManages its own maintenance with customer notice/testing windows typical of an EU operator controlling its stack; moderate autonomy -> opt3 (seal 4).
SOV-7.7Auditability5. Full independent audit by any entity143/143SEAL-4lowaudit_rights: the ENS-High sovereign offer for Spanish public administration implies tender-grade full audit rights for the contracting authority and independent EU bodies (uniform basis with the cluster's ENS-High/ACN-qualified members) -> full independent audit (opt5). (src: https://gigas.com/blog/es/empresas-ens-alto-gigas-blinda-su-estrategia-cloud/)

SOV-8 · Environmental Sustainability 43.8% · SEAL-1 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowUses Tier III/IV certified datacentres (Interxion/Equinix-class) that are modern and efficient; no public Gigas-specific PUE, so conservatively PUE<1.5 with a sustainability roadmap rather than verified sub-1.2 -> opt3 (seal 4).
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowOperating in certified colocation facilities implies a documented hardware lifecycle/recycling program, but no EU-certified circular-economy lifecycle published -> opt3 (documented program, seal 3).
SOV-8.3Environmental impact reporting2. Basic reporting63/250SEAL-1lowAs a BME Growth listed company Gigas publishes financial and some sustainability information, but no detailed EU-methodology environmental report for its datacentres is evident -> opt2 (basic reporting, seal 1).
SOV-8.4Energy supplies3. Mix of EU and non-EU supplies125/250SEAL-4lowEU datacentres draw on EU grids, but no published commitment to exclusively green/renewable energy and it operates non-EU facilities (Miami, LatAm); mix of EU and non-EU supplies -> opt3. (src: https://gigas.com/en/)