🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

GleSYS

Sweden · IaaS · https://glesys.com

Sovereignty score62.7%
Global (unweighted)64.3%
Overall SEAL
SEAL-1 Jurisdictional Sovereignty
SOV-1 Strategic Sovereignty61.6SEAL-2
SOV-2 Legal & Jurisdictional Sovereignty95.8SEAL-4
SOV-3 Data & AI Sovereignty65.0SEAL-1
SOV-4 Operational Sovereignty70.9SEAL-3
SOV-5 Supply Chain Sovereignty53.7SEAL-2
SOV-6 Technology Sovereignty45.0SEAL-2
SOV-7 Security & Compliance Sovereignty53.7SEAL-1
SOV-8 Environmental Sustainability68.8SEAL-2

SOV-1 · Strategic Sovereignty 61.6% · SEAL-2 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4highGleSYS AB is incorporated in Sweden; majority owned by Cube Infrastructure Managers (Luxembourg/Stockholm EU infrastructure fund) with the Swedish founder retaining a minority stake. Entity and control are entirely within the EU/EEA. (src: https://glesys.com/)
SOV-1.2Change of control risk3. Somewhat likely takeover/transfer to non-EU sovereign entity63/125SEAL-4mediumAs a PE-backed mid-market infrastructure firm (Cube Fund III), an eventual sale is plausible, though Cube is an EU investor and the sector trend favours EU buyers; a transfer to a non-EU sovereign entity is somewhat conceivable but not the base case.
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2lowNo published governance bodies with EU-actor participation; customers influence the roadmap mainly through standard support/sales 'voice of the customer' channels.
SOV-1.4Financial independence from non-EU capital4. Majority of funding is EU-based94/125SEAL-4mediumBacked by Cube Infrastructure Managers, a Luxembourg/Stockholm-based EU fund, plus prior Danish (VIA Equity) backing; funding is majority EU-based.
SOV-1.5EU economic contribution5. Fully in the EU125/125SEAL-4highAll operations, staff, data centres and revenue base are in Sweden and Finland; economic contribution is fully within the EU.
SOV-1.6Participation in EU strategic programs1. No clear participation0/125SEAL-4mediumNo clear evidence of participation in EU strategic programs such as Gaia-X or IPCEI-CIS; positions itself as a sovereign provider but without documented strategic-program involvement.
SOV-1.7Alignment with EU industrial strategies2. Existing action plan42/125SEAL-4lowMarkets itself around EU/Nordic sovereignty and renewable energy aligned with EU industrial aims; amounts to an existing positioning/action plan rather than measured governance with dedicated means.
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4mediumown_stack: vertically integrated EU provider that owns/operates its own EU data centres AND builds its own servers, with in-house teams able to source alternatives or internalise functions; only residual foreign-chip hardware as commodity input -> key 1.8 own_stack -> opt5 'Full autonomy and continuity' (seal 4), consistent with the Nordic OpenStack peers. (src: https://glesys.com/data-center/falkenberg)

SOV-2 · Legal & Jurisdictional Sovereignty 95.8% · SEAL-4 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highA Swedish company with EU ownership operating only EU/EEA data centres under EU jurisdiction; governed exclusively by EU/Swedish law with no non-EU parent imposing other jurisdiction. (src: https://glesys.com/)
SOV-2.2Extraterritorial laws exposure5. Verified legal immunity, non-EU laws unenforceable167/167SEAL-4mediumimmunity flag (a): pure-SE entity with an EU (Luxembourg/Stockholm) PE owner and no non-EU parent, subsidiary or operational nexus a foreign authority could compel -> key 2.2 immunity -> opt5 'Verified legal immunity' (seal 4), consistent with the pure-EU Nordic OpenStack peers (Elastx, Safespring). (src: https://glesys.com/)
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumNo foreign_parent and pure-EU no-nexus immunity: no non-EU jurisdictional hook to compel access (no US CLOUD Act/FISA reach); requests routed via MLAT/EU process and rejected -> SOV-2.3 opt5 (seal 4).
SOV-2.4Export control restrictions5. Part of offer shielded from restrictions towards EU MSs/intl orgs167/167SEAL-4lowPure-EU provider, revenue overwhelmingly in the EU, no non-EU technology gating its offer; the EU/EEA-exclusive sovereign offer is shielded from foreign export-control restrictions toward EU MSs and international orgs -> key 2.4 opt5 (seal 4), consistent with the Nordic OpenStack peers. (src: https://glesys.com/)
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4mediumGleSYS's own platform/automation software and operational IP are developed in-house in Sweden; underlying hypervisors and OS are largely open-source/foreign-origin, so IP is mostly within the EU.
SOV-2.6IP holder jurisdiction5. Fully under EU law167/167SEAL-4mediumGleSYS-developed IP is held by the Swedish entity under EU law; the company is fully EU-incorporated, placing its IP holding under EU jurisdiction.

SOV-3 · Data & AI Sovereignty 65.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys3. Shared - provider has override keys100/200SEAL-2lowGleSYS manages platform encryption (data at rest/in transit) while customers can manage their own application-level keys; the provider retains an override and there is no documented provider-incapable customer-exclusive (HYOK) offering -> key 3.1 shared (provider has override key) -> opt3 (seal 2). Safespring's customer-held-keys remains the cluster differentiator at opt5. (src: https://glesys.com/)
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowProvides monitoring and audit logs via its portal but with vendor-controlled, non-real-time independent auditability; no evidence of customer-controlled real-time oversight.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowISO 27001 ISMS implies documented deletion procedures validated against policy, but no customer-facing cryptographic proof-of-erasure is published.
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4mediumeu_exclusive: sovereign-cloud tier keeps all data in Swedish/Finnish DCs, never leaving sovereign borders, under EU Access Policy, no third-country fallback -> SOV-3.4 opt5 (seal 4). (src: https://glesys.com/locations/our-data-centers/)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3lowOffers dedicated GPU servers rather than a managed black-box AI service; customers run their own (often open-source/auditable) models on foreign-made accelerators, so no foreign-AI lock-in -> key judgment-call (no in-scope foreign AI dependency / EU-led AI on foreign accelerators) -> opt4 (seal 3), consistent with the Nordic OpenStack peers. (src: https://glesys.com/locations/our-data-centers/)

SOV-4 · Operational Sovereignty 70.9% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumStandard IaaS on KVM/VMware with documented APIs (public GitHub API docs) and standard export methods; portability via common formats but no special sovereign-migration guarantee beyond documented export.
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4mediumOwns and operates its full stack with the entire operation run from Sweden/Finland by EU-based teams; no critical operations delivered by non-EU teams.
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumA Nordic company with staff in Sweden and Finland; engineering and operations skills are EU-based, but no security-clearance regime is documented.
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3mediumSupport is delivered by GleSYS's own Nordic teams under a strict EU Access Policy ensuring only EU personnel handle EU data; all support staff EU-based but no security-clearance claim.
SOV-4.5Documentation & knowledge transfer3. EU primary with non-EU fallback84/167SEAL-4lowDocumentation and knowledge are maintained primarily in the EU by the in-house Nordic team; some public docs hosted on non-EU platforms (e.g. GitHub) act as fallback.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3lowOwns its data centres and builds its own servers, so it can source alternative suppliers or internalise functions if a hardware supplier were cut off, though full continuity is bounded by global chip supply.

SOV-5 · Supply Chain Sovereignty 53.7% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)3. Transparent with exceptions72/143SEAL-3lowGleSYS designs and builds its own servers and is transparent about owning its infrastructure, but underlying component (CPU/GPU/disk) provenance is foreign and only partially disclosed; transparent with exceptions.
SOV-5.2Manufacturing location4. Built by EU teams on foreign design107/143SEAL-3mediumServers are assembled/built in-house by GleSYS's EU teams from foreign-designed components (e.g. x86 CPUs), matching built-by-EU-teams-on-foreign-design.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowEmbedded firmware (BIOS/BMC/NIC) originates from foreign component vendors with only partial disclosure; no firmware-provenance certification published.
SOV-5.4Origin of software3. Core/essential parts maintained by EU teams72/143SEAL-3mediumCore control-plane/automation software is built and maintained in-house by EU teams; relies on foreign-origin but open hypervisors (KVM) and proprietary VMware for part of the stack, so essential parts are EU-maintained.
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3lowGleSYS controls and executes its own software builds/releases from its Nordic operations (EU control and execution), but no formal EU policy-gate attestation is documented.
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2lowSome non-EU vendors are unavoidable in critical services (hardware components, VMware licensing); dependencies are limited and documented but present in critical paths.
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowOwning its data centres and operations gives audit visibility into critical suppliers, but full upstream component supply-chain auditability is not demonstrated.

SOV-6 · Technology Sovereignty 45.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumOffers standards-based interfaces (documented REST API, standard VM formats, S3-compatible object storage) that are broadly compatible, though not fully open-by-default across all services.
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2lowAdopts open standards in core services (S3 API, standard hypervisor disk/VM formats, DNS) on a partial/ad-hoc basis rather than a published policy across all services.
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2lowBuilds on open-source foundations (Linux/KVM) but its own platform software is proprietary and not published; source is effectively vendor-controlled with limited external availability.
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowProvides public documentation, API references and infrastructure transparency (owns/operates its DCs), giving some public insight into architecture without full customer co-design.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowOffers GPU/HPC-style compute hosted in EU data centres but built on foreign accelerator and software stacks; EU-hosted with a foreign stack.

SOV-7 · Security & Compliance Sovereignty 53.7% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)2. EAL136/143SEAL-1mediumHolds ISO/IEC 27001:2022 (plus 9001/14001) but no SecNumCloud/EUCS/C5+ENS or Common Criteria EAL; per key, ISO 27001 only -> ~EAL1 opt2 (seal 1). No higher cert -> security cert remains a SEAL-1 gate. (src: https://glesys.com/sustainability/)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumFully GDPR-compliant and ISO/IEC 27001:2022 certified with an EU Access Policy; as an EU provider it is within NIS2 scope, but no independent DORA/full-suite audited attestation is documented, so partial compliance to most.
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3lowOperations and incident handling are run by GleSYS's own Nordic teams under an EU Access Policy, implying the full lifecycle is handled by EU teams; no ENISA/CSIRT formal sharing membership documented.
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1lowCustomers get a monitoring portal and logs but the provider retains primary control of security monitoring; no documented immutable customer-controlled logging.
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2lowAs a GDPR/NIS2-scoped EU provider it follows breach-notification obligations; incident disclosure is moderate and regulation-aligned without documented real-time CSIRT sharing or SLAs.
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowGleSYS controls maintenance of its own infrastructure with notice and testing windows for customers, giving moderate maintenance autonomy except for zero-day patching.
SOV-7.7Auditability3. Partial independent control72/143SEAL-1lowNo audit_rights flag: independent assurance is via ISO 27001 third-party auditors plus DPA customer audit rights (partial independent control), no contractual full audit by the contracting authority or any independent EU body (no SecNumCloud to imply it) -> key 7.7 -> opt3 (seal 1), consistent with the non-audit-rights Nordic peers. (src: https://glesys.com/sustainability/)

SOV-8 · Environmental Sustainability 68.8% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)4. PUE < 1.3188/250SEAL-4highGleSYS publishes a PUE of 1.28 (vs 1.57 global average), which falls below the 1.3 threshold. (src: https://glesys.com/sustainability/)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3mediumHas documented sustainability practices including 84% waste-heat reuse via district heating and ISO 14001 environmental management, indicating a documented hardware/resource program; no EU-certified full-lifecycle scheme stated.
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2mediumPublishes environmental metrics (PUE, renewable share, heat reuse) and holds ISO 14001, consistent with regular/annual environmental reporting rather than an EU-audited methodology.
SOV-8.4Energy supplies5. Only green EU energy supplies250/250SEAL-4highUses 100% renewable electricity with verified origin in its EU (Swedish/Finnish) data centres; only green EU energy supplies. (src: https://glesys.com/sustainability/)