🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

gridscale

Germany · IaaS/PaaS · https://www.gridscale.io

Sovereignty score66.0%
Global (unweighted)66.7%
Overall SEAL
SEAL-1 Jurisdictional Sovereignty
SOV-1 Strategic Sovereignty73.0SEAL-2
SOV-2 Legal & Jurisdictional Sovereignty87.4SEAL-2
SOV-3 Data & AI Sovereignty70.0SEAL-1
SOV-4 Operational Sovereignty62.6SEAL-3
SOV-5 Supply Chain Sovereignty57.2SEAL-2
SOV-6 Technology Sovereignty50.0SEAL-2
SOV-7 Security & Compliance Sovereignty64.2SEAL-1
SOV-8 Environmental Sustainability68.9SEAL-2

SOV-1 · Strategic Sovereignty 73.0% · SEAL-2 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity: gridscale GmbH (Cologne, DE) is 100% owned by OVHcloud SA (France, Euronext Paris). Both entities entirely within the EU -> opt4. (src: https://corporate.ovhcloud.com/en/newsroom/news/ovhcloud-to-acquire-gridscale/)
SOV-1.2Change of control risk4. Unlikely takeover/transfer to non-EU sovereign entity94/125SEAL-4mediumWholly-owned subsidiary of OVHcloud, a French listed company with European-sovereignty commitments; transfer to a non-EU sovereign entity is unlikely though not formally ring-fenced -> opt4.
SOV-1.3Control over roadmap3. Governance bodies exist with EU actors participation83/125SEAL-3mediumAs an OVHcloud entity and Gaia-X founding-member group, EU actors participate in governance bodies; customers lack full direct roadmap control -> opt3.
SOV-1.4Financial independence from non-EU capital4. Majority of funding is EU-based94/125SEAL-4mediumBacked by OVHcloud (Euronext Paris-listed, EU funding); majority of funding is EU-based -> opt4.
SOV-1.5EU economic contribution4. Majority in the EU94/125SEAL-4mediumEngineering in Cologne plus OVHcloud's EU manufacturing/R&D/datacenters; majority of economic contribution in the EU -> opt4.
SOV-1.6Participation in EU strategic programs3. Active participant in strategic projects63/125SEAL-4mediumParent OVHcloud is a Gaia-X founding member and active in EU sovereign-cloud initiatives; gridscale tech powers OVHcloud Local Zones -> active participant, opt3.
SOV-1.7Alignment with EU industrial strategies3. Measured achievement and dedicated governance83/125SEAL-4mediumOVHcloud group has an explicit EU digital-sovereignty strategy with measured commitments (SecNumCloud roadmap, Gaia-X, EU manufacturing) and dedicated governance -> opt3.
SOV-1.8Resilience to cut-off4. Ability to source alternatives or internalise key functions94/125SEAL-2lowown_stack but residual non-EU operational dependency (foreign silicon/firmware): EU-owned/operated stack on OVHcloud-built EU servers can source/internalise key functions; full autonomy not guaranteed -> opt4 (seal 2).

SOV-2 · Legal & Jurisdictional Sovereignty 87.4% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highGerman GmbH owned by a French parent; contracting entity and primary jurisdiction are exclusively EU law (German/French) -> opt3. (src: https://gridscale.io/en/about-us/compliance-and-certification/)
SOV-2.2Extraterritorial laws exposure4. Legal structures shielding from foreign law125/167SEAL-2mediumeu_entity with structural separation but no certified immunity (gridscale product holds ISO 27001/C5, not SecNumCloud/EUCS-High): legal structures shield from foreign law but immunity is not statutorily verified -> opt4 (seal 2). (src: https://gridscale.io/en/about-us/compliance-and-certification/)
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumNo foreign_parent (EU-owned, no US/CN nexus): not subject to CLOUD Act/FISA/PRC law; OVHcloud commits to reject/challenge foreign-authority compelled access -> opt5. (src: https://gridscale.io/en/about-us/compliance-and-certification/)
SOV-2.4Export control restrictions4. Part of offer shielded from restrictions towards EU MSs125/167SEAL-3lowEU (German/French) provider with no export-control restrictions toward EU member states; consistent with the pure-EU cluster, the sovereign offer is shielded from restrictions toward EU MSs -> opt4 (seal 3).
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4mediumgridscale platform is self-developed in Cologne and OVHcloud's core IP is developed in France; IP mostly within the EU -> opt4.
SOV-2.6IP holder jurisdiction5. Fully under EU law167/167SEAL-4mediumSoftware IP held by EU entities (gridscale GmbH / OVHcloud SA), fully under EU law -> opt5.

SOV-3 · Data & AI Sovereignty 70.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys4. Customer primary control but provider can read data150/200SEAL-3lowPlatform offers encryption and customer key management, but standard IaaS does not by default prevent provider read access (no default HYOK/confidential computing) -> opt4.
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3lowAccess logs and customer-visible monitoring with full traceability of data access; independent real-time auditability not clearly established -> opt4.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowStandard cloud deletion per policy with internal validation; no published independently-verified proof-of-erasure mechanism -> opt3 (seal 1).
SOV-3.4Data location strictly in EU/EEA4. EU by default, tightly controlled exceptions150/200SEAL-1mediumNOT eu_exclusive: datacenters are in DE/NL/AT (EU/EEA) PLUS Switzerland (non-EU); data is EU by default with tightly controlled exceptions, no contractual EU-only guarantee -> opt4 (seal 1). (src: https://gridscale.io/en/about-us/data-centers/)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3mediumParent OVHcloud AI Endpoints serve EU-hosted open models (Mistral, Llama) on foreign NVIDIA accelerators; EU-led AI on foreign chips -> opt4.

SOV-4 · Operational Sovereignty 62.6% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumStandards-based IaaS/PaaS (S3-compatible storage, managed Kubernetes, documented API) with documented export and OVHcloud formal migration services -> opt4.
SOV-4.2Ability to operate without foreign dependencies4. Ops predominantly EU-based teams125/167SEAL-3mediumeu_ops: operations on EU infrastructure with Cologne engineering and OVHcloud EU operations; teams predominantly EU-based -> opt4 (seal 3).
SOV-4.3Skill availability in the EU3. Majority EU, escalation abroad84/167SEAL-3lowEngineering and core staff EU-based (Cologne + OVHcloud France), majority of skills in the EU with some non-EU escalation -> opt3.
SOV-4.4Support channels3. Majority in EU, non-EU escalations84/167SEAL-3lowSupport primarily EU-based (German/French operations) with possible non-EU escalation across the global group -> opt3.
SOV-4.5Documentation & knowledge transfer3. EU primary with non-EU fallback84/167SEAL-4lowDocumentation/knowledge EU-primary (German/French/EU teams) with potential non-EU fallback within the global group -> opt3 (seal 4).
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3lowCritical infrastructure (OVHcloud EU-built servers, EU datacenters) lets the provider source alternatives or internalise within the EU; not a guaranteed full-autonomy continuity contract -> opt4 (seal 3).

SOV-5 · Supply Chain Sovereignty 57.2% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)3. Transparent with exceptions72/143SEAL-3mediumOVHcloud designs/assembles its own servers with transparent vertical integration, but underlying chips are foreign; transparent with exceptions -> opt3.
SOV-5.2Manufacturing location4. Built by EU teams on foreign design107/143SEAL-3mediumOVHcloud manufactures servers in its own EU factory (Croix, France); built by EU teams on foreign component designs -> opt4 (seal 3).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/microcode in CPUs/NICs/storage from foreign vendors with only partial disclosure; provenance not EU-certified -> opt2 (seal 4).
SOV-5.4Origin of software4. Large majority maintained by EU teams107/143SEAL-3mediumown_stack, no foreign_core: gridscale orchestration platform is self-developed by the Cologne EU team and OVHcloud's stack is largely EU-maintained; large majority maintained by EU teams -> opt4 (seal 3).
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3mediumSoftware developed, built and released by EU teams (gridscale Cologne / OVHcloud France) under EU control and execution -> opt4 (seal 3).
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2lowFew non-EU vendors remain in critical services (CPU/GPU silicon, certain firmware), documented at group level -> opt3 (seal 2).
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowCritical suppliers auditable within OVHcloud's vertically-integrated, ISO 27001-certified supply chain, but not the full upstream component chain -> opt3 (seal 2).

SOV-6 · Technology Sovereignty 50.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumDocumented public API, S3-compatible object storage and managed Kubernetes; standards-based and broadly compatible interfaces -> opt4.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumOpen standards (S3 API, Kubernetes, standard IaaS protocols) adopted as policy across most core services -> opt4.
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2lowgridscale orchestration platform is proprietary closed-source (built on/interoperable with open-source components but source not openly published) -> opt2 (seal 2).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowPublic API documentation and developer resources provide some public insight into the service architecture -> opt3.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowAny HPC/GPU capacity (via OVHcloud) is EU-hosted but runs a foreign hardware stack (NVIDIA); EU-hosted, foreign stack -> opt2 (seal 3).

SOV-7 · Security & Compliance Sovereignty 64.2% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumCerts held by gridscale product: ISO 27001 + BSI C5 + SOC 1 Type 2 (no SecNumCloud/EUCS-High). Per the key, BSI C5 is a high-assurance EU/national cloud certification mapping to EAL3 -> opt4 (seal 3). (src: https://gridscale.io/en/about-us/public-relations/bsi-c5-cloud-compliance/)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumGDPR-compliant EU operations; gridscale holds ISO 27001/27018, BSI C5, NIS2/DORA alignment; partial compliance to most regimes, not all independently audited for the product -> opt4.
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3lowSecurity operations and incident handling run by EU teams (German/French) with EU threat intelligence; full lifecycle within the EU group -> opt4 (seal 3).
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3lowCustomers get direct access to monitoring/logging with logs stored in EU datacenters; tamper-proof immutable logging not clearly documented -> opt4.
SOV-7.5Disclosure of incidents4. Partial compliance, monitored flow, SLAs107/143SEAL-3lowGDPR/NIS2-aligned incident disclosure with monitored flow and SLAs per OVHcloud group practice; real-time CSIRT sharing not confirmed -> opt4.
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowProvider controls maintenance windows with customer notice and testing; moderate autonomy -> opt3 (seal 4).
SOV-7.7Auditability2. Limited independent access36/143SEAL-1lowNo audit_rights: audits available only via certification frameworks (ISO 27001, C5), no tender-grade full audit rights for the contracting authority or independent EU bodies -> opt2 (seal 1).

SOV-8 · Environmental Sustainability 68.9% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)4. PUE < 1.3188/250SEAL-4mediumParent OVHcloud reports average PUE ~1.28 via in-house water cooling; PUE < 1.3 -> opt4. (src: https://corporate.ovhcloud.com/en/sustainability/environment/)
SOV-8.2Hardware reuse & recycling4. Circular economy, EU-aligned188/250SEAL-4mediumOVHcloud runs a vertically-integrated circular model dismantling 100% of servers for reuse; EU-aligned circular economy -> opt4.
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2lowOVHcloud publishes annual environmental/sustainability reporting (PUE, WUE); not clearly EU-audited at gridscale level -> opt3 (seal 2).
SOV-8.4Energy supplies4. Only EU energy supplies (high renewable)188/250SEAL-4lowEU datacenters (DE/NL/AT, plus OVHcloud FR) use largely traceable EU energy with high renewable share per OVHcloud green-tech commitments -> opt4. (src: https://corporate.ovhcloud.com/en/sustainability/environment/)