🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Heroku

United States · PaaS · https://www.heroku.com

Sovereignty score26.2%
Global (unweighted)27.3%
Overall SEAL
SEAL-0 No Sovereignty
SOV-1 Strategic Sovereignty22.9SEAL-0
SOV-2 Legal & Jurisdictional Sovereignty12.6SEAL-1
SOV-3 Data & AI Sovereignty35.0SEAL-0
SOV-4 Operational Sovereignty12.6SEAL-0
SOV-5 Supply Chain Sovereignty7.2SEAL-1
SOV-6 Technology Sovereignty35.0SEAL-0
SOV-7 Security & Compliance Sovereignty43.1SEAL-1
SOV-8 Environmental Sustainability50.0SEAL-2

SOV-1 · Strategic Sovereignty 22.9% · SEAL-0 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control1. Entirely outside the EU0/125SEAL-1highHeroku is a wholly owned subsidiary of Salesforce, Inc., a US company headquartered in San Francisco; no EU/EEA legal entity controls it (src: https://en.wikipedia.org/wiki/Heroku).
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4mediumHeroku is already controlled by a large US public company (Salesforce); transfer to a NON-EU sovereign entity is very unlikely as it is already non-EU and a stable parent (the rubric measures takeover by a non-EU sovereign actor).
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2mediumHeroku has a public GitHub roadmap and customer feedback channels, but governance is fully Salesforce-controlled; EU actors have only voice-of-the-customer influence.
SOV-1.4Financial independence from non-EU capital1. Almost entirely relying on non-EU funding0/125SEAL-4highFunding comes entirely from Salesforce, a US-based public corporation; effectively no EU capital.
SOV-1.5EU economic contribution2. Some31/125SEAL-4lowSalesforce has substantial EU operations and offices, but Heroku's value capture and R&D are predominantly US-based; some EU economic contribution at most.
SOV-1.6Participation in EU strategic programs1. No clear participation0/125SEAL-4mediumNo evidence of Heroku/Salesforce participation in Gaia-X, IPCEI-CIS or other EU strategic sovereignty programs for this product.
SOV-1.7Alignment with EU industrial strategies1. No evidence exists0/125SEAL-4mediumNo evidence of a Heroku-specific action plan aligned with EU industrial/sovereignty strategies.
SOV-1.8Resilience to cut-off2. Service would stop, with delay for customer reaction31/125SEAL-0mediumno own_stack (PaaS on non-EU hyperscaler AWS): on a vendor cut-off the service would stop with only a delay for customers to migrate; no independent EU continuity -> opt2 (seal 0).

SOV-2 · Legal & Jurisdictional Sovereignty 12.6% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction1. Non-EU only0/167SEAL-1highHeroku's terms are governed by Salesforce/US law; the contracting and controlling entity is non-EU only (src: https://www.salesforce.com/company/legal/agreements/).
SOV-2.2Extraterritorial laws exposure2. Mitigation clauses, exposure remains42/167SEAL-1highno immunity (US parent Salesforce): GDPR DPA/SCCs/BCRs are mitigation clauses only; full exposure to extraterritorial US law (CLOUD Act, FISA 702) remains -> opt2 (seal 1) (src: https://compliance.salesforce.com/en/documents/a005A00000kFeKeQAK).
SOV-2.3Data access pathways for non-EU authorities2. Can compel access without notification, specific cases42/167SEAL-1highconsistency (cluster norm 2.3=opt2): foreign_parent (Salesforce US) under CLOUD Act/FISA 702 can be compelled to grant access without customer notification in specific national-security cases (gag orders) -> opt2 (seal 1).
SOV-2.4Export control restrictions2. Restrictions towards EU citizens or international orgs42/167SEAL-1lowconsistency (cluster norm 2.4=opt2): US export-control regime (EAR/OFAC) applies; no EU-MS-targeted shielding and no >50% EU revenue dominance -> opt2 (restrictions towards EU citizens/intl orgs, seal 1).
SOV-2.5Origin of IP1. Entirely outside the EU0/167SEAL-4highHeroku's platform IP is developed and owned by Salesforce in the US; IP originates entirely outside the EU.
SOV-2.6IP holder jurisdiction1. Non-EU law, single country0/167SEAL-3highThe IP holder (Salesforce) sits under US law in a single non-EU country.

SOV-3 · Data & AI Sovereignty 35.0% · SEAL-0 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys2. Primarily provider, not exclusively50/200SEAL-1mediumHeroku/AWS manage encryption at rest; customers do not have exclusive customer-managed keys that prevent provider access, so control is primarily provider though some Postgres/data encryption options exist.
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowHeroku provides app/platform logs and add-on logging, but data-access/usage logs are vendor-controlled and not independently auditable in real time.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowDeletion follows Salesforce/AWS internal policy and contractual commitments, but no independent cryptographic proof of irreversible erasure is offered to customers.
SOV-3.4Data location strictly in EU/EEA2. Partly EU, significant third-country reliance50/200SEAL-0mediumno eu_exclusive: global-default US product; an EU (Ireland) region exists but Heroku states region selection does not guarantee confinement and the control plane, add-ons and support involve third-country (US) processing -> opt2 (significant third-country reliance, seal 0) (src: https://devcenter.heroku.com/articles/security-privacy-compliance).
SOV-3.5AI services sovereignty2. Mostly non-EU: licensed AI, chip dependency50/200SEAL-2highHeroku Managed Inference proxies non-EU models (Anthropic Claude, OpenAI-compatible, open-weights) on US hyperscaler/foreign accelerator infrastructure; mostly non-EU licensed AI with chip dependency.

SOV-4 · Operational Sovereignty 12.6% · SEAL-0 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumHeroku offers standard documented data export, pg:backups, and OCI-compliant Cloud Native Buildpacks that produce portable container images runnable on other platforms.
SOV-4.2Ability to operate without foreign dependencies1. Critical ops delivered by non-EU teams0/167SEAL-1highCritical platform operations, engineering and control plane are delivered by Salesforce/AWS US-based teams; cannot operate without non-EU dependencies.
SOV-4.3Skill availability in the EU1. Global team, mainly non-EU0/167SEAL-1lowconsistency (US-parented cluster norm 4.3=opt1): Heroku/Salesforce engineering and SRE staff are a global, predominantly US team; EU skill availability is a minority -> opt1 (seal 1).
SOV-4.4Support channels1. Global, majority outside EU0/167SEAL-1mediumHeroku support is a global, follow-the-sun model run by Salesforce, with the majority of support staff outside the EU.
SOV-4.5Documentation & knowledge transfer1. Global/non-EU exposure0/167SEAL-0mediumDocumentation (Dev Center) and knowledge repositories are global/US-hosted with non-EU exposure; no EU-only knowledge transfer guarantees.
SOV-4.6Subcontractor & supplier jurisdiction2. Service would stop with delay42/167SEAL-2mediumHeroku depends on AWS (US) as primary subcontractor; if cut off the service would stop with only a delay for customer reaction, no readily substitutable EU alternative.

SOV-5 · Supply Chain Sovereignty 7.2% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)1. No disclosure0/143SEAL-1lowHeroku runs on AWS; the physical component origins of underlying servers are not disclosed to Heroku customers.
SOV-5.2Manufacturing location1. Fully foreign, black box0/143SEAL-1lowUnderlying hardware is AWS-operated and foreign-manufactured, effectively a black box to Heroku and its customers.
SOV-5.3Embedded code/firmware provenance1. No disclosure0/143SEAL-4lowFirmware/embedded code provenance of the underlying AWS hardware is not disclosed.
SOV-5.4Origin of software2. Foreign origin, partial disclosure36/143SEAL-2highconsistency (cluster norm 5.4=opt2): core platform/control plane is closed US-developed Salesforce software, but Heroku open-sources its Buildpacks/Cloud Native Buildpacks giving partial disclosure of foreign-origin software, same profile as the other self-developed US PaaS -> opt2 (seal 2) (src: https://github.com/heroku/buildpacks).
SOV-5.5Software build/release jurisdiction1. Non-EU control & execution0/143SEAL-1mediumSoftware build and release are controlled and executed by Salesforce in the US; non-EU control and execution.
SOV-5.6Single point of dependency1. Only non-EU vendors/facilities0/143SEAL-1highHeroku depends entirely on non-EU vendors (Salesforce, AWS) for the platform and infrastructure.
SOV-5.7Supply chain transparency2. Some suppliers auditable36/143SEAL-1lowA sub-processor list and SOC reports exist, but only some suppliers are independently auditable by customers; full supply-chain audit rights are not provided.

SOV-6 · Technology Sovereignty 35.0% · SEAL-0 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces3. Mixed (partial openness)100/200SEAL-2mediumHeroku exposes a documented REST Platform API and OCI/CNB images (partial openness) but the managed PaaS itself is proprietary with significant lock-in.
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2mediumHeroku adopts several open standards (OCI images, buildpacks, standard language runtimes, OpenAI-compatible API) but only partially across core services.
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2mediumBuildpacks and CNBs are open source, but the core Heroku platform/control plane is closed-source and vendor-controlled by Salesforce.
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3mediumHeroku publishes extensive Dev Center documentation and architecture descriptions (some public insight) but customers cannot inspect or modify the underlying platform.
SOV-6.5HPC sovereignty1. Imported black-box HPC0/200SEAL-0lowHeroku offers no sovereign HPC; any high-performance/accelerator compute is imported black-box capacity via AWS.

SOV-7 · Security & Compliance Sovereignty 43.1% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)3. EAL272/143SEAL-2highcerts: Heroku holds ISO 27001/27017/27018 + SOC 1/2/3 (no SecNumCloud/EUCS/Common Criteria EAL); per key ISO 27001 + SOC 2 maps to opt3 (EAL2-equiv, seal 2) (src: https://www.heroku.com/compliance/).
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumSalesforce/Heroku provide GDPR DPA, SCCs/BCRs and security attestations (partial compliance to most EU regimes), but full DORA/NIS2 conformance is not independently demonstrated for this product.
SOV-7.3EU-based SOC & incident handling2. Hybrid EU/non-EU36/143SEAL-1lowSalesforce SOC/incident response is a global, hybrid EU/non-EU function; not an EU-resident SOC with EU threat intel.
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1lowCustomers get app/platform logging and a monitoring portal/add-ons, but security monitoring of the underlying platform is provider-controlled; basic customer visibility.
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2mediumSalesforce has GDPR/NIS2-aligned breach notification obligations and contractual SLAs for incident disclosure (moderate compliance).
SOV-7.6Maintenance autonomy2. Limited autonomy (vendor schedules)36/143SEAL-1lowHeroku schedules platform maintenance; customers have limited autonomy and follow vendor maintenance windows for the underlying platform.
SOV-7.7Auditability2. Limited independent access36/143SEAL-1mediumno audit_rights: independent audit limited to shared SOC/ISO reports; customers cannot have arbitrary entities audit the platform directly -> opt2 (seal 1).

SOV-8 · Environmental Sustainability 50.0% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowHeroku runs on AWS, whose data centres report PUE around/below 1.5 with efficiency roadmaps; Heroku itself does not publish a verified figure -> opt3 (PUE<1.5 + roadmap) (src: https://sustainability.aboutamazon.com/products-services/aws-cloud).
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowAWS (the underlying operator) runs documented hardware reuse and recycling programs; Heroku inherits this rather than certifying its own EU lifecycle -> opt3 (documented program) (src: https://sustainability.aboutamazon.com/products-services/aws-cloud).
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2lowSalesforce publishes an annual stakeholder-impact/sustainability report covering its operations and infrastructure, though not under an EU-specific audited methodology for Heroku -> opt3 (annual report) (src: https://www.salesforce.com/company/sustainability/).
SOV-8.4Energy supplies3. Mix of EU and non-EU supplies125/250SEAL-4lowUnderlying AWS regions use a mix of EU and non-EU energy supplies; AWS targets renewable matching but the supply mix is not exclusively EU/green for Heroku workloads (src: https://sustainability.aboutamazon.com/products-services/aws-cloud).