🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Hetzner

Germany · IaaS · https://www.hetzner.com

Sovereignty score70.2%
Global (unweighted)70.7%
Overall SEAL
SEAL-1 Jurisdictional Sovereignty
SOV-1 Strategic Sovereignty75.0SEAL-3
SOV-2 Legal & Jurisdictional Sovereignty91.6SEAL-2
SOV-3 Data & AI Sovereignty75.0SEAL-1
SOV-4 Operational Sovereignty74.9SEAL-3
SOV-5 Supply Chain Sovereignty64.2SEAL-3
SOV-6 Technology Sovereignty45.0SEAL-2
SOV-7 Security & Compliance Sovereignty71.3SEAL-1
SOV-8 Environmental Sustainability68.8SEAL-2

SOV-1 · Strategic Sovereignty 75.0% · SEAL-3 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity (Hetzner Online GmbH, Gunzenhausen, no non-EU parent) -> entity control entirely within the EU, opt4. (src: https://docs.hetzner.com/general/company-and-policy/information-security-at-hetzner/)
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4mediumPrivately held, founder-rooted German company (founded 1997 by Martin Hetzner), unfunded by external/VC capital and not publicly traded, making a non-EU takeover very unlikely.
SOV-1.3Control over roadmap3. Governance bodies exist with EU actors participation83/125SEAL-3mediumeu_entity with EU-actor feedback channels but informal governance -> governance/EU-actor participation, opt3.
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4mediumSelf-funded, profitable German company with no external/non-EU investors; financing is entirely EU-based.
SOV-1.5EU economic contribution4. Majority in the EU94/125SEAL-4highWorkforce, HQ, R&D, and owned data centres are in Germany and Finland; the large majority of economic activity is in the EU though some colocation/revenue arises in the US and Singapore.
SOV-1.6Participation in EU strategic programs2. Limited participation31/125SEAL-4lowPositioned as an EU sovereign-cloud alternative and a recognised EU-native provider, but no documented formal participation in Gaia-X or IPCEI-CIS; participation is limited at best.
SOV-1.7Alignment with EU industrial strategies2. Existing action plan42/125SEAL-4lowMarkets a 'made in Germany / European cloud' sovereignty proposition consistent with EU industrial goals, amounting to an action plan rather than measured, governed achievement.
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4mediumown_stack (EU-owned data centres, EU staff, self-built hypervisor/control plane, can internalise) with residual foreign chips only -> full autonomy & continuity, opt5.

SOV-2 · Legal & Jurisdictional Sovereignty 91.6% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highGerman GmbH with EU-only corporate structure and EU/Finland data centres; service governed exclusively under EU/German law, opt3. (src: https://docs.hetzner.com/general/company-and-policy/information-security-at-hetzner/)
SOV-2.2Extraterritorial laws exposure4. Legal structures shielding from foreign law125/167SEAL-2mediumeu_entity German ownership shields the core, but a US subsidiary (Hetzner US LLC) operational nexus and no SecNumCloud/EUCS-High certified immunity -> legal structures shielding (not verified immunity), opt4 (CEIL seal 2). Real differentiator vs. the pure-DE anchors (STACKIT/SysEleven/T-Systems = opt5).
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4highNo foreign_parent: purely German/EU-owned, not subject to US CLOUD Act/FISA or PRC law; foreign-authority requests have no legal basis over the parent and would be rejected, opt5.
SOV-2.4Export control restrictions5. Part of offer shielded from restrictions towards EU MSs/intl orgs167/167SEAL-4mediumConsistency with the German cohort: a pure-German EU IaaS provider with EU-based revenue and operations and no export-control restrictions toward EU member states or international orgs -> offer shielded toward EU MSs, opt5.
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4mediumCore software/hypervisor and operational IP are developed in-house in the EU; physical hardware/chip IP (Intel, NVIDIA, Ampere) is foreign, so IP is mostly but not fully EU-origin.
SOV-2.6IP holder jurisdiction5. Fully under EU law167/167SEAL-4highThe IP-holding entity is the German GmbH, fully under EU law, opt5.

SOV-3 · Data & AI Sovereignty 75.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys4. Customer primary control but provider can read data150/200SEAL-3lowCustomers can encrypt their own volumes/data with their own keys; absent confidential-compute/HSM by default the provider operating the infrastructure could technically read unencrypted data, opt4.
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3lowConsistency with the German C5 cohort: customer-accessible logging/access records plus annual TUV-audited TOMs under BSI C5 Type 2 give full customer-controlled visibility (real-time independent audit for opt5 not evidenced) -> opt4.
SOV-3.3Secure deletion & proof of erasure4. Deletion technically verified with access logs150/200SEAL-3lowConsistency with the German C5 cohort: under BSI C5 Type 2 / ISO 27001 secure-deletion controls, deletion is technically verified with access logs (no per-request cryptographic proof for opt5) -> opt4. (src: https://www.hetzner.com/news/hetzner-receives-bsi-c5-certification/)
SOV-3.4Data location strictly in EU/EEA4. EU by default, tightly controlled exceptions150/200SEAL-1highNo eu_exclusive guarantee (real differentiator vs. STACKIT/SysEleven/T-Systems): data is EU (Germany/Finland) by default with controlled exceptions, but US/Singapore exist as opt-in locations and there is no contractual no-third-country-fallback term -> EU-by-default, opt4 (CEIL seal 1).
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3mediumConsistency with the cohort (SysEleven/IONOS): AI is GPU IaaS (rent NVIDIA/Ampere hardware) on which customers run their own open-source/auditable models hosted in EU DCs; EU-led/customer AI on foreign accelerators -> opt4.

SOV-4 · Operational Sovereignty 74.9% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumStandard documented data export plus REST API/CLI, Terraform/Ansible/Kubernetes integrations and snapshot/image migration with no proprietary lock-in formats, opt4.
SOV-4.2Ability to operate without foreign dependencies4. Ops predominantly EU-based teams125/167SEAL-3mediumeu_ops: infrastructure operated by Hetzner's own German technician teams; staff predominantly EU-based -> ops predominantly EU teams, opt4.
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumEngineering and operations skills are concentrated in Germany; majority of staff EU-based with minor non-EU presence -> all/predominantly EU staff, opt4.
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3mediumSupport, including 24/7 cloud tickets, delivered by Hetzner's own technicians based in Germany; no documented security clearances -> all support in EU, opt4.
SOV-4.5Documentation & knowledge transfer4. EU-only primary repositories125/167SEAL-4lowDocumentation and knowledge repositories maintained in-house in the EU (Hetzner Docs), primarily EU-only, opt4.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3lowown_stack: core suppliers/facilities EU-based; US/Singapore colocation non-critical to the EU offering and alternatives can be sourced or internalised, opt4.

SOV-5 · Supply Chain Sovereignty 64.2% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)3. Transparent with exceptions72/143SEAL-3mediumConsistency with the cohort: Hetzner builds its own servers and is transparent about sourcing; underlying foreign chips/parts (Intel, AMD, NVIDIA, Ampere) are disclosed with exceptions -> transparent with exceptions, opt3.
SOV-5.2Manufacturing location4. Built by EU teams on foreign design107/143SEAL-3mediumHetzner builds/assembles its own servers in-house in Germany, but on foreign chip and component designs -> built by EU teams on foreign design, opt4.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/microcode in CPUs, GPUs, NICs and BMCs comes from foreign vendors with only partial provenance disclosure, opt2.
SOV-5.4Origin of software4. Large majority maintained by EU teams107/143SEAL-3mediumNo foreign_core: cloud control plane/hypervisor and management software developed and maintained in-house by EU teams; large majority of stack EU-maintained, opt4.
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3mediumSoftware is developed, built and released under EU control and execution from Germany, opt4.
SOV-5.6Single point of dependency4. Few non-EU in non-critical services, documented107/143SEAL-3mediumConsistency with the own-stack German cohort (STACKIT anchor): self-built servers and in-house EU software/hypervisor in owned DCs mean the only non-EU dependency is substitutable commodity silicon as a non-critical hardware input, documented -> opt4 (few non-EU in non-critical, documented).
SOV-5.7Supply chain transparency4. Most suppliers auditable107/143SEAL-3lowConsistency with the German C5 cohort: under ISO 27001:2022 + BSI C5 Type 2 supplier-management scopes in its owned DCs, most suppliers are auditable beyond just the critical ones -> opt4 (most suppliers auditable). (src: https://www.hetzner.com/news/hetzner-receives-bsi-c5-certification/)

SOV-6 · Technology Sovereignty 45.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumStandards-based, broadly compatible interfaces: REST API, CLI, and integrations for Terraform, Ansible and Kubernetes with portable images, opt4.
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2mediumAdopts common open standards/protocols (KVM virtualization, S3-compatible object storage, standard Linux images) across core services -> partial core adoption, opt3.
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2mediumNo foreign_core but control plane/hypervisor proprietary and closed; Hetzner supports open-source workloads but does not open-source its own platform -> source-available/closed, opt2. Genuine differentiator vs. the OpenStack-based cohort (STACKIT/SysEleven/T-Systems open-source their core).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowSome public architecture insight via extensive docs and status pages, but the core hypervisor platform is deliberately kept private, opt3.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3mediumGPU/HPC offering is EU-hosted (Germany/Finland) but runs an entirely foreign accelerator stack (NVIDIA, Intel) -> EU-hosted, foreign stack, opt2.

SOV-7 · Security & Compliance Sovereignty 71.3% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumISO/IEC 27001:2022 + BSI C5:2020 Type 2. Per the answer-key cert->EAL map, BSI C5 is a high-assurance EU/national cloud certification mapping to EAL3 (opt4 'EAL3', seal 3); applied identically to the German cohort (STACKIT anchor scored opt4 on BSI C5) -> opt4. (src: https://www.hetzner.com/news/hetzner-receives-bsi-c5-certification/)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)5. Fully compliant to all, independently audited143/143SEAL-4highGDPR-compliant with Art. 28 DPA, ISO/IEC 27001:2022 and BSI C5 Type 2, designated KRITIS/NIS-2 operator, with TOMs independently audited annually by TUV Rheinland.
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3mediumSecurity operations and incident response handled by Hetzner's own EU-based teams in Germany; no documented ENISA/CSIRT real-time sharing -> EU lifecycle, opt4.
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3lowCustomers get direct access to their own monitoring and logs and audit reports, with infrastructure logs stored in EU data centres; no immutable tamper-proof claim -> full access EU-stored, opt4.
SOV-7.5Disclosure of incidents4. Partial compliance, monitored flow, SLAs107/143SEAL-3mediumAs an NIS-2/KRITIS operator and GDPR processor it follows monitored breach-disclosure flows with SLAs; not documented as full real-time CSIRT sharing, opt4.
SOV-7.6Maintenance autonomy4. High autonomy (deploy independently, no checks)107/143SEAL-4lowHetzner controls its own maintenance and can deploy patches independently on its self-built stack without third-party vendor scheduling, opt4.
SOV-7.7Auditability2. Limited independent access36/143SEAL-1mediumNo audit_rights (real differentiator vs. the awarded sovereign offers): assurance only via ISO 27001, C5 Type 2 and TUV audits; no contractual full independent audit of the proprietary platform by the contracting authority/any EU body -> limited independent access, opt2 (CEIL seal 1). (src: https://www.hetzner.com/news/hetzner-receives-bsi-c5-certification/)

SOV-8 · Environmental Sustainability 68.8% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)4. PUE < 1.3188/250SEAL-4highReported average PUE of 1.13 (range ~1.10-1.16), comfortably below 1.3, though not independently EU-verified below 1.2 across all sites, opt4. (src: https://www.hetzner.com/unternehmen/nachhaltigkeit)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowDocumented sustainability practices including hardware reuse and energy efficiency, amounting to a documented program rather than EU-certified circular lifecycle, opt3.
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2lowPublishes sustainability information and CO2-reduction figures at roughly annual-report level, not an independently EU-audited methodology, opt3.
SOV-8.4Energy supplies5. Only green EU energy supplies250/250SEAL-4highEnergy is exclusively renewable EU supply: hydropower in Germany since 2008 and hydro/wind in Finland since 2018, with own solar/storage build-out via HT clean Energy GmbH. (src: https://www.hetzner.com/unternehmen/nachhaltigkeit)