🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Infomaniak

Switzerland · IaaS/PaaS · https://www.infomaniak.com

Sovereignty score56.8%
Global (unweighted)58.7%
Overall SEAL
SEAL-0 No Sovereignty
SOV-1 Strategic Sovereignty59.5SEAL-1
SOV-2 Legal & Jurisdictional Sovereignty62.7SEAL-1
SOV-3 Data & AI Sovereignty50.0SEAL-0
SOV-4 Operational Sovereignty50.1SEAL-1
SOV-5 Supply Chain Sovereignty57.2SEAL-2
SOV-6 Technology Sovereignty55.0SEAL-3
SOV-7 Security & Compliance Sovereignty53.7SEAL-1
SOV-8 Environmental Sustainability81.3SEAL-2

SOV-1 · Strategic Sovereignty 59.5% · SEAL-1 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control2. Mostly outside the EU42/125SEAL-1highNot eu_entity: Infomaniak SA is incorporated and headquartered in Geneva, Switzerland, a third country (not EU/EEA), with no EU legal entity, so entity control sits mostly outside the EU -> SOV-1.1 opt2 (seal 1; consistent with the other Swiss-incorporated peers). (src: https://www.infomaniak.com/en/support/faq/71/discover-infomaniak)
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4highSince May 2026 majority voting rights are held by the Swiss public-interest Infomaniak Foundation with non-transferable blocking shares; no acquisition possible without Foundation approval, making takeover by a non-EU sovereign entity very unlikely. (src: https://news.infomaniak.com/en/infomaniak-foundation-sovereign-cloud/)
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2mediumRoadmap is controlled by Swiss management/Foundation; customers influence mainly via public/voice-of-customer channels, with no formal EU-actor governance body over the roadmap -> opt2.
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4mediumPrivately funded by founders/employees and now a Swiss foundation, profitable and self-financed with no foreign hyperscaler/US capital; free of non-EU capital dependency in the relevant sense.
SOV-1.5EU economic contribution3. Balanced EU/non-EU63/125SEAL-4mediumEconomic activity and jobs are concentrated in Switzerland (third country) with a growing European customer base; contribution to the EU economy is balanced rather than majority-in-EU.
SOV-1.6Participation in EU strategic programs2. Limited participation31/125SEAL-4lowPositions itself as a European sovereign-cloud advocate (joined CISPE) but as a Swiss entity has limited formal participation in EU strategic programs such as Gaia-X or IPCEI-CIS.
SOV-1.7Alignment with EU industrial strategies2. Existing action plan42/125SEAL-4mediumHas an explicit ethical/sovereign-cloud action plan and public advocacy aligned with EU digital-sovereignty goals, but no EU-mandated governance measuring achievement against EU industrial strategy -> opt2.
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4mediumown_stack: owns and operates its Swiss data centers (designed/built by Infomaniak), OpenStack plus in-house tooling, own SRE teams and own renewable energy; continuity depends on no non-EU vendor (only residual foreign chips), with documented self-operation -> opt5 full autonomy & continuity. Genuine differentiator vs colo-tenant peers (owns DCs + own energy). (src: https://www.infomaniak.com/en/hosting/datacenter-housing)

SOV-2 · Legal & Jurisdictional Sovereignty 62.7% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction2. Mixed EU/non-EU84/167SEAL-1highPrimary jurisdiction is Swiss law (nFADP), a third country, not EU. Services are GDPR-aligned for EU customers, giving mixed EU/non-EU legal footing rather than exclusively EU law -> opt2 (seal 1; uniform across the Swiss cluster). (src: https://www.infomaniak.com/en/trust-center)
SOV-2.2Extraterritorial laws exposure4. Legal structures shielding from foreign law125/167SEAL-2highPure-Swiss company with no US/foreign subsidiary; structurally shielded from US CLOUD Act/FISA. But not eu_entity and holds no SecNumCloud/EUCS-High, so immunity is structural-not-certified and Swiss (non-EU) law still applies -> opt4 legal structures shielding (seal 2), not opt5. (src: https://www.infomaniak.com/en/sovereign-cloud)
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumNo foreign_parent: 100% Swiss, Foundation-controlled, Swiss-only hosting; not subject to US CLOUD Act/FISA or PRC law. Foreign-authority requests can only proceed via Swiss mutual-assistance channels (not direct compelled access) and Infomaniak commits to contest them -> requests always rejected, opt5 (seal 4). Normalised to opt5 for consistency with the identical pure-Swiss-no-foreign-parent peers Safe-Swiss-Cloud and Nine (Swiss domestic MLA is not 'non-EU compelled access' in the CLOUD-Act sense). (src: https://www.infomaniak.com/en/sovereign-cloud)
SOV-2.4Export control restrictions3. Share of revenues >50% in the EU84/167SEAL-2lowNo export-control restrictions toward EU MSs; Switzerland not under foreign export regimes affecting EU customers and a large revenue share is European, but no formal EU-MS shielding mechanism -> opt3.
SOV-2.5Origin of IP3. Mixed within/outside the EU84/167SEAL-4mediumCore platform IP (in-house tools, OpenStack-based stack) is Swiss/open-source; significant building blocks are open-source and Swiss-developed, giving mixed within/outside-EU IP origin (Switzerland being a third country).
SOV-2.6IP holder jurisdiction3. Mixed law, some EU84/167SEAL-3mediumIP is held under Swiss law (single non-EU country) with open-source components under mixed/EU-friendly licenses; treated as mixed-law with some EU exposure -> opt3.

SOV-3 · Data & AI Sovereignty 50.0% · SEAL-0 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys3. Shared - provider has override keys100/200SEAL-2lowStandard provider-managed encryption with some customer key options for certain services; provider generally retains override/operational keys, so control is shared rather than exclusively customer-held -> opt3.
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowProvides access and activity logs to customers, but vendor-controlled and not described as real-time independently auditable across all services -> opt3.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowDocumented deletion processes under ISO 27001/GDPR policy with internal validation, but no published independently verified cryptographic proof-of-erasure -> opt3 (policy with internal validation).
SOV-3.4Data location strictly in EU/EEA2. Partly EU, significant third-country reliance50/200SEAL-0highNot eu_exclusive: data hosted exclusively in Swiss data centers (Geneva, Winterthur), no EU/EEA region offered. Per the rubric Switzerland is a third country, so this is partly-EU with significant third-country (Swiss) reliance, not exclusively EU/EEA -> opt2 (seal 0). This is the SEAL-0 gate, shared with the other Swiss-only-hosting peers Safe-Swiss-Cloud and Nine. (src: https://www.infomaniak.com/en/hosting/datacenter-housing)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3mediumCurated sovereign-AI service: open-source/auditable models served via an OpenAI-compatible API hosted in Switzerland, EU/Swiss-led, running on foreign Nvidia L4/A100/H100 accelerators -> EU-led AI on foreign accelerators, opt4 (seal 3). Normalised to match the equivalent curated open-model AI offering of Safe-Swiss-Cloud. (src: https://www.infomaniak.com/en/hosting/ai-tools)

SOV-4 · Operational Sovereignty 50.1% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumOpen-source OpenStack/Kubernetes/Jelastic stack with documented export and formal migration paths; customers can move to or combine other providers with migration assistance -> opt4.
SOV-4.2Ability to operate without foreign dependencies3. Ops balanced EU/non-EU teams84/167SEAL-3highEntire stack managed by Infomaniak's own SRE teams with no foreign (US/Asia) intermediary, fully self-sufficient in one country; but staff are Swiss (third-country) not EU, so from the EU-sourcing standpoint this is balanced/non-EU teams -> opt3 (seal 3). Normalised to the Swiss-in-house-ops tier shared with Safe-Swiss-Cloud and Nine. (src: https://www.infomaniak.com/en/sovereign-cloud)
SOV-4.3Skill availability in the EU2. Mixed, majority outside EU42/167SEAL-1mediumEngineering/operations talent concentrated in Switzerland with no offshore (US/Asia) escalation, but Switzerland is outside the EU/EEA, so EU skill availability is majority-outside-EU -> opt2 (seal 1). Normalised to the Swiss-only-skills tier shared with Safe-Swiss-Cloud and Nine. (src: https://www.infomaniak.com/en/sovereign-cloud)
SOV-4.4Support channels3. Majority in EU, non-EU escalations84/167SEAL-3mediumSupport provided in-house from Switzerland in multiple European languages with no non-EU outsourcing; majority-local support without offshore escalation, but Swiss not EU -> opt3.
SOV-4.5Documentation & knowledge transfer2. EU optional, not enforced42/167SEAL-2lowDocumentation and knowledge maintained in-house in Switzerland (a third country); no enforced EU-region repositories, so EU placement is optional/not enforced -> opt2 (seal 2). Normalised to the Swiss-only-docs tier shared with Safe-Swiss-Cloud and Nine. (src: https://www.infomaniak.com/en/sovereign-cloud)
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3mediumown_stack: minimal critical subcontractors; owns its data centers and uses open-source software, so on supplier cut-off it can source alternatives or internalise rather than face shutdown -> opt4.

SOV-5 · Supply Chain Sovereignty 57.2% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)3. Transparent with exceptions72/143SEAL-3mediumPublishes meaningful component choices (Swissbit SSDs, Meyer-Burger panels, named GPUs) showing transparency with exceptions, though not full EU-certified provenance for all parts -> opt3.
SOV-5.2Manufacturing location3. Mixed sourcing, EU audit rights72/143SEAL-3mediumServers assembled/integrated by Infomaniak with mixed sourcing including European components and Swiss build, but base silicon is of foreign design/manufacture; mixed sourcing with audit rights -> opt3.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/microcode in CPUs, GPUs and SSDs comes from foreign vendors with only partial provenance disclosure; no full firmware transparency published -> opt2.
SOV-5.4Origin of software4. Large majority maintained by EU teams107/143SEAL-3highNo foreign_core: software stack is open-source (OpenStack, Kubernetes) plus extensive in-house tooling (e.g. OpenStack Cluster Installer) maintained by Infomaniak's own teams; large majority maintained in-house -> opt4.
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3mediumBuild and release controlled and executed by Infomaniak's own teams in Switzerland; in-house control and execution, without formal external EU policy-gate certification -> opt4.
SOV-5.6Single point of dependency4. Few non-EU in non-critical services, documented107/143SEAL-3mediumown_stack: few non-EU dependencies remain only in non-critical hardware (chips/GPUs); core operations rely on no single non-EU vendor or facility, documented and self-operated -> opt4.
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowCritical suppliers and own data centers auditable via ISO 27001/14001/50001 third-party audits, but no published full all-supplier auditable supply chain -> opt3.

SOV-6 · Technology Sovereignty 55.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumBuilt on standards-based open-source platforms (OpenStack, Kubernetes, S3-compatible APIs) that are broadly compatible and portable, but not entirely open-by-default across every product -> opt4.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumAdopts open standards (OpenStack APIs, S3, Kubernetes, OpenAI-compatible API) as policy for most core services -> opt4.
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3mediumNo foreign_core: core infrastructure rests on fully open-source software with substantial in-house contributions, but upstream governance is centralised/community-led rather than Infomaniak-EU-governed -> opt3 open source, centralised governance.
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3mediumProvides substantial public insight into its architecture, data-center design and operations via detailed technical posts, giving meaningful public transparency -> opt3.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3mediumHPC/GPU compute is EU-region-hosted (Swiss data centers) but built on a foreign stack (Nvidia A100/H100 and their software), i.e. EU-hosted foreign HPC stack -> opt2 (seal 3).

SOV-7 · Security & Compliance Sovereignty 53.7% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)2. EAL136/143SEAL-1mediumNo SecNumCloud/EUCS/C5/Common Criteria EAL; holds ISO 27001:2022 (since 2018) plus ISO 9001/14001/50001, but no SOC 2 or C5. Per key, ISO 27001 only maps to EAL1 -> opt2 (seal 1). (src: https://www.infomaniak.com/en/certifications)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4highDemonstrably GDPR- and nFADP-compliant with ISO 27001/9001/14001/50001, addressing most EU regulatory expectations; partial compliance across GDPR/NIS2/DORA without a single audit covering all three -> opt4.
SOV-7.3EU-based SOC & incident handling3. Primary SOC in EU, escalations non-EU72/143SEAL-1mediumSecurity operations and incident handling run end-to-end by Infomaniak's own teams, but the SOC is located in Switzerland (outside the EU), so the EU-lifecycle tiers (opt4/opt5) do not strictly apply -> primary SOC in-region with non-EU location, opt3 (seal 1). Normalised to the Swiss-in-house-SOC tier shared with Safe-Swiss-Cloud and Nine. (src: https://www.infomaniak.com/en/trust-center)
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1lowCustomers get direct access to monitoring and logs, but logs are stored in Swiss (non-EU) data centers, so the EU-storage tiers (opt4/opt5 'logs stored in EU') do not apply -> monitoring portal/basic access, opt3 (seal 1). Normalised to the Swiss-only-log-residency tier shared with Safe-Swiss-Cloud and Nine. (src: https://www.infomaniak.com/en/trust-center)
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2mediumIncident disclosure aligned with GDPR/nFADP notification obligations; moderate compliance with documented breach-notification practices -> opt3.
SOV-7.6Maintenance autonomy4. High autonomy (deploy independently, no checks)107/143SEAL-4mediumOwning and operating its own stack, Infomaniak can deploy patches and maintenance independently on its own schedule without vendor dependence -> opt4 high autonomy.
SOV-7.7Auditability3. Partial independent control72/143SEAL-1lowIndependent third-party audits exist for ISO security/quality/energy management systems, giving partial independent control, but no audit_rights-grade full audit by any independent EU body -> opt3.

SOV-8 · Environmental Sustainability 81.3% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)5. PUE < 1.2, EU verified250/250SEAL-4highGeneva data center (inaugurated 2025) operates at PUE 1.09, verified, well below the 1.2 threshold -> opt5. (src: https://www.infomaniak.com/en/ecology/certificates-rewards)
SOV-8.2Hardware reuse & recycling4. Circular economy, EU-aligned188/250SEAL-4highDocumented circular-economy program: upgrades/reuses servers to ~10-year lifespan and recovers 100% of waste heat to warm local buildings, aligned with EU sustainability practices -> opt4.
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2mediumPublishes regular environmental/ecology reporting and certificates; annual-report-level disclosure rather than fully EU-audited environmental accounting -> opt3.
SOV-8.4Energy supplies5. Only green EU energy supplies250/250SEAL-4highPowered entirely by renewable energy (Swiss hydro plus solar) with own/European solar panels; green energy supplies (sourced in Switzerland rather than EU grid) -> opt5. (src: https://www.infomaniak.com/en/ecology/certificates-rewards)