🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Jotelulu

Spain · IaaS/PaaS · https://jotelulu.com

Sovereignty score63.8%
Global (unweighted)63.6%
Overall SEAL
SEAL-2 Data Sovereignty
SOV-1 Strategic Sovereignty68.8SEAL-2
SOV-2 Legal & Jurisdictional Sovereignty75.0SEAL-2
SOV-3 Data & AI Sovereignty70.0SEAL-2
SOV-4 Operational Sovereignty70.9SEAL-3
SOV-5 Supply Chain Sovereignty50.2SEAL-2
SOV-6 Technology Sovereignty40.0SEAL-2
SOV-7 Security & Compliance Sovereignty71.4SEAL-2
SOV-8 Environmental Sustainability62.5SEAL-2

SOV-1 · Strategic Sovereignty 68.8% · SEAL-2 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity (Spanish company HQ Madrid, founder David Amorin, no controlling non-EU parent) -> SOV-1.1 opt4: legal entity entirely within the EU. (src: https://jotelulu.com/en-gb/about-jotelulu/)
SOV-1.2Change of control risk4. Unlikely takeover/transfer to non-EU sovereign entity94/125SEAL-4mediumPrivate VC-backed scale-up with mostly EU investors (Bankinter, Kibo, Adara) and a minority US fund (G2A); a future non-EU takeover is unlikely but not negligible -> opt4.
SOV-1.3Control over roadmap3. Governance bodies exist with EU actors participation83/125SEAL-3lowEU-controlled provider with own R&D; partner/voice-of-customer channels give EU actors some influence over the roadmap, but no formal governance body is published -> opt3 (governance bodies with EU-actor participation, generous read).
SOV-1.4Financial independence from non-EU capital4. Majority of funding is EU-based94/125SEAL-4mediumMajority of the ~12.7M raised comes from EU investors (Bankinter, Kibo, Adara, South Capital) with a minority from US fund G2A; majority EU funding -> opt4.
SOV-1.5EU economic contribution5. Fully in the EU125/125SEAL-4highSpanish company, EU staff, EU data centres and EU SME/reseller customer base; economic contribution essentially fully in the EU -> opt5.
SOV-1.6Participation in EU strategic programs2. Limited participation31/125SEAL-4lowCISPE member but no evidence of Gaia-X / IPCEI-CIS participation; limited participation in EU strategic programs -> opt2.
SOV-1.7Alignment with EU industrial strategies2. Existing action plan42/125SEAL-4lowMarkets itself as a European sovereign cloud with an action plan aligned to EU strategy, but no measured achievements or dedicated governance disclosed -> opt2 (existing action plan).
SOV-1.8Resilience to cut-off4. Ability to source alternatives or internalise key functions94/125SEAL-2lowNo own_stack: uses EU colocation (Equinix, Digital Realty, Data4) and commodity foreign hardware/hypervisor, so not full autonomy; as an EU operator of its own platform it could source alternatives or internalise key functions rather than face immediate shutdown -> opt4 (seal 2).

SOV-2 · Legal & Jurisdictional Sovereignty 75.0% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highSpanish entity operating EU-only infrastructure under EU/Spanish/French law; contract under EU member-state law only -> opt3 (exclusively EU law). (src: https://jotelulu.com/en-gb/about-jotelulu/)
SOV-2.2Extraterritorial laws exposure4. Legal structures shielding from foreign law125/167SEAL-2mediumimmunity is structural-only: EU-incorporated, EU-operated, no controlling non-EU parent shields from foreign law, but no SecNumCloud 3.2 / EUCS-High certified immunity -> opt4 'Legal structures shielding' (seal 2 ceiling), consistent with the Spanish-provider basis. (src: https://jotelulu.com/en-gb/about-jotelulu/)
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumNo foreign_parent: wholly EU entity with no US/non-EU parent, not subject to the CLOUD Act/FISA/PRC law; can reject non-EU authority requests and respond only to lawful EU process -> opt5.
SOV-2.4Export control restrictions3. Share of revenues >50% in the EU84/167SEAL-2lowEU provider with revenues overwhelmingly within the EU (>50% EU revenue); no part of the offer is specifically certification-shielded from export controls -> opt3.
SOV-2.5Origin of IP3. Mixed within/outside the EU84/167SEAL-4mediumOrchestration/platform software is in-house Spanish IP (EU), but the stack relies on foreign-origin hardware, hypervisor/OS and some non-EU components; mixed within/outside EU -> opt3.
SOV-2.6IP holder jurisdiction4. EU law with exceptions125/167SEAL-4mediumJotelulu's own IP is held under EU (Spanish) law; some third-party/open-source components carry non-EU licences -> opt4 (EU law with exceptions).

SOV-3 · Data & AI Sovereignty 70.0% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys3. Shared - provider has override keys100/200SEAL-2lowProvides AES-256 encryption but as a managed IaaS/PaaS the provider retains operational key management; no documented HYOK, so shared with provider override -> opt3.
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowProvides protected logs and traceability via the control panel, but logging is vendor-controlled and not real-time independently auditable -> opt3.
SOV-3.3Secure deletion & proof of erasure4. Deletion technically verified with access logs150/200SEAL-3lowENS-High plus ISO 27001/HDS mandate verified media-sanitisation controls with access logging, so deletion is technically verified with logs (uniform sovereign-operator basis, consistent with the cluster) -> opt4. (src: https://jotelulu.com/blog/ens-alto-infraestructura-cloud/)
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4mediumeu_exclusive (scoped EU offer): operates EU-only data centres (Madrid, Paris, Portugal); CISPE Code of Conduct permits EU-only storage AND processing with no third-country fallback for the scoped offer -> opt5. (src: https://jotelulu.com/en-gb/about-jotelulu/)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3lowNo in-scope EU AI service offered; no foreign-AI dependency to penalise -> opt4 (seal 3) per key SOV-3.5 'no in-scope AI service'.

SOV-4 · Operational Sovereignty 70.9% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumOffers documented data export plus a formal Migrations product and standard IaaS interfaces enabling migration -> opt4 (formal migration services).
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4mediumeu_ops: small Spanish company operating its own stack; the entire stack is managed by a fully EU-based team with no non-EU operating teams -> opt5.
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumEngineering/technical staff based in the EU (Spain, France, Portugal); no evidence of security-cleared staffing for opt5 -> opt4 (all EU staff).
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3mediumSupport delivered to EU partners from Spain/France in local languages; EU-based staff without documented security clearances -> opt4 (all support in EU).
SOV-4.5Documentation & knowledge transfer3. EU primary with non-EU fallback84/167SEAL-4lowDocumentation/knowledge base produced in-house in the EU; EU-primary with possible non-EU fallback, no explicit EU-only guarantee -> opt3 (seal 4).
SOV-4.6Subcontractor & supplier jurisdiction3. Continue temporarily per contractual agreement84/167SEAL-3lowRelies on EU colocation and hardware suppliers; with contractual agreements service could continue temporarily, though some critical suppliers (hardware, network) are non-EU -> opt3.

SOV-5 · Supply Chain Sovereignty 50.2% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)3. Transparent with exceptions72/143SEAL-3lowPhysical components are foreign-made, but as an ISO 27001 / ENS-High certified operator Jotelulu provides component transparency to customers/auditors with exceptions (uniform sovereign-operator basis, consistent with the cluster) -> transparent with exceptions (opt3).
SOV-5.2Manufacturing location3. Mixed sourcing, EU audit rights72/143SEAL-3mediumServer/storage hardware (Intel/AMD/NVIDIA OEMs) is foreign-manufactured but integrated and operated under ISO 27001 / ENS-High audited supply-chain controls (EU audit rights), matching the uniform key for EU sovereign providers -> mixed sourcing, EU audit rights (opt3).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/BIOS/microcode in commodity hardware is foreign with only partial published provenance -> opt2.
SOV-5.4Origin of software3. Core/essential parts maintained by EU teams72/143SEAL-3mediumNot foreign_core: core orchestration/platform is developed and maintained by Jotelulu's EU team, layered on open-source hypervisor/OS (not licensed Google/MS core); core essential parts maintained by EU teams -> opt3.
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3lowSoftware build and release controlled and executed by the EU-based engineering team in Spain; EU control and execution, no evidence of formal EU policy gates -> opt4.
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2lowDepends on a few non-EU vendors in critical services (chip/hardware vendors, commodity hypervisor), documented to a degree but a single point of dependency -> opt3 (seal 2).
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowISO 27001 and data-centre certifications give audit rights over critical suppliers/data centres, but the full supply chain is not fully auditable -> opt3.

SOV-6 · Technology Sovereignty 40.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces3. Mixed (partial openness)100/200SEAL-2lowProvides APIs and standard storage/compute (S3-compatible) with some openness, but not open-by-default; mixed partial openness -> opt3.
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2lowUses common protocols (S3-compatible object storage, standard remote desktop/storage) indicating partial core adoption of open standards, no formal all-services policy -> opt3.
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2lowJotelulu's platform is proprietary and vendor-controlled but layered on open-source hypervisor/OS components (source not openly available), consistent with the other Spanish providers' proprietary-with-OSS-underpinnings posture -> opt2 (source available for review/strict rights, seal 2).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowPublishes some architecture/security insight (blog, certification docs, security whitepapers) giving some public insight -> opt3.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowNo in-scope EU HPC service; no imported black-box HPC dependency in the offer -> opt2 (EU-hosted/no in-scope HPC, seal 3) per key SOV-6.5.

SOV-7 · Security & Compliance Sovereignty 71.4% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumHolds ISO 27001 + HDS (health-data hosting) + ENS Alto (High) infrastructure certification (confirmed for the Spanish PA framework); per key, ENS-High is a high-assurance national cloud certification mapping to EAL3 (opt4), consistent with the other ENS-High Spanish providers -> opt4 (EAL3, seal 3). (src: https://jotelulu.com/blog/ens-alto-infraestructura-cloud/)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumGDPR-compliant, CISPE Code of Conduct (CNIL-approved), ISO 27001, HDS and ENS certified; partial compliance to most EU regulations, NIS2/DORA not independently attested for all -> opt4. (src: https://jotelulu.com/en-gb/blog/new-certification-hds/)
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3lowEU company running security operations and incident response with EU teams in EU data centres; no ENISA/CSIRT information-sharing integration evidenced for opt5 -> opt4.
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3lowProvides direct access to protected logs and traceability via the control panel with EU-hosted logging in its EU DCs (ENS-High mandates security-log access/traceability); immutable tamper-proof logging not explicitly documented -> full direct access, logs stored in EU (opt4), consistent with the cluster.
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2lowGDPR/NIS2-aligned incident disclosure expected from a certified EU provider; moderate compliance, no published real-time CSIRT sharing -> opt3.
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowOperator of its own platform with moderate maintenance autonomy (notice and testing windows); dependence on third-party vendor patches for zero-days remains -> opt3 (seal 4).
SOV-7.7Auditability5. Full independent audit by any entity143/143SEAL-4lowaudit_rights: the ENS-High sovereign offer for Spanish public administration implies tender-grade full audit rights for the contracting authority and independent EU bodies (uniform basis with the cluster's ENS-High/ACN-qualified members) -> full independent audit (opt5). (src: https://jotelulu.com/blog/ens-alto-infraestructura-cloud/)

SOV-8 · Environmental Sustainability 62.5% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowModern certified EU data centres (ISO 50001 energy management) imply PUE under ~1.5 with an efficiency roadmap, no specific lower published figure -> opt3 (PUE<1.5 + roadmap). (src: https://jotelulu.com/en-gb/about-jotelulu/)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowOperates in data centres with documented circular/efficiency programs; a documented hardware reuse program is plausible but not evidenced as EU-certified lifecycle -> opt3.
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2mediumPerforms an annual carbon-footprint audit and offsets it (ClimateTrade), i.e. an annual environmental report, not EU-audited to a formal methodology -> opt3.
SOV-8.4Energy supplies5. Only green EU energy supplies250/250SEAL-4highStates 100% of data-centre energy from renewable sources (wind, hydro, solar) within EU facilities; only green EU energy supplies -> opt5. (src: https://jotelulu.com/en-gb/about-jotelulu/)