🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Koyeb

France · PaaS · https://www.koyeb.com

Sovereignty score56.8%
Global (unweighted)54.1%
Overall SEAL
SEAL-0 No Sovereignty
SOV-1 Strategic Sovereignty72.0SEAL-2
SOV-2 Legal & Jurisdictional Sovereignty83.3SEAL-2
SOV-3 Data & AI Sovereignty45.0SEAL-0
SOV-4 Operational Sovereignty58.5SEAL-3
SOV-5 Supply Chain Sovereignty43.0SEAL-1
SOV-6 Technology Sovereignty60.0SEAL-3
SOV-7 Security & Compliance Sovereignty39.5SEAL-1
SOV-8 Environmental Sustainability31.4SEAL-0

SOV-1 · Strategic Sovereignty 72.0% · SEAL-2 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity (French SAS, registered Nanterre/Boulogne-Billancourt; since Feb 2026 a wholly-owned subsidiary of Mistral AI, French) -> entity control entirely within the EU -> opt4 (src: https://www.koyeb.com/blog/koyeb-is-joining-mistral-ai-to-build-the-future-of-ai-infrastructure).
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4mediumOwned by Mistral AI, France's flagship sovereign-AI champion building a European AI cloud; transfer to a non-EU sovereign entity is very unlikely -> opt5 (all-seal-4 factor, existing choice kept).
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2lowCommercial PaaS/Mistral subsidiary; roadmap influence is via product feedback / voice-of-customer, no formal EU multi-stakeholder governance body over the roadmap -> opt2 (seal 2).
SOV-1.4Financial independence from non-EU capital4. Majority of funding is EU-based94/125SEAL-4mediumPre-acquisition funding from French VCs (Serena, ISAI); now backed by Mistral AI, majority EU-funded though with some non-EU investors -> majority EU funding -> opt4 (all-seal-4 factor, existing choice kept).
SOV-1.5EU economic contribution4. Majority in the EU94/125SEAL-4mediumEngineering team and HQ in France, joining Mistral's EU engineering division; economic contribution majority in the EU with some global revenue -> opt4 (all-seal-4 factor, existing choice kept).
SOV-1.6Participation in EU strategic programs3. Active participant in strategic projects63/125SEAL-4mediumThrough Mistral AI, part of an explicitly European sovereign AI-cloud initiative; active participant rather than named lead of formal programs -> opt3 (all-seal-4 factor, existing choice kept).
SOV-1.7Alignment with EU industrial strategies3. Measured achievement and dedicated governance83/125SEAL-4mediumMistral/Koyeb position the combined offering around Europe's sovereign full-stack AI cloud with dedicated investment and stated governance -> opt3 (all-seal-4 factor, existing choice kept).
SOV-1.8Resilience to cut-off4. Ability to source alternatives or internalise key functions94/125SEAL-2lowNo own_stack: PaaS runs on bare-metal/colo incl. US partner Vultr (32 global regions), a real non-EU operational dependency, but stack is open source (Nomad/Firecracker/Kuma) and EU-built and could be re-sourced/internalised -> 'ability to source alternatives' opt4 (seal 2), not full autonomy (src: https://www.koyeb.com/blog/partnering-with-vultr-for-serverless-and-global-ai-deployments).

SOV-2 · Legal & Jurisdictional Sovereignty 83.3% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highToS/MSA governed by French law with French jurisdiction; contracting entity is a French SAS -> contract exclusively under EU law -> opt3 (seal 4) (src: https://www.koyeb.com/blog/koyeb-is-joining-mistral-ai-to-build-the-future-of-ai-infrastructure).
SOV-2.2Extraterritorial laws exposure4. Legal structures shielding from foreign law125/167SEAL-2mediumPure-FR entity under a French parent (no US/foreign parent) gives legal structures shielding from foreign law, but immunity is not certified (no SecNumCloud/EUCS-High) -> opt4 'legal structures shielding' (seal 2), not opt5 verified immunity.
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumNo foreign_parent: French SAS with French parent is not subject to US CLOUD Act/FISA/PRC law and has no legal basis to comply with non-EU compelled-access orders, so such requests would be rejected -> opt5 (seal 4).
SOV-2.4Export control restrictions3. Share of revenues >50% in the EU84/167SEAL-2lowNo EU-facing export restrictions on a French provider; global customer base means the relevant tier is EU revenue share rather than a formally shielded offer -> opt3 (seal 2).
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4mediumCore orchestration/platform IP (serverless engine integrating Nomad/Firecracker/Kuma) developed by the French team; underlying OSS components and chips originate partly outside the EU -> IP mostly within the EU -> opt4 (all-seal-4 factor, existing choice kept).
SOV-2.6IP holder jurisdiction5. Fully under EU law167/167SEAL-4mediumProprietary platform IP held by the French SAS (now Mistral, French) -> IP holder fully under EU law -> opt5 (seal 4).

SOV-3 · Data & AI Sovereignty 45.0% · SEAL-0 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys2. Primarily provider, not exclusively50/200SEAL-1lowManaged PaaS with platform-managed encryption at rest; customer-managed/BYOK key control is not the default -> keys primarily provider-controlled -> opt2 (seal 1).
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowLogging/observability exists but data-flow and access logs are vendor-controlled and not independently real-time auditable by the customer -> opt3 (seal 2).
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowGDPR/DPA commits to deletion of customer data per policy on termination, but no published independently-verified proof-of-erasure -> internal validation per policy -> opt3 (seal 1).
SOV-3.4Data location strictly in EU/EEA2. Partly EU, significant third-country reliance50/200SEAL-0highNOT eu_exclusive: operates US (Washington DC, San Francisco), Singapore and Tokyo regions and partners with US provider Vultr (32 global regions); EU regions exist but the offer has significant third-country reliance -> opt2 'partly EU, significant third-country reliance' (seal 0). Genuine SEAL-0 gate, not shared with the EU-exclusive members; not inflated per directive (src: https://www.koyeb.com/blog/partnering-with-vultr-for-serverless-and-global-ai-deployments).
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3mediumAI offering centres on deploying EU-origin/open-source models (notably Mistral's) on the platform -> EU-led AI, but inference runs on foreign accelerators (Nvidia/AMD) -> opt4 (seal 3).

SOV-4 · Operational Sovereignty 58.5% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumSupports OCI/container images, Git- and Docker-based deploys and standard data export -> documented portability -> opt3 (seal 4).
SOV-4.2Ability to operate without foreign dependencies4. Ops predominantly EU-based teams125/167SEAL-3mediumeu_ops: engineering team is France-based and joining Mistral's EU engineering org -> operations predominantly EU-based teams -> opt4 (seal 3).
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumCore engineering staff EU-based (France); no evidence of security clearances -> all-EU staff -> opt4 (seal 3).
SOV-4.4Support channels3. Majority in EU, non-EU escalations84/167SEAL-3lowSupport by a small EU-based team with some community/global support -> majority-EU support with possible non-EU escalation -> opt3 (seal 3).
SOV-4.5Documentation & knowledge transfer3. EU primary with non-EU fallback84/167SEAL-4lowDocumentation served via global CDN, authored by the EU team -> EU-primary with non-EU/global fallback -> opt3 (seal 4).
SOV-4.6Subcontractor & supplier jurisdiction3. Continue temporarily per contractual agreement84/167SEAL-3lowReliance on some non-EU bare-metal/colo partners (e.g. Vultr); a supplier cut-off allows temporary continuation while re-sourcing rather than full autonomy -> opt3 (seal 3).

SOV-5 · Supply Chain Sovereignty 43.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowHardware uses AMD/Intel/Nvidia/Tenstorrent components; provenance disclosed only partially via vendor names, no full bill-of-materials -> opt2 (seal 1).
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1mediumServers and chips manufactured outside the EU (US/Asia fabs) with only partial disclosure; no EU manufacturing -> opt2 (seal 1).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowServer firmware/BIOS from foreign hardware vendors; provenance at best partially disclosed -> opt2 (all-seal-4 factor, existing choice kept).
SOV-5.4Origin of software4. Large majority maintained by EU teams107/143SEAL-3mediumNo foreign_core: platform software (serverless engine, orchestration) is built and maintained by Koyeb's EU team atop open-source components -> large majority EU-maintained -> opt4 (seal 3).
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3lowBuild/release controlled and executed by the EU-based engineering team; no documented certified policy gates -> EU control and execution -> opt4 (seal 3).
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2mediumDependence on non-EU vendors for critical compute (US partner Vultr, foreign chips), documented via partnerships but affecting critical infrastructure -> few non-EU in critical services -> opt3 (seal 2).
SOV-5.7Supply chain transparency2. Some suppliers auditable36/143SEAL-1lowSupply chain (chip vendors, colo/bare-metal partners) only partially auditable; some suppliers named, no comprehensive supplier-audit program -> opt2 (seal 1).

SOV-6 · Technology Sovereignty 60.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumStandards-based: OCI containers, HTTP/gRPC, Git/Docker workflows and documented APIs -> broadly portable -> opt4 (seal 3).
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumCore services rely on open standards (OCI, HTTP, TLS, standard networking) across most core services -> opt4 (seal 3).
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3mediumHeavy use of open-source (Firecracker, Nomad, Kuma) and deploys open-source models, but the Koyeb control-plane/orchestration code is proprietary with centralised governance -> open source, centralised governance -> opt3 (seal 3).
SOV-6.4Service architecture transparency4. Large corpus of public insight150/200SEAL-3mediumPublishes a large corpus of detailed engineering blog posts/docs on the serverless architecture (Nomad/Firecracker/Kuma) -> large corpus of public insight -> opt4 (seal 3).
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowGPU/HPC capacity uses foreign accelerators (Nvidia/AMD) on a foreign hardware/software stack, hosted and operated in EU (and other) regions -> EU-hosted, foreign stack -> opt2 (seal 3).

SOV-7 · Security & Compliance Sovereignty 39.5% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)1. EAL0 / none0/143SEAL-1mediumNo SecNumCloud and no Common Criteria EAL certification documented; ISO 27001/SOC 2 not evidenced as held -> effectively EAL0/none -> opt1 (seal 1). No SecNumCloud-IaaS basis, so not inflated per directive.
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumGDPR-compliant processor with a DPA; partial compliance to most relevant EU regimes, no evidence of full DORA/NIS2 audited compliance -> opt4 (all-seal-4 factor, existing choice kept).
SOV-7.3EU-based SOC & incident handling2. Hybrid EU/non-EU36/143SEAL-1lowSmall EU company with global regions and a US infrastructure partner; security operations/incident response likely a hybrid EU/non-EU function -> opt2 (seal 1).
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1lowCustomers get a monitoring/observability portal with logs/metrics, but not full direct access to immutable EU-stored security logs by default -> opt3 (seal 1).
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2lowGDPR-bound EU processor; incident disclosure is GDPR/NIS2-aligned (moderate) without documented real-time CSIRT sharing -> opt3 (seal 2).
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowKoyeb controls its own platform maintenance with notice/testing windows; emergency/zero-day patches may apply without prior notice -> moderate autonomy -> opt3 (seal 4).
SOV-7.7Auditability2. Limited independent access36/143SEAL-1lowNo audit_rights: independent auditability limited to certification-body audits; customers cannot freely conduct independent audits -> limited independent access -> opt2 (seal 1).

SOV-8 · Environmental Sustainability 31.4% · SEAL-0 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)2. PUE < 363/250SEAL-1lowKoyeb does not publish its own PUE; runs on third-party/colo data centres of varying efficiency -> conservative PUE<3 tier -> opt2 (seal 1).
SOV-8.2Hardware reuse & recycling2. Basic circular practices63/250SEAL-0lowNo published hardware reuse/recycling program; basic circular practices inherited from colo/hardware providers at most -> opt2 (seal 0).
SOV-8.3Environmental impact reporting2. Basic reporting63/250SEAL-1lowNo detailed environmental-impact reporting published; only basic/indirect reporting via underlying providers -> opt2 (seal 1).
SOV-8.4Energy supplies3. Mix of EU and non-EU supplies125/250SEAL-4lowEU and non-EU (US, APAC) regions on third-party data centres; energy supply is a mix of EU and non-EU sources without a published renewable-only guarantee -> opt3 (all-seal-4 factor, existing choice kept).