🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Krystal

United Kingdom · IaaS/PaaS · https://krystal.uk

Sovereignty score38.4%
Global (unweighted)40.9%
Overall SEAL
SEAL-0 No Sovereignty
SOV-1 Strategic Sovereignty33.4SEAL-1
SOV-2 Legal & Jurisdictional Sovereignty21.0SEAL-1
SOV-3 Data & AI Sovereignty40.0SEAL-0
SOV-4 Operational Sovereignty33.5SEAL-1
SOV-5 Supply Chain Sovereignty36.0SEAL-1
SOV-6 Technology Sovereignty45.0SEAL-2
SOV-7 Security & Compliance Sovereignty43.1SEAL-1
SOV-8 Environmental Sustainability75.0SEAL-2

SOV-1 · Strategic Sovereignty 33.4% · SEAL-1 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control2. Mostly outside the EU42/125SEAL-1highno eu_entity (Krystal Hosting Ltd incorporated in England and Wales, company 07571790, HQ London; UK is a third country outside EU/EEA), but a real EU footprint via the Amsterdam (NL) Katapult region keeps some presence in the EU -> SOV-1.1 opt2 'mostly outside the EU' (seal 1). Aligned with the other EU-footprint cluster member (Civo). (src: https://find-and-update.company-information.service.gov.uk/company/07571790)
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4highPrivately held, founder-owned (Simon Blackler majority shareholder) independent UK company, the UK's largest independently owned host; takeover/transfer to a non-EU sovereign entity is very unlikely -> opt5 (all-SEAL-4 factor, existing choice kept).
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2lowRoadmap set internally by the private UK company; EU customers have only standard 'voice of the customer' feedback channels, no governance bodies with EU-actor participation -> opt2 (seal 2).
SOV-1.4Financial independence from non-EU capital1. Almost entirely relying on non-EU funding0/125SEAL-4mediumSelf-funded/bootstrapped UK company with no EU capital base; almost entirely non-EU (UK) funding -> opt1 (all-SEAL-4 factor, existing choice kept).
SOV-1.5EU economic contribution2. Some31/125SEAL-4mediumSome EU economic contribution via the Amsterdam (NL) data centre and EU customers, but the bulk of operations, employment and revenue are UK/non-EU -> opt2 (all-SEAL-4 factor, existing choice kept).
SOV-1.6Participation in EU strategic programs1. No clear participation0/125SEAL-4highNo participation in EU strategic programs (Gaia-X, IPCEI-CIS); a UK B Corp web/cloud host with no EU sovereignty program involvement -> opt1 (all-SEAL-4 factor, existing choice kept).
SOV-1.7Alignment with EU industrial strategies1. No evidence exists0/125SEAL-4mediumNo evidence of alignment with EU industrial strategies; aligns with B Corp/sustainability goals, not EU digital-sovereignty industrial policy -> opt1 (all-SEAL-4 factor, existing choice kept).
SOV-1.8Resilience to cut-off4. Ability to source alternatives or internalise key functions94/125SEAL-2lowNo own_stack in EU-sovereign sense: Katapult is in-house-operated on commodity hardware Krystal controls (UK), could source alternatives or internalise key functions, but core silicon/storage vendors are non-EU and the operator is non-EU -> opt4 'Ability to source alternatives or internalise' (seal 2), not opt5.

SOV-2 · Legal & Jurisdictional Sovereignty 21.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction1. Non-EU only0/167SEAL-1highno eu_entity: primary jurisdiction is UK law (England and Wales) per Katapult/Krystal terms; non-EU only despite GDPR adequacy -> SOV-2.1 opt1 (seal 1). (src: https://find-and-update.company-information.service.gov.uk/company/07571790)
SOV-2.2Extraterritorial laws exposure2. Mitigation clauses, exposure remains42/167SEAL-1mediumNo immunity: UK entity with standard GDPR/DPA contractual clauses but remains exposed to UK extraterritorial law (Investigatory Powers Act 2016, technical capability notices, UK-US data access); mitigation clauses do not remove exposure -> opt2 (seal 1).
SOV-2.3Data access pathways for non-EU authorities2. Can compel access without notification, specific cases42/167SEAL-1highno immunity (UK provider subject to UK Investigatory Powers Act 2016) -> authorities can compel data access without customer notification in specific cases; no policy of always refusing -> SOV-2.3 opt2 (seal 1). This is the legal SEAL-1 cap. Normalised across the UK cluster (all subject to UK IPA).
SOV-2.4Export control restrictions2. Restrictions towards EU citizens or international orgs42/167SEAL-1lowno eu_exclusive: as a non-EU (UK) provider the offer is not specifically shielded from non-EU export controls affecting EU citizens/orgs, and UK-majority revenue is not >50% in the EU; no EU-MS-specific restriction identified -> SOV-2.4 opt2 (seal 1). Normalised with the UK cluster.
SOV-2.5Origin of IP3. Mixed within/outside the EU84/167SEAL-4lowKatapult platform software is developed in-house (UK) but the IP stack mixes in-house code with open-source and third-party vendor IP (VAST, StorPool, AMD, Nvidia); mixed within/outside the EU -> opt3 (all-SEAL-4 factor).
SOV-2.6IP holder jurisdiction1. Non-EU law, single country0/167SEAL-3mediumCore platform IP held by Krystal Hosting Ltd under UK (non-EU) law, a single non-EU country -> opt1 (seal 3).

SOV-3 · Data & AI Sovereignty 40.0% · SEAL-0 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys2. Primarily provider, not exclusively50/200SEAL-1lowStandard IaaS/hosting model with provider-managed infrastructure encryption; no published customer-held/HYOK key management, primarily provider-controlled though not exclusively -> opt2 (seal 1).
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowLogging/audit trails exist (ISO 27001:2022 controls) but are vendor-controlled with no published real-time, independently auditable customer access to data-flow logs -> opt3 (seal 2).
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowISO 27001-aligned data handling implies internal deletion validation per policy, but no cryptographic proof-of-erasure or independently verified irreversible deletion -> opt3 (seal 1).
SOV-3.4Data location strictly in EU/EEA2. Partly EU, significant third-country reliance50/200SEAL-0highNo eu_exclusive: Katapult regions are UK, US (Phoenix/NY) and Amsterdam (NL), controlled by a UK entity; data is partly EU with significant third-country (UK/US) reliance and no EU-exclusivity guarantee -> SOV-3.4 opt2 'Partly EU, significant third-country reliance' (seal 0). This sets the overall SEAL-0. (src: https://krystal.io/technology)
SOV-3.5AI services sovereignty3. Mixed: auditable/open-source AI, foreign chips100/200SEAL-2lowIn-scope GPU/AI: Krystal offers Nvidia GPUs on its KVM-based platform with auditable/open tooling but no EU-origin AI models or sovereign AI stack; mixed/open AI on foreign chips -> SOV-3.5 opt3 (seal 2). Aligned with the GPU-on-open-tooling cluster member (Civo).

SOV-4 · Operational Sovereignty 33.5% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumStandard documented data export and VPS/image portability on a KVM-based platform with standard APIs; no proprietary-format lock-in -> opt3 (seal 4).
SOV-4.2Ability to operate without foreign dependencies2. Ops partially sourced within EU42/167SEAL-1mediumNo eu_ops: critical operations delivered by Krystal's UK (non-EU) teams; only the Amsterdam footprint is partially within the EU, so EU-sourced operations are limited -> opt2 (seal 1).
SOV-4.3Skill availability in the EU2. Mixed, majority outside EU42/167SEAL-1mediumEngineering/operations staff predominantly UK-based (non-EU); majority of skilled staff sit outside the EU -> opt2 (seal 1).
SOV-4.4Support channels2. Mixed, majority outside EU42/167SEAL-2mediumSupport is UK-centric (24/7 in-house UK support); mixed with the majority outside the EU from an EU-sovereignty standpoint -> opt2 (seal 2).
SOV-4.5Documentation & knowledge transfer2. EU optional, not enforced42/167SEAL-2lowDocumentation/knowledge base is publicly available and not EU-restricted; primary repositories are UK/global, so EU handling is optional and not enforced -> opt2 (seal 2).
SOV-4.6Subcontractor & supplier jurisdiction3. Continue temporarily per contractual agreement84/167SEAL-3lowSubcontractors/suppliers (data-centre operators Iron Mountain/Netwise, StorPool, VAST) are contracted; service could continue temporarily per contractual agreement, though several critical suppliers are non-EU -> opt3 (seal 3).

SOV-5 · Supply Chain Sovereignty 36.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1mediumHardware vendors publicly named (AMD, Nvidia, Mellanox, Juniper, VAST, StorPool) giving partial provenance disclosure, but no EU-certified component provenance -> opt2 (seal 1).
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1highCompute/storage/networking hardware is foreign-origin (AMD/Nvidia US silicon, Juniper/Mellanox US networking, VAST US) with partial disclosure; not built by EU teams -> opt2 (seal 1).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/embedded code from foreign hardware vendors (AMD, Nvidia, Juniper, Mellanox) with partial disclosure and no EU-certified firmware provenance -> opt2 (all-SEAL-4 factor, existing choice kept).
SOV-5.4Origin of software3. Core/essential parts maintained by EU teams72/143SEAL-3mediumNo foreign_core: Katapult control-plane is developed and maintained in-house by Krystal's (UK) team on open-source (KVM); core/essential platform parts are team-maintained, integrating third-party non-EU storage/networking software -> opt3 'Core/essential parts maintained by EU teams' (seal 3). Not capped by foreign_core.
SOV-5.5Software build/release jurisdiction2. EU control, non-EU execution36/143SEAL-1lowSoftware build/release controlled by Krystal (UK) and executed on UK infrastructure; from an EU lens this is non-EU control with non-EU (UK) execution and no EU policy gates -> opt2 (seal 1).
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2mediumSeveral non-EU vendors sit in critical services (US AMD/Nvidia silicon, US VAST storage, US Juniper/Mellanox networking), documented; few non-EU critical dependencies -> opt3 (seal 2).
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowCritical suppliers and data-centre partners are named and covered by ISO 27001:2022 supply-chain controls, giving auditability of critical suppliers, but not full end-to-end transparency -> opt3 (seal 2).

SOV-6 · Technology Sovereignty 45.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumKatapult exposes standard APIs and runs KVM-based VMs with standard OS images: standards-based and broadly compatible interfaces -> opt4 (seal 3).
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2lowUses open standards (KVM, standard networking/storage protocols, standard VM images) across core services, but no published policy mandating open standards for all services -> opt3 (seal 2).
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2lowKatapult control plane is proprietary/in-house, built on open-source foundations (KVM/Linux) but not published as open source; source-available/closed governance -> opt2 (seal 2). No foreign_core but still vendor-controlled.
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowKrystal publishes technology details, knowledge base, status/changelog and blog posts giving some public architecture insight, but not deep contributable transparency -> opt3 (seal 3).
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowGPU/HPC capability uses imported Nvidia accelerators hosted in Krystal's data centres; EU-/UK-hosted on a foreign (US) hardware/software stack -> opt2 'EU-hosted, foreign stack' (seal 3).

SOV-7 · Security & Compliance Sovereignty 43.1% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)2. EAL136/143SEAL-1mediumNo SecNumCloud/EUCS/C5/EAL and no SOC 2; holds ISO 27001:2022 + Cyber Essentials (Plus) + PCI DSS. Per the key the EAL2 (opt3) bar requires ISO 27001 + SOC 2, so an ISO-27001-centred cert set without SOC 2 maps to ISO-27001-only -> SOV-7.1 opt2 'EAL1' (seal 1). Normalised with the equivalently-certified cluster member (iomart). (src: https://krystal.io/technology)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumStrong GDPR alignment plus ISO 27001:2022 and Cyber Essentials, but no fully independently audited NIS2/DORA compliance; partial compliance to most -> opt4 (all-SEAL-4 factor).
SOV-7.3EU-based SOC & incident handling2. Hybrid EU/non-EU36/143SEAL-1lowSecurity operations and incident handling run by Krystal's UK teams; from an EU sovereignty view a hybrid EU/non-EU posture given the Amsterdam footprint -> opt2 (seal 1).
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1lowCustomers get a control/monitoring portal and standard logs, but no published guarantee of full direct log access with logs stored in the EU -> opt3 (seal 1).
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2mediumIncident disclosure is GDPR/UK-DPA aligned (ISO 27001:2022 incident management); moderate, regulation-aligned disclosure but not real-time EU CSIRT sharing -> opt3 (seal 2).
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowAs operator of its own Katapult platform Krystal has moderate maintenance autonomy (scheduled maintenance with notice/testing), though dependent on third-party hardware/firmware vendor cycles -> opt3 (seal 4).
SOV-7.7Auditability2. Limited independent access36/143SEAL-1lowNo audit_rights: ISO 27001:2022 gives independent third-party audit of the ISMS, but customers have only limited independent audit access to the underlying platform -> opt2 (seal 1).

SOV-8 · Environmental Sustainability 75.0% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)5. PUE < 1.2, EU verified250/250SEAL-4highNew London data centre (Netwise East) designed for world-leading PUE (~1.05) and all data centres achieve PUE of at least 1.2, with verified figures -> opt5 'PUE < 1.2' (seal 4). (src: https://krystalhosting.com/green)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowAs a B Corp with sustainability commitments there is a documented circular/responsible hardware program, but no EU-certified lifecycle published -> opt3 (seal 3).
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2mediumB Corp certification (score 81.8) and 1% For The Planet membership imply annual impact reporting, but not a detailed EU-methodology or EU-audited environmental report -> opt3 (seal 2).
SOV-8.4Energy supplies5. Only green EU energy supplies250/250SEAL-4mediumAll data centres run on 100% renewable electricity (Ecotricity, wind/solar/sea); green energy supplies -> opt5 (all-SEAL-4 factor, existing choice kept). (src: https://krystalhosting.com/green)