🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Leafcloud

Netherlands · IaaS/PaaS · https://www.leaf.cloud

Sovereignty score67.0%
Global (unweighted)65.5%
Overall SEAL
SEAL-1 Jurisdictional Sovereignty
SOV-1 Strategic Sovereignty71.9SEAL-3
SOV-2 Legal & Jurisdictional Sovereignty71.0SEAL-2
SOV-3 Data & AI Sovereignty65.0SEAL-1
SOV-4 Operational Sovereignty83.2SEAL-3
SOV-5 Supply Chain Sovereignty43.1SEAL-1
SOV-6 Technology Sovereignty70.0SEAL-3
SOV-7 Security & Compliance Sovereignty57.2SEAL-1
SOV-8 Environmental Sustainability62.5SEAL-2

SOV-1 · Strategic Sovereignty 71.9% · SEAL-3 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity (Dutch B.V., Amsterdam HQ, founder + EU impact investor The Sharing Group holding a minority stake, no non-EU parent) -> entirely within the EU, opt4. (src: https://press.thesharinggroup.com/246202-the-sharing-group-and-leafcloud-join-forces-for-sustainable-european-cloud-services/)
SOV-1.2Change of control risk4. Unlikely takeover/transfer to non-EU sovereign entity94/125SEAL-4mediumFounder-led Dutch company with an EU (Amsterdam) impact investor holding a minority stake; no signals of non-EU takeover intent, though as a small startup acquisition cannot be fully excluded. (all-seal-4 factor, choice kept)
SOV-1.3Control over roadmap3. Governance bodies exist with EU actors participation83/125SEAL-3lowCore platform is community-governed open-source (OpenStack/Gardener) with EU actor participation in those governance bodies; EU-controlled provider with some external influence -> opt3.
SOV-1.4Financial independence from non-EU capital4. Majority of funding is EU-based94/125SEAL-4mediumFunding from the Dutch founder and Amsterdam-based The Sharing Group (EU impact investor); no disclosed non-EU capital -> majority/entirely EU-based, opt4. (all-seal-4 factor, choice kept)
SOV-1.5EU economic contribution5. Fully in the EU125/125SEAL-4highAll infrastructure, staff, datacentres and heat-reuse operations are in the Netherlands; economic contribution fully in the EU. (all-seal-4 factor, choice kept)
SOV-1.6Participation in EU strategic programs2. Limited participation31/125SEAL-4lowAligned with Gaia-X/EU sovereignty goals and in the EuroStack directory, but no documented active role in IPCEI-CIS or other EU strategic programs; limited participation. (all-seal-4 factor, choice kept)
SOV-1.7Alignment with EU industrial strategies2. Existing action plan42/125SEAL-4lowClear positioning as a European, open, sustainable alternative to US hyperscalers (an action plan), but no measured achievement framework or dedicated sovereignty governance published. (all-seal-4 factor, choice kept)
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4mediumown_stack: own NL datacentres + open-source OpenStack/Gardener (EU-maintained integration), continuity depends on no non-EU vendor with only residual foreign chips as hardware -> Full autonomy and continuity, opt5 (judgment call per key #1).

SOV-2 · Legal & Jurisdictional Sovereignty 71.0% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highDutch B.V. operating exclusively under Dutch/EU law with all data in the Netherlands -> exclusively EU law, opt3. (src: https://leaf.cloud/products/virtual-machines/)
SOV-2.2Extraterritorial laws exposure4. Legal structures shielding from foreign law125/167SEAL-2mediumeu_entity with structural separation (no non-EU parent/subsidiary for foreign authorities to compel) but no certified immunity (no SecNumCloud/EUCS-High) -> Legal structures shielding from foreign law, opt4 (seal 2). This is the SEAL-2 ceiling.
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4highNo foreign_parent; not subject to US CLOUD Act/FISA; non-EU requests must go through MLAT with EU judicial oversight, so direct non-EU compelled access is rejected -> Requests always rejected, opt5. (src: https://leaf.cloud/products/virtual-machines/)
SOV-2.4Export control restrictions3. Share of revenues >50% in the EU84/167SEAL-2lowEU-only provider with revenues overwhelmingly in the EU and no foreign-state export-control leverage over the service; no specific shielding mechanism documented -> share of revenues >50% in EU, opt3.
SOV-2.5Origin of IP3. Mixed within/outside the EU84/167SEAL-4mediumCore platform is open-source OpenStack/Gardener (mixed global/EU community IP) with EU-developed integration; underlying hypervisor and GPU/firmware IP originate outside the EU -> mixed, opt3. (all-seal-4 factor, choice kept)
SOV-2.6IP holder jurisdiction3. Mixed law, some EU84/167SEAL-3mediumOpen-source stack IP held under mixed jurisdictions (much of OpenStack/NVIDIA stack non-EU) with EU-held integration code; not fully under EU law -> mixed law, some EU, opt3.

SOV-3 · Data & AI Sovereignty 65.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys3. Shared - provider has override keys100/200SEAL-2lowVolumes use LUKS AES-256 by default but as an OpenStack IaaS the provider operates key management and can technically access keys/data; no customer-exclusive HYOK -> shared, provider has override, opt3.
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowOpenStack and facility logs exist but no documented real-time customer-controlled independent audit trail of all data access -> logs exist but not real-time, opt3.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowDPA covers retention/deletion (internal validation per policy) but no documented cryptographic proof of erasure or independent verification -> internal validation per policy, opt3.
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4higheu_exclusive: all persistent data stored and processed exclusively in Amsterdam/NL, never leaves NL unless the customer transfers it, no third-country fallback -> opt5. (src: https://leaf.cloud/products/virtual-machines/)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3mediumAI/GPU offering runs open-source/EU-controllable model stacks on NVIDIA A100/H100/Blackwell accelerators in NL; EU-led AI on foreign accelerators -> opt4.

SOV-4 · Operational Sovereignty 83.2% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability5. Already deployed on sovereign infrastructure167/167SEAL-4highStandard OpenStack APIs with S3-compatible object storage, Terraform/Ansible support, no lock-in; already deployed on sovereign open-standard infrastructure -> opt5.
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4higheu_ops: entire stack operated by the Amsterdam-based team, all operations in NL with no foreign operational dependency -> entire stack managed by fully EU-based team, opt5.
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumStaff Amsterdam/EU-based; no evidence of formal security clearances -> all EU staff, opt4.
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3highSupport by the Amsterdam-based team; all support staff in EU, no documented clearance regime -> all support staff in EU, opt4.
SOV-4.5Documentation & knowledge transfer4. EU-only primary repositories125/167SEAL-4lowDocumentation and operations Amsterdam/EU-centric with no non-EU repositories indicated -> EU-only primary repositories, opt4.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3lowSubcontractors (datacentre, hardware vendors) largely EU-based or substitutable; on open-source OpenStack it can source alternatives or internalise functions -> ability to source alternatives, opt4.

SOV-5 · Supply Chain Sovereignty 43.1% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowHardware components (servers, NVIDIA GPUs) foreign-sourced with only partial public disclosure of provenance -> partial disclosure, opt2.
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1lowServer and GPU hardware manufactured outside the EU with partial disclosure; Leafcloud assembles/operates but does not design or build hardware -> foreign origin, partial disclosure, opt2.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/embedded code (BIOS, NIC, GPU firmware) from foreign vendors with only partial disclosure -> partial disclosure, opt2. (all-seal-4 factor, choice kept)
SOV-5.4Origin of software3. Core/essential parts maintained by EU teams72/143SEAL-3mediumNo foreign_core: core platform is open-source OpenStack/Gardener with essential integration maintained by the EU team -> core/essential parts maintained by EU teams, opt3 (seal 3).
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3lowPlatform configuration and releases controlled and executed by the Amsterdam-based EU team (EU control and execution), without documented formal EU policy gates -> opt4.
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2mediumCritical hardware (servers, NVIDIA GPUs) is a documented but real non-EU dependency for some critical components; software/ops layer has none -> few non-EU in critical services, documented, opt3.
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowCritical suppliers (datacentre, NVIDIA, server OEMs) identifiable/auditable to a degree via certifications, but not a fully published auditable supplier chain -> critical suppliers auditable, opt3.

SOV-6 · Technology Sovereignty 70.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces5. Open-by-default with portability200/200SEAL-4highOpen-by-default OpenStack and S3-compatible APIs with Terraform/Ansible support and explicit no-lock-in stance -> open-by-default with portability, opt5.
SOV-6.2Open standards compliance5. Policy for all core services200/200SEAL-4highBuilt entirely on open standards (OpenStack, Kubernetes/Gardener, S3) across all core services -> policy for all core services, opt5.
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3highNo foreign_core; stack fully built on open-source software (OpenStack, Gardener) but governance centralised in upstream foundations rather than EU/Leafcloud-controlled -> open source, centralised governance, opt3 (seal 3).
SOV-6.4Service architecture transparency4. Large corpus of public insight150/200SEAL-3mediumOpen-source OpenStack/Gardener gives a large corpus of public architecture insight; customers cannot directly co-develop Leafcloud's deployment -> large corpus of public insight, opt4.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3mediumGPU/AI compute is EU-hosted (NL) on a foreign hardware/accelerator stack (NVIDIA); no EU-designed HPC silicon -> EU-hosted, foreign stack, opt2 (seal 3).

SOV-7 · Security & Compliance Sovereignty 57.2% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)3. EAL272/143SEAL-2mediumHolds ISO 27001 + SOC2 Type II (independent attestation beyond bare ISO) but no SecNumCloud/EUCS/C5/EAL -> EAL2-equivalent, opt3 (seal 2). Consistent with the SEAL-2 ceiling. (src: https://leaf.cloud/blog/iso-27001-certified/)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4highGDPR-compliant with DPA, ISO 27001 and SOC2 Type II, NIS2-aligned and DORA-aware, HAVEN+ in progress; partial compliance to most regimes but not a single independently audited full attestation -> opt4. (all-seal-4 factor, choice kept)
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3lowIncident handling and operations entirely by the Amsterdam-based EU team with EU threat intel; no documented ENISA sharing -> entire lifecycle by EU teams, opt4.
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3lowOpenStack gives customers direct access to logs/monitoring with all logs stored in NL; no documented immutable tamper-proof guarantee -> full direct access, logs stored in EU, opt4.
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2mediumIncident notification aligned to GDPR/NIS2 (24-72h reporting); not documented real-time CSIRT sharing -> moderate (GDPR/NIS2-aligned), opt3.
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowOpen-source self-operated stack gives moderate autonomy with notice/testing windows -> moderate autonomy, opt3 (seal 4).
SOV-7.7Auditability2. Limited independent access36/143SEAL-1lowNo audit_rights: only ISO 27001 + SOC2 Type II certification-body audits, no SecNumCloud/sovereign-offer contractual full audit right for the contracting authority/independent EU bodies -> limited independent access, opt2 (seal 1). Normalised to match the other pure-EU Benelux providers (none holds tender-grade audit rights). This sets the overall SEAL. (src: https://leaf.cloud/blog/iso-27001-certified/)

SOV-8 · Environmental Sustainability 62.5% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4mediumDistributed heat-reuse Leaf sites and Tier III core in NL; heat-reuse model makes each kWh dual-use and Dutch DC norms target low PUE, but no provider-published verified PUE figure -> PUE<1.5 + roadmap, opt3. (src: https://leaf.cloud/products/virtual-machines/)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowReuses existing buildings, avoids new construction, documented sustainability program; no published EU-certified hardware lifecycle/recycling scheme -> documented program, opt3.
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2mediumPublishes detailed carbon/heat-displacement metrics and whitepapers; treated as annual/structured reporting but not independently EU-audited -> annual report, opt3.
SOV-8.4Energy supplies5. Only green EU energy supplies250/250SEAL-4mediumPurchases renewable energy in NL and displaces fossil-gas heating via heat reuse; only green EU energy supplies -> opt5. (all-seal-4 factor, choice kept) (src: https://leaf.cloud/products/virtual-machines/)