🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Mittwald

Germany · IaaS/PaaS · https://www.mittwald.de

Sovereignty score68.1%
Global (unweighted)66.1%
Overall SEAL
SEAL-1 Jurisdictional Sovereignty
SOV-1 Strategic Sovereignty82.3SEAL-4
SOV-2 Legal & Jurisdictional Sovereignty87.4SEAL-2
SOV-3 Data & AI Sovereignty60.0SEAL-1
SOV-4 Operational Sovereignty79.0SEAL-3
SOV-5 Supply Chain Sovereignty46.6SEAL-1
SOV-6 Technology Sovereignty60.0SEAL-3
SOV-7 Security & Compliance Sovereignty57.2SEAL-1
SOV-8 Environmental Sustainability56.3SEAL-1

SOV-1 · Strategic Sovereignty 82.3% · SEAL-4 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4highMittwald CM Service GmbH & Co. KG is a German company registered in Espelkamp (Amtsgericht Bad Oeynhausen HRA 6640), entirely within the EU with no non-EU parent. (src: https://www.mittwald.de/darum-mittwald/technologie)
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4highFamily-owned ~80-year-old Mittelstand business controlled by founder/CEO Robert Meyer via Robert Meyer Verwaltungs GmbH; no external/non-EU investors, takeover very unlikely.
SOV-1.3Control over roadmap4. Full influence of EU actors125/125SEAL-4mediumAs an owner-controlled EU company that builds its own platform (mStudio), roadmap is fully controlled by EU actors and responsive to its EU agency customer base.
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4highPrivately held German family business financed from its own operations; no evidence of any non-EU capital.
SOV-1.5EU economic contribution5. Fully in the EU125/125SEAL-4highAll staff, data center, and operations are in Germany; the entire economic footprint is within the EU.
SOV-1.6Participation in EU strategic programs2. Limited participation31/125SEAL-4lowMember of the eco Association and active in the German hosting ecosystem, but no clear evidence of participation in EU strategic programs like Gaia-X or IPCEI-CIS; limited participation assumed.
SOV-1.7Alignment with EU industrial strategies2. Existing action plan42/125SEAL-4lowMarkets DSGVO-compliant German hosting and data sovereignty as a value proposition, indicating an action plan aligned with EU digital sovereignty, but no formal governance for industrial-strategy alignment is evidenced.
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4mediumown_stack: vertically integrated EU provider (own German DC, in-house mStudio on open-source Kubernetes/Linux/OpenEBS) with continuity depending on no non-EU vendor (only residual foreign chips) -> SOV-1.8 opt5 'Full autonomy and continuity'.

SOV-2 · Legal & Jurisdictional Sovereignty 87.4% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highA wholly German GmbH & Co. KG with German data centers operates exclusively under EU (German) law; no non-EU jurisdiction applies. (src: https://www.mittwald.de/darum-mittwald/technologie)
SOV-2.2Extraterritorial laws exposure4. Legal structures shielding from foreign law125/167SEAL-2mediumeu_entity with structural separation (pure-DE, no non-EU parent/nexus) but immunity NOT certified (ISO 27001 only, no SecNumCloud/EUCS-High) -> SOV-2.2 opt4 'Legal structures shielding' (seal 2). (src: https://www.mittwald.de/blog/mittwald/safety-first-gepruefte-informationssicherheit-bei-mittwald)
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumNo foreign_parent: pure-DE entity not subject to US CLOUD Act/FISA/PRC law, commits to reject extraterritorial requests -> SOV-2.3 opt5 'Requests always rejected' (seal 4). (src: https://www.mittwald.de/darum-mittwald/technologie)
SOV-2.4Export control restrictions4. Part of offer shielded from restrictions towards EU MSs125/167SEAL-3mediumPure-EU provider with no non-EU export-control exposure; the offer is shielded from restrictions toward EU Member States -> SOV-2.4 opt4 (seal 3).
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4mediumThe mStudio platform IP (microservices, API clients, CLI, Terraform provider) is developed in-house in Germany; built on open-source foundations but the proprietary platform IP is mostly EU-origin.
SOV-2.6IP holder jurisdiction5. Fully under EU law167/167SEAL-4mediumMittwald's own platform IP is held by the German company under German/EU law; underlying open-source components carry permissive licenses but the proprietary IP is fully under EU law.

SOV-3 · Data & AI Sovereignty 60.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys2. Primarily provider, not exclusively50/200SEAL-1lowAs a managed hosting/PaaS provider, encryption is primarily provider-managed; no evidence of customer-held exclusive key management (BYOK/HYOK), so the provider can technically access data.
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowmStudio provides logging and monitoring with AI-based anomaly detection, but logs are largely vendor-controlled and not described as real-time independently auditable customer oversight.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowISO 27001 implies documented deletion procedures validated internally per policy, but no independently verified cryptographic proof-of-erasure is published.
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4higheu_exclusive: data stored AND processed only in Mittwald's German DC (Espelkamp) with no third-country fallback -> SOV-3.4 opt5 'Exclusively EU' (seal 4). (src: https://www.mittwald.de/darum-mittwald/technologie)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3highEU-led AI on foreign accelerators: open-weight models served exclusively in the German DC on foreign GPUs -> SOV-3.5 opt4 (seal 3).

SOV-4 · Operational Sovereignty 79.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumStandards-based platform (Docker/Kubernetes, OpenAI-compatible API, Terraform, CLI) with documented export methods and migration support for agencies moving in/out.
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4highThe entire stack is operated by Mittwald's in-house team in Espelkamp, Germany, with 24/7 on-site technical staff; no non-EU operational dependency for running the service.
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3highAll staff are based at the single German site in Espelkamp; an EU-only workforce, though no formal security clearances are advertised.
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3highSupport is provided by the German team in Espelkamp (German/English); all support staff in the EU, no advertised security clearances.
SOV-4.5Documentation & knowledge transfer4. EU-only primary repositories125/167SEAL-4mediumDocumentation (developer portal, blog) is produced and hosted by the German company; primary repositories are EU-based with no non-EU dependency required.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3mediumOwning its data center and using standard/open-source software, Mittwald could source alternatives or internalise functions if a subcontractor failed, though hardware suppliers are non-EU.

SOV-5 · Supply Chain Sovereignty 46.6% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowServer hardware is sourced from global (non-EU) OEMs/component makers; Mittwald describes 'modern hardware' but provides only partial disclosure of physical component origin.
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1lowServers/CPUs are manufactured by foreign vendors (e.g., Intel/AMD, global ODMs); foreign manufacturing origin with limited disclosure.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/microcode in CPUs, NICs, and drives comes from non-EU vendors and is not fully disclosed; only partial provenance visibility typical of commodity hardware.
SOV-5.4Origin of software4. Large majority maintained by EU teams107/143SEAL-3mediumThe mStudio platform software is designed and maintained in-house by the German team and built on open-source (Kubernetes, OpenEBS, Linux); the large majority of the operated software stack is EU-maintained or open.
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3mediumSoftware for the platform is developed and released by Mittwald's German engineering team, so build/release is under EU control and EU execution.
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2lowCritical services run on Mittwald's own German infrastructure, but a few non-EU dependencies remain in critical layers (hardware OEMs, GPU accelerators for AI); documented but present.
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowThrough ISO 27001 audit scope, critical suppliers are subject to review, but full end-to-end supply-chain auditability across all hardware suppliers is not demonstrated.

SOV-6 · Technology Sovereignty 60.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3highPlatform exposes standards-based interfaces: Docker/Kubernetes, OpenAI-compatible API, REST API, CLI, and a Terraform provider, enabling broad compatibility and portability.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumCore services adopt open standards (OCI containers, Kubernetes, OpenAI-compatible API, HTTP/REST, Terraform) as a deliberate policy across most of the platform.
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3mediumMittwald maintains many open-source repositories (API clients, CLI, Terraform provider, deployer recipes) and contributes upstream to OpenEBS, but the core mStudio platform itself is proprietary with centralised governance.
SOV-6.4Service architecture transparency4. Large corpus of public insight150/200SEAL-3mediumPublishes detailed public architecture insights (Cloud Plattform Insights blog series), a developer portal, and open-source clients, providing a large corpus of public insight into the service architecture.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowNo in-scope HPC/supercomputing offering; per key, absence of HPC is not penalised as imported black-box -> SOV-6.5 opt2 'EU-hosted, foreign stack' (seal 3).

SOV-7 · Security & Compliance Sovereignty 57.2% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)2. EAL136/143SEAL-1highHolds ISO 27001 only (TUV Rheinland; no SecNumCloud/EUCS-High/C5/Common Criteria EAL); key maps ISO 27001-only -> SOV-7.1 opt2 'EAL1' (seal 1). This caps the overall SEAL. (src: https://www.mittwald.de/blog/mittwald/safety-first-gepruefte-informationssicherheit-bei-mittwald)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumISO 27001 certified and markets full GDPR compliance with German hosting; NIS2/DORA-relevant practices likely but not all independently audited across every framework, so partial compliance to most.
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3mediumSecurity operations and incident handling are run by the in-house German team with on-site 24/7 monitoring and AI anomaly detection; full lifecycle handled by EU teams, no advertised ENISA/CSIRT integration.
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3lowCustomers get monitoring/logging access through mStudio with logs stored in the German data center; not described as immutable tamper-proof, so full direct access with EU-stored logs.
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2lowAs a German provider it follows GDPR (and increasingly NIS2) breach-notification obligations; moderate, regulation-aligned disclosure with no evidence of real-time CSIRT sharing.
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4mediumAs operator of its own platform and data center, Mittwald has moderate-to-high maintenance autonomy, scheduling and testing updates itself with appropriate change control.
SOV-7.7Auditability3. Partial independent control72/143SEAL-1lowNo certified full audit_rights (only ISO 27001 cert-body audits + DPA rights, not full independent audit by any entity) -> SOV-7.7 opt3 (seal 1). Contributes to the SEAL cap.

SOV-8 · Environmental Sustainability 56.3% · SEAL-1 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowOperates a modern energy-efficient German data center with waste-heat recovery and a sustainability roadmap, consistent with PUE < 1.5 plus improvement plan, though no published PUE figure was found. (src: https://www.mittwald.de/darum-mittwald/technologie)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowReuses server waste heat to heat offices (~32,000 kWh/year saved) and operates efficiency programs, indicating a documented circular/efficiency program; no EU-certified lifecycle claim found.
SOV-8.3Environmental impact reporting2. Basic reporting63/250SEAL-1lowCommunicates climate-neutral operations and energy practices but no detailed annual environmental impact report following an EU methodology was found; basic reporting.
SOV-8.4Energy supplies5. Only green EU energy supplies250/250SEAL-4mediumOwn German data center runs on 100% CO2-neutral electricity with partial on-site solar generation in North Rhine-Westphalia; only green EU energy supplies. (src: https://www.mittwald.de/darum-mittwald/technologie)