🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Netlify

United States · PaaS · https://www.netlify.com

Sovereignty score23.4%
Global (unweighted)23.8%
Overall SEAL
SEAL-0 No Sovereignty
SOV-1 Strategic Sovereignty13.6SEAL-0
SOV-2 Legal & Jurisdictional Sovereignty12.6SEAL-1
SOV-3 Data & AI Sovereignty35.0SEAL-0
SOV-4 Operational Sovereignty12.6SEAL-0
SOV-5 Supply Chain Sovereignty7.2SEAL-1
SOV-6 Technology Sovereignty35.0SEAL-0
SOV-7 Security & Compliance Sovereignty43.1SEAL-1
SOV-8 Environmental Sustainability31.3SEAL-1

SOV-1 · Strategic Sovereignty 13.6% · SEAL-0 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control1. Entirely outside the EU0/125SEAL-1highforeign_parent (Netlify, Inc., San Francisco, US): controlling legal entity is entirely outside the EU -> SOV-1.1 opt1 (src: https://www.netlify.com/security/).
SOV-1.2Change of control risk3. Somewhat likely takeover/transfer to non-EU sovereign entity63/125SEAL-4mediumPrivate US VC-backed firm (a16z, Bessemer, Kleiner Perkins, BOND); takeover/transfer to a non-EU sovereign entity (acquisition or IPO) is a realistic medium-term scenario, hence somewhat likely (kept at existing choice; all-seal-4 factor).
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2mediumRoadmap set centrally by the US company; EU customers influence only via voice-of-the-customer channels, no EU governance body -> SOV-1.3 opt2.
SOV-1.4Financial independence from non-EU capital1. Almost entirely relying on non-EU funding0/125SEAL-4highFunding almost entirely US venture capital (a16z, Bessemer, Kleiner Perkins, Menlo, BOND, Bloomberg Beta, EQT Ventures); no meaningful EU capital base (all-seal-4 factor).
SOV-1.5EU economic contribution1. Minimal0/125SEAL-4mediumUS-centric: most economic activity, headcount and value capture in the US; EU contribution minimal (all-seal-4 factor).
SOV-1.6Participation in EU strategic programs1. No clear participation0/125SEAL-4highNo clear participation in EU strategic programs (Gaia-X, IPCEI-CIS) (all-seal-4 factor).
SOV-1.7Alignment with EU industrial strategies1. No evidence exists0/125SEAL-4mediumNo evidence of an action plan aligning Netlify with EU industrial/digital-sovereignty strategies (all-seal-4 factor).
SOV-1.8Resilience to cut-off2. Service would stop, with delay for customer reaction31/125SEAL-0mediumNo own_stack: PaaS on non-EU hyperscalers (AWS/GCP/Rackspace) under US parent control; if supply were cut off the managed service would stop, with only a delay for customers to migrate -> SOV-1.8 opt2 (seal 0).

SOV-2 · Legal & Jurisdictional Sovereignty 12.6% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction1. Non-EU only0/167SEAL-1highUS provider/contracting entity; service governed primarily by US (non-EU) law -> SOV-2.1 opt1 (src: https://www.netlify.com/legal/terms-of-use/).
SOV-2.2Extraterritorial laws exposure2. Mitigation clauses, exposure remains42/167SEAL-1highconsistency (cluster norm 2.2=opt2): US company exposed to US extraterritorial law (CLOUD Act, FISA 702); GDPR DPA/SCC mitigation clauses exist but residual exposure remains -> opt2 (seal 1) (src: https://www.netlify.com/legal/dpa/).
SOV-2.3Data access pathways for non-EU authorities2. Can compel access without notification, specific cases42/167SEAL-1highforeign_parent (US CLOUD Act / FISA): authorities can compel data access; gag provisions can bar customer notification in specific national-security cases -> SOV-2.3 opt2 (caps SEAL at 1).
SOV-2.4Export control restrictions2. Restrictions towards EU citizens or international orgs42/167SEAL-1lowUS-controlled provider subject to US export-control regimes (EAR/OFAC) that can restrict service to certain persons/jurisdictions; no EU-MS-level restriction identified -> SOV-2.4 opt2 (seal 1).
SOV-2.5Origin of IP1. Entirely outside the EU0/167SEAL-4highCore platform IP (build system, edge, CLI, acquired Gatsby/Stackbit) developed and owned in the US, entirely outside the EU (all-seal-4 factor).
SOV-2.6IP holder jurisdiction1. Non-EU law, single country0/167SEAL-3highIP held by Netlify, Inc. under US law in a single non-EU country -> SOV-2.6 opt1.

SOV-3 · Data & AI Sovereignty 35.0% · SEAL-0 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys2. Primarily provider, not exclusively50/200SEAL-1mediumNetlify manages encryption at rest/in transit; keys are primarily provider-controlled, no customer HYOK/BYOK preventing provider access -> SOV-3.1 opt2.
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2mediumEnterprise audit logs exist but are vendor-controlled and not independently real-time auditable by the customer -> SOV-3.2 opt3.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowDeletion per internal policy/DPA commitments on managed and underlying cloud storage; no independent cryptographic proof of irreversible erasure -> SOV-3.3 opt3.
SOV-3.4Data location strictly in EU/EEA2. Partly EU, significant third-country reliance50/200SEAL-0mediumNo eu_exclusive: backing store/CDN default to US (San Francisco); an opt-in EU (Amsterdam) region exists in the same global product but significant third-country (US) reliance and SCC cross-border transfers remain -> SOV-3.4 opt2 (seal 0) (src: https://docs.netlify.com/manage/security/overview/).
SOV-3.5AI services sovereignty2. Mostly non-EU: licensed AI, chip dependency50/200SEAL-2highAI offering (Agent Runners) wraps US-origin licensed models/agents (Claude Code, Gemini CLI, OpenAI Codex) on US cloud, with chip/model dependency outside the EU -> SOV-3.5 opt2.

SOV-4 · Operational Sovereignty 12.6% · SEAL-0 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumGit-based/static-site architecture with documented data export, standard build artifacts and CLI; portability of content is good though platform features (edge functions, forms) are provider-specific -> SOV-4.1 opt3.
SOV-4.2Ability to operate without foreign dependencies1. Critical ops delivered by non-EU teams0/167SEAL-1highNo eu_ops: critical platform operations run by US engineering/SRE teams on US-controlled infrastructure; no EU-only operational path -> SOV-4.2 opt1.
SOV-4.3Skill availability in the EU1. Global team, mainly non-EU0/167SEAL-1mediumEngineering/operations talent is a global, predominantly US-based team; EU staffing is a minority -> SOV-4.3 opt1.
SOV-4.4Support channels1. Global, majority outside EU0/167SEAL-1mediumSupport delivered globally with the majority of the team and escalation paths outside the EU -> SOV-4.4 opt1.
SOV-4.5Documentation & knowledge transfer1. Global/non-EU exposure0/167SEAL-0lowDocumentation/knowledge repositories are global and US-hosted with no EU-residency enforcement -> SOV-4.5 opt1 (seal 0).
SOV-4.6Subcontractor & supplier jurisdiction2. Service would stop with delay42/167SEAL-2mediumService depends on non-EU subprocessors/cloud (AWS, GCP, Rackspace); loss would stop the service with only a delay for customer reaction -> SOV-4.6 opt2.

SOV-5 · Supply Chain Sovereignty 7.2% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)1. No disclosure0/143SEAL-1mediumRuns on third-party hyperscaler hardware; nothing disclosed about physical component provenance -> SOV-5.1 opt1.
SOV-5.2Manufacturing location1. Fully foreign, black box0/143SEAL-1mediumUnderlying servers manufactured by/for foreign hyperscalers; hardware origin is an undisclosed black box to Netlify customers -> SOV-5.2 opt1.
SOV-5.3Embedded code/firmware provenance1. No disclosure0/143SEAL-4mediumFirmware/embedded-code provenance of the underlying hardware is not disclosed (all-seal-4 factor).
SOV-5.4Origin of software2. Foreign origin, partial disclosure36/143SEAL-2mediumforeign_core: core platform software developed by US teams; some parts (CLI, build tooling, Gatsby) are open/documented, giving partial disclosure of foreign-origin software -> SOV-5.4 opt2.
SOV-5.5Software build/release jurisdiction1. Non-EU control & execution0/143SEAL-1mediumSoftware build and release controlled and executed by US teams/CI outside the EU -> SOV-5.5 opt1.
SOV-5.6Single point of dependency1. Only non-EU vendors/facilities0/143SEAL-1highCritical dependency on non-EU vendors (AWS, GCP, Rackspace) and US parent operations; effectively only non-EU facilities for the core service -> SOV-5.6 opt1.
SOV-5.7Supply chain transparency2. Some suppliers auditable36/143SEAL-1lowSubprocessor list published in the Trust Center, but only some suppliers are auditable by customers; full critical-supplier audit rights not offered to standard customers -> SOV-5.7 opt2.

SOV-6 · Technology Sovereignty 35.0% · SEAL-0 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces3. Mixed (partial openness)100/200SEAL-2mediumDocumented REST API, CLI and Git workflow with framework adapters, but core features rely on partially proprietary, platform-specific interfaces (mixed openness) -> SOV-6.1 opt3.
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2mediumUses open web standards (HTTP, Git, standard build outputs) across part of the platform, but no formal policy mandating open standards for all core services -> SOV-6.2 opt3.
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2mediumforeign_core: platform itself is closed/proprietary SaaS; Netlify open-sources/stewards tooling (CLI, Gatsby, build images) under centralized vendor governance, so source is partly available with strict rights -> SOV-6.3 opt2.
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3mediumSome public insight via docs, engineering blog and open-source components, but core service architecture is not fully transparent -> SOV-6.4 opt3.
SOV-6.5HPC sovereignty1. Imported black-box HPC0/200SEAL-0lowNo EU HPC; any compute-intensive/AI workloads run on imported black-box hyperscaler/GPU infrastructure -> SOV-6.5 opt1 (seal 0).

SOV-7 · Security & Compliance Sovereignty 43.1% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)3. EAL272/143SEAL-2highcerts: ISO 27001 + ISO 27018 + SOC 2 Type 2 + PCI DSS v4.0 + HIPAA (no SecNumCloud/EUCS/Common Criteria EAL); per key ISO 27001 + SOC 2 maps to opt3 (EAL2-equiv, seal 2) (src: https://www.netlify.com/security/).
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4highDocumented GDPR/CCPA compliance with DPA, plus SOC 2 Type 2, ISO 27001/27018, PCI DSS v4.0 and HIPAA; partial compliance to most EU regimes (all-seal-4 factor; kept at existing choice).
SOV-7.3EU-based SOC & incident handling1. SOC/IR outside EU0/143SEAL-1mediumSecurity operations and incident response run by Netlify's US-based security team, outside the EU -> SOV-7.3 opt1.
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1mediumconsistency (cluster norm 7.4=opt3): customers get an audit-log/monitoring portal, but monitoring control and log storage are provider-managed in the US, not customer-controlled in the EU -> opt3 (basic monitoring portal, seal 1).
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2mediumIncident disclosure aligns with GDPR/contractual breach-notification obligations; moderate (GDPR/NIS2-aligned) compliance without real-time CSIRT sharing -> SOV-7.5 opt3.
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowManaged platform schedules maintenance with notice; customers have moderate autonomy (stage/test deploys) but cannot independently control underlying platform maintenance -> SOV-7.6 opt3.
SOV-7.7Auditability2. Limited independent access36/143SEAL-1mediumNo audit_rights: independent assurance limited to third-party SOC 2/ISO audits and Trust Center evidence; customers cannot perform arbitrary audits of the platform -> SOV-7.7 opt2 (caps at seal 1).

SOV-8 · Environmental Sustainability 31.3% · SEAL-1 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowconsistency (hyperscaler-PaaS cluster norm 8.1=opt3): runs on AWS/GCP data centres reporting PUE <1.5 with efficiency roadmaps which Netlify inherits; same profile as Vercel/Render -> opt3 (PUE<1.5 + roadmap) (src: https://sustainability.aboutamazon.com/products-services/aws-cloud).
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowconsistency (hyperscaler-PaaS cluster norm 8.2=opt3): hardware reuse/recycling handled by the underlying hyperscalers' documented circular-economy programs which Netlify inherits -> opt3 (documented program) (src: https://sustainability.aboutamazon.com/products-services/aws-cloud).
SOV-8.3Environmental impact reporting2. Basic reporting63/250SEAL-1lowconsistency (cluster norm 8.3=opt2): Netlify publishes no detailed own environmental report but inherits basic hyperscaler sustainability disclosures -> opt2 (basic reporting, seal 1).
SOV-8.4Energy supplies1. Non traceable0/250SEAL-4lowEnergy supply inherited from third-party hyperscaler data centres, not separately traceable or reported by Netlify (all-seal-4 factor).