🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Nine

Switzerland · IaaS/PaaS · https://www.nine.ch

Sovereignty score46.3%
Global (unweighted)46.0%
Overall SEAL
SEAL-0 No Sovereignty
SOV-1 Strategic Sovereignty42.8SEAL-1
SOV-2 Legal & Jurisdictional Sovereignty54.3SEAL-1
SOV-3 Data & AI Sovereignty50.0SEAL-0
SOV-4 Operational Sovereignty41.8SEAL-1
SOV-5 Supply Chain Sovereignty39.6SEAL-1
SOV-6 Technology Sovereignty55.0SEAL-3
SOV-7 Security & Compliance Sovereignty46.7SEAL-1
SOV-8 Environmental Sustainability37.6SEAL-1

SOV-1 · Strategic Sovereignty 42.8% · SEAL-1 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control2. Mostly outside the EU42/125SEAL-1highNine Internet Solutions AG is incorporated and headquartered in Zurich, Switzerland with no EU/EEA legal entity; Switzerland is a third country, so entity control sits mostly outside the EU -> opt2 (seal 1). Normalised from opt1 to opt2 for consistency with the other Swiss-incorporated peers (both are seal 1). (src: https://www.nine.ch/en/about)
SOV-1.2Change of control risk4. Unlikely takeover/transfer to non-EU sovereign entity94/125SEAL-4mediumFounder-led (Thomas Hug, 100% owner), privately held, independent ~40-person company with no known external/non-EU investors; a takeover/transfer to a non-EU sovereign entity is unlikely though not formally precluded. (src: https://www.nine.ch/en/about)
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2lowAs a small founder-led firm there are no formal EU-actor governance bodies over the roadmap; customers influence direction mainly through standard customer/support channels -> opt2.
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4mediumBootstrapped founder-owned Swiss company with no disclosed external funding; capital is non-EU (Swiss) but entirely independent of non-EU hyperscaler/state capital. Scored as not relying on non-EU (foreign-state) funding.
SOV-1.5EU economic contribution2. Some31/125SEAL-4mediumEconomic activity (jobs, taxes, data centres) is concentrated in Switzerland, a third country; only limited EU economic contribution via EU customers.
SOV-1.6Participation in EU strategic programs1. No clear participation0/125SEAL-4highNo evidence of participation in EU strategic programs (Gaia-X, IPCEI-CIS); a Swiss provider outside EU frameworks.
SOV-1.7Alignment with EU industrial strategies1. No evidence exists0/125SEAL-4mediumNo evidence of alignment with EU industrial strategies; positioning is Swiss-sovereignty oriented, not EU industrial-policy aligned.
SOV-1.8Resilience to cut-off4. Ability to source alternatives or internalise key functions94/125SEAL-2lowown_stack only partial: runs its own managed open-source-based stack on owned/colocated Swiss data centres so it could source alternatives or internalise key functions, but it has a real non-EU operational dependency (NVIDIA GPUs/chips) and the stack itself is non-EU, so not full EU autonomy -> opt4 (seal 2).

SOV-2 · Legal & Jurisdictional Sovereignty 54.3% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction2. Mixed EU/non-EU84/167SEAL-1highPrimary jurisdiction is Swiss law (FADP), a third country; GDPR applies contractually for EU customers, giving mixed EU/non-EU legal footing -> opt2 (seal 1). Normalised from opt1 to opt2 for consistency with the rest of the Swiss cluster (both are seal 1). (src: https://www.nine.ch/en/about)
SOV-2.2Extraterritorial laws exposure4. Legal structures shielding from foreign law125/167SEAL-2mediumNo foreign_parent (pure Swiss entity, no US/EU parent, all data in Switzerland) so structurally shielded from US CLOUD Act, but governed by non-EU Swiss law without certified EU immunity (no SecNumCloud/EUCS-High) -> legal structures shielding, opt4 (seal 2). Consistent with the pure-Swiss peers Infomaniak and Safe-Swiss. (src: https://www.nine.ch/en/about)
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumNo foreign_parent: not subject to US CLOUD Act/FISA/PRC law; as a wholly Swiss company with Swiss-only hosting it can refuse foreign-authority requests (which proceed only via Swiss mutual assistance, not direct compelled access) -> requests always rejected, opt5 (seal 4). Consistent with the identical pure-Swiss-no-foreign-parent peers Infomaniak and Safe-Swiss. (src: https://www.nine.ch/en/about)
SOV-2.4Export control restrictions3. Share of revenues >50% in the EU84/167SEAL-2lowNo export-control restrictions toward EU Member States evident; sizeable EU revenue share, but the offer is not specifically shielded from restrictions -> opt3.
SOV-2.5Origin of IP3. Mixed within/outside the EU84/167SEAL-4lowCore platform IP (Deploio, NKE, nctl) is developed in-house in Switzerland (non-EU) and built on open-source software with mixed EU/non-EU origins; overall a mix within/outside the EU.
SOV-2.6IP holder jurisdiction1. Non-EU law, single country0/167SEAL-3mediumIP is held by the Swiss company under Swiss (single non-EU country) law -> opt1.

SOV-3 · Data & AI Sovereignty 50.0% · SEAL-0 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys4. Customer primary control but provider can read data150/200SEAL-3lowManaged service model with customer-controllable encryption; customers can hold primary key control but as a managed provider Nine typically retains technical ability to read data (no documented hold-your-own-key with provider blindness) -> opt4.
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowLogging/monitoring available to customers but largely vendor-managed and not real-time independently auditable -> opt3.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowISO 27001 processes imply policy-based deletion validation, but no published cryptographic proof of irreversible erasure -> opt3.
SOV-3.4Data location strictly in EU/EEA2. Partly EU, significant third-country reliance50/200SEAL-0highNo eu_exclusive: data resides exclusively in two Swiss data centres (Zurich), no EU/EEA region offered; Switzerland is a third country so from the EU/EEA residency standpoint this is partly-EU with significant third-country reliance -> opt2 (seal 0). This is the binding SEAL-0 gate, shared with the other Swiss-only-hosting peers Infomaniak and Safe-Swiss. (src: https://nine.ch/en/infrastructure/)
SOV-3.5AI services sovereignty3. Mixed: auditable/open-source AI, foreign chips100/200SEAL-2mediumGPU servers run open-source ML stacks (PyTorch, TensorFlow, CUDA) on Swiss infrastructure but depend on foreign NVIDIA chips; auditable/open AI tooling with foreign accelerators -> opt3.

SOV-4 · Operational Sovereignty 41.8% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumOpen-standards Kubernetes/containers and open APIs (public nctl CLI) provide standard documented export/portability with a stated no-lock-in posture -> opt3.
SOV-4.2Ability to operate without foreign dependencies3. Ops balanced EU/non-EU teams84/167SEAL-3mediumOperations run by Nine's own Swiss team, fully self-sufficient in one country with no foreign (US/Asia) intermediary; from the EU-sourcing standpoint Swiss staff are non-EU, so balanced EU/non-EU -> opt3 (seal 3). Normalised to the Swiss-in-house-ops tier shared with Infomaniak and Safe-Swiss. (src: https://www.nine.ch/en/about)
SOV-4.3Skill availability in the EU2. Mixed, majority outside EU42/167SEAL-1mediumEngineering/skills are concentrated in Switzerland (non-EU); the team is predominantly outside the EU/EEA -> opt2.
SOV-4.4Support channels2. Mixed, majority outside EU42/167SEAL-2mediumSupport is provided from Switzerland (non-EU); from an EU perspective support staff are majority outside the EU -> opt2.
SOV-4.5Documentation & knowledge transfer2. EU optional, not enforced42/167SEAL-2lowDocumentation is primarily Swiss (non-EU) with public docs/GitHub; EU-only repositories are not enforced -> opt2.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3lowOwns/colocates its own Swiss infrastructure and runs open-source software, giving ability to source alternatives or internalise functions if a subcontractor/supplier were lost (subject to hardware constraints) -> opt4.

SOV-5 · Supply Chain Sovereignty 39.6% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowStandard x86/GPU server hardware of foreign (US/Asian) origin with limited public disclosure of component provenance -> opt2.
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1lowServers and GPUs are manufactured abroad (foreign origin) with only partial disclosure; no EU/Swiss hardware manufacturing -> opt2.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/BIOS/GPU microcode is foreign (vendor-supplied) with little provenance disclosure.
SOV-5.4Origin of software3. Core/essential parts maintained by EU teams72/143SEAL-3mediumNot foreign_core: platform software (Deploio, NKE, nctl) is developed and maintained in-house by Nine's own team on open-source components rather than licensed Google/MS tech, so core/essential parts are provider-maintained (not a foreign black box) -> opt3.
SOV-5.5Software build/release jurisdiction3. Non-EU control, EU execution72/143SEAL-3lowSoftware build/release is controlled and executed by the Swiss (non-EU) provider in-house; not a foreign black box, scored conservatively as EU-execution-equivalent under non-EU control -> opt3.
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2lowFew non-EU dependencies in critical services (NVIDIA GPUs, foreign hardware/firmware, optional Google Kubernetes Engine), documented and limited -> opt3 (seal 2).
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowISO 27001 implies critical suppliers (e.g. colocation data centres) are auditable, but full supply-chain auditability is not published -> opt3.

SOV-6 · Technology Sovereignty 55.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumBuilt on standards-based Kubernetes/containers with open APIs and a public CLI; broadly compatible/interoperable with explicit no-lock-in messaging -> opt4.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumCore services adopt open standards (Kubernetes, OCI containers, standard databases) as a policy across most of the platform -> opt4.
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3mediumNot foreign_core: stack is built on open-source software and nctl is published on GitHub, but the managed platform (Deploio/NKE) governance is centralised within Nine -> open source with centralised governance, opt3.
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowPublic architecture/documentation insight is available (docs, blogs, public CLI) beyond audit-only access -> opt3.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3mediumGPU/HPC capacity is Swiss-hosted but runs a fully foreign stack (NVIDIA GPUs, CUDA); EU/Swiss-hosted with foreign stack -> opt2 (seal 3).

SOV-7 · Security & Compliance Sovereignty 46.7% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)2. EAL136/143SEAL-1mediumNo SecNumCloud/EUCS/C5/ENS or Common Criteria EAL; security is covered by ISO 27001 (+ISO 9001) only, which the key maps to opt2 (EAL1-equivalent, seal 1). Consistent with Infomaniak (also ISO-only). (src: https://www.nine.ch/en/about)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumISO 27001/9001 certified and FINMA-compliant with Swiss FADP (GDPR-adequate) and GDPR where applicable; partial compliance to most EU regulations though, as a Swiss firm, not formally within NIS2/DORA scope.
SOV-7.3EU-based SOC & incident handling3. Primary SOC in EU, escalations non-EU72/143SEAL-1lowSecurity operations/incident handling are run end-to-end in-house from Switzerland; the SOC is located outside the EU, so the EU-lifecycle tiers (opt4/opt5) do not apply -> primary SOC in-region with non-EU location, opt3 (seal 1). Normalised to the Swiss-in-house-SOC tier shared with Infomaniak and Safe-Swiss (same profile, previously scored inconsistently at opt1). (src: https://www.nine.ch/en/about)
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1lowCustomers get direct access to monitoring/logging, but logs are stored in Swiss (non-EU) data centres and not documented as immutable EU-located logs, so the EU-storage tiers do not apply -> opt3 (seal 1).
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2mediumIncident disclosure follows ISO 27001 and FADP/GDPR-aligned breach-notification practices (moderate, GDPR/NIS2-aligned) -> opt3.
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowAs operator of its own open-source-based managed platform, Nine has moderate maintenance autonomy with notice/testing windows, constrained mainly by upstream/zero-day fixes -> opt3.
SOV-7.7Auditability2. Limited independent access36/143SEAL-1lowNo audit_rights at SecNumCloud grade: independent audit access is limited to certification audits (ISO 27001) plus contractual customer audit rights; no full independent audit by any entity -> opt2.

SOV-8 · Environmental Sustainability 37.6% · SEAL-1 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowModern carrier-neutral Zurich data centres with cold-aisle containment imply efficient PUE (<1.5) plus sustainability roadmap; no EU-verified figure (Switzerland not EU) so higher EU-verified tiers do not apply -> opt3. Consistent with the other colo-tenant peers. (src: https://nine.ch/en/infrastructure/)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowCarbon-neutral operations and myclimate certification indicate a documented sustainability program including hardware lifecycle, though not detailed as full circular-economy/EU-certified -> opt3.
SOV-8.3Environmental impact reporting2. Basic reporting63/250SEAL-1lowBasic environmental reporting via carbon-neutral/myclimate claims; no detailed audited annual environmental report published -> opt2.
SOV-8.4Energy supplies2. Only EU energy supplies63/250SEAL-4highBoth data centres run on 100% renewable electricity, but supplies are Swiss (non-EU) - so only non-EU green energy; scored as not EU energy supplies. Renewable but outside EU. (src: https://nine.ch/en/infrastructure/)