🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Northflank

United Kingdom · PaaS · https://northflank.com

Sovereignty score26.7%
Global (unweighted)27.5%
Overall SEAL
SEAL-0 No Sovereignty
SOV-1 Strategic Sovereignty16.7SEAL-0
SOV-2 Legal & Jurisdictional Sovereignty12.6SEAL-1
SOV-3 Data & AI Sovereignty35.0SEAL-0
SOV-4 Operational Sovereignty25.1SEAL-1
SOV-5 Supply Chain Sovereignty7.2SEAL-1
SOV-6 Technology Sovereignty40.0SEAL-0
SOV-7 Security & Compliance Sovereignty39.6SEAL-1
SOV-8 Environmental Sustainability43.8SEAL-1

SOV-1 · Strategic Sovereignty 16.7% · SEAL-0 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control1. Entirely outside the EU0/125SEAL-1highNorthflank Ltd is incorporated and headquartered in London, UK, a third country outside the EU/EEA; no EU legal entity controls the company (src: https://northflank.com/security).
SOV-1.2Change of control risk3. Somewhat likely takeover/transfer to non-EU sovereign entity63/125SEAL-4mediumVC-backed (~$25M, mostly US investors) startup with no controlling EU shareholder; acquisition by a non-EU acquirer is a realistic outcome typical of a growth-stage cloud startup.
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2mediumRoadmap is set by the UK company; customers can influence only through standard public/customer feedback channels, with no EU governance body.
SOV-1.4Financial independence from non-EU capital1. Almost entirely relying on non-EU funding0/125SEAL-4highFunding is almost entirely non-EU venture capital (Bain Capital Ventures, Vertex Ventures US, Kindred, Uncorrelated, Pebblebed, Tapestry VC); no significant EU capital identified.
SOV-1.5EU economic contribution2. Some31/125SEAL-4lowSmall UK-based company; some EU customers and EU-region usage but employment, IP and economic value are concentrated in the UK and globally, not the EU.
SOV-1.6Participation in EU strategic programs1. No clear participation0/125SEAL-4mediumNo evidence of participation in Gaia-X, IPCEI-CIS or other EU strategic programs; markets itself globally as a developer PaaS.
SOV-1.7Alignment with EU industrial strategies1. No evidence exists0/125SEAL-4mediumNo published action plan or evidence of alignment with EU industrial/digital-sovereignty strategies.
SOV-1.8Resilience to cut-off2. Service would stop, with delay for customer reaction31/125SEAL-0mediumNo own_stack: managed control plane and worker clusters depend on Google Cloud/Azure (non-EU hyperscalers); a cut-off would stop the managed service, with delay for customers to react via BYOC -> SOV-1.8 opt2 (seal 0).

SOV-2 · Legal & Jurisdictional Sovereignty 12.6% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction1. Non-EU only0/167SEAL-1highPrimary jurisdiction is UK law (a non-EU third country); the company is not governed exclusively by EU law (src: https://northflank.com/legal/terms-of-service).
SOV-2.2Extraterritorial laws exposure2. Mitigation clauses, exposure remains42/167SEAL-1highNo immunity (UK entity, US-VC funded, no SecNumCloud/EUCS-High, no trustee structure); exposed to UK IPA + US-UK CLOUD Act and US CLOUD Act via Google/Azure; contractual/GDPR clauses mitigate but exposure remains -> SOV-2.2 opt2 (seal 1) (src: https://northflank.com/security).
SOV-2.3Data access pathways for non-EU authorities2. Can compel access without notification, specific cases42/167SEAL-1highforeign_parent (UK entity + US-UK CLOUD Act Data Access Agreement; underlying Google/Azure subject to US CLOUD Act) -> authorities can compel access in specific cases without notification; no refusal mechanism -> SOV-2.3 opt2 (seal 1).
SOV-2.4Export control restrictions2. Restrictions towards EU citizens or international orgs42/167SEAL-1lowconsistency (cluster norm 2.4=opt2): subject to UK/US export-control regimes; no EU-MS shielding and no >50% EU revenue dominance -> opt2 (seal 1).
SOV-2.5Origin of IP1. Entirely outside the EU0/167SEAL-4highNorthflank's platform IP is developed by the UK company; origin of IP is entirely outside the EU.
SOV-2.6IP holder jurisdiction1. Non-EU law, single country0/167SEAL-3highThe IP holder (Northflank Ltd) sits under UK law, a single non-EU country.

SOV-3 · Data & AI Sovereignty 35.0% · SEAL-0 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys2. Primarily provider, not exclusively50/200SEAL-1mediumEncryption at rest uses provider/Google Cloud-managed keys; external secret management is only in beta and there is no customer-exclusive HYOK/BYOK that prevents the provider reading data.
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowActivity and audit logs exist but are vendor-controlled and not described as independently auditable in real time.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowconsistency (cluster norm 3.3=opt3): deletion on resource teardown follows documented internal policy with no published cryptographic proof-of-erasure or independent verification -> opt3 (internal validation per policy, seal 1).
SOV-3.4Data location strictly in EU/EEA2. Partly EU, significant third-country reliance50/200SEAL-0mediumNot eu_exclusive: default managed control plane (GCP London/Amsterdam) and worker clusters run on US hyperscalers; EU achievable only via BYOC opt-in, not the scoped default offer, with significant third-country reliance -> SOV-3.4 opt2 (seal 0) (src: https://northflank.com/features/bring-your-own-cloud).
SOV-3.5AI services sovereignty2. Mostly non-EU: licensed AI, chip dependency50/200SEAL-2lowAI/GPU workloads run on foreign accelerators via partners (e.g. CoreWeave) and major clouds; no EU-origin models or chips, licensed/foreign AI stack with chip dependency.

SOV-4 · Operational Sovereignty 25.1% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumStandards-based (containers/Kubernetes, OCI images, git) with documented export and the ability to run via BYOC on the customer's own Kubernetes, giving good portability though not pre-deployed on EU sovereign infra.
SOV-4.2Ability to operate without foreign dependencies1. Critical ops delivered by non-EU teams0/167SEAL-1lowconsistency (non-EU cluster norm 4.2=opt1): core engineering and operations are run by a UK/global (non-EU) team and the platform depends on US-controlled cloud infrastructure; no EU-only operational path -> opt1 (seal 1).
SOV-4.3Skill availability in the EU2. Mixed, majority outside EU42/167SEAL-1lowSmall UK-headquartered team with globally distributed/remote engineers; skills are mixed and majority sit outside the EU.
SOV-4.4Support channels2. Mixed, majority outside EU42/167SEAL-2lowSupport is provided globally (chat/email) from the UK and distributed staff, with the majority outside the EU.
SOV-4.5Documentation & knowledge transfer2. EU optional, not enforced42/167SEAL-2lowDocumentation is public and global; EU-only handling of knowledge/documentation is not enforced.
SOV-4.6Subcontractor & supplier jurisdiction2. Service would stop with delay42/167SEAL-2mediumCritical subcontractors are US hyperscalers (Google, Azure); loss of these would stop the managed service, with delay for customers to react/migrate via BYOC.

SOV-5 · Supply Chain Sovereignty 7.2% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)1. No disclosure0/143SEAL-1mediumAs a PaaS on third-party clouds, Northflank owns no hardware and provides no disclosure of physical component provenance.
SOV-5.2Manufacturing location1. Fully foreign, black box0/143SEAL-1mediumUnderlying hardware is manufactured/operated by foreign hyperscalers; effectively a foreign black box from Northflank's perspective.
SOV-5.3Embedded code/firmware provenance1. No disclosure0/143SEAL-4mediumNo disclosure of firmware/embedded-code provenance for the underlying hyperscaler hardware.
SOV-5.4Origin of software2. Foreign origin, partial disclosure36/143SEAL-2mediumCore orchestration software is maintained in-house but by a non-EU (UK/global) team, built on open-source components; not EU-maintained core, so foreign origin with partial disclosure -> SOV-5.4 opt2 (seal 2).
SOV-5.5Software build/release jurisdiction1. Non-EU control & execution0/143SEAL-1lowSoftware build and release are controlled and executed by the UK/non-EU company, with no EU control or EU policy gates.
SOV-5.6Single point of dependency1. Only non-EU vendors/facilities0/143SEAL-1mediumconsistency (pure-PaaS-on-hyperscaler cluster norm 5.6=opt1): total single-point dependency on non-EU vendors (Google Cloud, Azure) for the managed control plane and clusters, with no EU vendor on the critical path -> opt1 (only non-EU vendors/facilities, seal 1).
SOV-5.7Supply chain transparency2. Some suppliers auditable36/143SEAL-1lowSome supplier information is available (named clouds, SOC 2 report on request) but the full supply chain is not broadly auditable by customers.

SOV-6 · Technology Sovereignty 40.0% · SEAL-0 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumBuilt on standards (Kubernetes, OCI containers, git, REST API/CLI) and broadly compatible across clouds via BYOC, enabling portability though the management plane itself is proprietary.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumCore services adopt open standards (containers, Kubernetes, OCI, standard databases) across most of the platform.
SOV-6.3Open source availability1. Fully closed-source, vendor-controlled0/200SEAL-2mediumThe Northflank platform itself is proprietary and vendor-controlled, even though it is built on open-source components.
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowSome public insight via documentation, security page and blog on architecture, but no deep open contribution model for customers.
SOV-6.5HPC sovereignty1. Imported black-box HPC0/200SEAL-0lowNo EU HPC sovereignty; any HPC/GPU is imported black-box capacity from foreign clouds/CoreWeave.

SOV-7 · Security & Compliance Sovereignty 39.6% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)2. EAL136/143SEAL-1highcerts: SOC 2 Type 2 only (no ISO 27001/SecNumCloud/EUCS/Common Criteria EAL); per key SOC 2 without ISO 27001 maps to opt2 (EAL1-equiv, seal 1) (src: https://northflank.com/security).
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)3. Moderate compliance72/143SEAL-4mediumStates GDPR (UK GDPR) compliance and offers DPAs, but no independent ISO 27001/NIS2/DORA certification is published; moderate, partially evidenced compliance.
SOV-7.3EU-based SOC & incident handling2. Hybrid EU/non-EU36/143SEAL-1lowSecurity operations and incident response are run by the small UK/global team using cloud-provider tooling; hybrid EU/non-EU at best, not an EU-dedicated SOC.
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1lowCustomers get monitoring dashboards, logs and metrics through the portal, but logging is largely provider-controlled and not guaranteed EU-resident/immutable for the customer.
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2lowIncident disclosure aligned with GDPR/breach-notification expectations; moderate compliance, no evidence of real-time CSIRT sharing.
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowCustomers control deployment timing of their own workloads with notice/testing, but platform-level maintenance is scheduled by Northflank/the underlying cloud.
SOV-7.7Auditability2. Limited independent access36/143SEAL-1mediumNo audit_rights: independent assurance limited to a SOC 2 report on request; no full independent audit by the contracting authority or EU bodies -> SOV-7.7 opt2 (seal 1).

SOV-8 · Environmental Sustainability 43.8% · SEAL-1 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowconsistency (hyperscaler-PaaS cluster norm 8.1=opt3): runs on GCP/Azure data centres reporting PUE <1.5 with efficiency roadmaps which Northflank inherits; same profile as Vercel/Render -> opt3 (PUE<1.5 + roadmap) (src: https://www.google.com/about/datacenters/efficiency/).
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowconsistency (hyperscaler-PaaS cluster norm 8.2=opt3): hardware reuse/recycling handled by the underlying hyperscalers' documented circular-economy programs which Northflank inherits -> opt3 (documented program) (src: https://www.google.com/about/datacenters/efficiency/).
SOV-8.3Environmental impact reporting2. Basic reporting63/250SEAL-1lowconsistency (cluster norm 8.3=opt2): Northflank publishes no detailed own environmental report but inherits basic hyperscaler sustainability disclosures -> opt2 (basic reporting, seal 1).
SOV-8.4Energy supplies3. Mix of EU and non-EU supplies125/250SEAL-4lowEnergy depends on the underlying hyperscalers' grids across EU and non-EU regions; a mix of EU and non-EU energy supplies with no Northflank-specific green sourcing guarantee (src: https://www.google.com/about/datacenters/cleanenergy/).