🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

NumSpot

France · IaaS/PaaS · https://www.numspot.com

Sovereignty score78.9%
Global (unweighted)76.3%
Overall SEAL
SEAL-3 Digital Resilience
SOV-1 Strategic Sovereignty96.9SEAL-4
SOV-2 Legal & Jurisdictional Sovereignty95.8SEAL-4
SOV-3 Data & AI Sovereignty80.0SEAL-3
SOV-4 Operational Sovereignty83.2SEAL-3
SOV-5 Supply Chain Sovereignty60.7SEAL-3
SOV-6 Technology Sovereignty55.0SEAL-3
SOV-7 Security & Compliance Sovereignty82.0SEAL-3
SOV-8 Environmental Sustainability56.3SEAL-3

SOV-1 · Strategic Sovereignty 96.9% · SEAL-4 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity: French SAS in Courbevoie, 100% French-owned (Caisse des Depots/Banque des Territoires, Docaposte/La Poste, Dassault Systemes, Bouygues Telecom); legal control entirely within the EU -> opt4 (src: https://www.3ds.com/newsroom/press-releases/docaposte-dassault-systemes-bouygues-telecom-and-banque-des-territoires-sign-alliance-offer-reference-solution-trusted-cloud-services).
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4highMajority public/state ownership via Caisse des Depots and strategic French industrial shareholders explicitly created for sovereignty; takeover by a non-EU sovereign entity is very unlikely. (all-SEAL-4 factor, choice retained)
SOV-1.3Control over roadmap4. Full influence of EU actors125/125SEAL-4mediumEU-controlled venture; roadmap set by EU shareholders/board with own R&D -> full influence of EU actors -> opt4.
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4highEUR 50M capital raised entirely from French/EU investors (Caisse des Depots, Docaposte, Dassault Systemes, Bouygues Telecom); funding entirely EU-based. (all-SEAL-4 factor, choice retained)
SOV-1.5EU economic contribution5. Fully in the EU125/125SEAL-4highOperations, HQ, jobs and value creation fully in France; positioned as a 100% French sovereign cloud. (all-SEAL-4 factor, choice retained)
SOV-1.6Participation in EU strategic programs4. Strong participation94/125SEAL-4mediumFlagship French sovereign-cloud initiative backed by the state (Caisse des Depots), aligned with national digital-sovereignty strategy; strong participation. (all-SEAL-4 factor, choice retained)
SOV-1.7Alignment with EU industrial strategies4. Bold ambition and dedicated means125/125SEAL-4mediumExplicit sovereignty doctrine (portability, reversibility, open source, SecNumCloud target) with dedicated capital; bold ambition with dedicated means. (all-SEAL-4 factor, choice retained)
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4mediumown_stack: open-source-first platform (K8s/OpenShift/PostgreSQL) on EU-sovereign Outscale (SecNumCloud) IaaS, documented portability/reversibility; continuity depends on no non-EU vendor (only residual commodity chips) -> opt5 full autonomy & continuity.

SOV-2 · Legal & Jurisdictional Sovereignty 95.8% · SEAL-4 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highFrench legal entity, contract exclusively under French/EU law -> opt3 (seal 4).
SOV-2.2Extraterritorial laws exposure5. Verified legal immunity, non-EU laws unenforceable167/167SEAL-4mediumimmunity: NumSpot's foundational layer encapsulates 3DS Outscale's ANSSI SecNumCloud 3.2-qualified IaaS (key rule c: SecNumCloud 3.2 -> immunity), a pure-FR stack with no non-EU nexus -> non-EU laws unenforceable, verified legal immunity, opt5; consistent with the cluster's SecNumCloud-grade IaaS members (src: https://www.3ds.com/newsroom/press-releases/outscale-first-cloud-qualified-secnumcloud-32).
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumNo foreign_parent able to compel access; pure-FR entity (data on Outscale SecNumCloud 3.2) with no US/CN nexus, positioned '100% immunised against extraterritorial laws', would reject CLOUD Act/FISA requests -> opt5 requests always rejected (seal 4) (src: https://www.3ds.com/newsroom/press-releases/outscale-first-cloud-qualified-secnumcloud-32).
SOV-2.4Export control restrictions5. Part of offer shielded from restrictions towards EU MSs/intl orgs167/167SEAL-4mediumFrench-owned offer with no non-EU export-control entanglement; serviceable to EU member states and international orgs without foreign restrictions -> opt5.
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4mediumCore platform IP (NumSpot software, IAM, PaaS layer) developed in France on Outscale French IaaS; mostly EU-origin IP, some upstream OSS/chip IP foreign -> opt4. (all-SEAL-4 factor, choice retained)
SOV-2.6IP holder jurisdiction5. Fully under EU law167/167SEAL-4mediumNumSpot and Outscale IP held by French companies under French/EU law; IP holder jurisdiction fully EU -> opt5.

SOV-3 · Data & AI Sovereignty 80.0% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys4. Customer primary control but provider can read data150/200SEAL-3lowSecNumCloud-grade environment with Managed Secret Manager and customer key management; customer primary control but provider/IaaS operator can technically read absent confirmed HYOK/confidential computing -> opt4.
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3lowSecNumCloud/ISO 27001 controls require comprehensive access logging with customer-controlled visibility; full real-time independent auditability not specifically documented -> opt4.
SOV-3.3Secure deletion & proof of erasure4. Deletion technically verified with access logs150/200SEAL-3lowRuns on SecNumCloud-grade Outscale IaaS (3DS-Outscale itself scores opt4) whose framework mandates verified secure deletion with logging; deletion technically verified with access logs -> opt4 (seal 3).
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4mediumeu_exclusive: data hosted in French SecNumCloud-qualified Outscale data centres around Paris, sovereign region, no third-country fallback -> opt5 (src: https://numspot.com/2025/01/21/numspot-franchit-avec-succes-le-premier-jalon-de-la-qualification-secnumcloud-pour-sa-plateforme-de-services-cloud/).
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3mediumManaged AI Platform around Mistral AI (EU-origin models) plus open source in the sovereign region; EU-led AI on foreign GPU accelerators -> opt4 (seal 3).

SOV-4 · Operational Sovereignty 83.2% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability5. Already deployed on sovereign infrastructure167/167SEAL-4highPortability and reversibility are core to NumSpot's sovereignty doctrine, open standards and modular portable architecture; already deployed on sovereign (SecNumCloud Outscale) infrastructure -> opt5.
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4mediumeu_ops: entire stack (NumSpot platform + Outscale IaaS) operated by French/EU teams, no non-EU operational dependency -> opt5.
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumEngineering/ops teams in France/EU; all-EU staffing consistent with SecNumCloud, but formal security clearances across all staff not documented -> opt4 (all EU staff, seal 3).
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3mediumSupport delivered by France-based teams; all support staff in the EU, no documented clearance requirement on all support personnel -> opt4 (seal 3).
SOV-4.5Documentation & knowledge transfer4. EU-only primary repositories125/167SEAL-4lowFrench sovereign provider keeps documentation/knowledge in France/EU; EU-only primary repositories, strict end-to-end EU-only not explicitly confirmed -> opt4.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3mediumKey subcontractor (Outscale) is a French EU subsidiary and architecture is portable; able to source alternatives or internalise functions, commodity hardware residual -> opt4 (seal 3).

SOV-5 · Supply Chain Sovereignty 60.7% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)3. Transparent with exceptions72/143SEAL-3lowInherits Outscale hardware; standard x86 servers in certified data centres give transparent provenance with exceptions, no full EU-certified provenance disclosure -> opt3 (seal 3).
SOV-5.2Manufacturing location3. Mixed sourcing, EU audit rights72/143SEAL-3lowInherits Outscale's SecNumCloud-audited hardware (3DS-Outscale scores opt3); mixed sourcing of commodity servers with EU audit rights under the sovereign offer -> opt3 (seal 3).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/embedded code in commodity servers and network gear from foreign vendors with limited provenance disclosure -> opt2. (all-SEAL-4 factor, choice retained)
SOV-5.4Origin of software4. Large majority maintained by EU teams107/143SEAL-3mediumNo foreign_core: platform is 'open source first' (K8s/OpenShift/PostgreSQL), NOT licensed Google/MS/AWS core; large majority maintained by French/EU teams with foreign upstream OSS -> opt4 (seal 3).
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3lowSoftware developed and released by French/EU teams under EU control and execution; explicit EU policy gates beyond standard practice not documented -> opt4 (seal 3).
SOV-5.6Single point of dependency4. Few non-EU in non-critical services, documented107/143SEAL-3lowRuns on 3DS Outscale's SecNumCloud 3.2 IaaS (own TINA orchestrator); control plane EU-based and only non-EU dependency is residual commodity hardware/GPUs, documented and non-critical to continuity -> few non-EU non-critical, documented, opt4 (seal 3), consistent with the cluster's SecNumCloud-grade IaaS members (src: https://www.3ds.com/newsroom/press-releases/outscale-first-cloud-qualified-secnumcloud-32).
SOV-5.7Supply chain transparency4. Most suppliers auditable107/143SEAL-3lowSecNumCloud 3.2 supply-chain auditability inherited from the Outscale IaaS plus NumSpot ISO 27001 supplier management extend audit obligations to most suppliers, not only the critical few -> most suppliers auditable, opt4 (seal 3) (src: https://en.outscale.com/our-certifications/).

SOV-6 · Technology Sovereignty 55.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumOpen-standards-based PaaS (Kubernetes, S3-compatible storage, standard databases) with portability emphasised; standards-based and broadly compatible -> opt4 (seal 3).
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumAdopts open standards (Kubernetes, S3 API, open database engines) across most core services as part of its portability doctrine -> opt4 (seal 3).
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3mediumNo foreign_core: genuinely 'open source first' platform (K8s/OpenShift/PostgreSQL), open source with currently centralised (vendor) governance -> opt3 (seal 3).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowCommits to transparency, auditability and reversibility with some public insight into architecture; not yet a large public corpus or customer-contributable model -> opt3 (seal 3).
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowAny HPC/GPU compute is EU-hosted in French data centres on a foreign accelerator stack -> opt2 EU-hosted foreign stack (seal 3).

SOV-7 · Security & Compliance Sovereignty 82.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumNumSpot's foundational layer runs on 3DS Outscale's ANSSI SecNumCloud 3.2 IaaS and holds ISO 27001 + HDS in its own right; per the key SecNumCloud-grade assurance maps to EAL3 -> opt4 EAL3 (seal 3), consistent with the cluster's SecNumCloud-grade IaaS members (src: https://numspot.com/certification/hds-hebergeur-de-donnees-de-sante/).
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)5. Fully compliant to all, independently audited143/143SEAL-4mediumBuilt for GDPR/NIS2/DORA-regulated public, financial and health customers, with HDS and ISO 27001/27017/27018 (via Outscale) and SecNumCloud in progress; fully compliant and independently audited -> opt5. (all-SEAL-4 factor, choice retained)
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3lowSovereign French provider with EU-based security operations and incident handling; entire lifecycle by EU teams, explicit ENISA/CSIRT sharing not documented -> opt4 (seal 3).
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3lowSecNumCloud-aligned environment gives customers direct access to monitoring/logs stored in France/EU; tamper-proof immutable logging not specifically documented -> opt4 (seal 3).
SOV-7.5Disclosure of incidents4. Partial compliance, monitored flow, SLAs107/143SEAL-3lowNIS2/GDPR-bound French provider follows monitored incident-disclosure flows with SLAs; full real-time CSIRT sharing not explicitly confirmed -> opt4 (seal 3).
SOV-7.6Maintenance autonomy4. High autonomy (deploy independently, no checks)107/143SEAL-4lowOperates its own platform on EU infrastructure and can deploy patches/maintenance independently; high maintenance autonomy -> opt4 (seal 4).
SOV-7.7Auditability5. Full independent audit by any entity143/143SEAL-4lowaudit_rights: SecNumCloud qualification process subjects platform to independent ANSSI-accredited audit and the sovereign offer supports customer/regulator auditability -> opt5 (seal 4).

SOV-8 · Environmental Sustainability 56.3% · SEAL-3 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowHosted in modern Tier III French data centres (Outscale) with managed efficiency; PUE below 1.5 with improvement roadmap a reasonable inference, no published figure -> opt3 (seal 4).
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowOutscale holds LUCIE/ISO 26000 CSR labelling implying a documented circular/recycling program for hardware lifecycle -> opt3 documented program (seal 3).
SOV-8.3Environmental impact reporting4. Detailed EU methodology188/250SEAL-3lowHosted on 3DS Outscale infrastructure backed by Dassault Systemes CSRD-grade group reporting and Outscale's detailed environmental methodology/carbon-footprint service -> detailed EU methodology, opt4 (seal 3), consistent with 3DS Outscale (src: https://en.outscale.com/our-certifications/).
SOV-8.4Energy supplies3. Mix of EU and non-EU supplies125/250SEAL-4lowFrench data centres draw on the French/EU grid (largely low-carbon nuclear/renewable) but no confirmed exclusively-EU or fully-green guaranteed sourcing; treated as a mix -> opt3. (all-SEAL-4 factor, choice retained)