🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Oodrive

France · PaaS · https://www.oodrive.com

Sovereignty score75.5%
Global (unweighted)73.8%
Overall SEAL
SEAL-2 Data Sovereignty
SOV-1 Strategic Sovereignty86.5SEAL-4
SOV-2 Legal & Jurisdictional Sovereignty100.0SEAL-4
SOV-3 Data & AI Sovereignty80.0SEAL-3
SOV-4 Operational Sovereignty79.0SEAL-3
SOV-5 Supply Chain Sovereignty67.9SEAL-3
SOV-6 Technology Sovereignty45.0SEAL-2
SOV-7 Security & Compliance Sovereignty82.1SEAL-3
SOV-8 Environmental Sustainability50.1SEAL-3

SOV-1 · Strategic Sovereignty 86.5% · SEAL-4 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4highOodrive SAS is incorporated and headquartered in Paris, France; founders retain a majority stake and remaining capital is held by French investors (Tikehau Capital). Entirely within the EU (src: https://www.oodrive.com/secnumcloud/).
SOV-1.2Change of control risk4. Unlikely takeover/transfer to non-EU sovereign entity94/125SEAL-4mediumFounder-led with majority founder ownership and French PE backing; a sovereign cloud positioning and SecNumCloud business make a takeover by a non-EU sovereign entity unlikely, though PE-held minority stakes mean it is not 'very unlikely'.
SOV-1.3Control over roadmap4. Full influence of EU actors125/125SEAL-4mediumAs a French software publisher developing its own products, EU customers (notably French public sector and regulated industries) have full influence over the roadmap through direct contractual relationships.
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4highFunding is entirely EU-based: founders plus French investors Tikehau Capital, NextStage AM, and earlier French/EU funds. No non-EU capital identified.
SOV-1.5EU economic contribution5. Fully in the EU125/125SEAL-4highOperations, staff, data centers and revenue base are fully in France/EU; economic contribution is fully in the EU.
SOV-1.6Participation in EU strategic programs3. Active participant in strategic projects63/125SEAL-4mediumOodrive is an active sovereign-cloud advocate (publicly engaged on SecNumCloud/EUCS standards) and a recognized French sovereign actor, indicating active participation in EU/national strategic efforts.
SOV-1.7Alignment with EU industrial strategies3. Measured achievement and dedicated governance83/125SEAL-4mediumClear, sustained sovereignty strategy with measured achievement (first French SaaS publisher SecNumCloud-qualified, end-to-end 3.2) and dedicated governance/compliance function (src: https://www.oodrive.com/fr/actualites/oodrive-obtient-qualification-secnumcloud-au-niveau-3-2-pour-sa-suite-collaborative-francaise/).
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4mediumown_stack: vertically integrated EU provider - self-developed software on Oodrive-owned hardware in its own French data centers, SecNumCloud 3.2 qualified end-to-end with no non-EU operational vendor (only residual commodity chips). Full autonomy and continuity per key judgment call #1.

SOV-2 · Legal & Jurisdictional Sovereignty 100.0% · SEAL-4 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highFrench company with French/EU-only hosting; subject exclusively to EU/French law, explicitly positioned as not subject to non-European laws (src: https://www.oodrive.com/secnumcloud/).
SOV-2.2Extraterritorial laws exposure5. Verified legal immunity, non-EU laws unenforceable167/167SEAL-4highimmunity: SecNumCloud 3.2 qualification requires immunity from extra-EU law (HQ and capital on EU territory); Oodrive is a French-controlled entity with French data centers and explicitly states it is not subject to the US CLOUD Act or FISA, making non-EU laws unenforceable -> verified legal immunity opt5 (src: https://www.oodrive.com/secnumcloud/).
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4highAs a French SecNumCloud-qualified provider with no non-EU parent or establishment, it has no legal pathway to compel data disclosure to non-EU authorities; such requests would be rejected (src: https://www.oodrive.com/secnumcloud/).
SOV-2.4Export control restrictions5. Part of offer shielded from restrictions towards EU MSs/intl orgs167/167SEAL-4mediumFrench-developed and French-operated offer with EU-only customer base; no foreign export-control regime can restrict supply to EU Member States or international organisations.
SOV-2.5Origin of IP5. Fully within the EU167/167SEAL-4highOodrive is a software publisher that designs and develops its own products in France; the core IP is fully within the EU.
SOV-2.6IP holder jurisdiction5. Fully under EU law167/167SEAL-4highThe IP holder is the French Oodrive SAS, so IP is held fully under EU (French) law.

SOV-3 · Data & AI Sovereignty 80.0% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys4. Customer primary control but provider can read data150/200SEAL-3mediumStrong encryption (AES-256) with keys protected in HSM and per-customer compartmentalisation, giving customers primary control; however no documented zero-knowledge/BYOK scheme where the provider technically cannot read data, so not exclusive customer control -> opt4.
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3lowSecNumCloud/ISO 27001 require access logging and customer-controlled visibility, but no evidence of real-time independent auditability is published, so full customer-controlled (non-real-time) visibility is the best fit -> opt4.
SOV-3.3Secure deletion & proof of erasure4. Deletion technically verified with access logs150/200SEAL-3lowSecNumCloud and HDS impose verifiable deletion controls with access logs; deletion is technically verified, but independent proof of irreversible erasure to the customer is not clearly documented -> opt4.
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4higheu_exclusive: data hosted exclusively in two French data centers operated by Oodrive (active/active geo-cluster) with no third-country fallback; SecNumCloud forbids non-EU data location -> opt5 (src: https://www.oodrive.com/secnumcloud/).
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3lowOodrive states hosted data is not used for model training and any AI is EU-operated within its controlled framework, but inference still depends on foreign GPU/accelerator hardware; EU-led AI on foreign accelerators is the best fit -> opt4.

SOV-4 · Operational Sovereignty 79.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumStandard documented data export plus SecNumCloud-mandated reversibility/migration provisions; positioned as portable away from GAFAM. Formal migration services available -> opt4.
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4higheu_ops: entire stack (software development, hosting, operations) is managed by Oodrive's fully French/EU-based teams without intermediaries; SecNumCloud 3.2 end-to-end -> opt5 (src: https://www.oodrive.com/secnumcloud/).
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumWorkforce is France-based; SecNumCloud requires EU staffing. All-EU staff is well supported, though no provider-wide security-clearance requirement is documented across all roles -> opt4.
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3mediumSupport is delivered from France by Oodrive's own qualified teams; all support staff in the EU. No published clearance requirement for all support staff -> opt4.
SOV-4.5Documentation & knowledge transfer4. EU-only primary repositories125/167SEAL-4lowSecNumCloud-qualified, France-only operation implies EU-only primary documentation repositories; full end-to-end EU-only chain not explicitly evidenced -> opt4.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3lowSecNumCloud requires controlled subcontractors within the EU; Oodrive operates its own infrastructure, giving ability to source alternatives or internalise rather than depending on a single critical non-EU subcontractor -> opt4.

SOV-5 · Supply Chain Sovereignty 67.9% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)3. Transparent with exceptions72/143SEAL-3lowOodrive owns its hardware but the physical components (servers, chips) are sourced from global OEMs; SecNumCloud entails supply transparency, so transparent-with-exceptions best fits -> opt3 (seal 3).
SOV-5.2Manufacturing location3. Mixed sourcing, EU audit rights72/143SEAL-3lowServer hardware is foreign-designed but owned and operated by Oodrive under SecNumCloud audit rights (mixed sourcing with EU audit rights), consistent with the cluster anchor Clever Cloud -> opt3 (seal 3).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/microcode in commodity servers comes from foreign vendors with at best partial disclosure; not under EU control -> opt2 (seal 4).
SOV-5.4Origin of software5. Exclusively designed/maintained by EU teams143/143SEAL-4highOodrive is a software publisher that designs and maintains its application software exclusively with French/EU teams; SecNumCloud 3.2 qualifies the software layer itself -> opt5 (src: https://www.oodrive.com/secnumcloud/).
SOV-5.5Software build/release jurisdiction5. EU control + EU policy gates143/143SEAL-4mediumSoftware is developed, built and released in France under EU control; SecNumCloud imposes controlled build/release processes equivalent to EU control plus policy gates -> opt5.
SOV-5.6Single point of dependency4. Few non-EU in non-critical services, documented107/143SEAL-3lowCore service has no non-EU vendor dependency (own software, own hosting), with only non-critical hardware/components sourced from non-EU vendors; documented under SecNumCloud -> opt4 (seal 3).
SOV-5.7Supply chain transparency4. Most suppliers auditable107/143SEAL-3lowSecNumCloud qualification requires auditable supplier/subcontractor management; most suppliers are auditable, though full hardware-supply-chain auditability is not evidenced -> opt4 (seal 3).

SOV-6 · Technology Sovereignty 45.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3lowStandards-based: Oodrive exposes documented APIs and supports integration/export over standard protocols (eIDAS, TLS, standard file formats), giving broad interoperability even though the products themselves are proprietary SaaS -> opt4 (seal 3).
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3lowCore services rely on common open standards (eIDAS, standard file formats, TLS) for interoperability across most core services -> opt4 (seal 3).
SOV-6.3Open source availability1. Fully closed-source, vendor-controlled0/200SEAL-2mediumGenuine differentiator vs the open-source members of the cluster: Oodrive's products are proprietary, closed-source SaaS controlled by the vendor with no significant open-source release of its core software -> opt1 (seal 2). This is the real ceiling that caps Oodrive at SEAL-2 despite its end-to-end SecNumCloud sovereignty.
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowPublishes security/compliance documentation and architecture overviews publicly; some public insight into service architecture -> opt3.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowNo in-scope HPC: Oodrive is a collaborative SaaS provider, not an HPC operator, so there is no imported foreign HPC dependency. Per key, 'no in-scope HPC' maps to opt2 (seal 3), not penalised for absence.

SOV-7 · Security & Compliance Sovereignty 82.1% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)5. EAL4-5143/143SEAL-4mediumSecNumCloud 3.2 qualification (ANSSI), the highest French cloud assurance level (end-to-end, infra + software), maps to the top EAL tier per the key (src: https://www.oodrive.com/fr/actualites/oodrive-obtient-qualification-secnumcloud-au-niveau-3-2-pour-sa-suite-collaborative-francaise/).
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)5. Fully compliant to all, independently audited143/143SEAL-4highIndependently audited compliance with GDPR, NIS2, DORA, ISO 27001/27701, HDS, eIDAS and SecNumCloud; fully compliant and externally verified (src: https://www.oodrive.com/group-news/oodrive-renews-iso-27001-iso-27701-hds-2-0-certifications/).
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3mediumSecurity operations and incident handling are run by Oodrive's French teams as required by SecNumCloud; full lifecycle by EU teams, though formal ENISA/CSIRT sharing not explicitly evidenced -> opt4 (seal 3).
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3lowSecNumCloud/ISO 27001 require logging with logs stored in the EU and customer access to monitoring; full direct access with EU-stored logs is the best fit, though tamper-proof immutability is not documented -> opt4 (seal 3).
SOV-7.5Disclosure of incidents4. Partial compliance, monitored flow, SLAs107/143SEAL-3mediumComplies with GDPR/NIS2 breach-notification obligations with monitored flow and SLAs; full real-time CSIRT sharing not explicitly documented -> opt4 (seal 3).
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowAs operator of its own self-developed software and infrastructure, Oodrive has moderate-to-high maintenance autonomy (scheduled, tested deployments); moderate autonomy is the conservative fit -> opt3.
SOV-7.7Auditability5. Full independent audit by any entity143/143SEAL-4mediumaudit_rights: SecNumCloud, ISO 27001, ISO 27701 and HDS subject Oodrive to recurring independent third-party audits, supporting full independent auditability -> opt5 (src: https://www.oodrive.com/group-news/oodrive-renews-iso-27001-iso-27701-hds-2-0-certifications/).

SOV-8 · Environmental Sustainability 50.1% · SEAL-3 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowOperates modern French data centers (typical PUE around/below 1.5 with efficiency roadmaps) under SecNumCloud; Oodrive publishes no specific PUE figure -> opt3 (seal 4).
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowOwns its own hardware and runs a documented RSE/circular program (paper sorting, plastic removal, hardware lifecycle, residual-emissions compensation) via a dedicated cross-department RSE group -> documented program opt3 (seal 3).
SOV-8.3Environmental impact reporting4. Detailed EU methodology188/250SEAL-3lowPublishes an annual carbon footprint (928 t CO2 in 2020) with a reduction plan and certified carbon-compensation under a structured RSE methodology -> detailed EU methodology opt4 (seal 3).
SOV-8.4Energy supplies2. Only EU energy supplies63/250SEAL-4lowData centers in France draw on the EU (French) grid; EU energy supplies assumed, but no specific green/renewable sourcing documentation found -> opt2.