🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

OVHcloud

France · IaaS/PaaS · https://www.ovhcloud.com

Sovereignty score75.1%
Global (unweighted)74.9%
Overall SEAL
SEAL-3 Digital Resilience
SOV-1 Strategic Sovereignty86.5SEAL-4
SOV-2 Legal & Jurisdictional Sovereignty91.6SEAL-4
SOV-3 Data & AI Sovereignty85.0SEAL-3
SOV-4 Operational Sovereignty62.6SEAL-3
SOV-5 Supply Chain Sovereignty67.8SEAL-3
SOV-6 Technology Sovereignty55.0SEAL-3
SOV-7 Security & Compliance Sovereignty82.0SEAL-3
SOV-8 Environmental Sustainability68.9SEAL-3

SOV-1 · Strategic Sovereignty 86.5% · SEAL-4 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity (OVHcloud SA incorporated/HQ in Roubaix, France, Euronext Paris, no controlling non-EU parent) -> entity entirely within the EU, opt4 (src: https://corporate.ovhcloud.com/en/trusted-cloud/security-certifications/).
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4highFounder Klaba family retains ~68-81% of capital and ~82% of voting rights, reinforced via buybacks, making a takeover/transfer to a non-EU sovereign entity very unlikely, opt5.
SOV-1.3Control over roadmap4. Full influence of EU actors125/125SEAL-4mediumEU-controlled vendor with own R&D and a Gaia-X board seat; EU actors have full influence over the roadmap with no non-EU party constraining it, opt4.
SOV-1.4Financial independence from non-EU capital4. Majority of funding is EU-based94/125SEAL-4mediumMajority EU-based funding: founder-family-controlled French listed company; free float includes some global institutional investors so majority rather than fully EU, opt4.
SOV-1.5EU economic contribution4. Majority in the EU94/125SEAL-4mediumR&D, server factory (Croix), datacentres and most headcount are EU (chiefly France); economic contribution majority-EU though it operates globally, opt4.
SOV-1.6Participation in EU strategic programs4. Strong participation94/125SEAL-4highFounding member of Gaia-X (board vice-presidency) and IPCEI-CIS participant; strong participation in EU strategic programs, opt4.
SOV-1.7Alignment with EU industrial strategies3. Measured achievement and dedicated governance83/125SEAL-4mediumMarkets a trusted/sovereign cloud strategy with SecNumCloud roadmap and dedicated governance; measured achievement aligned with EU industrial strategy, opt3.
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4mediumown_stack (designs/builds own servers at Croix, runs own datacentres and OpenStack-based software stack, documented exit/continuity; only residual foreign-fabbed chips) -> full autonomy & continuity, opt5.

SOV-2 · Legal & Jurisdictional Sovereignty 91.6% · SEAL-4 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4high[CEIL] Sovereign offer contracts exclusively under French/EU law (US business handled by a separate US subsidiary); exclusively EU law, opt3 (src: https://www.ovhcloud.com/en/compliance/secnumcloud/).
SOV-2.2Extraterritorial laws exposure5. Verified legal immunity, non-EU laws unenforceable167/167SEAL-4mediumimmunity (SecNumCloud 3.2 qualification, certified protection against extraterritorial access; pure-FR entity, no non-EU parent) -> verified legal immunity, opt5 (src: https://www.ovhcloud.com/en/compliance/secnumcloud/).
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4medium[CEIL,NO3] No foreign_parent; SecNumCloud 3.2 + French blocking statute mean not subject to US CLOUD Act/FISA, with commitment to reject/challenge non-EU compelled access -> requests always rejected, opt5 (src: https://www.ovhcloud.com/en/compliance/secnumcloud/).
SOV-2.4Export control restrictions5. Part of offer shielded from restrictions towards EU MSs/intl orgs167/167SEAL-4mediumEU vendor whose sovereign offer is not subject to non-EU export controls toward EU Member States or international organisations, opt5.
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4mediumSoftware, server designs and water-cooling IP largely developed in-house in France; IP mostly within the EU, embedding foreign chip IP/open-source, opt4.
SOV-2.6IP holder jurisdiction4. EU law with exceptions125/167SEAL-4mediumOVHcloud's own IP held under French/EU law; some embedded third-party (chip/firmware) IP under non-EU law -> EU law with exceptions, opt4.

SOV-3 · Data & AI Sovereignty 85.0% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys5. Customer exclusive control - provider cannot read data200/200SEAL-4highKMS with BYOK/customer-managed keys, KMIP, plus dedicated Managed HSM enabling exclusive customer key control so the provider cannot read the data, opt5.
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3mediumCustomer-controlled logging/audit via Logs Data Platform and IAM giving full customer-controlled visibility, though not guaranteed real-time independent oversight of all provider access, opt4.
SOV-3.3Secure deletion & proof of erasure4. Deletion technically verified with access logs150/200SEAL-3mediumUnder SecNumCloud/ISO 27001 controls deletion is technically verified with access logs for the sovereign offer; independent cryptographic proof not separately published, opt4.
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4higheu_exclusive (SecNumCloud-qualified sovereign offer stores AND processes exclusively in EU, no third-country fallback) -> exclusively EU, opt5 (src: https://www.ovhcloud.com/en/compliance/secnumcloud/).
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3mediumAI Endpoints serves open-source/EU-origin models (Mistral, Llama) on EU infrastructure with zero data retention, running on foreign NVIDIA accelerators -> EU-led AI, foreign accelerators, opt4.

SOV-4 · Operational Sovereignty 62.6% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumBuilt on open standards (OpenStack, Kubernetes, S3-compatible) with documented export/migration tooling and formal migration services available, opt4.
SOV-4.2Ability to operate without foreign dependencies4. Ops predominantly EU-based teams125/167SEAL-3mediumeu_ops (SecNumCloud sovereign offer operated/administered/supported exclusively by EU staff); predominantly EU-based teams across the platform, opt4.
SOV-4.3Skill availability in the EU3. Majority EU, escalation abroad84/167SEAL-3mediumEngineering/R&D workforce concentrated in France/EU with possible escalation abroad for general (non-sovereign) services -> majority EU, escalation abroad, opt3.
SOV-4.4Support channels3. Majority in EU, non-EU escalations84/167SEAL-3mediumSovereign/SecNumCloud support handled by EU staff; broader global support exists -> majority in EU with non-EU escalation, opt3.
SOV-4.5Documentation & knowledge transfer3. EU primary with non-EU fallback84/167SEAL-4lowDocumentation/knowledge bases primarily EU-produced and hosted with non-EU regional fallback -> EU primary with non-EU fallback, opt3.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3mediumVertical integration (own factories, datacentres, software) lets OVHcloud source alternatives or internalise subcontracted functions; main irreplaceable dependency is foreign silicon, opt4.

SOV-5 · Supply Chain Sovereignty 67.8% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)3. Transparent with exceptions72/143SEAL-3mediumTransparent about building its own servers/components at Croix, but origin of underlying chips/disks is foreign and only partially disclosed -> transparent with exceptions, opt3.
SOV-5.2Manufacturing location4. Built by EU teams on foreign design107/143SEAL-3highServers assembled and cooling hardware built by OVHcloud's own EU teams in Croix on its own designs, with silicon foreign-designed -> built by EU teams on foreign-component design, opt4.
SOV-5.3Embedded code/firmware provenance3. Transparent with exceptions72/143SEAL-4lowControls own server/BMC integration and discloses much hardware, but CPU/GPU microcode and component firmware come from foreign vendors not fully disclosed -> transparent with exceptions, opt3.
SOV-5.4Origin of software4. Large majority maintained by EU teams107/143SEAL-3mediumNo foreign_core: control-plane/management software designed and maintained in-house by EU teams on open-source (OpenStack/KVM/Ceph); large majority EU-maintained, opt4.
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3mediumSoftware development and release pipelines controlled and executed by OVHcloud's EU engineering organisation -> EU control & execution, opt4.
SOV-5.6Single point of dependency4. Few non-EU in non-critical services, documented107/143SEAL-3mediumown_stack: vertically integrated (own factory/datacentres/software); only residual non-EU dependency is documented foreign silicon, treated as residual hardware (consistent with SOV-1.8) -> few non-EU, non-critical, documented, opt4.
SOV-5.7Supply chain transparency4. Most suppliers auditable107/143SEAL-3mediumUnder SecNumCloud 3.2's 2,000+ criteria supply-chain audit and ISO controls, most suppliers are auditable end-to-end -> most suppliers auditable, opt4.

SOV-6 · Technology Sovereignty 55.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumStandards-based, broadly compatible interfaces (OpenStack APIs, S3-compatible storage, Kubernetes) promoting interoperability and reversibility, opt4.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumClear policy of building most core services on open standards (OpenStack, Kubernetes, S3, OpenID) -> policy for most core services, opt4.
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3mediumRelies heavily on open source (OpenStack, KVM, Ceph, Kubernetes) and contributes upstream, but the integrated platform governance remains vendor-centralised -> open source, centralised governance, opt3.
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3mediumPublishes substantial public technical insight (blogs, docs, open-source repos) but customers cannot directly co-develop core services -> some public insight, opt3.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3mediumHPC/GPU compute EU-hosted on OVHcloud's own EU infrastructure but on a foreign accelerator stack (NVIDIA) -> EU-hosted, foreign stack (seal 3), opt2.

SOV-7 · Security & Compliance Sovereignty 82.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumHolds SecNumCloud 3.2 (Bare Metal Pod, Hosted Private Cloud) plus C5 and ENS; per key SecNumCloud 3.2 / C5+ENS-High maps to EAL3-equivalent, opt4 (src: https://corporate.ovhcloud.com/en/trusted-cloud/security-certifications/).
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)5. Fully compliant to all, independently audited143/143SEAL-4highHolds SecNumCloud, ISO 27001/27017/27018/27701, HDS, SOC 1/2 Type 2, C5, ENS, CSA STAR; GDPR/NIS2/DORA aligned -> fully compliant and independently audited, opt5.
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3mediumSecNumCloud services operated/monitored 24/7 exclusively by EU staff with EU incident handling -> entire lifecycle by EU teams, EU threat intel, opt4.
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3mediumCustomers get full direct access to security logs via Logs Data Platform with logs stored in the EU; immutable tamper-proof default for opt5 not clearly documented, opt4.
SOV-7.5Disclosure of incidents4. Partial compliance, monitored flow, SLAs107/143SEAL-3mediumAs an EU operator under NIS2/DORA with SecNumCloud incident processes, partial compliance with monitored flow and SLAs -> opt4.
SOV-7.6Maintenance autonomy4. High autonomy (deploy independently, no checks)107/143SEAL-4mediumAs an IaaS provider with its own stack, high autonomy to schedule and deploy maintenance/patches independently of any foreign vendor, opt4.
SOV-7.7Auditability5. Full independent audit by any entity143/143SEAL-4mediumaudit_rights (SecNumCloud sovereign offer grants full audit rights to the contracting authority and independent EU bodies) -> full independent audit by any entity, opt5.

SOV-8 · Environmental Sustainability 68.9% · SEAL-3 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4mediumProprietary water-cooling AC-free datacentres deliver PUE ~1.2-1.4 with a published improvement roadmap -> PUE < 1.5 + roadmap, opt3 (seal 4) (src: https://corporate.ovhcloud.com/en/sustainability/environment/).
SOV-8.2Hardware reuse & recycling4. Circular economy, EU-aligned188/250SEAL-4mediumStrong circular-economy model: refurbishes/reuses servers and components in its own factories with documented recycling, aligned with EU circular-economy goals, opt4.
SOV-8.3Environmental impact reporting4. Detailed EU methodology188/250SEAL-3highPublishes detailed environmental data (PUE, WUE, REF, CUE) and an Environmental Impact Tracker with a detailed methodology, not stated as independently EU-audited -> detailed EU methodology, opt4.
SOV-8.4Energy supplies4. Only EU energy supplies (high renewable)188/250SEAL-4mediumRenewable Energy Factor ~77% targeting 100%, EU-sourced energy supplies -> only EU energy supplies with high renewable share, opt4 (src: https://corporate.ovhcloud.com/en/sustainability/environment/).