🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Platform.sh

France · PaaS · https://upsun.com

Sovereignty score42.4%
Global (unweighted)42.3%
Overall SEAL
SEAL-0 No Sovereignty
SOV-1 Strategic Sovereignty41.8SEAL-0
SOV-2 Legal & Jurisdictional Sovereignty46.0SEAL-1
SOV-3 Data & AI Sovereignty40.0SEAL-0
SOV-4 Operational Sovereignty29.3SEAL-1
SOV-5 Supply Chain Sovereignty35.9SEAL-1
SOV-6 Technology Sovereignty55.0SEAL-0
SOV-7 Security & Compliance Sovereignty46.7SEAL-1
SOV-8 Environmental Sustainability43.8SEAL-1

SOV-1 · Strategic Sovereignty 41.8% · SEAL-0 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control3. Mostly within the EU83/125SEAL-3highParent is Platform.sh SAS, a French entity (RCS Paris), but it has a US subsidiary (San Francisco) and a UK Ltd, so control is mostly-within-EU (opt3) rather than entirely EU (src: https://www.bcorporation.net/en-us/find-a-b-corp/company/platformsh/).
SOV-1.2Change of control risk3. Somewhat likely takeover/transfer to non-EU sovereign entity63/125SEAL-4mediumVC-backed Series D scale-up with non-EU lead capital (Morgan Stanley Expansion Capital, Digital+Partners) alongside EU funds; unprofitable scale-up makes transfer to a non-EU buyer somewhat likely (seal 4 regardless).
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2mediumRoadmap set commercially by the company; customer influence only via product feedback / public channels and open-source issue trackers, no formal EU governance body -> opt2.
SOV-1.4Financial independence from non-EU capital3. Balanced mix of EU and non-EU funding63/125SEAL-4mediumBalanced mix: EU investors (Eurazeo, Revaia, Partech) alongside significant non-EU capital (US-led Series D, BGV) -> opt3 (seal 4 regardless).
SOV-1.5EU economic contribution3. Balanced EU/non-EU63/125SEAL-4mediumFrench HQ and EU operations contribute in the EU, but substantial US operations (San Francisco/Austin offices, US revenue) make contribution broadly balanced -> opt3 (seal 4 regardless).
SOV-1.6Participation in EU strategic programs2. Limited participation31/125SEAL-4lowNo clear evidence of Gaia-X or IPCEI-CIS participation; at most limited involvement in EU strategic programs -> opt2 (seal 4 regardless).
SOV-1.7Alignment with EU industrial strategies2. Existing action plan42/125SEAL-4lowB Corp with sovereignty messaging but no documented governance / measured achievement tied to EU industrial strategy beyond general intent -> opt2 (seal 4 regardless).
SOV-1.8Resilience to cut-off2. Service would stop, with delay for customer reaction31/125SEAL-0highNo own_stack: PaaS layered on non-EU hyperscalers (AWS/Azure/GCP); if a primary IaaS dependency were cut off the service would stop with delay to migrate, not continue autonomously -> opt2 (seal 0). Gating.

SOV-2 · Legal & Jurisdictional Sovereignty 46.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction2. Mixed EU/non-EU84/167SEAL-1highMixed jurisdiction: French SAS plus a US subsidiary and US-law hyperscaler infrastructure, so not exclusively EU law -> opt2 (src: https://upsun.com/trust-center/legal/impressum/).
SOV-2.2Extraterritorial laws exposure2. Mitigation clauses, exposure remains42/167SEAL-1highNo immunity: EU parent but a US subsidiary and US-hyperscaler reliance keep US extraterritorial exposure; only mitigation clauses exist -> opt2.
SOV-2.3Data access pathways for non-EU authorities2. Can compel access without notification, specific cases42/167SEAL-1highforeign US nexus (US subsidiary + workloads on US hyperscalers) -> US CLOUD Act/FISA can compel access without notification in specific cases -> opt2 (seal 1). Gating.
SOV-2.4Export control restrictions3. Share of revenues >50% in the EU84/167SEAL-2lowNo EU-targeted export restrictions; substantial EU revenue but large US customer base means EU share not clearly dominant -> opt3.
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4mediumCore Platform.sh/Upsun platform, CLI, SDKs and runtime spec are developed by the EU-HQ company (French founders); IP mostly EU-originated though built by a distributed team (seal 4 regardless).
SOV-2.6IP holder jurisdiction3. Mixed law, some EU84/167SEAL-3mediumIP held across the group including a US subsidiary, so governed by mixed law with an EU (French SAS) component -> opt3.

SOV-3 · Data & AI Sovereignty 40.0% · SEAL-0 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys2. Primarily provider, not exclusively50/200SEAL-1mediumEncryption keys provider-managed by default; customers get a Vault KMS for their own secrets but the provider holds underlying infrastructure keys -> primarily provider, not exclusively -> opt2.
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2mediumAccess/activity logs and observability provided but vendor-controlled and not real-time independently auditable oversight of provider/hyperscaler access -> opt3.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowDeletion follows documented policy on project deletion with internal validation, no published independently verified proof-of-erasure -> opt3 (internal validation per policy).
SOV-3.4Data location strictly in EU/EEA2. Partly EU, significant third-country reliance50/200SEAL-0highNo eu_exclusive: global product offers many third-country regions (US, Canada, Australia, plus AWS/Azure/GCP/OVH) and runs control-plane/subprocessors outside the EU; partly EU with significant third-country reliance -> opt2 (seal 0). Gating (src: https://support.platform.sh/hc/en-us/articles/8138808781458-Where-in-the-world-is-my-project-s-data-located).
SOV-3.5AI services sovereignty3. Mixed: auditable/open-source AI, foreign chips100/200SEAL-2lowDeployment platform, not an AI provider; any AI/ML relies on foreign accelerators in the underlying hyperscalers with no EU-sovereign AI offering -> opt3 (mixed/foreign chips).

SOV-4 · Operational Sovereignty 29.3% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4highGit-driven platform with documented export, open-source CLI/SDKs and config-as-code (YAML) -> standard documented data export methods -> opt3 (seal 4).
SOV-4.2Ability to operate without foreign dependencies2. Ops partially sourced within EU42/167SEAL-1highNo eu_ops: globally distributed engineering/ops with significant US presence and US-hyperscaler operations -> ops partially sourced within EU -> opt2.
SOV-4.3Skill availability in the EU2. Mixed, majority outside EU42/167SEAL-1mediumGlobally distributed remote workforce with substantial non-EU (US) staff; skills mixed, not predominantly EU -> opt2.
SOV-4.4Support channels2. Mixed, majority outside EU42/167SEAL-2medium24/7 follow-the-sun support including US, so a majority of coverage is not EU-confined -> opt2.
SOV-4.5Documentation & knowledge transfer2. EU optional, not enforced42/167SEAL-2lowDocumentation/knowledge is public/global (developer center, docs, GitHub); EU-only handling not enforced -> EU optional, not enforced -> opt2.
SOV-4.6Subcontractor & supplier jurisdiction2. Service would stop with delay42/167SEAL-2highCritical subcontractors are US hyperscalers; loss of one stops the service with delay to migrate, not seamless continuity -> opt2.

SOV-5 · Supply Chain Sovereignty 35.9% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)1. No disclosure0/143SEAL-1lowconsistency (hyperscaler-PaaS cluster norm 5.1=opt1): as a PaaS it owns no hardware and the physical component origin set by the hyperscaler/OVH datacenters is not disclosed to Platform.sh's customers -> opt1 (no disclosure, seal 1).
SOV-5.2Manufacturing location1. Fully foreign, black box0/143SEAL-1lowconsistency (hyperscaler-PaaS cluster norm 5.2=opt1): underlying servers are manufactured/operated by the foreign hyperscalers, a black box from Platform.sh's perspective with no disclosure -> opt1 (seal 1).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/embedded code in underlying hardware controlled by hyperscaler suppliers, partial disclosure -> opt2 (seal 4 regardless).
SOV-5.4Origin of software4. Large majority maintained by EU teams107/143SEAL-3mediumNot foreign_core (genuine differentiator vs US members): the orchestration/CLI/SDKs/runtime images are designed and largely maintained by the EU-HQ (French) company and substantially open-source -> large majority maintained by EU teams -> opt4 (src: https://github.com/platformsh).
SOV-5.5Software build/release jurisdiction3. Non-EU control, EU execution72/143SEAL-3lowSoftware controlled by the EU parent but built/released by a distributed team with CI partly on US infrastructure -> non-EU execution element; EU execution present -> opt3.
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2highFew non-EU dependencies in critical services (the hyperscaler IaaS plus US SaaS subprocessors), documented in the subprocessor list -> opt3 (seal 2).
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowSubprocessor list published and critical hosting suppliers are certified/auditable, but full end-to-end supply-chain auditability not provided -> critical suppliers auditable -> opt3.

SOV-6 · Technology Sovereignty 55.0% · SEAL-0 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3highStandards-based git/container-driven platform with open APIs, open-source CLI/SDKs and documented config -> standards-based and broadly compatible -> opt4.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumCore services rely on open standards (Git, OCI/containers, standard runtimes, SSH, HTTP) for most services -> policy for most core services -> opt4.
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3mediumSignificant components (CLI, SDKs, runtime specs, tools) open-source on GitHub, but core orchestration/control plane proprietary with centralised governance -> open source, centralised governance -> opt3.
SOV-6.4Service architecture transparency4. Large corpus of public insight150/200SEAL-3mediumExtensive public documentation, developer center, blog and open-source code -> large corpus of public insight -> opt4.
SOV-6.5HPC sovereignty1. Imported black-box HPC0/200SEAL-0lowNo EU-sovereign HPC; any HPC would be imported black-box hyperscaler hardware -> opt1 (imported black-box HPC, seal 0). Gating.

SOV-7 · Security & Compliance Sovereignty 46.7% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)3. EAL272/143SEAL-2highcerts: ISO 27001 + SOC 2 Type 2 + PCI DSS Level 1 + HIPAA (no SecNumCloud/EUCS-High/Common Criteria EAL); per key ISO 27001 + SOC 2 maps to opt3 (EAL2-equiv, seal 2) (src: https://upsun.com/solutions/compliance-and-governance/).
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4highStrong independently audited posture: GDPR (DPA), ISO 27001, SOC 2 Type 2, PCI DSS Level 1, HIPAA; partial compliance to most major EU frameworks, full NIS2/DORA not demonstrated -> opt4 (seal 4 regardless).
SOV-7.3EU-based SOC & incident handling2. Hybrid EU/non-EU36/143SEAL-1mediumSecurity/incident handling run by globally distributed 24/7 teams -> hybrid EU/non-EU SOC -> opt2.
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1mediumCustomers get monitoring/observability and log access via portal, but full immutable customer-controlled EU-stored logging is not standard -> basic monitoring portal -> opt3.
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2mediumIncident disclosure GDPR/contractually aligned with breach-notification commitments -> moderate, GDPR/NIS2-aligned -> opt3.
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowManaged platform; customers control app deployments with notice/testing windows for platform maintenance -> moderate autonomy -> opt3 (seal 4).
SOV-7.7Auditability2. Limited independent access36/143SEAL-1mediumNo audit_rights: audit evidence via SOC 2/ISO reports and provider certifications only, not full independent audit by any entity -> limited independent access -> opt2.

SOV-8 · Environmental Sustainability 43.8% · SEAL-1 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowRuns on hyperscaler/OVH datacenters that publish PUE typically <1.5 with efficiency roadmaps; Platform.sh owns no facilities -> opt3 (PUE<1.5 + roadmap) (src: https://corporate.ovhcloud.com/en/sustainability/).
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowHardware reuse/recycling governed by the underlying hyperscaler/OVH circular-economy programs which are documented; no own-hardware program -> documented program -> opt3.
SOV-8.3Environmental impact reporting2. Basic reporting63/250SEAL-1lowAs a B Corp it reports some sustainability info but no detailed EU-methodology environmental impact report for the service -> basic reporting -> opt2.
SOV-8.4Energy supplies3. Mix of EU and non-EU supplies125/250SEAL-4lowEnergy supply depends on datacenters used; mix of EU (OVH/Azure FR) and non-EU (US AWS/Azure/GCP) regions -> mix of EU and non-EU supplies -> opt3 (seal 4 regardless) (src: https://corporate.ovhcloud.com/en/sustainability/).