🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Qovery

France · PaaS · https://www.qovery.com

Sovereignty score60.7%
Global (unweighted)57.4%
Overall SEAL
SEAL-0 No Sovereignty
SOV-1 Strategic Sovereignty59.5SEAL-2
SOV-2 Legal & Jurisdictional Sovereignty91.6SEAL-2
SOV-3 Data & AI Sovereignty80.0SEAL-1
SOV-4 Operational Sovereignty62.6SEAL-2
SOV-5 Supply Chain Sovereignty50.1SEAL-1
SOV-6 Technology Sovereignty65.0SEAL-3
SOV-7 Security & Compliance Sovereignty50.0SEAL-1
SOV-8 Environmental Sustainability0.0SEAL-0

SOV-1 · Strategic Sovereignty 59.5% · SEAL-2 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4highLegal entity is BIRDSIGHT SAS, a French simplified joint-stock company (RCS 852 571 108) headquartered at 128 rue de la Boetie, Paris; entirely EU-incorporated and EU-controlled (src: https://www.qovery.com/sovereignty).
SOV-1.2Change of control risk3. Somewhat likely takeover/transfer to non-EU sovereign entity63/125SEAL-4mediumFounder-led French startup but VC-backed and actively expanding into the US with $13M Series A including US investors/angels; an acquisition by a non-EU acquirer is plausible for a growth-stage company though not imminent.
SOV-1.3Control over roadmap3. Governance bodies exist with EU actors participation83/125SEAL-3mediumEU-controlled French company with its own R&D; the engine is open-source so EU actors can influence the roadmap via public issues/PRs, giving EU-actor participation in governance (key 1.3: EU governance with some external influence -> opt3).
SOV-1.4Financial independence from non-EU capital4. Majority of funding is EU-based94/125SEAL-4mediumSeries A was led by IRIS Capital (France) with Speedinvest (Austria) and Crane (UK), plus US participants (Techstars, US angels); the majority/lead funding is EU-based.
SOV-1.5EU economic contribution4. Majority in the EU94/125SEAL-4mediumCompany is incorporated, headquartered and primarily staffed/engineered in Paris, so the majority of economic value-add is in the EU despite a nascent US sales push.
SOV-1.6Participation in EU strategic programs1. No clear participation0/125SEAL-4mediumNo evidence of participation in EU strategic programs such as Gaia-X or IPCEI-CIS; Qovery markets sovereignty independently.
SOV-1.7Alignment with EU industrial strategies2. Existing action plan42/125SEAL-4lowHas an explicit sovereignty positioning/action plan (dedicated sovereignty page, EU-law-by-default, self-hostable control plane) but no measured governance or dedicated EU-industrial-strategy means.
SOV-1.8Resilience to cut-off4. Ability to source alternatives or internalise key functions94/125SEAL-2highNot own_stack (SaaS control plane runs on AWS and customer workloads typically on non-EU hyperscalers), but the open-source GPL engine + air-gapped self-hosting genuinely let customers source alternatives/internalise; key 1.8: real non-EU operational dependency with internalisation path -> opt4 (seal 2), not full autonomy.

SOV-2 · Legal & Jurisdictional Sovereignty 91.6% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highQovery (BIRDSIGHT SAS) operates under EU law by default as a French entity; its terms and processing are governed by French/EU law (src: https://www.qovery.com/sovereignty).
SOV-2.2Extraterritorial laws exposure4. Legal structures shielding from foreign law125/167SEAL-2mediumeu_entity (pure-FR SAS, no non-EU parent) gives legal structures shielding from foreign law, but with no SecNumCloud/EUCS-High certified immunity and a real AWS/US nexus for the control plane; key 2.2: EU entity, structural separation, no certified immunity -> opt4 (seal 2).
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumNo foreign_parent (wholly French entity, not reachable by CLOUD Act/FISA) and by architecture Qovery never holds customer data, secrets or DB contents; key 2.3: not subject to non-EU compelled access and commits to refuse -> opt5 (seal 4) (src: https://www.qovery.com/sovereignty).
SOV-2.4Export control restrictions4. Part of offer shielded from restrictions towards EU MSs125/167SEAL-3lowAs a French SAS the offer faces no export restrictions toward EU Member States and is structurally shielded toward EU MSs; intl-org shielding is not documented (key 2.4: part of offer shielded toward EU MSs -> opt4).
SOV-2.5Origin of IP5. Fully within the EU167/167SEAL-4highCore IP (the deployment engine, control-plane API and platform) is designed and developed by the Paris-based team; the engine is published as Qovery's own open-source code.
SOV-2.6IP holder jurisdiction5. Fully under EU law167/167SEAL-4highIP is held by the French entity BIRDSIGHT SAS and thus falls fully under EU law.

SOV-3 · Data & AI Sovereignty 80.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys5. Customer exclusive control - provider cannot read data200/200SEAL-4highQovery explicitly never accesses application data, database contents or environment secrets; encryption keys and secrets remain entirely under the customer's control in their own cloud account, so the provider cannot read the data. Genuine customer-exclusive-key strength preserved (src: https://www.qovery.com/sovereignty).
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3mediumDeployment events, audit logs and resource metrics are exposed to the customer via the platform, and customers run workloads in their own account with their own cloud-native logging, giving strong customer-controlled visibility though not independently real-time audited.
SOV-3.3Secure deletion & proof of erasure4. Deletion technically verified with access logs150/200SEAL-3lowData lives in the customer's own cloud account and deletion is technically verifiable through the customer's own cloud-native deletion plus Qovery's audit logs of every change; key 3.3: deletion technically verified with access logs -> opt4.
SOV-3.4Data location strictly in EU/EEA4. EU by default, tightly controlled exceptions150/200SEAL-1mediumNOT eu_exclusive: workloads run in the customer's own cloud account (which may be a non-EU hyperscaler), EU residency is only 'available' not contractually exclusive, and the hosted control plane runs on AWS with US subprocessors; key 3.4: EU by default with opt-in non-EU -> opt4 (seal 1). Genuine SEAL-1 gate, not shared with the EU-exclusive members; not inflated per directive (src: https://www.qovery.com/sovereignty).
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3lowThe core sovereign PaaS offer has no in-scope first-party AI service (any agentic features call customer-chosen LLMs in the customer's own environment, creating no Qovery-side foreign-AI dependency); key 3.5: no in-scope AI service -> opt4 (seal 3).

SOV-4 · Operational Sovereignty 62.6% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability5. Already deployed on sovereign infrastructure167/167SEAL-4highWorkloads already run on the customer's own sovereign-capable infrastructure using standard Kubernetes/Terraform/Helm/Docker, and the open-source engine plus air-gapped self-hosting mean there is no Qovery lock-in for the runtime.
SOV-4.2Ability to operate without foreign dependencies4. Ops predominantly EU-based teams125/167SEAL-3mediumeu_ops (partial): engineering/operations predominantly run by the Paris team, but the SaaS control plane depends on AWS infrastructure; not a fully EU stack, so key 4.2: ops predominantly EU-based -> opt4 (seal 3).
SOV-4.3Skill availability in the EU3. Majority EU, escalation abroad84/167SEAL-3mediumCore engineering is in France/EU with a growing US presence; skills are majority-EU with escalation/expansion abroad, no security-clearance regime documented.
SOV-4.4Support channels3. Majority in EU, non-EU escalations84/167SEAL-3lowSupport is run from the Paris-based company (community forum, EU team) with US expansion; majority EU with possible non-EU escalation, though staffing geography is not formally published.
SOV-4.5Documentation & knowledge transfer2. EU optional, not enforced42/167SEAL-2lowDocumentation (hub.qovery.com) and code are public on globally hosted platforms (GitHub) in English; EU-only handling is not enforced for knowledge repositories.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3mediumThe control plane depends on AWS, but if Qovery or that dependency were lost the customer's infrastructure keeps running and the open-source engine/self-hosting let customers source alternatives or internalise the function.

SOV-5 · Supply Chain Sovereignty 50.1% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowQovery owns no physical hardware; the underlying servers belong to the customer's chosen IaaS (AWS/GCP/Azure/Scaleway) with only the cloud vendor's partial disclosure of component provenance.
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1lowPhysical hardware is manufactured by the underlying hyperscaler/IaaS supply chain (foreign origin, partial disclosure); Qovery has no manufacturing control.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware provenance is inherited from the underlying cloud hardware with only partial disclosure by the IaaS provider; Qovery itself does not control or certify it.
SOV-5.4Origin of software5. Exclusively designed/maintained by EU teams143/143SEAL-4highQovery's own software (the Rust deployment engine and platform) is designed and maintained by the EU team and is partly open-sourced under GPL-3.0; the core product is EU-built rather than foreign black-box (src: https://github.com/Qovery/engine).
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3mediumBuild and release of Qovery's software is controlled by the French company and its EU engineering team, though CI likely executes on globally hosted runners; EU control with EU execution is the reasonable read.
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2mediumThe hosted control plane has a documented critical dependency on AWS (a non-EU vendor) for the SaaS offering, though the dependency is documented and removable via self-hosting.
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowSubprocessors are listed in the privacy policy and DPAs are available on request, giving auditability of critical suppliers, but a full auditable supply-chain inventory is not published.

SOV-6 · Technology Sovereignty 65.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces5. Open-by-default with portability200/200SEAL-4highOpen-by-default: built on standard Kubernetes, Terraform, Helm and Docker with an open-source engine and full portability, since everything runs in the customer's own account.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumCore services adopt open standards (Kubernetes, OCI containers, Terraform, Helm) as a matter of architecture across most of the platform.
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3highThe deployment engine is genuinely open source (GPL-3.0 on GitHub) but the control plane/API remains proprietary and governance is centralised by the vendor, so open source with centralised governance (src: https://github.com/Qovery/engine).
SOV-6.4Service architecture transparency4. Large corpus of public insight150/200SEAL-3mediumSubstantial public insight exists via open-source code, detailed engineering blog posts and public documentation describing the architecture.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowQovery offers no in-scope HPC service of its own, so there is no imported HPC dependency to penalise; key 6.5: no in-scope HPC -> opt2 (seal 3).

SOV-7 · Security & Compliance Sovereignty 50.0% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)2. EAL136/143SEAL-1mediumHolds SOC 2 Type II (independently audited) but no SecNumCloud/EUCS/C5/ENS-High or Common Criteria EAL; SOC 2 alone sits below the ISO+SOC2+C5 (EAL2) tier, mapping to ~EAL1; key 7.1 -> opt2 (seal 1). SEAL-1 gate; no SecNumCloud basis so not inflated per directive (src: https://www.qovery.com/blog/qovery-achieves-soc-2-type-ii-compliance).
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumClaims GDPR, HIPAA and DORA alignment and holds SOC 2 Type II, indicating partial compliance to most relevant EU regulatory frameworks; no NIS2/EUCS certification documented.
SOV-7.3EU-based SOC & incident handling2. Hybrid EU/non-EU36/143SEAL-1lowNo dedicated EU-only SOC/incident-response function is documented; for a small EU startup expanding to the US, a hybrid EU/non-EU security operation is the realistic assumption.
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3mediumCustomers run workloads in their own cloud account with full direct access to their own monitoring and logs, which can be stored in the chosen EU region, though tamper-proof immutability is not guaranteed by Qovery.
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2lowAs a GDPR/DORA-aligned EU company it follows moderate, GDPR/NIS2-style breach-notification practice; real-time CSIRT sharing is not documented.
SOV-7.6Maintenance autonomy4. High autonomy (deploy independently, no checks)107/143SEAL-4mediumQovery automates day-2 operations and customers can deploy, upgrade and patch independently on their own clusters at their own schedule, giving high maintenance autonomy.
SOV-7.7Auditability2. Limited independent access36/143SEAL-1lowNo audit_rights: only SOC 2 Type II reports and a trust center provide assurance, no contractual full independent audit by the contracting authority or any EU body; key 7.7: audits only via certification bodies -> opt2 (seal 1). SEAL-1 gate.

SOV-8 · Environmental Sustainability 0.0% · SEAL-0 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)1. PUE unmanaged/high0/250SEAL-1lowQovery operates no data centres of its own and publishes no PUE; energy efficiency is entirely inherited from the customer's chosen IaaS and unmanaged by Qovery.
SOV-8.2Hardware reuse & recycling1. No policy0/250SEAL-0lowNo hardware reuse or recycling policy is applicable or published since Qovery owns no physical hardware.
SOV-8.3Environmental impact reporting1. No reporting0/250SEAL-1lowNo environmental impact reporting is published by Qovery.
SOV-8.4Energy supplies1. Non traceable0/250SEAL-4lowEnergy supply is not traceable at the Qovery level; it depends entirely on the underlying cloud provider chosen by the customer and is not reported by Qovery.