🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Rackspace

United States · IaaS/PaaS · https://www.rackspace.com

Sovereignty score34.9%
Global (unweighted)36.2%
Overall SEAL
SEAL-1 Jurisdictional Sovereignty
SOV-1 Strategic Sovereignty26.1SEAL-1
SOV-2 Legal & Jurisdictional Sovereignty25.1SEAL-1
SOV-3 Data & AI Sovereignty50.0SEAL-1
SOV-4 Operational Sovereignty25.1SEAL-1
SOV-5 Supply Chain Sovereignty21.6SEAL-1
SOV-6 Technology Sovereignty45.0SEAL-2
SOV-7 Security & Compliance Sovereignty46.7SEAL-1
SOV-8 Environmental Sustainability50.0SEAL-2

SOV-1 · Strategic Sovereignty 26.1% · SEAL-1 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control1. Entirely outside the EU0/125SEAL-1highforeign_parent (US HQ San Antonio, TX, Apollo-controlled) -> entity control entirely outside the EU -> SOV-1.1 opt1. (src: https://www.sec.gov/cgi-bin/browse-edgar?action=getcompany&CIK=0001810019&type=10-K)
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4mediumAlready a US-controlled entity majority-owned by US PE firm Apollo; transfer to a non-EU sovereign entity is moot/very unlikely as it is already non-EU controlled. Kept at existing all-SEAL-4 choice.
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2mediumRoadmap set by US corporate leadership; EU customers influence only via voice-of-customer/support channels, no EU governance body -> SOV-1.3 opt2.
SOV-1.4Financial independence from non-EU capital1. Almost entirely relying on non-EU funding0/125SEAL-4highMajority owned by US private equity (Apollo Global Management); funding almost entirely non-EU. Kept at existing all-SEAL-4 choice.
SOV-1.5EU economic contribution2. Some31/125SEAL-4mediumHas EU data centers and some EU staff but bulk of revenue, R&D and employment is in US/India; only some EU economic contribution. Kept at existing all-SEAL-4 choice.
SOV-1.6Participation in EU strategic programs1. No clear participation0/125SEAL-4mediumNo evidence of participation in EU strategic programs (Gaia-X, IPCEI-CIS). Kept at existing all-SEAL-4 choice.
SOV-1.7Alignment with EU industrial strategies1. No evidence exists0/125SEAL-4mediumNo public evidence of an action plan aligned with EU industrial/digital sovereignty strategies. Kept at existing all-SEAL-4 choice.
SOV-1.8Resilience to cut-off3. Can continue temporarily per contractual agreement63/125SEAL-2lowNot own_stack (managed/multicloud on non-EU hyperscalers and a US parent), but a managed service with documented data-export/migration tooling and contractual terms under which the service could continue temporarily after a cut-off rather than shutting down immediately -> SOV-1.8 opt3 (seal 2), consistent with US commodity-IaaS peers.

SOV-2 · Legal & Jurisdictional Sovereignty 25.1% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction2. Mixed EU/non-EU84/167SEAL-1highEU customers served via EU entities under EU law, but US parent/US jurisdiction also apply; jurisdiction is mixed EU/non-EU -> SOV-2.1 opt2.
SOV-2.2Extraterritorial laws exposure2. Mitigation clauses, exposure remains42/167SEAL-1highNo certified immunity; US-headquartered group with foreign_parent remains exposed to US extraterritorial law despite contractual/GDPR clauses -> SOV-2.2 opt2.
SOV-2.3Data access pathways for non-EU authorities2. Can compel access without notification, specific cases42/167SEAL-1highforeign_parent (US CLOUD Act/FISA): US authorities can compel data access without customer notification in specific cases -> SOV-2.3 opt2 (seal 1, gates SEAL to 1).
SOV-2.4Export control restrictions2. Restrictions towards EU citizens or international orgs42/167SEAL-1lowUS export-control/OFAC can restrict service to specific sanctioned EU citizens/orgs, but no EU Member State is under restriction and EU revenue is not a >50% majority -> SOV-2.4 opt2.
SOV-2.5Origin of IP2. Mostly outside the EU42/167SEAL-4mediumCore IP (management platform, tooling) is largely US-originated with some open-source heritage; mostly outside the EU. Kept at existing all-SEAL-4 choice.
SOV-2.6IP holder jurisdiction1. Non-EU law, single country0/167SEAL-3mediumRackspace IP held by the US parent under US law, single non-EU country -> SOV-2.6 opt1.

SOV-3 · Data & AI Sovereignty 50.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys3. Shared - provider has override keys100/200SEAL-2lowManaged-cloud model: customer-managed keys possible but as managed operator Rackspace retains override/operational access -> shared keys, SOV-3.1 opt3.
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowLogging/access reporting via platform but largely vendor-controlled, not real-time independently auditable -> SOV-3.2 opt3.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowDeletion handled per internal policy with confirmation; no independently verified irreversible-erasure proof -> SOV-3.3 opt3.
SOV-3.4Data location strictly in EU/EEA4. EU by default, tightly controlled exceptions150/200SEAL-1mediumNo eu_exclusive sovereign offer, but Rackspace operates EU data centres (Frankfurt FRA, Amsterdam) designed to keep customer data within the EU under German/EU data-protection law: EU-by-default with tightly controlled exceptions rather than a contractual no-third-country guarantee -> SOV-3.4 opt4 (seal 1). (src: https://www.rackspace.com/lp/germany-data-center)
SOV-3.5AI services sovereignty2. Mostly non-EU: licensed AI, chip dependency50/200SEAL-2mediumAI offerings (FAIR/AI Anywhere) built on US/foreign LLMs and foreign GPU accelerators; mostly non-EU with chip dependency -> SOV-3.5 opt2.

SOV-4 · Operational Sovereignty 25.1% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumMulticloud/OpenStack heritage provides standard documented data export/portability methods -> SOV-4.1 opt3.
SOV-4.2Ability to operate without foreign dependencies1. Critical ops delivered by non-EU teams0/167SEAL-1mediumNo eu_ops: critical operations delivered by global teams concentrated in the US and India; the EU cannot operate the stack independently -> SOV-4.2 opt1, consistent with US commodity-IaaS peers.
SOV-4.3Skill availability in the EU2. Mixed, majority outside EU42/167SEAL-1mediumEngineering/ops talent is a global workforce concentrated in US/India, majority outside the EU -> SOV-4.3 opt2.
SOV-4.4Support channels2. Mixed, majority outside EU42/167SEAL-2medium24x7 Fanatical Support delivered from a mix of locations including large India centers; majority outside the EU -> SOV-4.4 opt2.
SOV-4.5Documentation & knowledge transfer2. EU optional, not enforced42/167SEAL-2lowDocumentation/knowledge repositories are global with no enforced EU-only residency -> SOV-4.5 opt2 (EU optional, not enforced).
SOV-4.6Subcontractor & supplier jurisdiction2. Service would stop with delay42/167SEAL-2lowHeavy reliance on US hyperscaler subcontractors (AWS/Azure/GCP); a cut-off would stop service with only a reaction delay -> SOV-4.6 opt2.

SOV-5 · Supply Chain Sovereignty 21.6% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowHardware components foreign-sourced (US/Asia) with at best partial provenance disclosure -> SOV-5.1 opt2.
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1lowServer/network hardware of foreign origin (US/Asian ODMs), partial disclosure, not EU-built -> SOV-5.2 opt2.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/embedded code from foreign hardware vendors with only partial provenance disclosure. Kept at existing all-SEAL-4 choice.
SOV-5.4Origin of software2. Foreign origin, partial disclosure36/143SEAL-2mediumforeign_core: sovereign offer built on US-licensed VMware plus US-originated management software; partial disclosure via OpenStack/OSS but maintenance largely non-EU -> SOV-5.4 opt2 (seal 2 ceiling).
SOV-5.5Software build/release jurisdiction1. Non-EU control & execution0/143SEAL-1lowSoftware build/release controlled and executed by US-based engineering org, outside the EU -> SOV-5.5 opt1.
SOV-5.6Single point of dependency2. Mostly non-EU, undocumented36/143SEAL-1mediumCritical services depend on non-EU vendors (US parent plus AWS/Azure/GCP hyperscalers); mostly non-EU and largely undocumented for EU customers -> SOV-5.6 opt2.
SOV-5.7Supply chain transparency2. Some suppliers auditable36/143SEAL-1lowSome suppliers/certifications auditable (SOC/ISO) but full supply chain not transparently auditable -> SOV-5.7 opt2.

SOV-6 · Technology Sovereignty 45.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumStandards-based and broadly compatible: OpenStack/multicloud APIs, S3-compatible storage and Kubernetes alongside proprietary management tooling -> SOV-6.1 opt4, consistent with US commodity-IaaS peers.
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2mediumPartial adoption of open standards in core services (OpenStack, Kubernetes, standard cloud APIs) -> SOV-6.2 opt3.
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2mediumforeign_core: commercial sovereign platform built on US-licensed VMware with centralised US-controlled governance; OSS heritage but core is source-available/vendor-controlled -> SOV-6.3 opt2 (seal 2 ceiling).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowSome public architectural insight via OpenStack/docs and reference materials -> SOV-6.4 opt3.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowHPC/GPU capacity is offered in/through EU regions but runs on imported foreign (US/NVIDIA) accelerators and stack: EU-hosted on a foreign stack rather than imported black-box with no EU footprint -> SOV-6.5 opt2 (seal 3), consistent with US commodity-IaaS peers.

SOV-7 · Security & Compliance Sovereignty 46.7% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)3. EAL272/143SEAL-2lowNo SecNumCloud/EUCS-High/Common Criteria EAL, but holds ISO 27001 plus SOC 2/SOC 3 Type II (and PCI-DSS, HIPAA alignment); per the key's cert map ISO 27001 + SOC 2 -> EAL2-equivalent -> SOV-7.1 opt3 (seal 2). (src: https://www.rackspace.com/compliance/soc)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumStrong compliance program (ISO 27001, SOC 2/3, GDPR, HIPAA, PCI-DSS) -> partial compliance to most. Kept at existing all-SEAL-4 choice.
SOV-7.3EU-based SOC & incident handling2. Hybrid EU/non-EU36/143SEAL-1lowSecurity ops/incident response run by global teams; hybrid EU/non-EU SOC at best -> SOV-7.3 opt2.
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1lowCustomers get monitoring/logging via portal but provider retains substantial control; logs not guaranteed EU-resident immutable -> SOV-7.4 opt3 (basic monitoring portal).
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2mediumIncident disclosure GDPR/NIS2-aligned (moderate compliance) -> SOV-7.5 opt3.
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowManaged service provides moderate maintenance autonomy with notice and testing windows -> SOV-7.6 opt3.
SOV-7.7Auditability2. Limited independent access36/143SEAL-1lowNo tender-grade audit_rights: audit access limited to certification reports (SOC/ISO) under NDA, not full independent audit by any entity -> SOV-7.7 opt2.

SOV-8 · Environmental Sustainability 50.0% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowModern data centers; plausibly PUE < 1.5 with efficiency roadmap, no EU-verified low PUE published -> SOV-8.1 opt3.
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowDocumented sustainability/hardware-lifecycle program but not an EU-certified circular lifecycle -> SOV-8.2 opt3. (src: https://www.rackspace.com/about/corporate-sustainability)
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2lowPublishes annual ESG/sustainability reporting without EU-specific audited methodology -> SOV-8.3 opt3 (annual report). (src: https://www.rackspace.com/about/corporate-sustainability)
SOV-8.4Energy supplies3. Mix of EU and non-EU supplies125/250SEAL-4lowOperates globally; energy supply is a mix of EU and non-EU sources. Kept at existing all-SEAL-4 choice.