🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

S3NS

France · IaaS/PaaS · https://www.s3ns.io

Sovereignty score66.8%
Global (unweighted)64.9%
Overall SEAL
SEAL-2 Data Sovereignty
SOV-1 Strategic Sovereignty73.0SEAL-2
SOV-2 Legal & Jurisdictional Sovereignty75.0SEAL-2
SOV-3 Data & AI Sovereignty75.0SEAL-2
SOV-4 Operational Sovereignty79.0SEAL-3
SOV-5 Supply Chain Sovereignty43.2SEAL-2
SOV-6 Technology Sovereignty45.0SEAL-2
SOV-7 Security & Compliance Sovereignty78.5SEAL-3
SOV-8 Environmental Sustainability50.0SEAL-2

SOV-1 · Strategic Sovereignty 73.0% · SEAL-2 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4highS3NS is a French-law company controlled by Thales (France) in a strategic partnership with Google Cloud; Google's stake is capped well below control. Legal entity is entirely within the EU -> opt4. (src: https://www.s3ns.io/en/news/premi3ns-secnumcloud-qualification)
SOV-1.2Change of control risk4. Unlikely takeover/transfer to non-EU sovereign entity94/125SEAL-4mediumThales majority control plus SecNumCloud share-cap rules legally block any non-EU takeover; transfer to a non-EU sovereign entity is unlikely while the SecNumCloud structure stands, though Google's strategic stake creates some residual exposure.
SOV-1.3Control over roadmap3. Governance bodies exist with EU actors participation83/125SEAL-3mediumS3NS controls operations and validates all updates, but the underlying technology roadmap (e.g. timing of Gemini/Vertex availability) is set by Google; governance bodies with EU/Thales participation exist but EU does not have full roadmap control.
SOV-1.4Financial independence from non-EU capital4. Majority of funding is EU-based94/125SEAL-4mediumFunding is predominantly EU-based via Thales as majority shareholder; Google holds a minority capped stake, so the majority of capital is EU-based.
SOV-1.5EU economic contribution4. Majority in the EU94/125SEAL-4highNearly 200 employees in France, three French data centres, French operations and revenue concentrated in France/EU; economic contribution is majority in the EU.
SOV-1.6Participation in EU strategic programs3. Active participant in strategic projects63/125SEAL-4mediumS3NS is an active player in French/EU sovereign cloud strategy (Trusted Cloud / Cloud au Centre doctrine) and was a winner in EU sovereign cloud tenders, an active participant in strategic projects.
SOV-1.7Alignment with EU industrial strategies3. Measured achievement and dedicated governance83/125SEAL-4mediumStrong alignment with France's sovereign cloud doctrine with measurable achievement (SecNumCloud 3.2 qualification) and dedicated governance, though it is not an independent foundational-technology champion.
SOV-1.8Resilience to cut-off4. Ability to source alternatives or internalise key functions94/125SEAL-2lowSecNumCloud requires reversibility and continuity provisions; updates are quarantined and validated by S3NS so the platform can run on the licensed snapshot, giving ability to operate temporarily and source alternatives, but full autonomy is limited by Google technology dependence.

SOV-2 · Legal & Jurisdictional Sovereignty 75.0% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highS3NS operates exclusively under French/EU law as a SecNumCloud 3.2 qualified provider (ANSSI, Dec 2025); the offering is structured to be governed solely by EU law -> opt3. (src: https://www.s3ns.io/en/news/premi3ns-secnumcloud-qualification)
SOV-2.2Extraterritorial laws exposure4. Legal structures shielding from foreign law125/167SEAL-2highimmunity is structural-not-certified-as-absolute: Thales-control + SecNumCloud share caps shield from foreign law, but the core platform is licensed Google tech so the key rates S3NS as legal structures shielding (opt4, seal 2), not verified immunity -> SOV-2.2 opt4. (src: https://www.s3ns.io/en/news/premi3ns-secnumcloud-qualification)
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4highS3NS states extraterritorial requests would be rejected; there is no technical mechanism for Google to access data and Google staff cannot access the infrastructure, so foreign-authority requests are always rejected by the provider -> opt5. (src: https://www.s3ns.io/en/news/premi3ns-secnumcloud-qualification)
SOV-2.4Export control restrictions5. Part of offer shielded from restrictions towards EU MSs/intl orgs167/167SEAL-4mediumOperated exclusively under French jurisdiction by French staff; the offering is structured to be shielded from non-EU export restrictions affecting EU member states and international organisations.
SOV-2.5Origin of IP2. Mostly outside the EU42/167SEAL-4highCore platform software, AI stack and GCP technology IP originate from Google (US); only the operational/security layer IP is Thales/S3NS, so IP origin is mostly outside the EU.
SOV-2.6IP holder jurisdiction3. Mixed law, some EU84/167SEAL-3mediumUnderlying GCP technology IP is held under US law while operational and security IP sits with Thales/S3NS under French law, a mixed situation with some EU holding.

SOV-3 · Data & AI Sovereignty 75.0% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys5. Customer exclusive control - provider cannot read data200/200SEAL-4highPREMI3NS provides externalised customer-controlled encryption keys; with key management held by the customer and no Google access path, the provider cannot read the data.
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3mediumSecNumCloud mandates comprehensive access logging available to customers and auditors, giving full customer-controlled visibility, though not necessarily real-time independent auditability.
SOV-3.3Secure deletion & proof of erasure4. Deletion technically verified with access logs150/200SEAL-3lowSecNumCloud 3.2 requires secure deletion practices with logging; deletion is technically verified with access logs, but independent proof-of-erasure attestation is not clearly evidenced.
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4highData is hosted exclusively in S3NS data centres in France under SecNumCloud 3.2 with no third-country fallback; Google cannot access the infrastructure -> opt5. (src: https://www.s3ns.io/en/news/premi3ns-secnumcloud-qualification)
SOV-3.5AI services sovereignty2. Mostly non-EU: licensed AI, chip dependency50/200SEAL-2mediumAI services are licensed Google/Vertex technology (initially open models, Gemini later) running on NVIDIA H100 (A3) accelerators, so the AI stack and chips are non-EU with licensed models and chip dependency.

SOV-4 · Operational Sovereignty 79.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumBuilt on GCP-compatible APIs with standard export methods and SecNumCloud-mandated reversibility; formal migration support is available, though lock-in to GCP semantics limits true portability.
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4highThe entire stack is operated and administered exclusively by S3NS employees in France; Google staff cannot access the infrastructure, so operations are run by a fully EU-based team.
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumS3NS staff are based in France with required vetting under SecNumCloud; all operational staff are EU-based, though full named security-clearance regime is not documented for every role.
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3mediumSupport is delivered by S3NS in France under SecNumCloud requirements, with all support staff in the EU.
SOV-4.5Documentation & knowledge transfer4. EU-only primary repositories125/167SEAL-4lowSecNumCloud requires documentation and knowledge held within the qualified perimeter in France, implying EU-only primary repositories.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3lowCritical operations are internalised by S3NS and updates are quarantined; in a cut-off the platform can continue on validated snapshots and S3NS can internalise key functions, though deep Google technology dependence caps full autonomy.

SOV-5 · Supply Chain Sovereignty 43.2% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)3. Transparent with exceptions72/143SEAL-3lowHardware runs on dedicated Google infrastructure operated by S3NS within the SecNumCloud 3.2 perimeter audited by ANSSI; component provenance is transparent with exceptions (audit rights inside the qualified perimeter) -> SOV-5.1 opt3.
SOV-5.2Manufacturing location3. Mixed sourcing, EU audit rights72/143SEAL-3mediumServers/accelerators are foreign-designed (Google/NVIDIA) but sourced and operated under the SecNumCloud 3.2 perimeter with ANSSI audit rights -> mixed sourcing with EU audit rights, SOV-5.2 opt3.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/embedded code on the underlying Google and NVIDIA hardware is foreign with only partial disclosure to S3NS.
SOV-5.4Origin of software2. Foreign origin, partial disclosure36/143SEAL-2highforeign_core: core cloud software and AI components are Google-origin licensed technology; S3NS operates and validates but does not develop the core stack, so software origin is foreign with partial disclosure -> opt2 (seal 2 ceiling). (src: https://www.s3ns.io/en/news/premi3ns-secnumcloud-qualification)
SOV-5.5Software build/release jurisdiction3. Non-EU control, EU execution72/143SEAL-3mediumGoogle controls the upstream build/release of the technology while S3NS quarantines, analyses and validates updates and executes deployment in France: non-EU control with EU execution and EU policy gating.
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2highGoogle is a single critical non-EU technology dependency for the core platform and AI; this is documented and the SecNumCloud structure mitigates access risk, but the dependency on one non-EU vendor for critical services remains.
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowCritical suppliers are auditable within the SecNumCloud qualification perimeter audited by ANSSI, though the full upstream Google/NVIDIA supply chain is not openly auditable by any party.

SOV-6 · Technology Sovereignty 45.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumBuilt on GCP APIs that are broadly standards-based and widely compatible, supporting interoperability, though core interfaces remain Google-defined rather than open-by-default.
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2lowPartial adoption of open standards through Kubernetes/GKE and standard cloud interfaces across core services.
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2mediumforeign_core: core platform is Google proprietary technology; some source is available for review/validation by S3NS under strict rights but it is not open source with EU governance -> opt2 (seal 2 ceiling). Initial AI offering favours open models but the platform itself is vendor-controlled. (src: https://www.s3ns.io/en/news/premi3ns-secnumcloud-qualification)
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowS3NS publishes some architecture/sovereignty insight and the design is auditable by ANSSI; some public insight exists into how the service is built and isolated.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3mediumHPC/AI acceleration uses NVIDIA H100 (A3) hardware hosted in France but running a foreign (Google/NVIDIA) stack: EU-hosted, foreign stack.

SOV-7 · Security & Compliance Sovereignty 78.5% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumcert mapping: SecNumCloud 3.2 qualification (ANSSI, Dec 17 2025, covering IaaS+CaaS+PaaS, 20+ services) maps to EAL3-equivalent per the key -> SOV-7.1 opt4 (seal 3). (src: https://www.s3ns.io/en/news/premi3ns-secnumcloud-qualification)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)5. Fully compliant to all, independently audited143/143SEAL-4highSecNumCloud 3.2 qualification by ANSSI plus French/EU regulatory alignment (GDPR, NIS2, DORA) constitutes full, independently audited EU regulatory compliance.
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3mediumSecurity operations and incident handling are performed by S3NS teams in France under SecNumCloud, covering the full lifecycle with EU threat intelligence.
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3mediumSecNumCloud requires customer access to monitoring/logging with logs stored in France/EU, giving full direct access with EU-stored logs.
SOV-7.5Disclosure of incidents4. Partial compliance, monitored flow, SLAs107/143SEAL-3mediumIncident disclosure follows GDPR/NIS2 with monitored flows and SLAs under the SecNumCloud regime; partial compliance with monitored flow and SLAs.
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4mediumS3NS quarantines and validates all updates before deployment with notice and testing, giving moderate maintenance autonomy except for zero-day situations.
SOV-7.7Auditability5. Full independent audit by any entity143/143SEAL-4mediumSecNumCloud 3.2 qualification entails full independent audit by ANSSI and accredited auditors of the qualified perimeter -> opt5. (src: https://www.s3ns.io/en/news/premi3ns-secnumcloud-qualification)

SOV-8 · Environmental Sustainability 50.0% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowModern French data centres in the Paris region with efficiency commitments suggest PUE under 1.5 with a roadmap, though no specific verified PUE figure is published for S3NS.
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowHardware lifecycle/recycling is expected to follow a documented program consistent with Thales/data-centre operator practices, but no S3NS-specific certified program is evidenced.
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2lowEnvironmental reporting is expected at least annually consistent with Thales group sustainability reporting, but no detailed S3NS-specific EU-methodology report is published.
SOV-8.4Energy supplies3. Mix of EU and non-EU supplies125/250SEAL-4lowFrench grid power is largely low-carbon EU energy; without a published S3NS-specific 100% renewable commitment, treated as a mix of EU supplies.