🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Safe Swiss Cloud

Switzerland · IaaS/PaaS · https://www.safeswisscloud.ch

Sovereignty score49.4%
Global (unweighted)50.5%
Overall SEAL
SEAL-0 No Sovereignty
SOV-1 Strategic Sovereignty40.8SEAL-1
SOV-2 Legal & Jurisdictional Sovereignty62.7SEAL-1
SOV-3 Data & AI Sovereignty50.0SEAL-0
SOV-4 Operational Sovereignty45.9SEAL-1
SOV-5 Supply Chain Sovereignty39.6SEAL-1
SOV-6 Technology Sovereignty55.0SEAL-3
SOV-7 Security & Compliance Sovereignty53.7SEAL-1
SOV-8 Environmental Sustainability56.3SEAL-1

SOV-1 · Strategic Sovereignty 40.8% · SEAL-1 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control2. Mostly outside the EU42/125SEAL-1highNot eu_entity: 100% Swiss-owned AG (majority EveryWare AG), HQ Zurich. Switzerland is a third country, not EU/EEA, so legal entity control sits outside the EU -> opt2 'mostly outside the EU' (seal 1; uniform across the Swiss cluster). (src: https://safeswisscloud.com/en/)
SOV-1.2Change of control risk4. Unlikely takeover/transfer to non-EU sovereign entity94/125SEAL-4mediumPrivately owned Swiss company held by Swiss IT firm EveryWare AG; no signals of imminent takeover by a non-EU sovereign entity, but as a small private firm a transfer is not impossible -> 'unlikely' (seal 4 on all options).
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2lowSmall independent provider with customer-facing channels but no published EU governance bodies; roadmap influence is voice-of-customer rather than formal EU-actor governance -> opt2 (seal 2).
SOV-1.4Financial independence from non-EU capital3. Balanced mix of EU and non-EU funding63/125SEAL-4lowFunding is Swiss (EveryWare AG), neither EU nor non-EU hyperscaler capital; Swiss capital is non-EU, treated as a balanced/mixed position absent evidence of substantial EU funding (seal 4 on all options).
SOV-1.5EU economic contribution2. Some31/125SEAL-4lowOperations and economic footprint concentrated in Switzerland (non-EU) with only some EU-facing customer activity; EU economic contribution is limited (seal 4 on all options).
SOV-1.6Participation in EU strategic programs1. No clear participation0/125SEAL-4mediumNo evidence of participation in EU strategic programs (Gaia-X, IPCEI-CIS); positioning is Swiss sovereignty, not EU strategic projects (seal 4 on all options).
SOV-1.7Alignment with EU industrial strategies2. Existing action plan42/125SEAL-4lowMarkets as a VMware/hyperscaler alternative aligned with European sovereignty themes (cites CISPE), an action-plan-level alignment but without measured governance or dedicated EU industrial means (seal 4 on all options).
SOV-1.8Resilience to cut-off4. Ability to source alternatives or internalise key functions94/125SEAL-2mediumown_stack partial: vertically integrated Swiss stack (own data centres, OpenStack/open tech, Swiss ops) could source alternatives or internalise key functions if cut off; full autonomy not demonstrated given foreign hardware/chips, and the operator itself is non-EU -> opt4 'source alternatives' (seal 2), not opt5.

SOV-2 · Legal & Jurisdictional Sovereignty 62.7% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction2. Mixed EU/non-EU84/167SEAL-1highBound primarily by Swiss law (SR 235.1, a third country) with GDPR applying contractually for EU customers; mixed EU/non-EU jurisdiction, not exclusively EU law -> opt2 (seal 1; uniform across the Swiss cluster). (src: https://safeswisscloud.com/en/swiss-secure-compliant/)
SOV-2.2Extraterritorial laws exposure4. Legal structures shielding from foreign law125/167SEAL-2mediumSwiss incorporation + Swiss-only data location materially shield from US CLOUD Act, but no certified immunity (no SecNumCloud/EUCS-High) and Swiss law is itself non-EU -> 'legal structures shielding from foreign law' opt4 (seal 2), not verified EU-law immunity. (src: https://safeswisscloud.com/en/swiss-secure-compliant/)
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumNo foreign_parent: 100% Swiss company, no US/CN hyperscaler parent, Swiss-only hosting; explicitly states it does not fall under the CLOUD Act and would route any foreign request through Swiss MLA channels -> 'requests always rejected' opt5 (seal 4). Consistent with the identical pure-Swiss-no-foreign-parent peers Infomaniak and Nine. (src: https://safeswisscloud.com/en/swiss-secure-compliant/)
SOV-2.4Export control restrictions3. Share of revenues >50% in the EU84/167SEAL-2lowNo EU/international export restrictions target it and it derives revenue from European customers; absent EU-MS-specific shielding mechanisms, the revenue-share mid option fits -> opt3 (seal 2).
SOV-2.5Origin of IP3. Mixed within/outside the EU84/167SEAL-4lowStack built on open-source software (OpenStack, Kubernetes, OpenShift, Ceph/S3) with global community origin plus Swiss integration; IP origin mixed within/outside the EU (seal 4 on all options).
SOV-2.6IP holder jurisdiction3. Mixed law, some EU84/167SEAL-3lowUnderlying open-source IP held under mixed jurisdictions (global foundations, some EU contributors); not single-country, not fully EU -> opt3 (seal 3).

SOV-3 · Data & AI Sovereignty 50.0% · SEAL-0 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys3. Shared - provider has override keys100/200SEAL-2lowStandard IaaS/OpenStack with provider-managed encryption and TFA; no documented customer-exclusive HYOK offering, so shared control with provider override -> opt3 (seal 2).
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowISO 27001/27017/27018 and ISAE 3000 Type 2 imply audit logging, but logs are vendor-controlled and not advertised as real-time customer-auditable -> opt3 (seal 2).
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowISO 27001/27018-governed deletion implies policy-based validation; no published cryptographic proof-of-erasure, so internal validation per policy without proof -> opt3 (seal 1).
SOV-3.4Data location strictly in EU/EEA2. Partly EU, significant third-country reliance50/200SEAL-0highNot eu_exclusive: all data hosted exclusively in Switzerland (Interxion/Digital Realty Glattbrugg), a third country, not EU/EEA, with no EU region offered. From an EU-sovereignty standpoint this is partly-EU/significant third-country reliance -> opt2 (seal 0). This is the SEAL-0 gate, shared with the other Swiss-only-hosting peers Infomaniak and Nine. (src: https://safeswisscloud.com/en/cloud-computing/)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3mediumOffers sovereign Private AI and Swiss GPU computing with auditable/open models hosted in CH, but relies on foreign GPU accelerators -> EU/Swiss-led AI on foreign accelerators, opt4 (seal 3). Consistent with Infomaniak's equivalent curated open-model AI offering. (src: https://safeswisscloud.com/en/products/)

SOV-4 · Operational Sovereignty 45.9% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumBuilt on OpenStack with standard APIs and S3-compatible object storage plus positioning as a VMware-migration target, implying documented export and formal migration assistance -> opt4 (seal 4).
SOV-4.2Ability to operate without foreign dependencies3. Ops balanced EU/non-EU teams84/167SEAL-3lowNot eu_ops: operations run by a Swiss team on a Swiss stack; from an EU perspective these are non-EU teams, landing at the balanced EU/non-EU mid option -> opt3 (seal 3).
SOV-4.3Skill availability in the EU2. Mixed, majority outside EU42/167SEAL-1lowEngineering and skills are Swiss-based (non-EU from the framework's view), no evidence of EU-majority staffing; majority of skills sit outside the EU/EEA -> opt2 (seal 1).
SOV-4.4Support channels2. Mixed, majority outside EU42/167SEAL-2low24x7 support operated from Switzerland (Zurich/Basel); Swiss support is non-EU/EEA, a mixed/majority-outside-EU position -> opt2 (seal 2).
SOV-4.5Documentation & knowledge transfer2. EU optional, not enforced42/167SEAL-2lowDocumentation is Swiss/English partly referencing upstream OpenStack manuals; no enforced EU-only knowledge repositories, so EU placement is optional/not enforced -> opt2 (seal 2).
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3lowOwns its data centres and uses open-standard software, giving an ability to source alternatives or internalise functions if a subcontractor failed; full autonomy not proven given hardware suppliers -> opt4 (seal 3).

SOV-5 · Supply Chain Sovereignty 39.6% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowNo public hardware bill-of-materials or component-provenance disclosure beyond '100% SSD'; partial disclosure of physical component origin -> opt2 (seal 1).
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1lowServer hardware is foreign-manufactured (x86 OEM/chips) with no EU manufacturing claim; foreign origin with only partial disclosure -> opt2 (seal 1).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowNo published firmware/embedded-code provenance for the underlying hardware; standard OEM firmware implies at most partial disclosure (seal 4 on all options).
SOV-5.4Origin of software3. Core/essential parts maintained by EU teams72/143SEAL-3mediumNo foreign_core: core platform is open-source (OpenStack, Kubernetes, OpenShift, S3) operated and integrated by the provider, not licensed Google/MS tech; essential parts are maintained/configured in-house, though upstream is global -> opt3 (seal 3).
SOV-5.5Software build/release jurisdiction3. Non-EU control, EU execution72/143SEAL-3lowSoftware built/released from open-source upstreams (non-EU/global control) but deployed and operated within Switzerland; non-EU control with regional execution -> opt3 (seal 3).
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2lowOwns Swiss data centres but depends on a few non-EU vendors (hardware OEMs, GPU/chip suppliers) for critical components; documented but present non-EU dependency in critical services -> opt3 (seal 2).
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowISO 27001/27017/27018 + ISAE 3000 + C5 give an audit basis covering critical suppliers/facilities, though the broader hardware/chip chain is not fully auditable -> critical suppliers auditable, opt3 (seal 2). Normalised to the same ISO-driven supplier-auditability tier as Nine and the other certified peers. (src: https://safeswisscloud.com/en/swiss-secure-compliant/)

SOV-6 · Technology Sovereignty 55.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3highStandards-based platform on OpenStack with extensive APIs, Kubernetes/OpenShift and S3-compatible storage, explicitly positioned against proprietary lock-in -> standards-based and broadly compatible, opt4 (seal 3).
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumUses OpenStack, Kubernetes, S3 and other open standards across its core services as a deliberate policy, covering most core services -> opt4 (seal 3).
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3mediumNo foreign_core: core stack is fully open-source (OpenStack/Kubernetes/OpenShift) but governance of those projects is centralised in external (non-EU) foundations rather than EU-controlled -> open source under centralised governance, opt3 (seal 3).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowArchitecture relies on well-documented open-source components and the provider publishes platform/blog material, giving some public insight into the service architecture -> opt3 (seal 3).
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowOffers Swiss-hosted GPU computing for AI but the HPC/GPU stack is foreign (NVIDIA-class accelerators); EU/Swiss-hosted on a foreign stack -> opt2 (seal 3).

SOV-7 · Security & Compliance Sovereignty 53.7% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumHolds ISO 27001/27017/27018 plus German BSI C5 (Cloud Computing Compliance Criteria Catalogue) per its own compliance page. Per key, BSI C5 is a high-assurance national cloud certification mapping to EAL3 -> opt4 (seal 3). Corrects the prior opt1 which ignored the held C5 (key applied uniformly with the other C5 holder, Exoscale). (src: https://safeswisscloud.com/en/swiss-secure-compliant/)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4highDocumented GDPR, Swiss DPA, FINMA, BAFIN, DORA and NIS2 alignment with annual ISO 27001 audits since 2015; broad partial-to-strong compliance to most relevant EU regulations (seal 4 on all options).
SOV-7.3EU-based SOC & incident handling3. Primary SOC in EU, escalations non-EU72/143SEAL-1lowSecurity operations and incident handling run from Switzerland; from the EU framework's view a non-EU primary SOC, mapped to primary-SOC-with-non-EU-escalation -> opt3 (seal 1).
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1lowISO-certified monitoring with customer reporting and a management portal, but not advertised as full direct customer access with logs guaranteed in the EU -> basic monitoring portal, opt3 (seal 1).
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2mediumStates compliance with GDPR and NIS2 incident-disclosure obligations; moderate, GDPR/NIS2-aligned disclosure -> opt3 (seal 2).
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowOperates its own open-source platform, giving moderate maintenance autonomy with change-management/testing windows; not vendor-locked patch schedules -> opt3 (seal 4).
SOV-7.7Auditability2. Limited independent access36/143SEAL-1lowNo audit_rights: independent assurance exists via ISO 27001 and ISAE 3000 Type 2 audits, but full independent audit by any entity is not offered -> limited independent access, opt2 (seal 1).

SOV-8 · Environmental Sustainability 56.3% · SEAL-1 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowHosts in modern Interxion/Digital Realty Swiss data centres that typically run efficient PUE with sustainability roadmaps; no published figure, so PUE<1.5+roadmap is the reasonable estimate -> opt3 (seal 4). Consistent with the other colo-tenant peers. (src: https://safeswisscloud.com/en/cloud-computing/)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowOperates in professionally managed colocation facilities with standard hardware lifecycle practices, but no detailed published circular-economy program -> documented program, opt3 (seal 3).
SOV-8.3Environmental impact reporting2. Basic reporting63/250SEAL-1lowPublishes sustainability claims (100% renewable, TUV SUD CMS 89) but no full annual environmental report with detailed methodology -> basic reporting, opt2 (seal 1).
SOV-8.4Energy supplies5. Only green EU energy supplies250/250SEAL-4highData centres have run on 100% renewable electricity (water and wind) for over ten years, TUV SUD CMS 89 certified in 2024; green renewable energy supplies (seal 4 on all options). (src: https://safeswisscloud.com/en/swiss-secure-compliant/)