🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Safespring

Sweden · IaaS/PaaS · https://www.safespring.com

Sovereignty score78.0%
Global (unweighted)77.8%
Overall SEAL
SEAL-1 Jurisdictional Sovereignty
SOV-1 Strategic Sovereignty85.5SEAL-4
SOV-2 Legal & Jurisdictional Sovereignty95.8SEAL-4
SOV-3 Data & AI Sovereignty80.0SEAL-1
SOV-4 Operational Sovereignty83.2SEAL-3
SOV-5 Supply Chain Sovereignty53.7SEAL-2
SOV-6 Technology Sovereignty75.0SEAL-3
SOV-7 Security & Compliance Sovereignty67.8SEAL-1
SOV-8 Environmental Sustainability81.3SEAL-2

SOV-1 · Strategic Sovereignty 85.5% · SEAL-4 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4highSafespring AB is 100% Swedish, owned by employees and board; HQ in Solna, Sweden. Entirely within the EU. (src: https://www.safespring.com/blogg/2025/2025-11-the-eu-just-defined-sovereign-cloud-here-is-our-score/)
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4highEmployee/board ownership with no external or non-EU capital makes takeover/transfer to a non-EU sovereign entity very unlikely.
SOV-1.3Control over roadmap4. Full influence of EU actors125/125SEAL-4mediumIndependent Swedish company controlling its own OpenStack-based roadmap; as an EU actor it has full influence over its product direction.
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4highNo non-European capital dependencies; entirely EU-based (Swedish employee) funding per self-assessment and ownership facts.
SOV-1.5EU economic contribution5. Fully in the EU125/125SEAL-4highAll operations, data centers, staff and revenue are in Sweden/Norway (EU/EEA); economic contribution fully in the EU.
SOV-1.6Participation in EU strategic programs3. Active participant in strategic projects63/125SEAL-4mediumActive participant in EU research/education cloud programs (OCRE 2024 via GEANT, EOSC) but not a named participant in IPCEI-CIS or Gaia-X.
SOV-1.7Alignment with EU industrial strategies2. Existing action plan42/125SEAL-4lowOpen-source, sovereignty-focused positioning aligns with EU industrial strategy and the company published a CSF self-assessment, but no formal governance/measured-achievement program is evidenced.
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4mediumown_stack: vertically integrated EU provider running its own OpenStack/Ceph on owned EU/EEA infra with documented continuity; foreign chips are residual hardware only -> SOV-1.8 opt5 (full autonomy and continuity).

SOV-2 · Legal & Jurisdictional Sovereignty 95.8% · SEAL-4 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highOnly Swedish and EU law governs contracts, services and operations; no exposure to legal systems outside the EU/EEA. (src: https://www.safespring.com/blogg/2025/2025-11-the-eu-just-defined-sovereign-cloud-here-is-our-score/)
SOV-2.2Extraterritorial laws exposure5. Verified legal immunity, non-EU laws unenforceable167/167SEAL-4mediumimmunity rule (a): pure-EU entity (Safespring AB), no non-EU parent/subsidiary/operational nexus a foreign authority could compel; non-EU court orders invalid -> SOV-2.2 opt5 (verified legal immunity).
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4highNo foreign_parent: not subject to US CLOUD Act/FISA/PRC law; pure-EU entity commits to reject any non-EU compelled access -> SOV-2.3 opt5 (requests always rejected). (src: https://www.safespring.com/blogg/2025/2025-11-the-eu-just-defined-sovereign-cloud-here-is-our-score/)
SOV-2.4Export control restrictions5. Part of offer shielded from restrictions towards EU MSs/intl orgs167/167SEAL-4mediumSwedish provider with EU/EEA-only operations and no non-EU control point; offer is shielded from export-control restrictions toward EU MSs and international orgs.
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4mediumCore platform IP (their OpenStack/Ceph integration, automation, operational tooling) is developed in Sweden; relies on global open-source upstreams so not fully EU-origin.
SOV-2.6IP holder jurisdiction5. Fully under EU law167/167SEAL-4mediumSafespring's own IP and the company holding it are fully under Swedish/EU law.

SOV-3 · Data & AI Sovereignty 80.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys5. Customer exclusive control - provider cannot read data200/200SEAL-4highCustomers can use their own encryption with keys only they hold; Safespring states it does not see, log or use customer data, so it cannot read the data. (src: https://www.safespring.com/blogg/2025/2025-11-the-eu-just-defined-sovereign-cloud-here-is-our-score/)
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3mediumProvides customer-controlled logging/visibility and audit access; not evidenced as real-time independent auditability across all flows.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowStandard cloud deletion per policy; no published independent proof-of-erasure mechanism found.
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4higheu_exclusive: data stored and processed exclusively in Sweden/Norway (EU/EEA), contractually no third-country fallback -> SOV-3.4 opt5 (exclusively EU). (src: https://www.safespring.com/blogg/2025/2025-11-the-eu-just-defined-sovereign-cloud-here-is-our-score/)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3lowEU-led AI on EU-controlled open-source infra with foreign accelerators (no EU-origin chips) -> SOV-3.5 opt4 (EU-led AI, foreign accelerators).

SOV-4 · Operational Sovereignty 83.2% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability5. Already deployed on sovereign infrastructure167/167SEAL-4highOpen OpenStack/Ceph/S3-compatible APIs and the platform can be deployed on-premise/at customer sites; effectively already sovereign infrastructure with strong portability.
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4higheu_ops: entire stack from hardware to Kubernetes operated by Safespring's own EU/EEA (Swedish/Norwegian) team -> SOV-4.2 opt5 (fully EU-based team).
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumAll staff are stated to be EU/EES citizens working in Sweden/Norway; no evidence of formal security clearances for the full team.
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3mediumSupport delivered by the Nordic (Sweden/Norway) team; all support staff in EU/EEA, no evidence of clearances.
SOV-4.5Documentation & knowledge transfer4. EU-only primary repositories125/167SEAL-4mediumDocumentation and knowledge held within the EU/EEA Nordic operation; no global/non-EU exposure indicated.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3mediumOpen-source stack on commodity hardware lets Safespring source alternatives or internalise functions if a non-EU supplier is cut off; hardware vendors are foreign.

SOV-5 · Supply Chain Sovereignty 53.7% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)3. Transparent with exceptions72/143SEAL-3mediumSelf-assessment discloses server hardware uses Chinese, Korean and American components; provenance transparent but with non-EU exceptions.
SOV-5.2Manufacturing location3. Mixed sourcing, EU audit rights72/143SEAL-3mediumHardware is of foreign origin/design but deployed and operated by EU teams in EU/EEA data centers with audit rights; mixed sourcing.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowServer/firmware embedded code originates from foreign hardware vendors with only partial disclosure; not EU-certified provenance.
SOV-5.4Origin of software4. Large majority maintained by EU teams107/143SEAL-3mediumNo foreign_core: core platform is open-source OpenStack/Ceph maintained/integrated by Safespring's EU team (not licensed Google/MS/AWS) -> large majority maintained by EU teams -> SOV-5.4 opt4 (seal 3).
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3mediumBuild/release and deployment of their platform is controlled and executed by the EU-based team.
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2mediumFew critical non-EU dependencies remain (server hardware vendors, chips) and are documented in their self-assessment.
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowCritical suppliers (hardware, data center operators) are identifiable/auditable, but full end-to-end supplier auditability is not evidenced.

SOV-6 · Technology Sovereignty 75.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces5. Open-by-default with portability200/200SEAL-4highOpen-by-default OpenStack/Ceph with S3-compatible and standard APIs; portable and deployable at customer sites.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3highBuilt on open standards (OpenStack APIs, S3, Kubernetes) across core services as a deliberate policy.
SOV-6.3Open source availability5. Fully open-source, independent/EU governance200/200SEAL-4highServices based exclusively on open-source software (OpenStack, Ceph) with independent/community governance; Safespring is an OpenInfra supporting member.
SOV-6.4Service architecture transparency4. Large corpus of public insight150/200SEAL-3mediumOpen-source architecture is publicly documented and transparent; large corpus of public insight via OpenStack/Ceph and Safespring docs.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowAny HPC/compute is EU-hosted on a foreign hardware/accelerator stack; no EU-designed processors.

SOV-7 · Security & Compliance Sovereignty 67.8% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)2. EAL136/143SEAL-1mediumCerts held: FR2000 + ISO 27001 (forthcoming); no SecNumCloud/EUCS-High/C5/ENS-High/EAL product cert. Key: ISO 27001 only -> opt2 (EAL1, seal 1). This is the gating cap -> overall SEAL-1. (src: https://www.safespring.com/blogg/2025/2025-11-the-eu-just-defined-sovereign-cloud-here-is-our-score/)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumCompliant with GDPR and NIS2 with transparent audit access; FR2000 and ISO 27001 listed, but not all (e.g., DORA) independently audited as fully compliant.
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3mediumSecurity operations and incident handling run by the in-house EU/EEA Nordic team; no evidence of formal ENISA/CSIRT threat-intel sharing.
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3mediumCustomers get direct access to monitoring/logs stored in Sweden/Norway (EU/EEA); not evidenced as immutable tamper-proof.
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2mediumIncident disclosure aligned with GDPR/NIS2 obligations; no evidence of full real-time CSIRT sharing with SLAs.
SOV-7.6Maintenance autonomy4. High autonomy (deploy independently, no checks)107/143SEAL-4mediumOperating its own open-source stack, Safespring can deploy patches/maintenance independently on its own schedule with high autonomy.
SOV-7.7Auditability5. Full independent audit by any entity143/143SEAL-4mediumaudit_rights: customers can audit datacenters, operations and compliance; sovereign-offer terms imply full audit by the contracting authority and independent EU bodies -> SOV-7.7 opt5 (full independent audit). (src: https://www.safespring.com/blogg/2025/2025-11-the-eu-just-defined-sovereign-cloud-here-is-our-score/)

SOV-8 · Environmental Sustainability 81.3% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)5. PUE < 1.2, EU verified250/250SEAL-4highData center designed for >90% efficiency with PUE of 1.1, below the EU-verifiable 1.2 threshold. (src: https://www.safespring.com/blogg/2025/2025-11-the-eu-just-defined-sovereign-cloud-here-is-our-score/)
SOV-8.2Hardware reuse & recycling4. Circular economy, EU-aligned188/250SEAL-4mediumResponsible hardware recycling and reuse aligned with circular-economy practices per the environmental self-assessment.
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2lowEnvironmental performance reported (PUE, renewables, heat reuse) but no evidence of EU-audited reporting; treated as annual reporting.
SOV-8.4Energy supplies5. Only green EU energy supplies250/250SEAL-4high100% renewable electricity: Oslo on hydropower, Stockholm Norr on green energy since 2012 with heat recovery to district heating; only green EU/EEA energy. (src: https://www.safespring.com/blogg/2025/2025-11-the-eu-just-defined-sovereign-cloud-here-is-our-score/)