🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Scaleway

France · IaaS/PaaS · https://www.scaleway.com

Sovereignty score77.3%
Global (unweighted)77.0%
Overall SEAL
SEAL-3 Digital Resilience
SOV-1 Strategic Sovereignty88.5SEAL-3
SOV-2 Legal & Jurisdictional Sovereignty95.8SEAL-4
SOV-3 Data & AI Sovereignty80.0SEAL-3
SOV-4 Operational Sovereignty79.0SEAL-3
SOV-5 Supply Chain Sovereignty64.2SEAL-3
SOV-6 Technology Sovereignty55.0SEAL-3
SOV-7 Security & Compliance Sovereignty78.4SEAL-3
SOV-8 Environmental Sustainability75.1SEAL-3

SOV-1 · Strategic Sovereignty 88.5% · SEAL-3 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity (French SAS, Paris HQ, 96% owned by French Iliad Group / Xavier Niel, no non-EU parent) -> entity control entirely within the EU, opt4 (src: https://www.scaleway.com/en/security-and-resilience/).
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4mediumControlled by Iliad/Xavier Niel, a French founder-led group committed to European digital sovereignty; non-EU takeover very unlikely (kept per instruction).
SOV-1.3Control over roadmap3. Governance bodies exist with EU actors participation83/125SEAL-3mediumEU-controlled provider with public feature-request channels and EU customer/public-sector governance; EU actors participate but lack full formal control -> opt3.
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4mediumFunded through the French Iliad Group's own capital; financing essentially EU-based with no material non-EU reliance (kept per instruction).
SOV-1.5EU economic contribution5. Fully in the EU125/125SEAL-4highR&D, data centres, employment and revenue concentrated in France/EU within the Iliad Group; economic contribution overwhelmingly EU-based (kept per instruction).
SOV-1.6Participation in EU strategic programs4. Strong participation94/125SEAL-4mediumActive player in EU/French sovereignty initiatives; won the France Health Data Hub migration from Microsoft Azure; strong participation (kept per instruction).
SOV-1.7Alignment with EU industrial strategies3. Measured achievement and dedicated governance83/125SEAL-4mediumDemonstrable alignment with EU industrial/sovereignty strategy via SecNumCloud pursuit, public-sector wins and dedicated sovereign-cloud governance (kept per instruction).
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4mediumown_stack (vertically integrated EU provider running its own EU data centres + internally developed software stack on open source) with a documented continuity/exit plan; residual foreign chips treated as hardware only -> Full autonomy and continuity, opt5 (judgment call 1).

SOV-2 · Legal & Jurisdictional Sovereignty 95.8% · SEAL-4 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highFrench company operating EU-only data centres under French/EU law; service governed exclusively by EU law -> opt3 (src: https://www.scaleway.com/en/security-and-resilience/).
SOV-2.2Extraterritorial laws exposure5. Verified legal immunity, non-EU laws unenforceable167/167SEAL-4lowimmunity flag (a): pure-FR entity with no non-EU parent, subsidiary or operational nexus a foreign authority could compel; whole Scaleway Cloud offer in active SecNumCloud 3.2 qualification -> non-EU laws unenforceable, 'Verified legal immunity', opt5 (low confidence: SecNumCloud not yet awarded) (src: https://www.scaleway.com/en/news/scaleway-begins-the-secnumcloud-qualification-process/).
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumNo foreign_parent: not subject to US CLOUD Act/FISA or PRC law; pure-FR entity (immunity flag a) commits to reject non-EU compelled-access requests, responding only to EU/French legal process -> opt5 (src: https://www.scaleway.com/en/security-and-resilience/).
SOV-2.4Export control restrictions5. Part of offer shielded from restrictions towards EU MSs/intl orgs167/167SEAL-4lowEU-based provider; offer not subject to non-EU export-control regimes affecting EU member states or international organisations -> opt5.
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4mediumCore cloud platform and IP developed in-house by EU teams, integrating open-source; IP origin mostly within the EU -> opt4 (kept per instruction).
SOV-2.6IP holder jurisdiction5. Fully under EU law167/167SEAL-4mediumIP held by the French Scaleway/Iliad entities fully under EU/French law -> opt5.

SOV-3 · Data & AI Sovereignty 80.0% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys4. Customer primary control but provider can read data150/200SEAL-3mediumCustomer-managed encryption and Key Manager give customer primary key control (BYOK), but managed services can still let the provider technically read data -> opt4 (seal 3).
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3lowProvides audit/activity/access logs giving full customer-controlled visibility; independent real-time external auditability not clearly established -> opt4 (seal 3).
SOV-3.3Secure deletion & proof of erasure4. Deletion technically verified with access logs150/200SEAL-3lowDeletion technically verified with access/audit logs under the sovereign offer's SecNumCloud-grade data-lifecycle controls; no fully independent cryptographic proof-of-erasure -> opt4 (seal 3) per key 'technically verified w/ logs'.
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4higheu_exclusive: all data centres in the EU (France, Netherlands, Poland, Italy); data stored and processed exclusively in EU with no third-country fallback -> opt5 (src: https://www.scaleway.com/en/security-and-resilience/).
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3mediumAI/inference EU-operated, hosting open and EU-trained models (e.g. Mixtral trained on its own clusters) under EU jurisdiction, on foreign NVIDIA accelerators -> EU-led AI on foreign accelerators, opt4 (seal 3).

SOV-4 · Operational Sovereignty 79.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability4. Formal migration services available125/167SEAL-4mediumStandards-based APIs, Terraform/OpenTofu provider, Kubernetes (Kapsule) and documented export methods; formal migration support available -> opt4.
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4mediumeu_ops: entire in-house stack operated by EU-based (primarily French) teams, no critical non-EU operating teams -> opt5.
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumEngineering and operations staff EU-based (France); strong EU skill availability, but 100% staff security clearances not documented -> opt4 (seal 3).
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3mediumSupport delivered by EU-based teams in France; clearances for all support staff not specifically documented -> opt4 (seal 3).
SOV-4.5Documentation & knowledge transfer4. EU-only primary repositories125/167SEAL-4lowDocumentation and knowledge bases maintained primarily within the EU by EU teams; no mandated non-EU repositories -> EU-only primary repositories, opt4.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3mediumKey non-EU dependency is hardware/chips (NVIDIA, x86); can source alternatives or internalise, EU-controlled subcontractors dominate -> opt4 (seal 3).

SOV-5 · Supply Chain Sovereignty 64.2% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)3. Transparent with exceptions72/143SEAL-3lowReasonable transparency on infrastructure/components, but underlying servers/chips are foreign-sourced with disclosure exceptions -> transparent with exceptions, opt3 (seal 3).
SOV-5.2Manufacturing location4. Built by EU teams on foreign design107/143SEAL-3lowData centres designed, built and operated by EU teams (notably its own DC5) while underlying hardware design originates abroad -> built by EU teams on foreign design, opt4 (seal 3).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/embedded code in servers, GPUs and network gear comes from foreign vendors (NVIDIA, Intel/AMD); only partial provenance disclosure realistic -> opt2 (seal 4) (kept per instruction).
SOV-5.4Origin of software4. Large majority maintained by EU teams107/143SEAL-3mediumNo foreign_core: control plane and platform software designed and maintained by EU teams using open-source; large majority EU-maintained -> opt4 (seal 3).
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3mediumSoftware controlled and built by EU-based engineering teams in France; EU control and execution, formal policy gates not documented -> opt4 (seal 3).
SOV-5.6Single point of dependency4. Few non-EU in non-critical services, documented107/143SEAL-3lowOnly non-EU dependency is residual hardware (NVIDIA GPUs, x86 CPUs), documented; treated as non-critical-service dependency for a vertically integrated EU provider that runs its own DCs/software and can source alternatives (per key judgment-call-1 'foreign chips as residual hardware only') -> few non-EU in non-critical services, opt4 (seal 3).
SOV-5.7Supply chain transparency4. Most suppliers auditable107/143SEAL-3lowWhole-offer SecNumCloud 3.2 qualification + ISO 27001 supplier-management extend audit obligations to most suppliers, not just the critical few -> most suppliers auditable, opt4 (seal 3).

SOV-6 · Technology Sovereignty 55.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumStandards-based, broadly compatible interfaces (S3-compatible storage, Kubernetes, Terraform provider, open APIs) -> opt4 (seal 3).
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumAdopts open standards (S3 API, Kubernetes, OCI containers, Terraform/OpenTofu) as policy across most core services -> opt4 (seal 3).
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3mediumNo foreign_core: 128+ open-source repositories (SDKs, Terraform provider, tooling) with EU-centralised governance; core platform itself not fully open-sourced -> open source, centralised governance, opt3 (seal 3).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowPublic documentation, architecture references and a trust center giving meaningful public insight, short of customer co-adaptation -> some public insight, opt3 (seal 3).
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3mediumHPC/AI clusters (Jeroboam/Nabuchodonosor, France) EU-hosted but built on foreign NVIDIA DGX H100 stack -> EU-hosted, foreign stack, opt2 (seal 3).

SOV-7 · Security & Compliance Sovereignty 78.4% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3lowHolds ISO 27001:2022 + HDS and is in active SecNumCloud 3.2 qualification (J0 passed Jan 2025) for the whole Scaleway Cloud offer; per key cert->EAL mapping SecNumCloud-grade ~ EAL3 -> opt4 (seal 3). Confidence low: SecNumCloud not yet awarded (src: https://www.scaleway.com/en/security-and-resilience/).
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4highStrong GDPR alignment, ISO 27001:2022, HDS, SecNumCloud in progress; partial-to-strong compliance across GDPR/NIS2/DORA, not yet fully independently audited against all three (kept per instruction).
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3lowSecurity operations and incident response handled by EU-based teams in France with EU threat intel -> entire lifecycle by EU teams, opt4 (seal 3); full ENISA/CSIRT sharing not documented.
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3lowCustomers get full direct access to logs/monitoring (audit logs, Cockpit) stored within the EU; immutable tamper-proof guarantees not clearly published -> opt4 (seal 3).
SOV-7.5Disclosure of incidents4. Partial compliance, monitored flow, SLAs107/143SEAL-3lowIncident disclosure aligns with GDPR/NIS2 with monitored notification flows and SLAs -> partial compliance, monitored flow, SLAs, opt4 (seal 3).
SOV-7.6Maintenance autonomy4. High autonomy (deploy independently, no checks)107/143SEAL-4lowOperator of its own EU stack with high maintenance autonomy; can deploy patches independently on its own schedule -> opt4.
SOV-7.7Auditability5. Full independent audit by any entity143/143SEAL-4lowaudit_rights: sovereign offer + SecNumCloud-grade qualification imply full audit rights for the contracting authority and independent EU bodies -> opt5 (tender-grade commitment, low confidence per key note 4).

SOV-8 · Environmental Sustainability 75.1% · SEAL-3 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)4. PUE < 1.3188/250SEAL-4highAverage fleet PUE 1.38 (2024), flagship DC5 at 1.25, documented efficiency roadmap; best sites well below 1.3 -> opt4 (src: https://www.scaleway.com/en/security-and-resilience/).
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowDocumented hardware lifecycle and circular practices, but no EU-certified circular-economy lifecycle certification -> documented program, opt3 (seal 3).
SOV-8.3Environmental impact reporting4. Detailed EU methodology188/250SEAL-3mediumDetailed environmental footprint reporting and a public footprint calculator with defined methodology; not yet fully EU third-party audited -> detailed EU methodology, opt4 (seal 3).
SOV-8.4Energy supplies5. Only green EU energy supplies250/250SEAL-4highPowered by 100% renewable energy since 2017, mainly EU hydropower; only green EU energy supplies -> opt5 (kept per instruction) (src: https://www.scaleway.com/en/security-and-resilience/).