🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Scalingo

France · PaaS · https://www.scalingo.com

Sovereignty score77.0%
Global (unweighted)75.1%
Overall SEAL
SEAL-3 Digital Resilience
SOV-1 Strategic Sovereignty86.5SEAL-4
SOV-2 Legal & Jurisdictional Sovereignty95.8SEAL-4
SOV-3 Data & AI Sovereignty80.0SEAL-3
SOV-4 Operational Sovereignty83.2SEAL-3
SOV-5 Supply Chain Sovereignty60.7SEAL-3
SOV-6 Technology Sovereignty60.0SEAL-3
SOV-7 Security & Compliance Sovereignty78.4SEAL-3
SOV-8 Environmental Sustainability56.3SEAL-3

SOV-1 · Strategic Sovereignty 86.5% · SEAL-4 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity (French SAS, HQ Strasbourg, no non-EU parent) -> entity control entirely within EU -> opt4 (src: https://scalingo.com/qualification-secnumcloud).
SOV-1.2Change of control risk4. Unlikely takeover/transfer to non-EU sovereign entity94/125SEAL-4mediumIndependent French firm with French/EU investors (BPI, Caisse d'Epargne, BNP Paribas); no non-EU parent, but a small VC-funded company cannot fully exclude a future takeover -> opt4.
SOV-1.3Control over roadmap4. Full influence of EU actors125/125SEAL-4mediumEU-controlled with own R&D: Scalingo builds and controls its own orchestrator and roadmap as an independent French firm -> full EU-actor influence -> opt4.
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4highFunding rounds entirely from French/EU sources (Side Angels, BPI France, Caisse d'Epargne, BNP Paribas); funding entirely EU-based -> opt5.
SOV-1.5EU economic contribution5. Fully in the EU125/125SEAL-4highOperations, employment, taxation and value creation entirely in France/EU -> opt5.
SOV-1.6Participation in EU strategic programs3. Active participant in strategic projects63/125SEAL-4lowActive participant in the French sovereign-cloud ecosystem (SecNumCloud partners) but no documented role in flagship programs (Gaia-X, IPCEI-CIS) -> opt3.
SOV-1.7Alignment with EU industrial strategies3. Measured achievement and dedicated governance83/125SEAL-4mediumMeasured achievement and dedicated governance: explicit sovereignty positioning with a dedicated SecNumCloud-qualification effort and French sovereign infrastructure choice -> opt3.
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4mediumown_stack: EU-maintained orchestrator on EU-sovereign IaaS (its sovereign region runs on 3DS Outscale SecNumCloud osc-secnum-fr1); like the anchor Clever Cloud, no non-EU vendor whose withdrawal halts service, only residual foreign chips, with ability to source alternatives/internalise -> full autonomy & continuity opt5 (src: https://scalingo.com/blog/new-osc-fr1-region).

SOV-2 · Legal & Jurisdictional Sovereignty 95.8% · SEAL-4 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highFrench SAS contracting exclusively under French/EU law with all data and infra in France -> exclusively EU law -> opt3 (src: https://doc.scalingo.com/security/overview/compliance).
SOV-2.2Extraterritorial laws exposure5. Verified legal immunity, non-EU laws unenforceable167/167SEAL-4mediumimmunity: pure-FR entity with no non-EU parent/nexus, and the scoped sovereign offer runs on 3DS Outscale SecNumCloud-qualified IaaS (same pattern as the anchor Clever Cloud on Cloud Temple), so non-EU law is genuinely unenforceable -> verified legal immunity opt5 (src: https://scalingo.com/qualification-secnumcloud).
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumNo foreign_parent: pure-French entity with no US/CN nexus, not subject to CLOUD Act/FISA/PRC compelled access; sovereign-cloud positioning indicates non-EU requests refused -> opt5 (src: https://scalingo.com/qualification-secnumcloud).
SOV-2.4Export control restrictions5. Part of offer shielded from restrictions towards EU MSs/intl orgs167/167SEAL-4lowEU-based provider not subject to non-EU export-control regimes; the French sovereign offer is shielded from restrictions toward EU Member States and international organisations (consistent with the anchor Clever Cloud) -> opt5.
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4mediumCore orchestrator developed in France by the Scalingo team; IP mostly within the EU atop third-party open-source components of varied origin -> opt4.
SOV-2.6IP holder jurisdiction5. Fully under EU law167/167SEAL-4mediumScalingo's own software IP held by the French company under EU law -> fully under EU law -> opt5.

SOV-3 · Data & AI Sovereignty 80.0% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys4. Customer primary control but provider can read data150/200SEAL-3lowScoped SecNumCloud sovereign offer (on 3DS Outscale) provides customer-managed/BYOK encryption keys with customer primary control, consistent with the anchor Clever Cloud; provider can still read data operationally -> opt4 (seal 3).
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3lowSecNumCloud-grade sovereign offer (on 3DS Outscale) gives full customer-controlled visibility of access logs and data flows (audit-mandated), consistent with the anchor Clever Cloud, though not necessarily real-time -> opt4 (seal 3).
SOV-3.3Secure deletion & proof of erasure4. Deletion technically verified with access logs150/200SEAL-3lowSecNumCloud/HDS processes (via the Outscale SecNumCloud region) give deletion technically verified with access logs rather than policy-only, consistent with the anchor Clever Cloud -> opt4 (seal 3) (src: https://scalingo.com/blog/scalingo-iso27001-hds-certifications-next-secnumcloud).
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4higheu_exclusive: all datacenters in France/EU, stated no data transfer outside EU, no third-country fallback -> opt5 (src: https://scalingo.com/datacenters).
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3lowNo in-scope native AI service (only AI-friendly open-source vector DBs); no foreign-AI dependency -> opt4 (seal 3) per key.

SOV-4 · Operational Sovereignty 83.2% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability5. Already deployed on sovereign infrastructure167/167SEAL-4highHeroku-compatible open PaaS already deployed on sovereign French infrastructure with documented export and Git-based deployment -> opt5.
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4mediumeu_ops: entire stack operated by Scalingo's French team on French IaaS -> fully EU-based team -> opt5.
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumSmall French company, engineering/ops staff in France (all-EU staff), no documented security-clearance program -> opt4.
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3mediumHuman support delivered by the French team, EU-based, no documented security clearances -> opt4.
SOV-4.5Documentation & knowledge transfer4. EU-only primary repositories125/167SEAL-4lowDocumentation and engineering knowledge produced and held by the EU team; primary repositories EU-only, consistent with the anchor Clever Cloud -> opt4.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3mediumPrimary subcontractor is French IaaS 3DS Outscale (Dassault); contractual continuity and ability to source alternatives/internalise key functions -> opt4 (seal 3).

SOV-5 · Supply Chain Sovereignty 60.7% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)3. Transparent with exceptions72/143SEAL-3lowHardware sourced through EU-sovereign IaaS partner 3DS Outscale (SecNumCloud), whose component provenance is transparent under audit with exceptions for foreign silicon, consistent with the anchor Clever Cloud -> opt3 (seal 3).
SOV-5.2Manufacturing location3. Mixed sourcing, EU audit rights72/143SEAL-3lowUnderlying hardware is foreign-designed but operated through EU-sovereign partner 3DS Outscale under SecNumCloud audit rights (mixed sourcing, EU audit rights), consistent with the anchor Clever Cloud -> opt3 (seal 3).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/microcode (BIOS, NICs, drives) foreign and proprietary with partial disclosure -> opt2 (seal 4).
SOV-5.4Origin of software4. Large majority maintained by EU teams107/143SEAL-3mediumNo foreign_core: core orchestrator and platform software designed/maintained by the French team atop open-source; large majority EU-maintained -> opt4 (seal 3).
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3mediumSoftware developed and released by the French team under EU control and execution; no documented formal EU policy gates -> opt4.
SOV-5.6Single point of dependency4. Few non-EU in non-critical services, documented107/143SEAL-3mediumCritical services (own software + EU-sovereign Outscale SecNumCloud IaaS) carry no non-EU vendor dependency; remaining non-EU dependency is residual non-critical hardware/chips, documented, consistent with the anchor Clever Cloud -> opt4 (seal 3).
SOV-5.7Supply chain transparency4. Most suppliers auditable107/143SEAL-3lowUnder the SecNumCloud audit regime (via 3DS Outscale) plus ISO 27001, most suppliers are auditable end-to-end, consistent with the anchor Clever Cloud -> opt4 (seal 3) (src: https://scalingo.com/qualification-secnumcloud).

SOV-6 · Technology Sovereignty 60.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces5. Open-by-default with portability200/200SEAL-4highHeroku-compatible buildpack/Git-based open PaaS with standard APIs and documented export; open-by-default with portability -> opt5.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumBuilt around open standards (HTTP, Git, buildpacks, standard DB protocols, S3-compatible storage) across most core services -> opt4.
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3lowHeavily built on open-source and supports open runtimes/DBs, but the core orchestrator is proprietary and vendor-governed -> open source, centralised governance -> opt3 (seal 3).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowSubstantial public documentation/blogs on architecture and sovereignty model -> some public insight -> opt3.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowNo in-scope HPC service -> EU-hosted, no own HPC stack -> opt2 (seal 3) per key (no in-scope HPC).

SOV-7 · Security & Compliance Sovereignty 78.4% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumScoped sovereign offer runs on 3DS Outscale SecNumCloud-qualified IaaS (osc-secnum-fr1), exactly the anchor Clever Cloud pattern; SecNumCloud 3.2 maps to EAL3 per the key -> opt4 (seal 3) (src: https://scalingo.com/qualification-secnumcloud).
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumISO 27001 and HDS certified, EU-resident data, GDPR-aligned; partial compliance to most EU regimes, no full NIS2/DORA independent attestation -> opt4 (src: https://doc.scalingo.com/security/overview/compliance).
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3lowSecurity operations and incident handling run by the French team in the EU with EU threat intel; no documented ENISA/CSIRT sharing -> entire lifecycle by EU teams -> opt4 (seal 3).
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3lowCustomers get full direct access to application logs/monitoring with data stored in the EU under the SecNumCloud region, consistent with the anchor Clever Cloud; tamper-proof immutability not specifically documented -> opt4 (seal 3).
SOV-7.5Disclosure of incidents4. Partial compliance, monitored flow, SLAs107/143SEAL-3lowIncident disclosure under NIS2/DORA with monitored notification flow and SLAs, consistent with the anchor Clever Cloud; not full real-time CSIRT sharing -> opt4 (seal 3).
SOV-7.6Maintenance autonomy4. High autonomy (deploy independently, no checks)107/143SEAL-4mediumManaged PaaS auto-patches OS/databases/stacks and the EU team deploys maintenance independently -> high maintenance autonomy -> opt4.
SOV-7.7Auditability5. Full independent audit by any entity143/143SEAL-4mediumaudit_rights: the scoped SecNumCloud-grade sovereign offer (on 3DS Outscale, same basis as the anchor Clever Cloud on Cloud Temple) implies full audit rights for the contracting authority and independent EU bodies -> full independent audit opt5 (src: https://scalingo.com/qualification-secnumcloud).

SOV-8 · Environmental Sustainability 56.3% · SEAL-3 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowRuns on 3DS Outscale's modern French datacenters targeting efficient PUE around/below 1.5 with roadmaps; Scalingo publishes no own PUE -> opt3 (seal 4) (src: https://scalingo.com/datacenters).
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowHardware lifecycle managed by IaaS partner 3DS Outscale with documented hardware-reuse/recycling practices -> documented program -> opt3 (seal 3).
SOV-8.3Environmental impact reporting4. Detailed EU methodology188/250SEAL-3lowEnvironmental reporting follows EU methodology via the 3DS Outscale SecNumCloud datacenters plus Scalingo's own ISO-framework reporting, consistent with the anchor Clever Cloud -> detailed EU methodology opt4 (seal 3).
SOV-8.4Energy supplies3. Mix of EU and non-EU supplies125/250SEAL-4lowPowered via French/EU grid (largely low-carbon) through Outscale datacenters; treated as mix of EU supplies without a verified fully-green dedicated guarantee -> opt3.