🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Stackscale

Spain · IaaS · https://www.stackscale.com

Sovereignty score62.2%
Global (unweighted)61.8%
Overall SEAL
SEAL-2 Data Sovereignty
SOV-1 Strategic Sovereignty64.7SEAL-2
SOV-2 Legal & Jurisdictional Sovereignty71.0SEAL-2
SOV-3 Data & AI Sovereignty70.0SEAL-2
SOV-4 Operational Sovereignty70.9SEAL-3
SOV-5 Supply Chain Sovereignty50.2SEAL-2
SOV-6 Technology Sovereignty40.0SEAL-2
SOV-7 Security & Compliance Sovereignty71.4SEAL-2
SOV-8 Environmental Sustainability56.3SEAL-2

SOV-1 · Strategic Sovereignty 64.7% · SEAL-2 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity: Spanish company (Madrid), part of Spanish Grupo Aire; legal entity control entirely within the EU -> SOV-1.1 opt4. (src: https://www.stackscale.com/about-us/)
SOV-1.2Change of control risk4. Unlikely takeover/transfer to non-EU sovereign entity94/125SEAL-4mediumOwned by Grupo Aire whose PE backer is Ardian (France, EU); transfer to a non-EU sovereign entity unlikely, though PE-owned assets can be sold -> opt4.
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2lowSmall EU provider; roadmap influence mainly via standard voice-of-customer/account channels, no formal EU governance body documented -> opt2.
SOV-1.4Financial independence from non-EU capital4. Majority of funding is EU-based94/125SEAL-4mediumFunding flows through Grupo Aire, backed by EU private equity (Ardian, France); majority EU-based funding, not entirely (PE structures may include non-EU LPs) -> opt4.
SOV-1.5EU economic contribution5. Fully in the EU125/125SEAL-4highOperations, data centers, staff and revenue concentrated in Spain/Netherlands/Portugal; economic contribution fully in the EU -> opt5. (src: https://www.stackscale.com/data-centers/)
SOV-1.6Participation in EU strategic programs2. Limited participation31/125SEAL-4lowListed in pan-European federated infrastructure (Virtuora), but no named IPCEI-CIS or major EU strategic program participation; limited participation -> opt2.
SOV-1.7Alignment with EU industrial strategies2. Existing action plan42/125SEAL-4lowMarkets itself as EU sovereign infrastructure with renewable-energy positioning (action plan), but no measured achievements or dedicated sovereignty governance published -> opt2.
SOV-1.8Resilience to cut-off4. Ability to source alternatives or internalise key functions94/125SEAL-2mediumown_stack: self-owns its stack on Dell/AMD hardware in EU data centers operated by EU teams; could source alternatives or internalise key functions, but residual non-EU vendor dependency (Dell/AMD/VMware) -> opt4 'ability to source alternatives' (seal 2), not full autonomy.

SOV-2 · Legal & Jurisdictional Sovereignty 71.0% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highSpanish entity within Grupo Aire; services governed exclusively under EU (Spanish/Dutch) law, no non-EU parent jurisdiction -> opt3 (seal 4). (src: https://www.stackscale.com/about-us/)
SOV-2.2Extraterritorial laws exposure4. Legal structures shielding from foreign law125/167SEAL-2mediumimmunity structural-not-certified: fully EU-owned with no US/non-EU parent so structurally shielded from extraterritorial law, but lacks SecNumCloud/EUCS-High verified immunity -> opt4 'legal structures shielding' (seal 2 ceiling), consistent with the Spanish-provider basis. (src: https://www.stackscale.com/about-us/)
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumNo foreign_parent: wholly EU-owned, no non-EU establishment, not subject to US CLOUD Act/FISA/PRC law; only EU legal process applies and requests would be rejected -> opt5 (seal 4).
SOV-2.4Export control restrictions3. Share of revenues >50% in the EU84/167SEAL-2lowEU-based provider with large majority of revenue in the EU; no export-control restrictions toward EU MSs, but no formally shielded offering documented -> opt3 (share of revenues >50% in EU).
SOV-2.5Origin of IP3. Mixed within/outside the EU84/167SEAL-4mediumOwn platform/orchestration developed by EU teams, but core dependencies (VMware virtualization, hardware firmware, OS) are non-EU IP; mixed origin -> opt3.
SOV-2.6IP holder jurisdiction3. Mixed law, some EU84/167SEAL-3lowIP for own software sits under EU law, but underlying licensed platform/hardware IP held under non-EU (mainly US) law; mixed -> opt3.

SOV-3 · Data & AI Sovereignty 70.0% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys3. Shared - provider has override keys100/200SEAL-2lowIaaS/bare-metal/private cloud where customers run their own encryption; provider manages underlying infra and retains administrative access -> shared control with provider override -> opt3.
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowProvides monitoring/access logging consistent with ISO 27001, but logs are vendor-controlled and not independently real-time auditable -> opt3.
SOV-3.3Secure deletion & proof of erasure4. Deletion technically verified with access logs150/200SEAL-3lowENS-High plus ISO 27001/27018 mandate verified media-sanitisation controls with access logging, so deletion is technically verified with logs (uniform sovereign-operator basis, consistent with the cluster) -> opt4. (src: https://www.stackscale.com/about-us/)
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4higheu_exclusive: all compute/storage data centers in EU/EEA (Madrid, Amsterdam, Spain/Portugal); EU-only with no third-country fallback for customer workloads -> opt5 (seal 4). (src: https://www.stackscale.com/data-centers/)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3lowNo in-scope managed AI service (customers self-deploy on bare-metal); per key SOV-3.5 'no in-scope AI service -> opt4 (seal 3)', and consistent with the other Spanish provider with no AI service -> opt4.

SOV-4 · Operational Sovereignty 70.9% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumStandard IaaS/bare-metal with VMware/Proxmox/standard tooling, documented data export, no proprietary lock-in beyond common virtualization -> opt3 (seal 4).
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4higheu_ops: entire stack operated by EU-based teams in Spain and the Netherlands; no critical operations delivered by non-EU teams -> opt5 (seal 4).
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumEngineering/operations staff in Spain (Madrid, Alicante) and Netherlands (Amsterdam); all-EU staff, no documented security-clearance program -> opt4 (seal 3).
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3medium24x7 support delivered from EU offices (Madrid/Amsterdam) by EU staff; no documented security clearances -> opt4 (seal 3).
SOV-4.5Documentation & knowledge transfer3. EU primary with non-EU fallback84/167SEAL-4lowDocumentation/knowledge maintained by EU teams; no published guarantee of EU-only repositories -> EU-primary with possible non-EU fallback -> opt3 (seal 4).
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3mediumSubcontractors are EU colocation (Interxion/Equinix EU sites) and EU network; hardware vendors (Dell) non-EU but replaceable -> ability to source alternatives -> opt4 (seal 3).

SOV-5 · Supply Chain Sovereignty 50.2% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)3. Transparent with exceptions72/143SEAL-3mediumDiscloses use of Dell PowerEdge servers with AMD EPYC processors; as an ISO 27001 / ENS-High certified operator it provides component transparency to customers/auditors with exceptions (uniform sovereign-operator basis, consistent with the cluster) -> transparent with exceptions (opt3).
SOV-5.2Manufacturing location3. Mixed sourcing, EU audit rights72/143SEAL-3mediumServers (Dell) and CPUs (AMD/Intel) are foreign-manufactured but integrated and operated under ISO 27001 / ENS-High audited supply-chain controls (EU audit rights), matching the uniform key for EU sovereign providers -> mixed sourcing, EU audit rights (opt3).
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/BIOS and processor microcode from non-EU vendors (Dell/AMD/Intel); partial provenance disclosure -> opt2 (seal 4 per rubric).
SOV-5.4Origin of software3. Core/essential parts maintained by EU teams72/143SEAL-3lowforeign_core: own orchestration/platform maintained by EU teams, but the core virtualization software (VMware) is licensed non-EU tech; core/essential parts maintained by EU teams atop foreign software -> opt3 (seal 3).
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3lowSoftware/configuration for its own platform controlled and built by EU teams in Spain/Netherlands (EU control & execution); no formal EU policy-gate certification -> opt4 (seal 3).
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2mediumA few non-EU dependencies in critical services (Dell/AMD hardware, VMware virtualization), documented; the rest of supply (DCs, network, ops) is EU -> opt3 (few non-EU critical, seal 2).
SOV-5.7Supply chain transparency3. Critical suppliers auditable72/143SEAL-2lowCritical suppliers are large auditable vendors (Dell, Interxion/Equinix) and ISO-certified facilities; partial supply-chain auditability, not a fully published chain -> opt3 (critical suppliers auditable, seal 2).

SOV-6 · Technology Sovereignty 40.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces3. Mixed (partial openness)100/200SEAL-2mediumIaaS/bare-metal with standard APIs and common virtualization formats offering partial openness/compatibility, not fully open-by-default -> opt3 (seal 2).
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2lowUses standard protocols and virtualization formats (partial core adoption of open standards) without a published open-standards policy across all services -> opt3 (seal 2).
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2lowforeign_core: core platform/orchestration relies on proprietary VMware; customers can run open-source on top but the provider stack itself is not open source -> opt2 (seal 2).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowProvides some public insight into architecture (network design, DC setup, SLAs) via blog/docs, but not a large corpus or customer-contributable platform -> opt3 (seal 3).
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowOffers high-performance bare-metal/GPU in EU data centers but the HPC/compute stack (AMD EPYC, foreign accelerators) is foreign; EU-hosted on a foreign stack -> opt2 (seal 3).

SOV-7 · Security & Compliance Sovereignty 71.4% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumHolds Spanish ENS High plus ISO 27001/27017/27018 and ISO 22301; per key, ENS-High is a high-assurance national cloud certification mapping to EAL3 (opt4), consistent with the other ENS-High Spanish providers. No SecNumCloud/EUCS-High/Common Criteria held -> opt4 (EAL3, seal 3). (src: https://www.stackscale.com/about-us/)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumHolds ISO 27001/27017/27018, ISO 22301 and ENS High, GDPR-compliant EU provider; partial compliance to most relevant EU regimes, NIS2/DORA-specific attestations not published -> opt4.
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3lowSecurity operations and incident handling run by EU-based teams (Spain/Netherlands) on EU infrastructure, full lifecycle by EU teams; no formal ENISA threat-intel sharing documented -> opt4 (seal 3).
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3lowCustomers have direct access to monitoring/logs with EU-hosted logging in its EU DCs (ENS-High mandates security-log access/traceability); immutable tamper-proof logging not explicitly documented -> full direct access, logs stored in EU (opt4), consistent with the cluster.
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2lowEU provider following GDPR/NIS2-aligned breach-notification obligations; moderate compliance without documented real-time CSIRT sharing -> opt3 (seal 2).
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowOperates its own infrastructure and can schedule maintenance/patching with notice and testing as an independent EU operator -> moderate autonomy -> opt3 (seal 4).
SOV-7.7Auditability5. Full independent audit by any entity143/143SEAL-4lowaudit_rights: the ENS-High sovereign offer for Spanish public administration implies tender-grade full audit rights for the contracting authority and independent EU bodies (uniform basis with the cluster's ENS-High/ACN-qualified members) -> full independent audit (opt5). (src: https://www.stackscale.com/about-us/)

SOV-8 · Environmental Sustainability 56.3% · SEAL-2 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowClaims low PUE with free-cooling and efficiency programs in modern EU data centers (Interxion/Equinix), but no specific verified figure published; consistent with PUE <1.5 + roadmap -> opt3 (seal 4). (src: https://www.stackscale.com/data-centers/)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowHolds ISO 14001 environmental-management certification, entailing a documented program covering equipment lifecycle/recycling -> opt3 documented program (seal 3). (src: https://www.stackscale.com/about-us/)
SOV-8.3Environmental impact reporting3. Annual report125/250SEAL-2lowHolds ISO 14001 environmental management (which mandates periodic environmental-performance reporting/review); annual-report-level reporting rather than a fully EU-audited methodology -> annual report (opt3, seal 2). (src: https://www.stackscale.com/about-us/)
SOV-8.4Energy supplies4. Only EU energy supplies (high renewable)188/250SEAL-4mediumEU data centers rely on renewable energy with free cooling; only EU energy supplies with high renewable content, not certified exclusively green -> opt4 (seal 4). (src: https://www.stackscale.com/data-centers/)