🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

SysEleven

Germany · IaaS/PaaS · https://www.syseleven.de

Sovereignty score81.1%
Global (unweighted)80.1%
Overall SEAL
SEAL-3 Digital Resilience
SOV-1 Strategic Sovereignty88.5SEAL-3
SOV-2 Legal & Jurisdictional Sovereignty95.8SEAL-4
SOV-3 Data & AI Sovereignty80.0SEAL-3
SOV-4 Operational Sovereignty83.2SEAL-3
SOV-5 Supply Chain Sovereignty60.7SEAL-3
SOV-6 Technology Sovereignty75.0SEAL-3
SOV-7 Security & Compliance Sovereignty82.0SEAL-3
SOV-8 Environmental Sustainability75.1SEAL-3

SOV-1 · Strategic Sovereignty 88.5% · SEAL-3 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity (SysEleven GmbH Berlin, subsidiary of secunet Security Networks AG -> Giesecke+Devrient, all German) -> entity control entirely within the EU -> opt4. (src: https://www.secunet.com/en/about-us/press/article/compliance-fuer-souveraene-cloud-dienste-syseleven-und-secunet-jetzt-mit-it-grundschutz-iso-27001-und-c5)
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4highParent secunet is 75% owned by Germany's Giesecke+Devrient and is the German federal government's leading IT-security partner; takeover by a non-EU sovereign entity is very unlikely given its national-security role.
SOV-1.3Control over roadmap3. Governance bodies exist with EU actors participation83/125SEAL-3mediumOpenStack/SCS-based stack with active community and Gaia-X governance participation; EU actors can meaningfully influence the roadmap via governance bodies -> opt3.
SOV-1.4Financial independence from non-EU capital5. Entirely EU-based funding125/125SEAL-4highFunded entirely via its German parent secunet/Giesecke+Devrient; no reliance on non-EU capital.
SOV-1.5EU economic contribution5. Fully in the EU125/125SEAL-4highAll operations, staff (~170), and data centers are in Germany serving the DACH market; economic contribution is fully in the EU.
SOV-1.6Participation in EU strategic programs4. Strong participation94/125SEAL-4highDay-1 Gaia-X member, SCS-certified, and provider of sovereign cloud for German critical infrastructure (DFS air traffic control); strong participation in EU/German strategic programs.
SOV-1.7Alignment with EU industrial strategies3. Measured achievement and dedicated governance83/125SEAL-4mediumClear digital-sovereignty strategy with measured achievement (certification triad, SCS, sovereign cloud deployments) and dedicated governance via secunet -> opt3.
SOV-1.8Resilience to cut-off5. Full autonomy and continuity125/125SEAL-4mediumown_stack (open-source OpenStack/Kubernetes/SCS on owned German data centers; foreign chips are residual hardware only) + documented portability/continuity -> full autonomy and continuity -> opt5 (judgment-call lever per key).

SOV-2 · Legal & Jurisdictional Sovereignty 95.8% · SEAL-4 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highGerman GmbH with entirely German/EU operations and ownership; contract under EU/EEA member-state law only -> opt3. (src: https://www.syseleven.de/en/press-releases/syseleven-and-secunet-now-with-it-grundschutz-iso-27001-and-c5/)
SOV-2.2Extraterritorial laws exposure5. Verified legal immunity, non-EU laws unenforceable167/167SEAL-4mediumimmunity gate (a): pure-EU entity, no non-EU parent/subsidiary/operational nexus a foreign authority could compel -> verified legal immunity -> opt5. (src: https://www.syseleven.de/en/press-releases/syseleven-and-secunet-now-with-it-grundschutz-iso-27001-and-c5/)
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumNo foreign_parent, immunity holds: not subject to US CLOUD Act/FISA/PRC law; requests without an EU legal basis are rejected -> opt5. (src: https://www.syseleven.de/en/press-releases/syseleven-and-secunet-now-with-it-grundschutz-iso-27001-and-c5/)
SOV-2.4Export control restrictions5. Part of offer shielded from restrictions towards EU MSs/intl orgs167/167SEAL-4mediumGerman-owned, EU-only revenue and operations; the sovereign offer is shielded from export-control restrictions targeting EU MSs and international orgs -> opt5.
SOV-2.5Origin of IP4. Mostly within the EU125/167SEAL-4mediumCore platform IP (MetaKube, SysEleven Stack integration) is developed in Germany on open-source OpenStack/Kubernetes; bulk of differentiating IP originates within the EU -> opt4.
SOV-2.6IP holder jurisdiction5. Fully under EU law167/167SEAL-4highThe IP-holding entity (SysEleven GmbH) is fully under German/EU law -> opt5.

SOV-3 · Data & AI Sovereignty 80.0% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys4. Customer primary control but provider can read data150/200SEAL-3lowCustomer-managed encryption keys give primary control, but standard IaaS allows provider-side data access absent confidential computing; no documented zero-access guarantee -> opt4.
SOV-3.2Transparent data flows & access logs4. Full customer-controlled visibility, not real-time150/200SEAL-3lowOpenStack/MetaKube and C5 controls provide full customer-controlled log visibility, but real-time independent auditability of all data flows is not explicitly documented -> opt4.
SOV-3.3Secure deletion & proof of erasure4. Deletion technically verified with access logs150/200SEAL-3mediumC5 (PI-03 secure deletion) + IT-Grundschutz + ISO 27001 mandate technical secure-deletion procedures evidenced with access logs as part of the audited sovereign offer -> deletion technically verified with logs -> opt4.
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4higheu_exclusive: all solutions consist of open-source components hosted exclusively in German data centers (Berlin, Frankfurt, Hamburg, Dusseldorf), no third-country fallback -> opt5. (src: https://www.syseleven.de/en/press-releases/syseleven-and-secunet-now-with-it-grundschutz-iso-27001-and-c5/)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3mediumAI/ML offered as open-source GPU compute (customers run their own auditable models); EU-led AI on foreign (NVIDIA) accelerators -> opt4.

SOV-4 · Operational Sovereignty 83.2% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability5. Already deployed on sovereign infrastructure167/167SEAL-4highBuilt on open-source OpenStack and CNCF Kubernetes with SCS certification enabling migration to/from other SCS providers; already deployed on sovereign infrastructure -> opt5.
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4mediumeu_ops: entire stack operated by SysEleven's German team in German data centers; no critical operations delivered by non-EU teams -> opt5.
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumBerlin-based company with ~170 staff in Germany; all skills EU-based, formal clearance of all staff not documented -> opt4.
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3mediumGerman company serving DACH with German-language support; all support staff EU-based, published clearance of all staff not confirmed -> opt4.
SOV-4.5Documentation & knowledge transfer4. EU-only primary repositories125/167SEAL-4lowDocumentation maintained in-house in Germany (German/English docs portal); EU-only primary repositories -> opt4.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3mediumOpen-source stack and owned data centers let SysEleven source alternative subcontractors or internalise functions; subcontractors predominantly EU-based -> opt4.

SOV-5 · Supply Chain Sovereignty 60.7% · SEAL-3 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)3. Transparent with exceptions72/143SEAL-3lowStandard server hardware of international origin; transparency exists for the open-source stack but physical component provenance is disclosed only with exceptions -> opt3.
SOV-5.2Manufacturing location3. Mixed sourcing, EU audit rights72/143SEAL-3lowServers/chips foreign-manufactured (x86/NVIDIA) but assembled and operated under EU audit rights (C5/ISO scope) in German data centers; mixed sourcing -> opt3.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/microcode in commodity hardware (BIOS, NICs, GPUs) is foreign and only partially disclosed -> opt2 (all options seal 4).
SOV-5.4Origin of software4. Large majority maintained by EU teams107/143SEAL-3mediumNo foreign_core: software stack is open-source (OpenStack, Kubernetes) with the large majority of integration/operation (MetaKube, SysEleven Stack) maintained by SysEleven's EU team -> opt4.
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3mediumBuild/release of platform components controlled and executed in Germany; EU control and EU execution, formal EU policy gates not documented -> opt4.
SOV-5.6Single point of dependency4. Few non-EU in non-critical services, documented107/143SEAL-3lowConsistency with the own-stack German cohort (STACKIT anchor): the only non-EU dependency is substitutable commodity silicon/GPUs as non-critical hardware inputs; the EU-maintained open-source software and German DCs carry no non-EU vendor lock-in -> opt4 (few non-EU in non-critical, documented). (src: https://www.syseleven.de/en/press-releases/syseleven-and-secunet-now-with-it-grundschutz-iso-27001-and-c5/)
SOV-5.7Supply chain transparency4. Most suppliers auditable107/143SEAL-3lowConsistency with the own-stack German cohort: running its own German DCs under the C5 + IT-Grundschutz + ISO 27001 triad, most suppliers are auditable beyond just the critical ones -> opt4 (most suppliers auditable). (src: https://www.syseleven.de/en/press-releases/syseleven-and-secunet-now-with-it-grundschutz-iso-27001-and-c5/)

SOV-6 · Technology Sovereignty 75.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces5. Open-by-default with portability200/200SEAL-4highOpen-by-default OpenStack and CNCF Kubernetes APIs with SCS-certified portability -> opt5.
SOV-6.2Open standards compliance5. Policy for all core services200/200SEAL-4highCore services built on open standards (OpenStack APIs, Kubernetes/CNCF, S3-compatible object storage) across the platform -> opt5.
SOV-6.3Open source availability4. Open source, significant EU contributions, restricted governance150/200SEAL-4highNo foreign_core: stack is 100% open-source with significant EU contributions and SCS/Gaia-X participation, though MetaKube product governance remains company-led -> opt4.
SOV-6.4Service architecture transparency4. Large corpus of public insight150/200SEAL-3mediumLarge public documentation corpus plus open-source codebase gives substantial public insight into the architecture -> opt4.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowGPU/HPC-class compute is EU-hosted in German data centers but runs on a foreign (NVIDIA/x86) hardware and accelerator stack -> opt2 (EU-hosted, foreign stack; seal 3).

SOV-7 · Security & Compliance Sovereignty 82.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)4. EAL3107/143SEAL-3mediumcerts: holds the full triad BSI C5 + BSI IT-Grundschutz (ISO 27001 based on IT baseline protection) + ISO 27001/27017/27018 (one of only two German sovereign providers with the complete triad); maps to high-assurance EU cloud cert / EAL3-equivalent per key -> opt4 (EAL3). (src: https://www.syseleven.de/en/press-releases/syseleven-and-secunet-now-with-it-grundschutz-iso-27001-and-c5/)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)5. Fully compliant to all, independently audited143/143SEAL-4highGDPR-aligned with the full independently audited certification triad (BSI IT-Grundschutz, BSI C5, ISO 27001/27017/27018), supporting NIS2/DORA obligations -> opt5.
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3mediumBacked by secunet (Germany's leading security firm); security operations and incident handling run by German/EU teams with German threat intel; explicit ENISA CSIRT sharing not documented -> opt4.
SOV-7.4Control over security monitoring/logging4. Full direct access, logs stored in EU107/143SEAL-3lowCustomers get full direct access to monitoring/logging via the OpenStack/Kubernetes platform with logs stored in German data centers; tamper-proof immutability not explicitly published -> opt4.
SOV-7.5Disclosure of incidents4. Partial compliance, monitored flow, SLAs107/143SEAL-3mediumC5/ISO and GDPR/NIS2 obligations drive monitored incident-disclosure flows with SLAs; full real-time CSIRT sharing not documented -> opt4.
SOV-7.6Maintenance autonomy4. High autonomy (deploy independently, no checks)107/143SEAL-4mediumAs operator of its own open-source stack, SysEleven deploys patches independently without dependence on a foreign vendor's schedule -> opt4.
SOV-7.7Auditability5. Full independent audit by any entity143/143SEAL-4mediumaudit_rights: open-source stack plus C5/ISO/IT-Grundschutz audits and sovereign-offer/KRITIS customer audit provisions enable full independent auditability -> opt5. (src: https://www.syseleven.de/en/press-releases/syseleven-and-secunet-now-with-it-grundschutz-iso-27001-and-c5/)

SOV-8 · Environmental Sustainability 75.1% · SEAL-3 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)4. PUE < 1.3188/250SEAL-4highSysEleven publishes a PUE below 1.3 for its German data centers -> opt4.
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowModular, resource-efficient data-center design with documented circular/sustainability practices, but no published EU-certified lifecycle program -> opt3.
SOV-8.3Environmental impact reporting4. Detailed EU methodology188/250SEAL-3lowConsistency with the German cohort: backed by the Giesecke+Devrient/secunet group, sustainability is reported under EU methodology (climate-neutral DCs, green electricity, cooling efficiency) at detailed-methodology level -> opt4 (detailed EU methodology).
SOV-8.4Energy supplies5. Only green EU energy supplies250/250SEAL-4highData centers operated with 100% green electricity from the German/EU grid; only green EU energy supplies -> opt5.