🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Vercel

United States · PaaS · https://vercel.com

Sovereignty score26.4%
Global (unweighted)26.9%
Overall SEAL
SEAL-0 No Sovereignty
SOV-1 Strategic Sovereignty19.8SEAL-0
SOV-2 Legal & Jurisdictional Sovereignty12.6SEAL-1
SOV-3 Data & AI Sovereignty30.0SEAL-0
SOV-4 Operational Sovereignty12.6SEAL-0
SOV-5 Supply Chain Sovereignty7.2SEAL-1
SOV-6 Technology Sovereignty50.0SEAL-0
SOV-7 Security & Compliance Sovereignty39.5SEAL-1
SOV-8 Environmental Sustainability43.8SEAL-1

SOV-1 · Strategic Sovereignty 19.8% · SEAL-0 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control1. Entirely outside the EU0/125SEAL-1highnon-EU HQ (Vercel Inc., California; US company) -> SOV-1.1 opt1; no EU entity exercises control (src: https://vercel.com/legal/terms).
SOV-1.2Change of control risk5. Very unlikely125/125SEAL-4mediumAlready US-owned/controlled, so a transfer FROM EU TO a non-EU entity is not applicable; 'very unlikely' fits (all-seal-4 factor, choice retained).
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2mediumforeign-set roadmap (US leadership) -> SOV-1.3 opt2; EU customers influence only via public feedback channels, no EU governance body.
SOV-1.4Financial independence from non-EU capital1. Almost entirely relying on non-EU funding0/125SEAL-4highFunding (~$863M) overwhelmingly US/global VC (Accel, CRV, Tiger Global, GV, Khosla, General Catalyst); no EU capital control (all-seal-4 factor).
SOV-1.5EU economic contribution1. Minimal0/125SEAL-4mediumR&D, headcount and economic activity concentrated in the US; EU contribution minimal (all-seal-4 factor).
SOV-1.6Participation in EU strategic programs1. No clear participation0/125SEAL-4mediumNo participation in EU strategic programs (Gaia-X, IPCEI-CIS) (all-seal-4 factor).
SOV-1.7Alignment with EU industrial strategies1. No evidence exists0/125SEAL-4mediumNo action plan/governance aligned with EU industrial/sovereignty strategies; US commercial PaaS (all-seal-4 factor).
SOV-1.8Resilience to cut-off2. Service would stop, with delay for customer reaction31/125SEAL-0mediumno own_stack: PaaS on non-EU hyperscalers (AWS/Azure/GCP) whose withdrawal halts the service -> SOV-1.8 opt2 (seal 0); customers get only a delay to migrate.

SOV-2 · Legal & Jurisdictional Sovereignty 12.6% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction1. Non-EU only0/167SEAL-1highContract under US (Delaware/California) law only -> SOV-2.1 opt1 (non-EU only, seal 1) (src: https://vercel.com/legal/terms).
SOV-2.2Extraterritorial laws exposure2. Mitigation clauses, exposure remains42/167SEAL-1highno immunity: US company fully exposed to CLOUD Act/FISA 702; DPA/SCC mitigation clauses but residual exposure remains -> SOV-2.2 opt2 (seal 1) (src: https://vercel.com/legal/dpa).
SOV-2.3Data access pathways for non-EU authorities2. Can compel access without notification, specific cases42/167SEAL-1highconsistency (cluster norm 2.3=opt2): foreign US parent under CLOUD Act/FISA can compel access (incl. EU-region data, Schrems II) without notification in specific national-security cases (gag orders) -> opt2 (seal 1); caps SEAL at 1.
SOV-2.4Export control restrictions2. Restrictions towards EU citizens or international orgs42/167SEAL-1lowconsistency (cluster norm 2.4=opt2): subject to US export controls (EAR/OFAC), no EU-MS shielding and no >50% EU revenue dominance -> opt2 (seal 1).
SOV-2.5Origin of IP1. Entirely outside the EU0/167SEAL-4highCore IP (Vercel platform, Next.js, Turbopack, AI SDK) created and owned by US-based Vercel Inc.; entirely outside EU (all-seal-4 factor).
SOV-2.6IP holder jurisdiction1. Non-EU law, single country0/167SEAL-3highIP held by Vercel Inc. under US law, single non-EU country -> SOV-2.6 opt1 (seal 3).

SOV-3 · Data & AI Sovereignty 30.0% · SEAL-0 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys1. Provider only0/200SEAL-0highProvider-managed AES-256 keys, no customer-managed/BYOK -> SOV-3.1 opt1 (provider can decrypt, seal 0).
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2mediumAudit/observability logs and Trust Center exist but data-access logs are vendor-controlled, not real-time customer-auditable -> SOV-3.2 opt3 (seal 2).
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowDeletion follows internal GDPR-aligned policy with no independently verifiable cryptographic erasure proof -> SOV-3.3 opt3 (policy-only, seal 1).
SOV-3.4Data location strictly in EU/EEA2. Partly EU, significant third-country reliance50/200SEAL-0highno eu_exclusive: default region is US (iad1), data runs on US hyperscalers with third-country processing/fallback under SCCs (not EU-default) -> SOV-3.4 opt2 (partly EU, significant third-country reliance, seal 0). US PaaS without EU-exclusivity guarantee (src: https://vercel.com/docs/regions).
SOV-3.5AI services sovereignty2. Mostly non-EU: licensed AI, chip dependency50/200SEAL-2highAI Gateway/AI SDK route to mostly non-EU proprietary models (OpenAI, Anthropic, Google, xAI, Meta) on foreign accelerators -> SOV-3.5 opt2 (seal 2).

SOV-4 · Operational Sovereignty 12.6% · SEAL-0 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumStandard documented export via Git source, CLI and APIs on open frameworks (Next.js) -> SOV-4.1 opt3 (seal 4).
SOV-4.2Ability to operate without foreign dependencies1. Critical ops delivered by non-EU teams0/167SEAL-1highno eu_ops: critical platform ops/SRE run by US-centric global teams on US hyperscaler infra -> SOV-4.2 opt1 (seal 1).
SOV-4.3Skill availability in the EU1. Global team, mainly non-EU0/167SEAL-1mediumEngineering/ops is a global, predominantly US team; EU staffing a minority -> SOV-4.3 opt1 (seal 1).
SOV-4.4Support channels1. Global, majority outside EU0/167SEAL-1mediumSupport delivered globally, majority of staff/coverage outside EU (US-centric follow-the-sun) -> SOV-4.4 opt1 (seal 1).
SOV-4.5Documentation & knowledge transfer1. Global/non-EU exposure0/167SEAL-0mediumDocumentation/knowledge repos are global/US-hosted (platform + GitHub) with no EU-only guarantee -> SOV-4.5 opt1 (global/non-EU exposure, seal 0).
SOV-4.6Subcontractor & supplier jurisdiction2. Service would stop with delay42/167SEAL-2mediumCore subcontractors (AWS/Azure/GCP) are non-EU US hyperscalers; cut-off stops service after a delay, not readily substitutable in place -> SOV-4.6 opt2 (seal 2).

SOV-5 · Supply Chain Sovereignty 7.2% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)1. No disclosure0/143SEAL-1mediumVercel owns no hardware; physical component origin sits with US hyperscalers, undisclosed -> SOV-5.1 opt1 (no disclosure, seal 1).
SOV-5.2Manufacturing location1. Fully foreign, black box0/143SEAL-1mediumUnderlying hardware manufactured by foreign (US/Asian) vendors via hyperscalers; foreign black box -> SOV-5.2 opt1 (seal 1).
SOV-5.3Embedded code/firmware provenance1. No disclosure0/143SEAL-4lowFirmware/embedded-code provenance of underlying hyperscaler hardware undisclosed -> SOV-5.3 opt1 (all-seal-4 factor).
SOV-5.4Origin of software2. Foreign origin, partial disclosure36/143SEAL-2highPlatform software designed/maintained by US-based Vercel (foreign origin); developer-facing stack (Next.js, Turbopack, AI SDK) is open-source MIT giving partial disclosure -> SOV-5.4 opt2 (seal 2).
SOV-5.5Software build/release jurisdiction1. Non-EU control & execution0/143SEAL-1highSoftware build/release controlled and executed by US-based Vercel engineering -> SOV-5.5 opt1 (non-EU control & execution, seal 1).
SOV-5.6Single point of dependency1. Only non-EU vendors/facilities0/143SEAL-1highCritical dependency on non-EU vendors/facilities (AWS/Azure/GCP and Vercel Inc.); no EU vendor on the critical path -> SOV-5.6 opt1 (seal 1).
SOV-5.7Supply chain transparency2. Some suppliers auditable36/143SEAL-1lowSome subprocessors disclosed via Trust Center and SOC 2/ISO audits, but full customer supply-chain auditability is limited -> SOV-5.7 opt2 (seal 1).

SOV-6 · Technology Sovereignty 50.0% · SEAL-0 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumStandards-based, broadly compatible interfaces (Git, HTTP/REST, OpenAI-compatible AI Gateway) on open frameworks -> SOV-6.1 opt4 (seal 3).
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3mediumMost core developer services use open standards (Web/HTTP, React/Next.js, OCI-style builds, open AI SDK) as product policy -> SOV-6.2 opt4 (seal 3).
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3highFlagship software (Next.js, Turbopack, AI SDK) fully open-source MIT but governance centralised within US Vercel; hosting platform proprietary -> SOV-6.3 opt3 (open-source centralised governance, seal 3).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3mediumExtensive public docs, architecture/engineering blogs and open-source code give substantial public insight -> SOV-6.4 opt3 (seal 3).
SOV-6.5HPC sovereignty1. Imported black-box HPC0/200SEAL-0lowNo EU-sovereign HPC; heavy compute/AI acceleration relies on imported black-box hyperscaler/GPU infrastructure -> SOV-6.5 opt1 (imported black-box HPC, seal 0).

SOV-7 · Security & Compliance Sovereignty 39.5% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)3. EAL272/143SEAL-2highcerts: ISO 27001:2022 + SOC 2 Type II (+PCI DSS, HIPAA; no SecNumCloud/EUCS/C5/Common Criteria EAL); per key ISO 27001 + SOC 2 maps to opt3 (EAL2-equiv, seal 2) (src: https://vercel.com/docs/security/compliance).
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4highGDPR-compliant with DPA/SCCs, EU-US DPF, SOC 2 Type II and ISO 27001:2022; partial compliance to most EU regimes, no independently-audited NIS2/DORA -> SOV-7.2 opt4 (all-seal-4 factor).
SOV-7.3EU-based SOC & incident handling1. SOC/IR outside EU0/143SEAL-1lowconsistency (US-centric cluster norm): SecOps/IR run by US-based team, no dedicated EU SOC -> opt1 (SOC outside EU, seal 1).
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1mediumconsistency (cluster norm 7.4=opt3): customers get a logs/observability monitoring portal but Vercel retains primary control and logs are not guaranteed EU-resident/immutable -> opt3 (basic monitoring portal, seal 1).
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2mediumBreach notification aligned with GDPR/contractual SLAs (moderate, not real-time CSIRT) -> SOV-7.5 opt3 (seal 2).
SOV-7.6Maintenance autonomy2. Limited autonomy (vendor schedules)36/143SEAL-1lowManaged PaaS: Vercel schedules/applies platform updates, customers control only their own deployments -> SOV-7.6 opt2 (vendor-scheduled, seal 1).
SOV-7.7Auditability2. Limited independent access36/143SEAL-1mediumno audit_rights: independent auditability limited to attestation reports (SOC 2, ISO) and Trust Center requests; no unrestricted independent audit -> SOV-7.7 opt2 (seal 1).

SOV-8 · Environmental Sustainability 43.8% · SEAL-1 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowRuns on hyperscaler data centers (AWS/Azure/GCP) with PUE typically <1.5 plus roadmaps; Vercel publishes no PUE, inferred from infra -> SOV-8.1 opt3 (seal 4) (src: https://sustainability.aboutamazon.com/products-services/aws-cloud).
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowconsistency (hyperscaler-PaaS cluster norm 8.2=opt3): hardware reuse/recycling handled by the underlying hyperscalers' documented circular-economy programs which Vercel inherits -> opt3 (documented program) (src: https://sustainability.aboutamazon.com/products-services/aws-cloud).
SOV-8.3Environmental impact reporting2. Basic reporting63/250SEAL-1lowOnly basic environmental info, no detailed audited sustainability report of its own; inherits hyperscaler disclosures -> SOV-8.3 opt2 (seal 1).
SOV-8.4Energy supplies3. Mix of EU and non-EU supplies125/250SEAL-4lowEnergy supply follows underlying hyperscaler regions, a mix of EU and non-EU sources, no EU-only guarantee for Vercel's footprint (all-seal-4 factor).