🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Vultr

United States · IaaS · https://www.vultr.com

Sovereignty score32.6%
Global (unweighted)33.2%
Overall SEAL
SEAL-1 Jurisdictional Sovereignty
SOV-1 Strategic Sovereignty23.0SEAL-1
SOV-2 Legal & Jurisdictional Sovereignty25.1SEAL-1
SOV-3 Data & AI Sovereignty45.0SEAL-1
SOV-4 Operational Sovereignty25.1SEAL-1
SOV-5 Supply Chain Sovereignty21.6SEAL-1
SOV-6 Technology Sovereignty45.0SEAL-2
SOV-7 Security & Compliance Sovereignty43.2SEAL-1
SOV-8 Environmental Sustainability37.5SEAL-1

SOV-1 · Strategic Sovereignty 23.0% · SEAL-1 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control1. Entirely outside the EU0/125SEAL-1highforeign_parent (Vultr = The Constant Company, LLC, US-incorporated, West Palm Beach FL); controlling entity entirely outside the EU -> SOV-1.1 opt1. (src: https://www.vultr.com/company/)
SOV-1.2Change of control risk3. Somewhat likely takeover/transfer to non-EU sovereign entity63/125SEAL-4lowTook first outside capital (LuminArx, AMD Ventures) Dec 2024 at $3.5B; venture-backed US firm, realistic acquisition target amid AI-cloud consolidation, any change of control stays non-EU.
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2mediumRoadmap set by US parent and strategic investor AMD; EU customers have only voice-of-the-customer channels, no governance bodies giving EU actors influence -> opt2 (seal 2).
SOV-1.4Financial independence from non-EU capital2. Mostly relying on non-EU funding31/125SEAL-4highDec 2024 raised $333M from US investors LuminArx Capital and AMD Ventures; relies mostly on non-EU funding.
SOV-1.5EU economic contribution2. Some31/125SEAL-4lowUS-HQ global business with some EU data-centre spend/revenue, but HQ, R&D and profits accrue outside the EU -> Some EU contribution.
SOV-1.6Participation in EU strategic programs1. No clear participation0/125SEAL-4mediumNo clear participation in EU strategic programs (Gaia-X, IPCEI-CIS); positioned as a US 'alternative hyperscaler'.
SOV-1.7Alignment with EU industrial strategies1. No evidence exists0/125SEAL-4mediumNo action plan/governance aligning the company with EU industrial strategies; strategy driven by US AI-cloud expansion.
SOV-1.8Resilience to cut-off3. Can continue temporarily per contractual agreement63/125SEAL-2lowNot own_stack (depends on US chip vendors and a US-controlled control plane), but a standard IaaS with documented data-export tooling and contractual terms under which the service could continue temporarily after a cut-off rather than shutting down immediately -> opt3 (seal 2), consistent with US commodity-IaaS peers.

SOV-2 · Legal & Jurisdictional Sovereignty 25.1% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction2. Mixed EU/non-EU84/167SEAL-1highEU customers contract under a GDPR DPA/SCCs while the contracting entity and parent are US (Florida-law ToS); primary jurisdiction is therefore mixed EU/non-EU rather than exclusively EU -> opt2. (src: https://www.vultr.com/legal/eea-gdpr-privacy/)
SOV-2.2Extraterritorial laws exposure2. Mitigation clauses, exposure remains42/167SEAL-1highNo immunity (US company, no SecNumCloud/EUCS-High, no EU trustee structure); DPA/SCC mitigation clauses exist but exposure to US extraterritorial law (CLOUD Act, FISA 702) remains -> opt2.
SOV-2.3Data access pathways for non-EU authorities2. Can compel access without notification, specific cases42/167SEAL-1highforeign_parent: under US CLOUD Act a US provider can be compelled to produce data, with gag provisions in specific cases -> opt2; key caps data-access at seal 1.
SOV-2.4Export control restrictions2. Restrictions towards EU citizens or international orgs42/167SEAL-1lowUS entity subject to US export-control/OFAC regimes that can restrict access for specific sanctioned EU citizens/orgs, but no EU Member State is under restriction and EU revenue is not a >50% majority -> opt2.
SOV-2.5Origin of IP2. Mostly outside the EU42/167SEAL-4mediumProprietary control-plane IP developed by the US company; uses open-source components but core IP originates mostly outside the EU.
SOV-2.6IP holder jurisdiction1. Non-EU law, single country0/167SEAL-3mediumIP held by the single US entity The Constant Company, LLC under non-EU (US) law, single country -> opt1.

SOV-3 · Data & AI Sovereignty 45.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys2. Primarily provider, not exclusively50/200SEAL-1mediumStandard IaaS; provider manages platform encryption and could access guest storage; customer can self-manage in-guest keys but control is primarily provider's -> opt2.
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowVendor-controlled activity/audit logs and monitoring portal exist but are not real-time independently auditable oversight of all provider access -> opt3.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowDeletion follows internal policy with platform wiping; no published independently verifiable proof-of-erasure for customers -> opt3 (policy-only).
SOV-3.4Data location strictly in EU/EEA4. EU by default, tightly controlled exceptions150/200SEAL-1mediumNo eu_exclusive sovereign offer in the default IaaS, but data uploaded to a chosen EU region (Amsterdam, Frankfurt, Paris, Madrid, Milan, Stockholm, Warsaw) stays in that region: EU-by-default with tightly controlled exceptions rather than a contractual no-third-country guarantee -> opt4 (seal 1). (src: https://www.vultr.com/features/datacenter-regions/)
SOV-3.5AI services sovereignty2. Mostly non-EU: licensed AI, chip dependency50/200SEAL-2highAI/GPU offering built on US NVIDIA/AMD accelerators and licensed model stacks (NVIDIA Nemotron/Dynamo); mostly non-EU, licensed AI + chip dependency -> opt2.

SOV-4 · Operational Sovereignty 25.1% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumStandard documented data-export methods and compatible APIs/snapshots; no formal sovereign-migration program -> opt3 (seal 4).
SOV-4.2Ability to operate without foreign dependencies1. Critical ops delivered by non-EU teams0/167SEAL-1mediumNo eu_ops at platform level: critical operations, engineering and control plane run by the US parent's global teams, not EU teams -> opt1 (seal 1).
SOV-4.3Skill availability in the EU2. Mixed, majority outside EU42/167SEAL-1lowEngineering/operations skills sit mainly in the US/global org; only a minority of relevant staff are EU-based -> opt2.
SOV-4.4Support channels2. Mixed, majority outside EU42/167SEAL-2lowSupport delivered globally 24x7 from the US-led org, majority of support capacity outside the EU -> opt2.
SOV-4.5Documentation & knowledge transfer2. EU optional, not enforced42/167SEAL-2lowDocumentation/knowledge bases are global/US-hosted; EU residency is optional and not enforced -> opt2 (seal 2), consistent with US commodity-IaaS peers.
SOV-4.6Subcontractor & supplier jurisdiction2. Service would stop with delay42/167SEAL-2lowRelies on non-EU subcontractors/suppliers (US chip vendors, global facilities); a forced cut-off stops service after a delay rather than allowing continuity -> opt2.

SOV-5 · Supply Chain Sovereignty 21.6% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowHardware built from US/Asian components (AMD, NVIDIA, Broadcom, Juniper); only partial public provenance disclosure, no EU-certified provenance -> opt2.
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1mediumServers/accelerators manufactured outside the EU (US-designed chips, Asian fab) with partial disclosure; not built/designed by EU teams -> opt2.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/microcode from foreign OEM and chip vendors (AMD, NVIDIA) with partial disclosure, no EU-certified provenance.
SOV-5.4Origin of software2. Foreign origin, partial disclosure36/143SEAL-2mediumCore control-plane software is the US company's proprietary stack (foreign origin) with limited disclosure; not maintained by EU teams -> opt2 (seal 2).
SOV-5.5Software build/release jurisdiction1. Non-EU control & execution0/143SEAL-1lowSoftware build and release controlled and executed by the US engineering org; no EU control or EU policy gates -> opt1.
SOV-5.6Single point of dependency2. Mostly non-EU, undocumented36/143SEAL-1lowCritical dependencies (US chip vendors, US-controlled control plane and facilities ops) mostly non-EU and not comprehensively documented for EU customers -> opt2.
SOV-5.7Supply chain transparency2. Some suppliers auditable36/143SEAL-1lowSome suppliers disclosed via sub-processor list, but the broader hardware/firmware supply chain is not independently auditable by customers -> opt2.

SOV-6 · Technology Sovereignty 45.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumStandards-based, broadly compatible interfaces (standard Linux VMs, S3-compatible object storage, Kubernetes, public REST API) despite proprietary control plane -> opt4.
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2lowAdopts common open standards for several core services (S3 API, Kubernetes, standard hypervisor images) but no published policy mandating open standards across all services -> opt3.
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2lowPlatform/control plane vendor-controlled and closed-source; uses/exposes open-source tooling but core service code is not open source -> opt2 (seal 2).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowSome public insight via docs, blogs and trust center, but no deep architectural transparency or customer ability to inspect/adapt internals -> opt3.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3mediumGPU/HPC clusters hosted in EU regions but built entirely on foreign (US) NVIDIA/AMD stacks; EU-hosted on a foreign stack -> opt2 (seal 3), consistent with US commodity-IaaS peers.

SOV-7 · Security & Compliance Sovereignty 43.2% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)3. EAL272/143SEAL-2highNo SecNumCloud/EUCS-High/Common Criteria EAL, but holds ISO 27001/27017/27018, SOC 1/2, PCI DSS and HIPAA; per the key's cert map ISO 27001 + SOC 2 -> EAL2-equivalent -> opt3 (seal 2). (src: https://www.vultr.com/legal/compliance/)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)3. Moderate compliance72/143SEAL-4mediumGDPR alignment via DPAs/sub-processor controls plus ISO/SOC attestations and an independent DORA assessment, but no full independently-audited NIS2/DORA -> moderate compliance opt3.
SOV-7.3EU-based SOC & incident handling2. Hybrid EU/non-EU36/143SEAL-1lowSecurity operations/incident response run by the global US-led org; at best hybrid EU/non-EU, not an EU-only SOC lifecycle -> opt2.
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1lowCustomers get a basic monitoring/logging portal and activity logs, not full direct access with EU-stored immutable logs -> opt3 (basic monitoring portal).
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2lowIncident disclosure aligned with GDPR/NIS2-style breach notification via DPAs, without published real-time CSIRT/SLA flows -> opt3 (seal 2).
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowAs IaaS the customer controls guest patching with notice/testing for platform maintenance, except emergency/zero-day fixes pushed by the provider -> moderate autonomy opt3 (seal 4).
SOV-7.7Auditability2. Limited independent access36/143SEAL-1highNo audit_rights: assurance only via vendor SOC 2/ISO reports under NDA; customers cannot perform full independent audits -> opt2 (seal 1).

SOV-8 · Environmental Sustainability 37.5% · SEAL-1 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowOperates in modern data centres with reported annualised PUE around 1.15 (e.g. Sabey hydropower sites): PUE well under 1.5 with an efficiency focus -> opt3. (src: https://www.businesswire.com/news/home/20240305527534/en/Vultr-Expands-Footprint-with-New-NVIDIA-Cloud-GPU-Capacity-Using-Clean-Renewable-Hydropower-in-Sabey-Data-Centers)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowHardware lifecycle is handled via Vultr's colocation partners (e.g. Sabey), whose documented circular/recycling and net-zero programs provide a documented hardware-lifecycle program -> opt3, consistent with US commodity-IaaS peers. (src: https://www.businesswire.com/news/home/20240305527534/en/Vultr-Expands-Footprint-with-New-NVIDIA-Cloud-GPU-Capacity-Using-Clean-Renewable-Hydropower-in-Sabey-Data-Centers)
SOV-8.3Environmental impact reporting1. No reporting0/250SEAL-1lowNo public environmental-impact or sustainability report from Vultr/The Constant Company itself (genuine gap vs peers that publish annual reports) -> opt1.
SOV-8.4Energy supplies3. Mix of EU and non-EU supplies125/250SEAL-4lowGlobal footprint across six continents means a mix of EU and non-EU energy supplies; no traceable EU-only or green-EU commitment published -> opt3.