🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

World4You

Austria · IaaS/PaaS · https://www.world4you.com

Sovereignty score55.3%
Global (unweighted)54.2%
Overall SEAL
SEAL-0 No Sovereignty
SOV-1 Strategic Sovereignty57.4SEAL-2
SOV-2 Legal & Jurisdictional Sovereignty75.1SEAL-2
SOV-3 Data & AI Sovereignty50.0SEAL-1
SOV-4 Operational Sovereignty75.0SEAL-3
SOV-5 Supply Chain Sovereignty39.5SEAL-1
SOV-6 Technology Sovereignty50.0SEAL-2
SOV-7 Security & Compliance Sovereignty43.1SEAL-1
SOV-8 Environmental Sustainability43.9SEAL-0

SOV-1 · Strategic Sovereignty 57.4% · SEAL-2 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control4. Entirely within the EU125/125SEAL-4higheu_entity: World4You Internet Services GmbH (Linz, part of the group since 2018) -> IONOS Group SE (Montabaur, DE) -> United Internet AG (German-listed, controlled by German national R. Dommermuth ~51-54%); entire control chain within the EU -> opt4. (src: https://www.ionos-group.com/brands/world4you.html)
SOV-1.2Change of control risk4. Unlikely takeover/transfer to non-EU sovereign entity94/125SEAL-4mediumUS PE Warburg Pincus fully exited IONOS in March 2025; majority German ownership (United Internet ~64% of IONOS, Dommermuth majority of United Internet). Publicly traded so a non-EU takeover is possible but unlikely -> opt4.
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2lowA commercial Austrian webhost with no published governance bodies; customers influence the roadmap only through voice-of-customer support/feedback channels -> opt2.
SOV-1.4Financial independence from non-EU capital4. Majority of funding is EU-based94/125SEAL-4mediumFunding flows from EU parent United Internet AG (German capital); Warburg Pincus (US) fully exited in 2025, so majority of funding is EU-based with residual free-float possibly non-EU -> opt4.
SOV-1.5EU economic contribution5. Fully in the EU125/125SEAL-4highOperations, staff, data centres and customer base are entirely in Austria; economic contribution fully within the EU -> opt5.
SOV-1.6Participation in EU strategic programs1. No clear participation0/125SEAL-4mediumNo evidence of participation in EU strategic programs (Gaia-X, IPCEI-CIS); commercial Austrian webhost without disclosed strategic-program involvement -> opt1.
SOV-1.7Alignment with EU industrial strategies1. No evidence exists0/125SEAL-4lowNo published formal action plan or governance aligned to EU industrial strategies; sovereignty positioning limited to GDPR/EU-hosting marketing -> opt1.
SOV-1.8Resilience to cut-off4. Ability to source alternatives or internalise key functions94/125SEAL-2lowRuns own Austrian DCs on commodity x86 + open-source virtualization (Proxmox/KVM), so it could source alternatives or internalise; but real non-EU deps (Plesk, chips) and no documented exit/continuity plan, so not full autonomy -> opt4 (seal 2).

SOV-2 · Legal & Jurisdictional Sovereignty 75.1% · SEAL-2 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction3. Exclusively EU law167/167SEAL-4highAustrian GmbH, Austrian DCs (Linz, Wels, Vienna/Voesendorf), EU-only server locations; service governed exclusively by Austrian/EU law -> opt3. (src: https://www.world4you.com/en)
SOV-2.2Extraterritorial laws exposure5. Verified legal immunity, non-EU laws unenforceable167/167SEAL-4mediumimmunity (pure-EU entity, no non-EU parent/subsidiary/operational nexus after the March 2025 Warburg Pincus exit; control chain wholly German/EU) -> non-EU laws genuinely unenforceable -> opt5. (src: https://www.ionos-group.com/brands/world4you.html)
SOV-2.3Data access pathways for non-EU authorities5. Requests always rejected by the provider167/167SEAL-4mediumNo foreign_parent and immunity hold: not subject to US CLOUD Act/FISA/PRC compelled access; only EU/Austrian legal process applies, requests rejected -> opt5. (src: https://www.ionos-group.com/brands/world4you.html)
SOV-2.4Export control restrictions3. Share of revenues >50% in the EU84/167SEAL-2mediumEU-only operator with effectively all revenue in the EU/Austria (>50% EU); no specific shielding of the offer against export controls -> opt3.
SOV-2.5Origin of IP3. Mixed within/outside the EU84/167SEAL-4lowCore operations mix EU-maintained config with widely-used third-party software (Linux open source, Plesk of non-EU origin); IP mixed within/outside the EU -> opt3.
SOV-2.6IP holder jurisdiction3. Mixed law, some EU84/167SEAL-3lowProvider-developed IP under EU/Austrian law, but underlying third-party stack held under mixed (partly non-EU) licences -> opt3.

SOV-3 · Data & AI Sovereignty 50.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys2. Primarily provider, not exclusively50/200SEAL-1lowShared/managed webhosting and vServers; keys are primarily provider-controlled with no advertised customer-held-key (HYOK/BYOK) option -> opt2.
SOV-3.2Transparent data flows & access logs2. Basic incomplete logs50/200SEAL-1lowBasic access/activity logs to customers but no documented real-time, independently auditable data-flow visibility -> opt2.
SOV-3.3Secure deletion & proof of erasure2. Manual confirmation only50/200SEAL-1lowData deletion offered on request/cancellation but no published cryptographic proof or independent verification of irreversible erasure -> opt2.
SOV-3.4Data location strictly in EU/EEA5. Exclusively EU, no third-country fallback200/200SEAL-4higheu_exclusive: server locations explicitly EU-only, geo-redundant across own Austrian DCs (Linz, Wels, Vienna/Voesendorf); no third-country fallback -> opt5. (src: https://www.world4you.com/en)
SOV-3.5AI services sovereignty4. EU-led AI, foreign accelerators150/200SEAL-3lowNo in-scope AI service offered, so no foreign-AI dependency to penalise; per key 'no in-scope AI -> opt4 (seal 3)'.

SOV-4 · Operational Sovereignty 75.0% · SEAL-3 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumStandard hosting/server platform with documented data export (file/database backups, standard protocols); portability via documented methods, no formal migration service -> opt3.
SOV-4.2Ability to operate without foreign dependencies5. Entire stack managed by fully EU-based team167/167SEAL-4higheu_ops: entire stack operated by World4You's own Austrian teams in Austrian DCs, no reliance on non-EU operations teams -> opt5.
SOV-4.3Skill availability in the EU4. All EU staff125/167SEAL-3mediumAll engineering/operations staff EU-based (Linz, Vienna); no documented security-clearance regime -> opt4.
SOV-4.4Support channels4. All support staff in EU125/167SEAL-3mediumSupport provided from Austria (German/English); all support staff EU-based, no security clearances -> opt4.
SOV-4.5Documentation & knowledge transfer4. EU-only primary repositories125/167SEAL-4lowAustrian operator; documentation and knowledge repositories EU-based with no non-EU exposure, though EU-only end-to-end not formally certified -> opt4.
SOV-4.6Subcontractor & supplier jurisdiction4. Ability to source alternatives or internalise125/167SEAL-3lowCore subcontractors (DCs, connectivity) Austrian/EU; on supply disruption could source alternatives or internalise, though foreign hardware vendors remain a factor -> opt4.

SOV-5 · Supply Chain Sovereignty 39.5% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowCommodity x86 servers (Intel/AMD) with no published bill-of-materials; component provenance only partially disclosed -> opt2.
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1mediumServer hardware manufactured by foreign OEMs/chipmakers (Intel/AMD, Asian/US fabs); foreign origin with at most partial disclosure -> opt2.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/microcode in CPUs, BMCs and NICs from foreign vendors with no published provenance; partial disclosure at best -> opt2.
SOV-5.4Origin of software3. Core/essential parts maintained by EU teams72/143SEAL-3lowNo foreign_core: platform built on open-source software (Debian/Linux, KVM/Proxmox) with EU teams maintaining core integration/operations; some non-EU components (Plesk) -> opt3 (core maintained by EU teams).
SOV-5.5Software build/release jurisdiction4. EU control & execution107/143SEAL-3lowProvider's platform configuration and releases controlled and executed by its Austrian (EU) teams; upstream software built elsewhere but operational build/release control is EU -> opt4.
SOV-5.6Single point of dependency3. Few non-EU in critical services / documented72/143SEAL-2lowCritical infrastructure (DCs, network) EU-based, but a few non-EU vendors (CPU/hardware OEMs, Plesk control-panel software) embedded in critical services with limited documentation -> opt3.
SOV-5.7Supply chain transparency2. Some suppliers auditable36/143SEAL-1lowNo published supply-chain transparency program; only some suppliers (own EU DCs) auditable, hardware supply chains opaque -> opt2.

SOV-6 · Technology Sovereignty 50.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3lowBuilt on standards-based, broadly compatible technologies (Linux, standard web/email protocols, SSH/FTP, REST/Plesk APIs); broadly interoperable but not open-by-default with guaranteed portability -> opt4.
SOV-6.2Open standards compliance4. Policy for most core services150/200SEAL-3lowCore services rely on open internet standards (HTTP(S), IMAP/SMTP, DNS, TLS) across most services, though no formal published open-standards policy -> opt4.
SOV-6.3Open source availability3. Open source, centralised governance100/200SEAL-3lowNo foreign_core: stack heavily open source (Debian/Linux, KVM/Proxmox, ownCloud) but governance centralised by vendor and proprietary management layer not open -> opt3 (open source, centralised governance).
SOV-6.4Service architecture transparency2. Insight accessible during audits50/200SEAL-2lowLimited public architectural insight beyond marketing and DC descriptions; deeper insight only under audit/NDA -> opt2.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3lowNo in-scope HPC offering; per key 'no in-scope HPC -> opt2 (seal 3)'; any GPU capability would be EU-hosted foreign stack -> opt2.

SOV-7 · Security & Compliance Sovereignty 43.1% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)1. EAL0 / none0/143SEAL-1lowNo security certification published under World4You itself (no ISO 27001, no SecNumCloud/EUCS/C5/ENS); effectively EAL0/none -> opt1 (seal 1). (src: https://www.datacenters.com/providers/world4you-internet-services-gmbh)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)3. Moderate compliance72/143SEAL-4mediumDemonstrates GDPR compliance (DPA/AVV, EU-only server locations, free SSL) but no published independent NIS2/DORA audit; moderate compliance -> opt3.
SOV-7.3EU-based SOC & incident handling4. Entire lifecycle by EU teams, EU threat intel107/143SEAL-3low24/7 monitoring and incident handling run by own Austrian teams; full lifecycle EU-based, though no formal ENISA/CSIRT sharing documented -> opt4.
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1lowCustomers get a basic monitoring/management portal with some logs; no documented full direct access to immutable security logs -> opt3.
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2lowSubject to GDPR/NIS2 breach-notification obligations as an Austrian provider; moderate, regulation-aligned disclosure without published real-time CSIRT sharing -> opt3.
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowOperates own infrastructure with moderate maintenance autonomy (scheduled patching/notice with testing), dependent on upstream vendor patches for OS/hardware firmware -> opt3.
SOV-7.7Auditability2. Limited independent access36/143SEAL-1lowNo audit_rights: no published independent third-party audit/certification (no ISO 27001) and no sovereign-offer terms implying full contractual audit rights; independent audit access limited -> opt2 (seal 1).

SOV-8 · Environmental Sustainability 43.9% · SEAL-0 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)2. PUE < 363/250SEAL-1lowModern Austrian DCs with redundant cooling/power but no published PUE figure; treated conservatively as managed but unverified (PUE < 3) -> opt2. (src: https://www.world4you.com/en)
SOV-8.2Hardware reuse & recycling2. Basic circular practices63/250SEAL-0lowNo published hardware reuse/recycling program; at most basic circular practices implied for an operator of its own DCs -> opt2.
SOV-8.3Environmental impact reporting2. Basic reporting63/250SEAL-1lowMarkets 100% green energy but publishes no formal annual environmental-impact report with EU methodology; basic reporting only -> opt2.
SOV-8.4Energy supplies5. Only green EU energy supplies250/250SEAL-4mediumExplicitly states Austrian DCs run on 100% green energy (renewable electricity since 2021, Green Web Foundation partner); only green EU energy supplies -> opt5. (src: https://www.world4you.com/en)