Exoscale is a cloud platform with its center of gravity in Switzerland and Austria. Selling points for Exoscale are engineering mindset, Open Source culture and products, data security, GDPR compliance, data privacy and good geographical distribution of data centres.
Features & Services
The service portfolio of Exoscale is a straightforward set of IaaS services. All of the services are built on raw Open Source products, which means that lock-in with Exoscale is low. On the other hand, a lot may have to be built on top of the basic building blocks provided by Exoscale.
The DBaaS services of Exoscale seem to be powered by Norwegian Aiven, a mature cloud-scale platform for managed Kafka and various other managed databases.
Developer Experience
There are several ways to interact with the Exoscale platform.
Console
The Exoscale Console is well-ordered and easy to get around.

API
Behind libraries, CLI, Terraform and all other ways to interact with Exoscale lies the Exoscale API.
CLI
The Exoscale Command Line Interface (CLI) covers the whole surface and is well-structured and easy to understand and work with.
For more information, check the documentation of the Exoscale CLI.
Terraform
The Exoscale Terraform provider is published in the Terraform Registry, along with it’s documentation.
The first steps to set up the Exoscale Terraform provider with credentials and a container for the Terraform state are described in the Exoscale Terraform provider documentation.
SDKs
There is a larger-than-average number of official libraries to work with Exoscale resources.
| egoscale | The Golang library for Exoscale. | egoscale on GitHub |
| python-exoscale | Python bindings for the Exoscale API. | python-exoscale on GitHub |
| exoscale-sdk-java | Java API for Exoscale services. | exoscale-sdk-java on GitHub |
| pulumi-exoscale | Pulumi provider to manage Exoscale resources. | pulumi-exoscale on GitHub |
| crossplane-exoscale | Crossplane provider to manage Exoscale resources. | crossplane-exoscale on GitHub |
Sovereignty Assessment
For the sovereignty assessment, we are following the EU's Cloud Sovereignty Framework. It defines 8 sovereignty objectives and makes sovereignty measurable and quantifiable.
Disclaimer: this assessment is conducted as an outside-in analysis, based on public information and, for some questions, educated guessing. The results may be factually wrong and in no way replace your own due diligence.
Overall Score
59.8 %
SEAL Level
SEAL 1
- Provider
- Exoscale
- Framework
- Initial framework from the Sovereignty assessment calculator annex (v1.0)
- Assessment date
- 2. September 2026
- Overall score
- 59.8 %
- SEAL level
- SEAL 1
SOV-1 — Strategic Sovereignty
Strategic sovereignty captures the degree to which a cloud provider (or technology actor) is anchored within the European Union/EEA legal, financial, and industrial ecosystem. It assesses ownership stability, governance influence, and alignment with EU strategic priorities.
Weight 20%
Selected answer: 2. Mostly outside the EU Value 41 SEAL 1
Notes: Operating entity Akenes SA is Swiss (non-EU/EEA). Intermediate parents (A1 Digital, Telekom Austria) are EU, but ultimate control via América Móvil (Mexico) places decision authority outside EU.
Evidence
- A1 Group — Investor Relations / Share Page other 3. September 2026
Official A1 Group investor relations page showing shareholder structure: América Móvil (~56-58%) and ÖBAG (~28%), with ISIN AT0000720008 listed on Vienna Stock Exchange.
Relevance: Confirms the majority shareholder is América Móvil (Mexican), not EU-based. While Telekom Austria is listed in Austria, ultimate control sits outside the EU, impacting strategic sovereignty assessment. - A1 Telekom Austria Group — Wikipedia other 3. September 2026
Wikipedia article detailing América Móvil's ~58% majority stake in Telekom Austria and the 2014 syndicate agreement giving it controlling influence.
Relevance: Establishes that ultimate decision-making authority rests with América Móvil (Mexico), a non-EU entity, through majority shareholding and syndicate agreement — placing corporate control outside EU jurisdiction. - About Us | Exoscale European Cloud Services other 3. September 2026
Official Exoscale page confirming Akenes SA (Switzerland) is the legal entity, part of A1 Digital and A1 Telekom Austria Group.
Relevance: Confirms operating entity is Swiss (non-EU/EEA) and part of the A1 ownership chain. Switzerland is not in EU/EEA, so direct legal entity control is outside EU jurisdiction.
All possible answer options (4)
- 1. Entirely outside the EU (value 0.00, SEAL 1)
- 2. Mostly outside the EU (value 41.00, SEAL 1) ✓
- 3. Mostly within the EU (value 83.00, SEAL 3)
- 4. Entirely within the EU (value 125.00, SEAL 4)
Selected answer: 5. Very unlikely Value 125 SEAL 4
Notes: ÖBAG's 28% stake with veto rights (via Austria Package) and AMX's private (non-sovereign) ownership make transfer to a non-EU sovereign entity very unlikely.
No evidence provided for this answer.
All possible answer options (5)
- 1. Very likely (value 0.00, SEAL 4)
- 2. Likely takeover by or transfer to a non-EU sovereign entity (value 31.00, SEAL 4)
- 3. Somewhat likely takeover by or transfer to a non-EU sovereign entity (value 62.00, SEAL 4)
- 4. Unlikely takeover by or transfer to a non-EU sovereign entity (value 93.00, SEAL 4)
- 5. Very unlikely (value 125.00, SEAL 4) ✓
Selected answer: 3. Governance bodies exist with EU actors participation Value 83 SEAL 3
Notes: ÖBAG (Austrian state) holds SB chair and veto rights via syndicate agreement, but AMX (non-EU) controls majority stake and CEO nomination.
No evidence provided for this answer.
All possible answer options (4)
- 1. No influence possible (value 0.00, SEAL 2)
- 2. Through "voice of the customer" public channels (e.g. feedback portals, online communities) (value 41.00, SEAL 2)
- 3. Governance bodies exist with EU actors participation (value 83.00, SEAL 3) ✓
- 4. Full influence of EU actors (value 125.00, SEAL 4)
Selected answer: 2. Mostly relying on non-EU funding Value 31 SEAL 4
Notes: A1 Group (Exoscale's ultimate parent) is majority-owned (~56-58%) by América Móvil (Mexico). EU state stake (ÖBAG) is ~28%. Majority non-EU capital.
No evidence provided for this answer.
All possible answer options (5)
- 1. Almost entirely relying on non-EU funding (value 0.00, SEAL 4)
- 2. Mostly relying on non-EU funding (value 31.00, SEAL 4) ✓
- 3. Balanced mix of EU and non-EU funding (value 62.00, SEAL 4)
- 4. Majority of funding is EU-based (value 93.00, SEAL 4)
- 5. Entirely EU-based funding (value 125.00, SEAL 4)
Selected answer: 3. Balanced EU/non-EU Value 62 SEAL 4
Notes: Exoscale is HQ in Switzerland (non-EU/EEA). Parent A1 Digital (Vienna) invests in EU: €40M Vienna DC, expansion to Spain, DCs in DE/AT/BG/HR/CZ. A1 Group has €5.4B revenue, ~17k employees in EU.
No evidence provided for this answer.
All possible answer options (5)
- 1. Minimal (value 0.00, SEAL 4)
- 2. Some (value 31.00, SEAL 4)
- 3. Balanced EU/non-EU (value 62.00, SEAL 4) ✓
- 4. Majority in the EU (value 93.00, SEAL 4)
- 5. Fully in the EU (value 125.00, SEAL 4)
Selected answer: 2. Active participant in strategic projects Value 62 SEAL 4
Notes: Exoscale is a Day One Member and Silver Market-X Partner of Gaia-X, confirming active participation in a key EU strategic initiative. No evidence of IPCEI-CIS or Horizon Europe involvement.
No evidence provided for this answer.
All possible answer options (3)
- 1. No clear participation (value 0.00, SEAL 4)
- 2. Active participant in strategic projects (value 62.00, SEAL 4) ✓
- 3. Strategic projects depend on contractor's involvement (value 125.00, SEAL 4)
Selected answer: Existing Action plan (how to measure ambition? Through means linked to the goals? Relative to the size of the company?) Value 41 SEAL 4
Notes: Exoscale aligns with EU digital (Gaia-X/Structura-X) and green (100% renewables) strategies with measurable actions, but ambition is moderate relative to size and lacks IPCEI-CIS participation.
No evidence provided for this answer.
All possible answer options (3)
- Existing Action plan (how to measure ambition? Through means linked to the goals? Relative to the size of the company?) (value 41.00, SEAL 4) ✓
- Already measured achievement and existing dedicated governance (value 83.00, SEAL 4)
- Bold ambition and dedicated means (value 125.00, SEAL 4)
Selected answer: 4. Ability to source alternative suppliers or internalise key functions Value 93 SEAL 2
Notes: Built on open-source Apache CloudStack; open standards (S3, K8s) and data portability tools enable migration to alternative providers or self-hosting if support is withdrawn.
No evidence provided for this answer.
All possible answer options (4)
- 2. Service would likely stop but with a delay to provide time for customer reaction (value 31.00, SEAL 0)
- 3. Can continue temporarily based on contractual agreement with EC (value 62.00, SEAL 2)
- 4. Ability to source alternative suppliers or internalise key functions (value 93.00, SEAL 2) ✓
- 5. Full autonomy and continuity (value 125.00, SEAL 4)
SOV-2 — Legal & Jurisdictional Sovereignty
Legal & Jurisdictional sovereignty evaluates the legal environment, exposure to foreign authority, and enforceability of rights that govern a technology provider and its services. It determines the extent to which a provider is anchored in European jurisdiction and insulated from external legal claims.
Weight 10%
Selected answer: 2. Mixed EU/non-EU Value 84 SEAL 1
Notes: Ops entity is Swiss (non-EU); parent A1 Digital is Austrian (EU); majority owner América Móvil is Mexican (non-EU). Mixed EU/non-EU.
No evidence provided for this answer.
All possible answer options (3)
- 1. Non-EU only (value 0.00, SEAL 1)
- 2. Mixed EU/non-EU (value 84.00, SEAL 1) ✓
- 3. Exclusively EU law (value 167.00, SEAL 4)
Selected answer: EU subsidiary with contractual protections Value 83 SEAL 1
Notes: EU parent (A1 Digital, AT) with syndicate agreement & Swiss law T&Cs, but America Movil majority ownership leaves residual non-EU exposure.
No evidence provided for this answer.
All possible answer options (4)
- Mitigation clauses, exposure remains (value 41.00, SEAL 1)
- EU subsidiary with contractual protections (value 83.00, SEAL 1) ✓
- Legal structures shielding from foreign law (value 125.00, SEAL 2)
- Verified legal immunity, non-EU laws unenforceable (value 167.00, SEAL 4)
Selected answer: 4. Non-EU authorities requests to access data or systems are disputed by the provider and eventually in some cases are accepted with customers being notified Value 125 SEAL 1
Notes: Swiss-incorporated Exoscale blocks direct foreign data requests via Art. 271 SCC. Some accepted via Swiss mutual legal assistance with customer notification.
No evidence provided for this answer.
All possible answer options (4)
- 2. Non-EU authorities can compel access to data or systems without customers being notified, in specific cases (value 41.00, SEAL 1)
- 3. Non-EU authorities can compel access to data or systems with customers being notified in all cases (value 83.00, SEAL 1)
- 4. Non-EU authorities requests to access data or systems are disputed by the provider and eventually in some cases are accepted with customers being notified (value 125.00, SEAL 1) ✓
- 5. Non-EU authorities requests to access data or systems are always rejected by the provider (value 167.00, SEAL 4)
Selected answer: Part of the offer cannot be exposed to restrictions towards EU MSs or international organisations Value 167 SEAL 4
Notes: Exoscale's EUC imposes EAR on NVIDIA GPUs only (part of offer); restrictions target D:1/D:4/D:5 countries & sanctioned parties, not EU MSs or intl orgs.
No evidence provided for this answer.
All possible answer options (4)
- Restrictions exists towards EU citizens or international organisations (value 41.00, SEAL 1)
- Share of revenues >50% in the EU (value 83.00, SEAL 2)
- Part of the offer cannot be exposed to restrictions towards EU MSs (value 125.00, SEAL 3)
- Part of the offer cannot be exposed to restrictions towards EU MSs or international organisations (value 167.00, SEAL 4) ✓
Selected answer: 3. Mixed within/outside the EU Value 83 SEAL 4
Notes: IP created and registered in Switzerland (non-EU); development now spans EU (AT, DE, BG, HR) and non-EU (CH) locations.
No evidence provided for this answer.
All possible answer options (4)
- 2. Mostly outside the EU (value 41.00, SEAL 4)
- 3. Mixed within/outside the EU (value 83.00, SEAL 4) ✓
- 4. Mostly within the EU (value 125.00, SEAL 4)
- 5. Fully within the EU (value 167.00, SEAL 4)
Selected answer: Mixed law, some EU Value 83 SEAL 3
Notes: IP owned by Akenes SA (Switzerland, non-EU) under Swiss law; parent A1 Digital (Austria, EU); majority shareholder América Móvil (Mexico, non-EU). Mixed jurisdictions with some EU presence.
No evidence provided for this answer.
All possible answer options (4)
- non-EU law, mixed non-EU countries (value 41.00, SEAL 3)
- Mixed law, some EU (value 83.00, SEAL 3) ✓
- EU law with exceptions (value 125.00, SEAL 4)
- fully under EU law (value 167.00, SEAL 4)
SOV-3 — Data & AI Sovereignty
Data & AI sovereignty focuses on the protection, control, and independence of data assets and AI services within the EU/EEA. It addresses how data is secured, where it is processed, and the degree of autonomy customers retain over AI capabilities.
Weight 10%
Selected answer: 4. Customer primary control but provider can read the data or some of the data Value 150 SEAL 3
Notes: Exoscale offers CYOK via KMS — customers control key lifecycle, but keys reside in Exoscale's boundary. Root key is provider-managed. HYOK/XKS only planned.
No evidence provided for this answer.
All possible answer options (4)
- 2. Primarily the provider but not exclusively (value 50.00, SEAL 1)
- 3. Shared - provider has override keys (value 100.00, SEAL 2)
- 4. Customer primary control but provider can read the data or some of the data (value 150.00, SEAL 3) ✓
- 5. Customer exclusive control - provider can not read the data (value 200.00, SEAL 4)
Selected answer: 4. Full customer controlled visibility of log access but not in real time Value 150 SEAL 3
Notes: Audit Trail logs who/what/when/where with customer-controlled SOS bucket storage. SOC 2 assures auditability, but platform logs are not real-time.
No evidence provided for this answer.
All possible answer options (4)
- 2. Basic logs incomplete (missing date; missing user; missing type of access; missing means of access etc.) (value 50.00, SEAL 1)
- 3. Logs exist but not real-time or controlled by vendor (vendor is replaced by CUSTOMER in the survey) (value 100.00, SEAL 2)
- 4. Full customer controlled visibility of log access but not in real time (value 150.00, SEAL 3) ✓
- 5. Real-time customer oversight and independent auditability (value 200.00, SEAL 4)
Selected answer: 3. Internal validation based on policies - no proof of validation left Value 100 SEAL 1
Notes: EUSA mandates erasure and confirms completion upon request, but no systematic proof or independent verification of erasure is provided.
No evidence provided for this answer.
All possible answer options (4)
- 2. Manual confirmation only (value 50.00, SEAL 1)
- 3. Internal validation based on policies - no proof of validation left (value 100.00, SEAL 1) ✓
- 4. Deletion is technically verified with access logs (value 150.00, SEAL 3)
- 5. Yes, irreversible deletion is systematically enforced and independently verified (value 200.00, SEAL 4)
Selected answer: 4. Data in the EU by default, tightly controlled exceptions Value 150 SEAL 1
Notes: 6 of 8 zones in EU; 2 in Switzerland (non-EU/EEA but with adequacy decision). All data in Europe, no non-European fallback, no CLOUD Act exposure.
No evidence provided for this answer.
All possible answer options (4)
- 2. Data partly in the EU, significant reliance on third countries and limited control (value 50.00, SEAL 0)
- 3. Data mainly in the EU, some third-country use with standard safeguards (value 100.00, SEAL 1)
- 4. Data in the EU by default, tightly controlled exceptions (value 150.00, SEAL 1) ✓
- 5. All data exclusively in the EU with no third-country fallback (value 200.00, SEAL 4)
Selected answer: Mixed Control with alternatives: Auditable or open source AI, foreign chips Value 100 SEAL 2
Notes: EU-hosted AI infra supports open-source models (Hugging Face), but relies entirely on NVIDIA GPUs/chips. No EU-origin AI models or domestic chip alternatives.
No evidence provided for this answer.
All possible answer options (4)
- Mostly non-EU dependencies: Licensed AI, chip dependency (value 50.00, SEAL 2)
- Mixed Control with alternatives: Auditable or open source AI, foreign chips (value 100.00, SEAL 2) ✓
- EU-led AI, foreign accelerators (value 150.00, SEAL 3)
- EU-origin models and chips - no dependencies from outside EU (value 200.00, SEAL 4)
SOV-4 — Operational Sovereignty
Operational sovereignty measures the practical ability of EU actors to run, support, and evolve a technology independently of foreign control. It focuses on continuity of operations, skill availability, and resilience against external dependencies.
Weight 15%
Selected answer: 3. Standard documented methods for data export are available Value 83 SEAL 4
Notes: Exoscale provides documented data export via QCOW2, S3 API, and DB dumps with migration guides, EU Data Act compliance, and no switching fees — but no formal migration service offering.
No evidence provided for this answer.
All possible answer options (4)
- 2. Data export and workload portability is provided on a "best-effort" basis (value 41.00, SEAL 1)
- 3. Standard documented methods for data export are available (value 83.00, SEAL 4) ✓
- 4. Formal migration services are available to assist with moving data and workloads (value 125.00, SEAL 4)
- 5. Solution already deployed on sovereign infrastructure (value 167.00, SEAL 4)
Selected answer: 4. Operational services are predominantly delivered by EU-based teams Value 125 SEAL 3
Notes: EU-based engineering and support teams manage all operations; however NVIDIA GPU dependencies and non-EU majority shareholder create partial foreign dependencies.
No evidence provided for this answer.
All possible answer options (4)
- 2. Operational services are partially sourced from within the EU (value 41.00, SEAL 1)
- 3. Operational responsibilities are balanced between EU and non-EU teams (value 83.00, SEAL 3)
- 4. Operational services are predominantly delivered by EU-based teams (value 125.00, SEAL 3) ✓
- 5. The entire technology stack is managed and supported by a fully EU-based team (value 167.00, SEAL 4)
Selected answer: Majority EU, escalation abroad Value 83 SEAL 3
Notes: Staff primarily EU-based (AT, DE, ES, BG); HQ in Switzerland + A1 Group ops in Serbia/Belarus constitute non-EU escalation paths.
No evidence provided for this answer.
All possible answer options (4)
- Mixed, majority outside EU (value 41.00, SEAL 1)
- Majority EU, escalation abroad (value 83.00, SEAL 3) ✓
- All EU staff (value 125.00, SEAL 3)
- 100% EU staff + clearance (value 167.00, SEAL 4)
Selected answer: 3. The majority of support staff are in the EU but escalations are handled by non-EU teams Value 83 SEAL 3
Notes: Most SRE/support staff in EU (Vienna, Munich, Madrid, remote-EU); HQ in Lausanne, CH (non-EU/EEA) likely handles escalations.
No evidence provided for this answer.
All possible answer options (4)
- 2. The team is mixed but the majority of support staff reside outside the EU (value 41.00, SEAL 2)
- 3. The majority of support staff are in the EU but escalations are handled by non-EU teams (value 83.00, SEAL 3) ✓
- 4. All support staff are located within the EU (value 125.00, SEAL 3)
- 5. All support staff are located within the EU and hold relevant security clearances (value 167.00, SEAL 4)
Selected answer: 4. EU-only primary repositories - All primary documentation and knowledge repositories are stored in the EU (no routine non-EU storage/processing) Value 125 SEAL 4
Notes: All documentation hosted on EU infrastructure; open-source tools & SDKs publicly available; operational know-how with EU-based engineering team.
No evidence provided for this answer.
All possible answer options (4)
- 2. EU optional, not enforced - EU storage is available as an option, but it is not enforced (value 41.00, SEAL 2)
- 3. EU primary with non-EU fallback - Stored/managed in the EU by default, but some storage/replication/access outside the EU may occur (e.g., disaster recovery/support) (value 83.00, SEAL 4)
- 4. EU-only primary repositories - All primary documentation and knowledge repositories are stored in the EU (no routine non-EU storage/processing) (value 125.00, SEAL 4) ✓
- 5. EU-only end-to-end - Content, metadata, and backups/replicas are stored in the EU and privileged administration/support access is restricted to EU-based staff under EU jurisdiction (value 167.00, SEAL 4)
Selected answer: 4. Ability to source alternative suppliers or internalise key functions Value 125 SEAL 3
Notes: Core platform is open-source (Apache CloudStack), enabling internalisation. Backed by large EU telecom group (A1) for alternative sourcing, though non-EU majority ownership limits full autonomy.
No evidence provided for this answer.
All possible answer options (4)
- 2. Service would likely stop but with a delay to provide time for customer reaction (value 41.00, SEAL 2)
- 3. Can continue temporarily based on contractual agreement with EC (value 83.00, SEAL 3)
- 4. Ability to source alternative suppliers or internalise key functions (value 125.00, SEAL 3) ✓
- 5. Full autonomy and continuity (value 167.00, SEAL 4)
SOV-5 — Supply Chain Sovereignty
Supply chain sovereignty evaluates the geographic origin, transparency, and resilience of the technology supply chain, focusing on the extent to which critical components and processes remain under EU control or exposed to non-EU dependencies.
Weight 10%
Selected answer: Partial disclosure Value 35 SEAL 1
Notes: Partial disclosure: Exoscale names data center partners and GPU models but omits server, networking, storage OEMs and their geographic origin.
No evidence provided for this answer.
All possible answer options (4)
- Partial disclosure (value 35.00, SEAL 1) ✓
- Transparent with exceptions (value 71.00, SEAL 3)
- Full transparency (value 107.00, SEAL 3)
- EU-certified provenance (value 143.00, SEAL 4)
Selected answer: Build by EU Teams, on the basis of a foreign code Value 107 SEAL 3
Notes: EU hardware team in Lausanne designs/specifies servers, but core components (NVIDIA GPUs, x86 CPUs) are foreign-designed and manufactured outside EU.
No evidence provided for this answer.
All possible answer options (4)
- Foreign origin, partial disclosure (value 35.00, SEAL 1)
- Mixed sourcing, EU audit rights (value 71.00, SEAL 3)
- Build by EU Teams, on the basis of a foreign code (value 107.00, SEAL 3) ✓
- Exclusive designed and build by EU Teams (value 143.00, SEAL 4)
Selected answer: Partial disclosure Value 35 SEAL 4
Notes: Open-source control stack (KVM, CloudStack) is auditable; GPU models (NVIDIA) disclosed. Firmware provenance, SBOMs, and server hardware suppliers undisclosed.
No evidence provided for this answer.
All possible answer options (4)
- Partial disclosure (value 35.00, SEAL 4) ✓
- Transparent with exceptions (value 71.00, SEAL 4)
- Full transparency (value 107.00, SEAL 4)
- EU-certified provenance (value 143.00, SEAL 4)
Selected answer: 3. Core and essential parts of the software are designed and maintained by EU teams Value 71 SEAL 3
Notes: Exoscale's platform is built on Apache CloudStack (US-origin) and other global FOSS, but core custom software is developed by EU-based teams in Lausanne, Vienna, Munich, and Madrid. Foreign-origin dependencies prevent higher maturity.
No evidence provided for this answer.
All possible answer options (4)
- 2. Software is of foreign origin with partial disclosure on its development (value 35.00, SEAL 2)
- 3. Core and essential parts of the software are designed and maintained by EU teams (value 71.00, SEAL 3) ✓
- 4. A large majority of the software is designed and maintained by EU teams (value 107.00, SEAL 3)
- 5. The software is exclusively designed and maintained by EU teams (value 143.00, SEAL 4)
Selected answer: 5. EU control and EU policy gates - As (4), plus EU-based compliance/security gates enforced in the pipeline (e.g., signing under your control, vulnerability checks, segregation of duties, auditable approvals) Value 143 SEAL 4
Notes: Exoscale's EU-based teams manage packaging, distribution & updates. SOC 2 Type 2 + ISO 27001 + audit trails enforce compliance/security gates (vuln checks, segregation of duties, auditable approvals) in the EU.
No evidence provided for this answer.
All possible answer options (4)
- 2. EU control, non-EU execution - Execution is performed by non-EU teams, but pipeline administration and final release approvals are under EU jurisdiction (value 35.00, SEAL 1)
- 3. Non-EU control, EU execution - Execution is performed by EU teams, but pipeline administration and/or final release approvals (incl. signing) are under non-EU jurisdiction (value 71.00, SEAL 3)
- 4. EU control & execution - Build/release/deployment is executed by EU teams and governed from within the EU (pipeline administration, signing, approvals) (value 107.00, SEAL 3)
- 5. EU control and EU policy gates - As (4), plus EU-based compliance/security gates enforced in the pipeline (e.g., signing under your control, vulnerability checks, segregation of duties, auditable approvals) (value 143.00, SEAL 4) ✓
Selected answer: Few non-EU vendors or facilities involved in critical services, non documented, or non-EU vendors/facilities transparently documented Value 71 SEAL 2
Notes: Few non-EU critical deps (NVIDIA GPUs, Equinix datacenters) — most documented; hardware vendors not formally disclosed as supply-chain transparency
No evidence provided for this answer.
All possible answer options (4)
- Mostly non-EU vendors or facilities involved in critical services, non documented (value 35.00, SEAL 1)
- Few non-EU vendors or facilities involved in critical services, non documented, or non-EU vendors/facilities transparently documented (value 71.00, SEAL 2) ✓
- Few non-EU vendors or facilities involved in non-critical services, documented (value 107.00, SEAL 3)
- No depedency on non-EU vendor or facility (value 143.00, SEAL 4)
Selected answer: Critical suppliers and subcontractors can be audited Value 71 SEAL 2
Notes: Exoscale's ISMS framework covers supplier risk and audit rights focused on critical/data center operators; no evidence of end-to-end audit rights across all sub-suppliers.
No evidence provided for this answer.
All possible answer options (4)
- Some suppliers and subcontractors can be audited (value 35.00, SEAL 1)
- Critical suppliers and subcontractors can be audited (value 71.00, SEAL 2) ✓
- Most suppliers and subcontractors can be audited (value 107.00, SEAL 3)
- All suppliers and subcontractors can be audited (value 143.00, SEAL 4)
SOV-6 — Technology Sovereignty
Technology sovereignty evaluates the degree of openness, transparency, and independence in the underlying technological stack, ensuring EU actors can interoperate, audit, and evolve solutions without lock-in to foreign proprietary systems.
Weight 15%
Selected answer: 3. Mixed (partial openness) - Key interfaces are documented and partly standards-based, but important functions or data formats remain proprietary/vendor-specific Value 100 SEAL 2
Notes: OpenAPI-spec APIs, S3-compatible storage, standard Kubernetes; but core compute, IAM, KMS, DBaaS APIs are vendor-specific. Mixed openness profile.
No evidence provided for this answer.
All possible answer options (4)
- 2. Restricted proprietary APIs - Some vendor APIs exist, but they are limited/restricted (access, scope, licensing) and interoperability remains vendor-controlled (value 50.00, SEAL 1)
- 3. Mixed (partial openness) - Key interfaces are documented and partly standards-based, but important functions or data formats remain proprietary/vendor-specific (value 100.00, SEAL 2) ✓
- 4. Standards-based and broadly compatible - Interfaces and data formats predominantly follow recognised open standards (e.g., ETSI/CEN/CENELEC, ISO/IEC, IETF/W3C) with stable versioning and full documentation (value 150.00, SEAL 3)
- 5. Open-by-default with portability - All critical functions are accessible via open, well-documented, non-proprietary APIs and standard formats, with published specifications and minimal vendor-specific dependencies enabling easy third-party integration (value 200.00, SEAL 4)
Selected answer: 4. Policy for most core services - A formal policy mandates and documents open standards for most core services, with managed exceptions Value 150 SEAL 3
Notes: Open standards systematically adopted across most core services (OpenAPI, S3, Kubernetes/CSI, KVM, CloudStack, standard export formats) though no single formal policy document is publicly published.
No evidence provided for this answer.
All possible answer options (4)
- 2. Ad hoc use - Open standards are used inconsistently on a case-by-case basis, without documented rationale or governance (value 50.00, SEAL 0)
- 3. Partial core adoption - Open standards are used and documented for some core services, while other core services remain proprietary/vendor-specific (value 100.00, SEAL 2)
- 4. Policy for most core services - A formal policy mandates and documents open standards for most core services, with managed exceptions (value 150.00, SEAL 3) ✓
- 5. Policy for all core services - A formal policy mandates and documents open standards for all core services (value 200.00, SEAL 4)
Selected answer: 5. Fully open-source software is governed by an independent or EU-based entity, granting full rights to audit, modify, redistribute, and seamlessly transfer stewardship Value 200 SEAL 4
Notes: Core platform (Apache CloudStack, Kubernetes, KVM) is fully open source under independent foundations (ASF, CNCF). Exoscale's own SDKs/tools are Apache 2.0 on GitHub, granting full audit, modify, redistribute rights.
No evidence provided for this answer.
All possible answer options (4)
- 2. Source code is available for review but modification and handover rights are under very strict conditions (value 50.00, SEAL 2)
- 3. The software is open source , permitting modification and redistribution, but governance is centralised (e.g., single-company or non-open foundation), limiting strategic autonomy or smooth handover (value 100.00, SEAL 3)
- 4. The software is open source with significant EU contributions but governance is restricted and handover is possible (value 150.00, SEAL 4)
- 5. Fully open-source software is governed by an independent or EU-based entity, granting full rights to audit, modify, redistribute, and seamlessly transfer stewardship (value 200.00, SEAL 4) ✓
Selected answer: Large corpus of public insight exists (all) Value 150 SEAL 3
Notes: Exoscale publishes extensive architecture docs, data flows, open dependencies & 299 GitHub repos for full service transparency.
No evidence provided for this answer.
All possible answer options (4)
- Insight accessible during audits (value 50.00, SEAL 2)
- Some public insight exists (all) (value 100.00, SEAL 3)
- Large corpus of public insight exists (all) (value 150.00, SEAL 3) ✓
- Customers can contribute to adapt and enhance the service (value 200.00, SEAL 4)
Selected answer: EU-hosted, foreign stack Value 50 SEAL 3
Notes: Exoscale hosts in EU DCs but uses entirely foreign processors (Intel/AMD) and NVIDIA GPUs. No EU-designed processors or accelerators in their HPC stack.
No evidence provided for this answer.
All possible answer options (4)
- EU-hosted, foreign stack (value 50.00, SEAL 3) ✓
- Co-designed or integrated in EU (value 100.00, SEAL 3)
- EU processor IP, non-EU fabs (value 150.00, SEAL 3)
- EU design + EU fab + EU ops (value 200.00, SEAL 4)
SOV-7 — Security & Compliance Sovereignty
Security & Compliance sovereignty measures the extent to which security operations, compliance obligations, and resilience measures are controlled within the EU , ensuring independence from foreign jurisdictions and long-term operational assurance.
Weight 15%
Selected answer: ELA3 Value 107 SEAL 3
Notes: Comprehensive EU+intl certifications (ISO 27001/27017/27018, BSI C5, HDS, TISAX, SOC 2) but Swiss HQ and no SecNumCloud/EUCS limit full EU sovereignty.
No evidence provided for this answer.
All possible answer options (4)
- ELA1 (value 35.00, SEAL 1)
- EAL2 (value 71.00, SEAL 2)
- ELA3 (value 107.00, SEAL 3) ✓
- EAL4-5 (value 143.00, SEAL 4)
Selected answer: 4. Partial compliance to most of the well-known EU Regulations (requirements implemented and operational with minor exceptions) Value 107 SEAL 4
Notes: GDPR directly addressed; NIS2/DORA supported via ISO 27001, SOC 2, BSI C5 audits but not independently attested. Minor gaps remain.
No evidence provided for this answer.
All possible answer options (4)
- 2. Limited compliance to some well-known EU Regulations (basic practices exist but informal, incomplete, or non-systematic) (value 35.00, SEAL 4)
- 3. Moderate compliance to some well-know EU Regulations (controls exist but gaps remain; compliance not fully demonstrated) (value 71.00, SEAL 4)
- 4. Partial compliance to most of the well-known EU Regulations (requirements implemented and operational with minor exceptions) (value 107.00, SEAL 4) ✓
- 5. Fully compliant to all well-know EU regulations (verified compliance, independently audited) (value 143.00, SEAL 4)
Selected answer: 3. The primary SOC is in the EU but incidents may be escalated to non-EU teams Value 71 SEAL 1
Notes: EU-based SOC in Vienna handles primary incident response, but deep remediation escalates to Mandiant (US). No evidence of ENISA participation.
No evidence provided for this answer.
All possible answer options (4)
- 2. A hybrid model is used with SOC functions split between EU and non-EU locations (value 35.00, SEAL 1)
- 3. The primary SOC is in the EU but incidents may be escalated to non-EU teams (value 71.00, SEAL 1) ✓
- 4. The entire incident lifecycle is handled by teams operating exclusively within the EU. Threat intelligence and incident data obtained mostly via EU sources (value 107.00, SEAL 3)
- 5. The full incident lifecycle is handled by EU-based teams with active participation in ENISA's information sharing frameworks. Threat intelligence and incident data are gathered worldwide (value 143.00, SEAL 4)
Selected answer: 4. Customers have full direct access to their security monitoring and logs which are stored in the EU Value 107 SEAL 3
Notes: Customers have full direct access to security monitoring/logs via Portal, CLI, API, and webhook forwarding. All zones in Europe. No WORM immutability, so Option 5 not met.
No evidence provided for this answer.
All possible answer options (4)
- 2. Customers receive periodic reports based on security logs (value 35.00, SEAL 1)
- 3. Customers have access to a basic portal for monitoring (value 71.00, SEAL 1)
- 4. Customers have full direct access to their security monitoring and logs which are stored in the EU (value 107.00, SEAL 3) ✓
- 5. Customers have full access to immutable tamper-proof logs stored exclusively within the EU (value 143.00, SEAL 4)
Selected answer: 3. Moderate compliance - GDPR/NIS2-aligned reporting procedures in place with vulnerabilities and breaches communicated within mandated timelines; CSIRT cooperation available but not real-time Value 71 SEAL 2
Notes: GDPR/NIS2-aligned via ISO 27001 & A1 Digital NIS2 readiness; A1-CERT/FIRST enables CSIRT cooperation but no real-time EU CSIRT data sharing evidenced.
No evidence provided for this answer.
All possible answer options (4)
- 2. Limited compliance - reporting is reactive with limited transparency and unguaranteed timelines; CSIRT cooperation possible on best-effort basis (value 35.00, SEAL 1)
- 3. Moderate compliance - GDPR/NIS2-aligned reporting procedures in place with vulnerabilities and breaches communicated within mandated timelines; CSIRT cooperation available but not real-time (value 71.00, SEAL 2) ✓
- 4. Partial compliance - there is a monitored reporting flow with internal SLAs equal or below regulatory maximums; contractually prepared to support EU-directed investigations; data sharing with EU CSIRTs available but not in real-time (value 107.00, SEAL 3)
- 5. Full compliance - full EU-compliant breach disclosure with real-time data sharing to EU CSIRTs with audit-backed processes, proactive vulnerability disclosure and threat intel sharing; proven readiness for investigations (value 143.00, SEAL 4)
Selected answer: 3. Moderate Autonomy - security patches are deployed with sufficient notice to the customer and testing is possible, except for zero-day patching Value 71 SEAL 4
Notes: Platform patches follow Exoscale's schedule with changelog notice. IaaS customers independently test/patch guest OS. Zero-day platform patches lack advance notice. EU-based vendor, no non-EU dependency.
No evidence provided for this answer.
All possible answer options (4)
- 2. Limited Autonomy - security patches are deployed according to vendor schedules; basic testing is possible (value 35.00, SEAL 1)
- 3. Moderate Autonomy - security patches are deployed with sufficient notice to the customer and testing is possible, except for zero-day patching (value 71.00, SEAL 4) ✓
- 4. High Autonomy - security patches can be deployed independently by the customer, without customers' checks (value 107.00, SEAL 4)
- 5. Full Autonomy - security patches can be deployed independently by the customer, with customers' checks (value 143.00, SEAL 4)
Selected answer: 4. High control by independent entities to request data from the vendor Value 107 SEAL 1
Notes: DPA grants audit rights (annual, 30d notice, NDA) plus Compliance Center self-service access to third-party reports; not unrestricted, so not full control.
No evidence provided for this answer.
All possible answer options (4)
- 2. Limited access to independent entities to the data provided by the vendor (value 35.00, SEAL 1)
- 3. Partial control by independent entities on the data provided by the vendor (value 71.00, SEAL 1)
- 4. High control by independent entities to request data from the vendor (value 107.00, SEAL 1) ✓
- 5. Full control by any idependent entity to perform security and compliance audits (value 143.00, SEAL 4)
SOV-8 — Environmental Sustainability
Environmental sustainability assesses autonomy and resilience of cloud services over the long term in relation to energy usage, dependency and raw material scarcity.
Weight 5%
Selected answer: PUE < 1.5 + roadmap Value 125 SEAL 4
Notes: Exoscale's data center partners (A1 Vienna PUE ≤ 1.4, Equinix PUE ~1.37) are below 1.5, with carbon neutrality roadmap to 2030 and energy efficiency targets.
No evidence provided for this answer.
All possible answer options (5)
- PUE > 0 (value 0.00, SEAL 1)
- PUE < 3 (value 62.00, SEAL 1)
- PUE < 1.5 + roadmap (value 125.00, SEAL 4) ✓
- PUE < 1.3 (value 187.00, SEAL 4)
- PUE < 1.2 EU verified (value 250.00, SEAL 4)
Selected answer: Documented program Value 125 SEAL 3
Notes: Exoscale documents circular economy practices: server reuse, refurbishment, and ISO 14000 LCA, but lacks explicit EU circular economy regulatory alignment or certification.
No evidence provided for this answer.
All possible answer options (5)
- No policy (value 0.00, SEAL 0)
- Circular economy EU-aligned (value 62.00, SEAL 0)
- Documented program (value 125.00, SEAL 3) ✓
- Circular economy EU-aligned (value 187.00, SEAL 4)
- EU-certified lifecycle (value 250.00, SEAL 4)
Selected answer: Detailed EU methodology Value 62 SEAL 1
Notes: Exoscale uses ISO 14000 LCA, aligns with CSRD/ESRS via A1 Group, and provides per-zone carbon data—detailed EU methodology but no evidence of EU audit.
No evidence provided for this answer.
All possible answer options (5)
- No reporting (value 0.00, SEAL 1)
- Detailed EU methodology (value 62.00, SEAL 1) ✓
- Annual report (value 125.00, SEAL 2)
- Detailed EU methodology (value 187.00, SEAL 3)
- EU-audited reporting (value 250.00, SEAL 4)
Selected answer: Mix of EU and non-EU supplies Value 125 SEAL 4
Notes: Swiss data centers use non-EU energy; EU sites (Bulgaria 75%, Croatia 91% renewable) aren't fully green. Mix of EU/non-EU supplies.
No evidence provided for this answer.
All possible answer options (4)
- Only EU energy supplies (value 62.00, SEAL 4)
- Mix of EU and non-EU supplies (value 125.00, SEAL 4) ✓
- Only EU energy supplies (value 187.00, SEAL 4)
- Only green EU energy supplies (value 250.00, SEAL 4)
Data Centres
Exoscale has data centres in Switzerland, Austria, Germany, Croatia and in Bulgaria. According to Exoscale “Several peering connections with major local actors grant first in class performance in our geographical area”. The data centres are:
| Country | City | Name |
|---|---|---|
| Munich | DE-MUC-1 | |
| Sofia | BG-SOF-1 | |
| Zagreb | HR-ZAG-1 | |
| Zurich | CH-DK-2 | |
| Geneva | CH-GVA-2 | |
| Vienna | AT-VIE-1 | |
| Vienna | AT-VIE-2 | |
| Frankfurt | DE-FRA-1 |
More information about the data centres can be found here: Exoscale Data Centres. A map with the geograpical location of the data centres can be found here.
Environmental Policy
Exoscale is basing its environmental policy on several measures
- Renewable Energy
- High Density Rack Design
- Refurbished Equipment
- Extended Server Fleet Life
- Energy-Efficient Design
- Direct Shipping
- Work Policies
All the details about the Exoscale environmental policy are documented on the Exoscale Sustainability page.
Certifications
Over the course of their history, Exoscale have managed to obtain a large number of certifications. These include the basic security certifications as well as a few special, industry-specific ones, such as HDS, TISAX and HIPAA.
All the certifications, standards and frameworks that Exoscale complies with are listed on the Exoscale Compliance page.
Conclusion
As they claim themselves, Exoscale are offering a solid cloud platform. They have a good distribution of data centers to fulfill data residency and geo-redundancy requirements.
Regarding features and services, the Exoscale offering is a solid IaaS range but does not stick out compared to other players. Higher-level services are absent completely as of now and require a lot of platform work by the customer (with the notable exception of a managed Kafka service – something that many others are not offering).
A positive twist to this is that the Exoscale services are “just” repackaged Open Source – it should be relatively easy to move in and out and mix and match with Exoscale.
Resources
- HeadquartersLausanne, Switzerland
- Parent companyA1 Digital International GmbH & Co KG
- Cloud since2013
- ISINAT0000720008
- Websitewww.exoscale.com
BSI C5
CSA STAR
HDS
ISO 27001
SOC 2
TISAX