IONOS is a webhosting and cloud provider owned by United Internet AG. The company was previously known as 1&1 Internet AG. IONOS is part of several projects and initiatives to develop european sovereign infrastructure. They are one of the largest members of Gaia-X and Sovereign-X.
IONOS has a strong history in domain and webhosting, with many products around small company and private websites. With the IONOS Cloud, they are expanding the service portfolio with classic cloud products, such as Object Storage, the AI Model Hub, managed Kubernetes, and a full data platform with the Stackable Data Platform.
IONOS are taking a very unique approach to their cloud console with the Data Centre Designer. It is a visual tool which allows to configure IaaS components with a visual diagram tool. Peak click-ops.
Features & Services
The IONOS platform has the standard set of services, such as Kubernetes, storage, and databases. With a background as server hoster and webhosting provider, IONOS has a complete range in that area, e.g. webhosting, a website builder, a transactional email service, and SEO services.
A unique offering of IONOS is a managed Stackable Data Platform.
Developer Experience
IONOS are providing a variety of tools to work with their platform.
Console & Data Center Designer
At first glance, the IONOS console looks similar to that of other cloud providers: a menu on the left with a list of primitives and a large canvas with details taking the rest of the screen estate.

Taking a closer look, IONOS are following a unique approach with the Data Center Designer for virtual data centers. This graphical designer lets us lay out infrastructure in a visual diagram.

API
The IONOS API is grouped by cloud resource. It is well documented and easy to understand. Since IONOS is providing SDKs for many programming languages and is supporting many configuration management tools, we should very rarely get into the situation where we need to work with the API directly.
SDKs
Like the API, the IONOS SDKs are grouped by resource. One for DBaaS, one for the API gateway, one for the container registry, and so on… The SDKs are available for Golang, Python, Java, Ruby, and Node.js. All SDKs are open source on GitHub.
CLI, Terraform and others
Next to a Command Line Interface (CLI), the IonosCTL and a IONOS Terraform provider, IONOS supports a variety of other tools for configuration management:
- Ansible
- Chef
- Puppet
- Pulumi
Sovereignty Assessment
For the sovereignty assessment, we are following the EU's Cloud Sovereignty Framework. It defines 8 sovereignty objectives and makes sovereignty measurable and quantifiable.
Disclaimer: this assessment is conducted as an outside-in analysis, based on public information and, for some questions, educated guessing. The results may be factually wrong and in no way replace your own due diligence.
Overall Score
77.2 %
SEAL Level
SEAL 2
- Provider
- IONOS
- Framework
- Initial framework from the Sovereignty assessment calculator annex (v1.0)
- Assessment date
- 21. August 2026
- Overall score
- 77.2 %
- SEAL level
- SEAL 2
SOV-1 — Strategic Sovereignty
Strategic sovereignty captures the degree to which a cloud provider (or technology actor) is anchored within the European Union/EEA legal, financial, and industrial ecosystem. It assesses ownership stability, governance influence, and alignment with EU strategic priorities.
Weight 20%
Selected answer: 4. Entirely within the EU Value 125 SEAL 4
Notes: IONOS Group SE (Societas Europaea) HQs in Montabaur, Germany. Ultimate control via United Internet AG (also German) and founder Ralph Dommermuth (German). All governance bodies are EU-based.
Evidence
- IONOS Group SE – Imprint / Legal Notice other 21. August 2026
Official imprint confirming IONOS Group SE is a Societas Europaea headquartered in Montabaur, Germany, with Management and Supervisory Boards all based in Germany.
Relevance: Establishes that the cloud provider's top-level legal entity is an SE under EU law with all governance bodies (Management Board, Supervisory Board) located in Germany/EU jurisdiction. - IONOS Group SE – Investor Relations: Details on the Share other 21. August 2026
Official IR page showing IONOS Group SE shareholder structure: United Internet 63.8%, listed on Frankfurt Stock Exchange, ISIN DE000A3E00M1.
Relevance: Confirms majority ownership by United Internet AG (German entity), ensuring ultimate decision-making authority remains within EU jurisdiction. - United Internet AG – Investor Relations: Facts and Figures other 21. August 2026
Official IR page showing United Internet AG shareholder structure: Ralph Dommermuth holds 54.37% (via RD Holding GmbH & Co. KG, Germany), listed on Frankfurt Stock Exchange.
Relevance: Confirms the ultimate controlling shareholder of United Internet AG (and thereby IONOS) is Ralph Dommermuth, a German national with holding entities in Germany — placing ultimate control entirely within the EU.
All possible answer options (4)
- 1. Entirely outside the EU (value 0.00, SEAL 1)
- 2. Mostly outside the EU (value 41.00, SEAL 1)
- 3. Mostly within the EU (value 83.00, SEAL 3)
- 4. Entirely within the EU (value 125.00, SEAL 4) ✓
Selected answer: 5. Very unlikely Value 125 SEAL 4
Notes: Dommermuth's 54% EU-based control of United Internet (IONOS's 63.8% owner) blocks non-EU takeover; all entities are EU-domiciled.
Evidence
- IONOS Group SE – Imprint / Legal Notice other 21. August 2026
Official imprint confirming IONOS Group SE is a Societas Europaea headquartered in Montabaur, Germany, with Management and Supervisory Boards all based in Germany.
Relevance: Confirms full EU corporate governance anchoring of IONOS; board structure under EU/German law adds legal barrier to non-EU transfer of control. - IONOS Group SE – Investor Relations: Details on the Share other 21. August 2026
Official IR page showing IONOS Group SE shareholder structure: United Internet 63.8%, listed on Frankfurt Stock Exchange, ISIN DE000A3E00M1.
Relevance: Confirms IONOS majority-owned by EU-domiciled United Internet AG, making non-EU control of IONOS dependent on first acquiring its German parent. - United Internet AG – Investor Relations: Facts and Figures other 21. August 2026
Official IR page showing United Internet AG shareholder structure: Ralph Dommermuth holds 54.37% (via RD Holding GmbH & Co. KG, Germany), listed on Frankfurt Stock Exchange.
Relevance: Founder's majority control of IONOS's parent blocks hostile or non-EU takeover; concentrated EU-based ownership provides strategic stability.
All possible answer options (5)
- 1. Very likely (value 0.00, SEAL 4)
- 2. Likely takeover by or transfer to a non-EU sovereign entity (value 31.00, SEAL 4)
- 3. Somewhat likely takeover by or transfer to a non-EU sovereign entity (value 62.00, SEAL 4)
- 4. Unlikely takeover by or transfer to a non-EU sovereign entity (value 93.00, SEAL 4)
- 5. Very unlikely (value 125.00, SEAL 4) ✓
Selected answer: 4. Full influence of EU actors Value 125 SEAL 4
Notes: IONOS Group SE has a Supervisory Board entirely composed of EU nationals (German/Austrian) overseeing strategy; SE structure ensures EU employee co-determination and EU regulatory alignment.
Evidence
- IONOS – Report of the Supervisory Board 2025 other 21. August 2026
Formal Supervisory Board report covering strategy, EU regulatory matters (CSRD, NIS2, EU taxonomy), and board independence/quorum.
Relevance: Shows the board actively addresses EU regulatory and strategic matters, confirming EU actor participation in shaping direction. - IONOS and Broadcom: Making Sovereignty Operational, Not Aspirational other 21. August 2026
Article on how IONOS operationalizes EU cloud sovereignty, investing in sovereign infrastructure responding to EU customer and regulatory demands.
Relevance: Demonstrates EU stakeholder feedback (DORA, NIS2 compliance) directly shaping IONOS technology roadmap and service evolution. - Supervisory Board | IONOS Group SE other 21. August 2026
Official page listing IONOS Group SE Supervisory Board members — all EU nationals overseeing company strategy, appointed until 2028.
Relevance: Confirms governance body of EU actors with mandate to advise and supervise strategic direction including technology roadmap.
All possible answer options (4)
- 1. No influence possible (value 0.00, SEAL 2)
- 2. Through "voice of the customer" public channels (e.g. feedback portals, online communities) (value 41.00, SEAL 2)
- 3. Governance bodies exist with EU actors participation (value 83.00, SEAL 3)
- 4. Full influence of EU actors (value 125.00, SEAL 4) ✓
Selected answer: 4. Majority of funding is EU-based Value 93 SEAL 4
Notes: IONOS is ~64% owned by German-listed United Internet AG, itself ~54% controlled by German founder R. Dommermuth. EU/German financing dominates with some non-EU institutional investors in free float.
Evidence
- IONOS Group SE – Investor Relations: Details on the Share other 21. August 2026
Official IR page showing IONOS Group SE shareholder structure: United Internet 63.8%, listed on Frankfurt Stock Exchange, ISIN DE000A3E00M1.
Relevance: Shows majority (>63%) of IONOS equity held by German parent United Internet AG; remainder is Frankfurt-listed free float. Funding is predominantly EU-based. - IONOS Group SE: Shareholders & Shareholding Structure – MarketScreener other 21. August 2026
Comprehensive shareholder breakdown showing geographical origin: Germany 72.33%, UK 9.21%, France 0.21%, among others. Total 140M shares outstanding.
Relevance: Provides geographic origin of shareholders confirming that >72% of IONOS shares originate from Germany/EU, with only ~9% from UK (non-EU) and remaining from other markets. - United Internet AG – Investor Relations: Facts and Figures other 21. August 2026
Official IR page showing United Internet AG shareholder structure: Ralph Dommermuth holds 54.37% (via RD Holding GmbH & Co. KG, Germany), listed on Frankfurt Stock Exchange.
Relevance: Shows IONOS's ultimate controlling shareholder is German/EU-based. Dommermuth's majority stake in United Internet confirms deep EU financial anchoring.
All possible answer options (5)
- 1. Almost entirely relying on non-EU funding (value 0.00, SEAL 4)
- 2. Mostly relying on non-EU funding (value 31.00, SEAL 4)
- 3. Balanced mix of EU and non-EU funding (value 62.00, SEAL 4)
- 4. Majority of funding is EU-based (value 93.00, SEAL 4) ✓
- 5. Entirely EU-based funding (value 125.00, SEAL 4)
Selected answer: 4. Majority in the EU Value 93 SEAL 4
Notes: IONOS generates >€1.5B revenue primarily in EU markets, employs ~4,000 staff (~65%+ in EU), invests in EU IPCEI-CIS project and EU sovereign cloud; but has non-EU ops in UK, USA, Philippines.
Evidence
- IONOS Corporate Presentation May 2025 (Non-Deal Roadshow) other 21. August 2026
Corporate presentation: ~4,016 employees, 32 data centers (9 owned), #1 web hosting in Europe, FY2024 revenue €1.56B, CapEx €80-90M, sovereign cloud positioning.
Relevance: Provides employee count, data center footprint concentrated in EU, EU market leadership, and EU-focused investment program. Supports assessment of jobs and value creation in EU. - IONOS Reports Successful 2025 Fiscal Year – Profitability at Record Levels other 21. August 2026
Official FY2025 results: €1.32B revenue, €485M EBITDA, 6.63M customers, sovereign cloud investments, ITZBund government contract.
Relevance: Shows revenue generation primarily in EU, sovereign cloud investment, and value creation within EU through government contracts and AI ecosystem development. - IPCEI-CIS: IONOS participates in EU project for cloud and edge computing technologies other 21. August 2026
IONOS sub-project IONORA (€16.9M, €6.8M German gov funding) within EU IPCEI-CIS for energy-efficient data centres and Gaia-X compliant cloud-edge platform (2023-2026).
Relevance: Demonstrates direct EU co-funded investment in cloud sovereignty infrastructure, creating EU value through R&D and technological development aligned with EU strategic priorities.
All possible answer options (5)
- 1. Minimal (value 0.00, SEAL 4)
- 2. Some (value 31.00, SEAL 4)
- 3. Balanced EU/non-EU (value 62.00, SEAL 4)
- 4. Majority in the EU (value 93.00, SEAL 4) ✓
- 5. Fully in the EU (value 125.00, SEAL 4)
Selected answer: 2. Active participant in strategic projects Value 62 SEAL 4
Notes: IONOS is a Day-1 Gaia-X member, participates in IPCEI-CIS (IONORA, €16.9M), and is involved in multiple Horizon Europe projects.
Evidence
- Commission approves €1.2 billion State aid for IPCEI in cloud and edge computing other 21. August 2026
European Commission official press release approving the IPCEI-CIS strategic project, listing IONOS among 19 participating companies.
Relevance: EU-level confirmation that IONOS is a recognized participant in the IPCEI-CIS strategic program, validating its role in advancing EU digital sovereignty. - IONOS Cloud – Gaia-X other 21. August 2026
IONOS Cloud's dedicated Gaia-X page detailing Day-1 membership and involvement in 6 of 11 funded lighthouse projects.
Relevance: Shows IONOS is a founding member of Gaia-X and actively contributes to multiple lighthouse projects, demonstrating deep engagement in EU data sovereignty initiatives. - IPCEI-CIS: IONOS participates in EU project for cloud and edge computing technologies other 21. August 2026
IONOS sub-project IONORA (€16.9M, €6.8M German gov funding) within EU IPCEI-CIS for energy-efficient data centres and Gaia-X compliant cloud-edge platform (2023-2026).
Relevance: Confirms IONOS's formal participation in the EU's flagship IPCEI-CIS strategic funding project, developing sovereign cloud-edge technologies.
All possible answer options (3)
- 1. No clear participation (value 0.00, SEAL 4)
- 2. Active participant in strategic projects (value 62.00, SEAL 4) ✓
- 3. Strategic projects depend on contractor's involvement (value 125.00, SEAL 4)
Selected answer: Bold ambition and dedicated means Value 125 SEAL 4
Notes: IONOS shows bold ambition via EU Parliament engagement, Climate Strategy 2030, Gaia-X Day-1 membership, IPCEI-CIS, and multiple EU R&D projects with dedicated funding and governance.
Evidence
- IONOS Announces Climate Strategy 2030 other 22. August 2026
Comprehensive sustainability roadmap: 55% emission reduction, 100% renewable electricity, 50% own data centres with on-site renewables, already sourcing 99.5% renewable electricity.
Relevance: Demonstrates dedicated means and measurable targets for green sovereignty alignment with EU Green Deal objectives, with already achieved results (99.5% renewable) and ambitious future goals. - IONOS Group SE – Advancing Europe's Digital Sovereignty other 22. August 2026
IONOS hosted a Parliamentary Breakfast at the European Parliament on 'Advancing Europe's Digital Strategic Autonomy,' advocating for the Cloud & AI Development Act and strategic public procurement.
Relevance: Shows bold institutional-level ambition and direct engagement with EU policymakers on digital and industrial sovereignty strategy, going beyond operational compliance to active policy shaping. - IPCEI-CIS: IONOS participates in EU project for cloud and edge computing technologies other 21. August 2026
IONOS sub-project IONORA (€16.9M, €6.8M German gov funding) within EU IPCEI-CIS for energy-efficient data centres and Gaia-X compliant cloud-edge platform (2023-2026).
Relevance: Directly demonstrates alignment with EU digital, green, and industrial sovereignty objectives through funded participation in a major EU industrial project with dedicated means and measurable targets.
All possible answer options (3)
- Existing Action plan (how to measure ambition? Through means linked to the goals? Relative to the size of the company?) (value 41.00, SEAL 4)
- Already measured achievement and existing dedicated governance (value 83.00, SEAL 4)
- Bold ambition and dedicated means (value 125.00, SEAL 4) ✓
Selected answer: 5. Full autonomy and continuity Value 125 SEAL 4
Notes: IONOS operates its own proprietary cloud stack and 12+ data centers, reducing critical vendor dependencies. Open-source alternatives (KVM, Kubernetes) enable sourcing alternatives if key vendor support is withdrawn.
Evidence
- Deploy SUSE Rancher Workloads on IONOS CLOUD other 22. August 2026
IONOS-SUSE Rancher partnership delivering sovereign Kubernetes platform using open standards (Kubernetes, OpenTofu) with no hyperscaler dependency.
Relevance: Highlights use of open standards enabling flexible migration and multi-cloud portability, reducing cut-off risk from any single supplier relationship. - IONOS Celebrates 25 Years of Innovation and Growth other 22. August 2026
IONOS runs its own self-developed cloud stack with 12 self-operated data centers and 90,000+ servers, explicitly not relying on hyperscalers.
Relevance: Demonstrates IONOS has internalized key infrastructure functions via proprietary cloud stack and own data centers, critical for sustaining operations without external vendor support. - The Hypervisor Alternative | IONOS CLOUD other 22. August 2026
IONOS promotes open-source-based IaaS virtualization stack ensuring long-term technological freedom and no proprietary vendor lock-in.
Relevance: Shows IONOS can source open-source alternatives (KVM-based stack) if proprietary virtualization vendors withdraw support, enabling operational continuity.
All possible answer options (4)
- 2. Service would likely stop but with a delay to provide time for customer reaction (value 31.00, SEAL 0)
- 3. Can continue temporarily based on contractual agreement with EC (value 62.00, SEAL 2)
- 4. Ability to source alternative suppliers or internalise key functions (value 93.00, SEAL 2)
- 5. Full autonomy and continuity (value 125.00, SEAL 4) ✓
SOV-2 — Legal & Jurisdictional Sovereignty
Legal & Jurisdictional sovereignty evaluates the legal environment, exposure to foreign authority, and enforceability of rights that govern a technology provider and its services. It determines the extent to which a provider is anchored in European jurisdiction and insulated from external legal claims.
Weight 10%
Selected answer: 3. Exclusively EU law Value 167 SEAL 4
Notes: IONOS Group SE is a Societas Europaea in Montabaur, Germany; parent United Internet AG is German-listed. Operations exclusively under German/EU law.
Evidence
- Articles of Association of IONOS Group SE (Feb 2023) other 22. August 2026
Official Articles of Association of IONOS Group SE; §1 confirms registered seat in Montabaur, Germany, as a Societas Europaea under German law.
Relevance: Directly establishes IONOS as an SE registered in Germany governed by German corporate law and the German Corporate Governance Code — confirms EU-exclusive jurisdiction. - Best European Cloud Provider for Sovereign Hosting — Exoscale other 22. August 2026
Independent comparison classifying IONOS as a European-owned provider governed by European law, with no foreign parent subject to extra-territorial laws.
Relevance: Independently categorizes IONOS as European-owned and exclusively governed by EU law, explicitly distinguishing from US hyperscalers exposed to CLOUD Act. - Sovereignty-washing or real independence? — Computing.co.uk other 22. August 2026
IONOS CEO states services operate under German law for over a decade with no third-party access, contrasting with US hyperscalers subject to CLOUD Act.
Relevance: Explicitly confirms IONOS operates exclusively under German/EU law, not subject to US CLOUD Act or other foreign extra-territorial data access laws.
All possible answer options (3)
- 1. Non-EU only (value 0.00, SEAL 1)
- 2. Mixed EU/non-EU (value 84.00, SEAL 1)
- 3. Exclusively EU law (value 167.00, SEAL 4) ✓
Selected answer: Verified legal immunity, non-EU laws unenforceable Value 167 SEAL 4
Notes: IONOS is a European SE under German parent United Internet AG, not subject to US CLOUD Act/FISA. Own cloud stack, no US hyperscaler dependency. EU jurisdiction governs core operations.
Evidence
- IONOS and Broadcom: Making Sovereignty Operational, Not Aspirational other 21. August 2026
Article on how IONOS operationalizes EU cloud sovereignty, investing in sovereign infrastructure responding to EU customer and regulatory demands.
Relevance: Confirms IONOS operates all customer workloads within European territory under EU jurisdiction, avoiding extra-jurisdictional access by foreign authorities. - IONOS CLOUD Documentation – Glossary of Terms other 22. August 2026
IONOS's official cloud documentation defines 'EU Legal Sovereignty' and 'US CLOUD Act', explaining how EU-based providers are insulated from foreign jurisdictional claims.
Relevance: Directly addresses IONOS's own definition of legal structures that shield from US extraterritorial law via European jurisdiction, infrastructure, and contracts. - IONOS Digital Guide: CLOUD Act vs. Data Privacy and Control other 22. August 2026
IONOS-published analysis of the US CLOUD Act, arguing only European-headquartered providers with EU data centers can offer full legal protection from US extraterritorial reach.
Relevance: Explains why IONOS's corporate structure (EU HQ, EU parent) and operational model legally shield it from CLOUD Act and similar cross-border US laws.
All possible answer options (4)
- Mitigation clauses, exposure remains (value 41.00, SEAL 1)
- EU subsidiary with contractual protections (value 83.00, SEAL 1)
- Legal structures shielding from foreign law (value 125.00, SEAL 2)
- Verified legal immunity, non-EU laws unenforceable (value 167.00, SEAL 4) ✓
Selected answer: 5. Non-EU authorities requests to access data or systems are always rejected by the provider Value 167 SEAL 4
Notes: IONOS disputes direct CLOUD Act requests, redirecting to German authorities. Some MLAT requests may eventually succeed via German courts with GDPR-mandated customer notification.
Evidence
- How IONOS is looking towards privacy and Europe for a solid share of the cloud market other 22. August 2026
IONOS UK head states they are CLOUD Act-safe; if US authorities wanted client data they would need to go to German authorities for a subpoena.
Relevance: Directly quotes IONOS leadership on dispute-and-redirect practice: non-EU authority requests are not honoured directly but are redirected through EU legal channels, indicating a dispute process. - IONOS Digital Guide: CLOUD Act vs. Data Privacy and Control other 22. August 2026
IONOS-published analysis of the US CLOUD Act, arguing only European-headquartered providers with EU data centers can offer full legal protection from US extraterritorial reach.
Relevance: IONOS's own legal analysis acknowledges US CLOUD Act extraterritorial reach and argues only EU-headquartered providers with EU data centres avoid exposure; supports accessibility assessment. - Sovereignty-washing or real independence? (Computing.co.uk) other 22. August 2026
Computing.co.uk analysis on IONOS sovereignty claims based on interview with IONOS CEO; emphasised over a decade of operations under German law with no third-party access.
Relevance: Shows IONOS CEO states services operate under German law with no third-party access available to non-EU authorities; supports dispute stance.
All possible answer options (4)
- 2. Non-EU authorities can compel access to data or systems without customers being notified, in specific cases (value 41.00, SEAL 1)
- 3. Non-EU authorities can compel access to data or systems with customers being notified in all cases (value 83.00, SEAL 1)
- 4. Non-EU authorities requests to access data or systems are disputed by the provider and eventually in some cases are accepted with customers being notified (value 125.00, SEAL 1)
- 5. Non-EU authorities requests to access data or systems are always rejected by the provider (value 167.00, SEAL 4) ✓
Selected answer: Part of the offer cannot be exposed to restrictions towards EU MSs or international organisations Value 167 SEAL 4
Notes: IONOS's core IaaS uses open-source virtualization; part of its offer is free from ITAR/EAR restrictions for EU MSs and international organisations.
Evidence
- Export Controls in the European Union as Regime at Risk of Fragmentation – Global Investigations Review other 22. August 2026
Overview of EU dual-use export control rules (EU 2021/821) and interaction with US regimes
Relevance: Establishes that EU-based providers operate under EU export control regime, not US ITAR/EAR, and that open-source components used by IONOS are not subject to these controls. - IONOS and Broadcom: Making Sovereignty Operational, Not Aspirational other 21. August 2026
Article on how IONOS operationalizes EU cloud sovereignty, investing in sovereign infrastructure responding to EU customer and regulatory demands.
Relevance: Confirms IONOS operates under European ownership, jurisdiction, and governance with EU data centres and EU-based personnel, ensuring EU law applies and ITAR/EAR does not restrict its core offer. - What is Digital Sovereignty? – IONOS Digital Guide other 22. August 2026
Explains how EU-based providers like IONOS protect data under European jurisdiction
Relevance: Shows IONOS stores data in German data centres, operates under EU law, and is not subject to US CLOUD Act or US extraterritorial claims like ITAR/EAR.
All possible answer options (4)
- Restrictions exists towards EU citizens or international organisations (value 41.00, SEAL 1)
- Share of revenues >50% in the EU (value 83.00, SEAL 2)
- Part of the offer cannot be exposed to restrictions towards EU MSs (value 125.00, SEAL 3)
- Part of the offer cannot be exposed to restrictions towards EU MSs or international organisations (value 167.00, SEAL 4) ✓
Selected answer: 4. Mostly within the EU Value 125 SEAL 4
Notes: Core cloud and AI IP developed in Germany (ProfitBricks/1&1 heritage, Berlin). IP registered to IONOS Group SE (EU). Some US technical staff exist but development primarily EU-based.
Evidence
- Bechtle & IONOS Cloud – Open Clouds for Research Environments (OCRE) other 22. August 2026
Bechtle offers IONOS Cloud across 13 European countries, described as 'Made in Germany' with its own code stack and data stored exclusively in German data centres.
Relevance: Confirms IONOS developers its own proprietary code stack in Germany, establishing IP creation and development primarily within the EU. - IONOS Management Team – Decades of Industry Know-How other 22. August 2026
IONOS management page detailing CEO Achim Weiss's founding of ProfitBricks in Berlin, developing Germany's first IaaS cloud stack. CTO leads all product development from Germany.
Relevance: Shows core cloud platform IP was created and developed in Berlin, Germany. Leadership responsible for product development is EU-based, indicating IP creation origin is primarily EU. - IONOS Reports Successful 2025 Fiscal Year – Profitability at Record Levels other 22. August 2026
FY2025 annual results announcement highlighting IONOS Moment AI ecosystem, AI Model Hub, and sovereign European cloud infrastructure—all proprietary developments.
Relevance: Shows IONOS develops proprietary AI products and cloud technology in-house on European infrastructure, reinforcing IP creation and development primarily within the EU.
All possible answer options (4)
- 2. Mostly outside the EU (value 41.00, SEAL 4)
- 3. Mixed within/outside the EU (value 83.00, SEAL 4)
- 4. Mostly within the EU (value 125.00, SEAL 4) ✓
- 5. Fully within the EU (value 167.00, SEAL 4)
Selected answer: EU law with exceptions Value 125 SEAL 4
Notes: IP primarily owned by IONOS Group SE (German SE) under EU/German law, but has US trademark registrations and US subsidiaries, creating minor non-EU IP exposure.
Evidence
- IONOS Group SE Consolidated Financial Statements 2021 other 22. August 2026
Official financial statements listing all subsidiaries and confirming ownership structure under German/EU jurisdiction.
Relevance: Confirms IONOS Group SE as a German-headquartered entity owning 100% of US subsidiaries; ultimate parent United Internet AG controls IP rights under German corporate law. - IONOS Trademark — Trademarkia (USPTO Registration #4298521) other 22. August 2026
USPTO registration for 'IONOS' trademark owned by IONOS SE (Montabaur, Germany), filed 2010, registered 2013, renewed 2023.
Relevance: Shows core IP (IONOS trademark) is owned by the German entity IONOS SE, registered in the US but assigned to a German/EU parent — confirming EU jurisdiction over core IP rights, plus minimal US registration footprint. - United Internet — Wikipedia other 22. August 2026
Overview of United Internet AG, its Montabaur (Germany) HQ, founder Ralph Dommermuth, and majority ownership of IONOS Group SE.
Relevance: Confirms the ultimate parent (United Internet AG) is a German AG with >50% control by Ralph Dommermuth (German national), anchoring IP rights under German/EU jurisdiction.
All possible answer options (4)
- non-EU law, mixed non-EU countries (value 41.00, SEAL 3)
- Mixed law, some EU (value 83.00, SEAL 3)
- EU law with exceptions (value 125.00, SEAL 4) ✓
- fully under EU law (value 167.00, SEAL 4)
SOV-3 — Data & AI Sovereignty
Data & AI sovereignty focuses on the protection, control, and independence of data assets and AI services within the EU/EEA. It addresses how data is secured, where it is processed, and the degree of autonomy customers retain over AI capabilities.
Weight 10%
Selected answer: 4. Customer primary control but provider can read the data or some of the data Value 150 SEAL 3
Notes: Default storage uses provider-managed keys; SSE-C and Confidential VMs offer customer key control. No dedicated KMS with full BYOK/HYOK.
Evidence
- Data Security | IONOS Cloud Block Storage other 22. August 2026
IONOS Block Storage docs: automatic AES-XTS 256-bit encryption with unique per-volume keys, inaccessible to root, retrieved via authenticated IONOS infrastructure processes.
Relevance: Shows default storage encryption keys are provider-managed within IONOS infrastructure, illustrating primary provider control over keys. - IONOS Cloud · Enterprise Fit: Security & Scale (RFP.wiki) other 22. August 2026
Third-party enterprise procurement guide scoring IONOS 3.8/5 on encryption and KMS; notes customer-managed key workflows exist but KMS breadth trails hyperscalers.
Relevance: Independent assessment confirms customer-managed key options exist but are limited compared to hyperscalers, supporting 'Customer primarily control but not exclusively.' - Security and Trust Model | IONOS Cloud Confidential VM other 22. August 2026
IONOS Confidential VM docs: AMD SEV-SNP hardware isolation, user-operated attestation, LUKS2 disk encryption with customer-controlled VMK. IONOS holds no keys.
Relevance: Demonstrates non-exclusive customer key control via Confidential VMs where IONOS cannot access keys or data, justifying 'but not exclusively' part.
All possible answer options (4)
- 2. Primarily the provider but not exclusively (value 50.00, SEAL 1)
- 3. Shared - provider has override keys (value 100.00, SEAL 2)
- 4. Customer primary control but provider can read the data or some of the data (value 150.00, SEAL 3) ✓
- 5. Customer exclusive control - provider can not read the data (value 200.00, SEAL 4)
Selected answer: 4. Full customer controlled visibility of log access but not in real time Value 150 SEAL 3
Notes: IONOS offers customer-controlled, immutable Activity Logs via API (who/what/when/where) with tamper-proof design, but no real-time streaming or alerts. 35-day retention.
Evidence
- Activity Logs - Overview | IONOS Cloud Documentation other 22. August 2026
Official documentation of IONOS Cloud Activity Logs: read-only, tamper-proof audit trail accessible via authenticated GET API by contract owners and administrators.
Relevance: Directly documents customer-controlled access to immutable activity logs capturing user actions, source IPs, timestamps. Confirms contract-level isolation but no real-time streaming. - Activity Logs and Monitoring — IONOS CLOUD Foundational Course other 22. August 2026
Training module covering Activity Logs, Flow Logs, Monitoring Service, and Logging Service for IONOS Cloud observability and compliance.
Relevance: Confirms Activity Logs capture who/what/when/where with tamper-proof design, but 35-day retention and API-only access indicate no real-time access monitoring capability. - Best Practices for IONOS CLOUD Storage Products — Security Safeguards other 22. August 2026
Security best practices guide covering Object Storage access logging, versioning, Object Lock (WORM), and compliance certifications (ISO 27001, IT-Grundschutz, GDPR).
Relevance: Describes audit trail capabilities for object storage access logging and WORM storage for compliance-grade auditability, supporting full customer visibility of data access.
All possible answer options (4)
- 2. Basic logs incomplete (missing date; missing user; missing type of access; missing means of access etc.) (value 50.00, SEAL 1)
- 3. Logs exist but not real-time or controlled by vendor (vendor is replaced by CUSTOMER in the survey) (value 100.00, SEAL 2)
- 4. Full customer controlled visibility of log access but not in real time (value 150.00, SEAL 3) ✓
- 5. Real-time customer oversight and independent auditability (value 200.00, SEAL 4)
Selected answer: 4. Deletion is technically verified with access logs Value 150 SEAL 3
Notes: IONOS uses tamper-proof activity logs verifying deletion and NIST 800-88 media sanitization, but no independent verification or certificates of erasure.
Evidence
- Activity Logs and Monitoring — IONOS CLOUD Foundational Course other 22. August 2026
Training module covering Activity Logs, Flow Logs, Monitoring Service, and Logging Service for IONOS Cloud observability and compliance.
Relevance: Directly relevant: tamper-proof logs record every deletion action, providing technical verification of data deletion with auditable evidence — matches answer option 4. - Best Practices for IONOS CLOUD Storage Products — Security Safeguards other 22. August 2026
Security best practices guide covering Object Storage access logging, versioning, Object Lock (WORM), and compliance certifications (ISO 27001, IT-Grundschutz, GDPR).
Relevance: Documents logging capability tracking deletion events and lifecycle management for permanent removal, but lacks independent verification or erasure certificates. - IONOS Cloud – Backup Service Data Security other 23. August 2026
Details IONOS backup data security including secure deletion via NIST SP 800-88 Rev.1 media sanitization and physical destruction of drives when erasure is not possible.
Relevance: Shows IONOS enforces irreversible removal on decommissioned media per NIST 800-88, but no customer-facing certificates or independent verification of deletion are provided.
All possible answer options (4)
- 2. Manual confirmation only (value 50.00, SEAL 1)
- 3. Internal validation based on policies - no proof of validation left (value 100.00, SEAL 1)
- 4. Deletion is technically verified with access logs (value 150.00, SEAL 3) ✓
- 5. Yes, irreversible deletion is systematically enforced and independently verified (value 200.00, SEAL 4)
Selected answer: 5. All data exclusively in the EU with no third-country fallback Value 200 SEAL 4
Notes: IONOS EU cloud services default to EU data centres (DE, FR, ES), no automatic fallback. But US and UK (post-Brexit third country) DCs exist as customer-chosen options.
Evidence
- Data Protection and Cloud Security | IONOS other 23. August 2026
IONOS Cloud data protection page: GDPR compliance, geo-redundant DCs in Europe and USA, customers choose DC location, data never moved without consent, TOM measures.
Relevance: States data never moves without consent and customers can choose DC location. EU is default for EU customers, but US DCs are available — controlled third-country exception, not strict no-fallback. - IONOS and Broadcom: Making Sovereignty Operational, Not Aspirational other 21. August 2026
Article on how IONOS operationalizes EU cloud sovereignty, investing in sovereign infrastructure responding to EU customer and regulatory demands.
Relevance: Confirms IONOS positions EU jursidiction as default for sovereign cloud, but does not claim exclusion of all third-country infrastructure — consistent with tightly controlled exceptions model. - IONOS Cloud – Data Centers other 23. August 2026
Official IONOS data center locations page listing EU sites (Frankfurt, Berlin, Paris, Logroño) alongside third-country sites (Las Vegas, Newark, Lenexa in US; London, Worcester in UK post-Brexit).
Relevance: Shows IONOS operates data centres in both EU and third countries (US, UK post-Brexit). EU is default for sovereign services, but third-country options exist as customer-chosen exceptions — not strict EU-only.
All possible answer options (4)
- 2. Data partly in the EU, significant reliance on third countries and limited control (value 50.00, SEAL 0)
- 3. Data mainly in the EU, some third-country use with standard safeguards (value 100.00, SEAL 1)
- 4. Data in the EU by default, tightly controlled exceptions (value 150.00, SEAL 1)
- 5. All data exclusively in the EU with no third-country fallback (value 200.00, SEAL 4) ✓
Selected answer: Mixed Control with alternatives: Auditable or open source AI, foreign chips Value 100 SEAL 2
Notes: IONOS uses open-source AI models (Llama, Mistral) hosted in EU, but relies on NVIDIA H200 GPUs. Q.ANT photonic NPU partnership shows EU chip alternatives emerging.
Evidence
- IONOS CLOUD AI Model Hub — Sovereign AI Platform other 23. August 2026
IONOS AI Model Hub offers sovereign AI inference in European data centres with open-weight models (Llama, Mistral, Qwen) via OpenAI-compatible API, no US CLOUD Act exposure.
Relevance: Shows IONOS provides auditable open-source AI models hosted in EU, but Llama (Meta/US) and Qwen (Alibaba/China) origins show mixed non-EU model dependencies. - IONOS Cloud GPU VM — NVIDIA H200 GPUs other 23. August 2026
IONOS Cloud GPU VMs offer NVIDIA H200 PCIe GPUs dedicated for AI training and inference, hosted in Germany with GDPR compliance.
Relevance: Confirms IONOS AI acceleration relies on NVIDIA H200 GPUs (US chip vendor), demonstrating foreign chip dependency for AI workloads despite EU hosting. - Q.ANT Takes Photonic AI Computing Commercial with IONOS other 23. August 2026
Q.ANT partnership brings German-made photonic NPU into IONOS cloud as first commercial EU-designed photonic AI accelerator co-processor.
Relevance: Demonstrates IONOS exploring EU-based AI accelerator alternatives (Q.ANT) alongside foreign GPUs, fitting 'alternatives' criterion of mixed control.
All possible answer options (4)
- Mostly non-EU dependencies: Licensed AI, chip dependency (value 50.00, SEAL 2)
- Mixed Control with alternatives: Auditable or open source AI, foreign chips (value 100.00, SEAL 2) ✓
- EU-led AI, foreign accelerators (value 150.00, SEAL 3)
- EU-origin models and chips - no dependencies from outside EU (value 200.00, SEAL 4)
SOV-4 — Operational Sovereignty
Operational sovereignty measures the practical ability of EU actors to run, support, and evolve a technology independently of foreign control. It focuses on continuity of operations, skill availability, and resilience against external dependencies.
Weight 15%
Selected answer: 4. Formal migration services are available to assist with moving data and workloads Value 125 SEAL 4
Notes: IONOS offers free expert migration services, up to $100K migration grant, open-source IaaS stack, standard image formats, and no vendor lock-in.
Evidence
- How to Do a Server Migration Without Data Loss — IONOS Digital Guide other 25. August 2026
IONOS-authored guide covering server image export/import in multiple formats (.vdi, .qcow2, .vhd, .vmdk), database migration tools, and zero-downtime migration methods.
Relevance: Documents standard methods for data export and workload migration across multiple image formats and tools, illustrating interoperability and portability capabilities. - The Hypervisor Alternative | IONOS CLOUD other 22. August 2026
IONOS promotes open-source-based IaaS virtualization stack ensuring long-term technological freedom and no proprietary vendor lock-in.
Relevance: Directly demonstrates formal migration services including consulting, financial grants, open standards support, and vendor-lock-in-free architecture enabling workload portability. - What is Vendor Lock-In? — IONOS Digital Guide other 25. August 2026
IONOS article explaining cloud vendor lock-in risks and mitigation via open standards, Infrastructure-as-Code (Terraform), and orchestration tools (OpenShift) for portability.
Relevance: Explains IONOS's strategic approach to avoiding vendor lock-in using open standards and IaC, supporting interoperability with alternative EU-controlled solutions.
All possible answer options (4)
- 2. Data export and workload portability is provided on a "best-effort" basis (value 41.00, SEAL 1)
- 3. Standard documented methods for data export are available (value 83.00, SEAL 4)
- 4. Formal migration services are available to assist with moving data and workloads (value 125.00, SEAL 4) ✓
- 5. Solution already deployed on sovereign infrastructure (value 167.00, SEAL 4)
Selected answer: 4. Operational services are predominantly delivered by EU-based teams Value 125 SEAL 3
Notes: IONOS self-develops its cloud stack, operates EU data centres, and delivers support from EU teams. Residual non-EU dependencies remain (hardware, firmware, Broadcom/NVIDIA partnerships), preventing full autonomy.
Evidence
- IONOS — Independent Sovereignty Assessment (EuroTechGuide) other 25. August 2026
Independent assessment scoring IONOS across 8 sovereignty criteria; operational independence scored 4/5, noting EU-based operations, support, and service continuity without hyperscaler runtime control.
Relevance: Directly addresses operational sovereignty: confirms IONOS operates and supports cloud infrastructure from EU data centres under EU jurisdiction, but notes supply-chain dependencies (hardware/firmware globally sourced), aligning with predominantly EU-based operations. - IONOS and Broadcom: Making Sovereignty Operational, Not Aspirational other 21. August 2026
Article on how IONOS operationalizes EU cloud sovereignty, investing in sovereign infrastructure responding to EU customer and regulatory demands.
Relevance: Highlights that operational management, support, and service continuity are delivered by EU-based teams under EU jurisdiction, while also revealing a non-EU vendor partnership (Broadcom/VMware), supporting predominantly but not fully EU-based operations. - IONOS Celebrates 25 Years of Innovation and Growth other 22. August 2026
IONOS runs its own self-developed cloud stack with 12 self-operated data centers and 90,000+ servers, explicitly not relying on hyperscalers.
Relevance: Confirms IONOS independently develops and operates its cloud technology stack without hyperscaler dependency, demonstrating EU-based operational capacity for managing and maintaining the technology.
All possible answer options (4)
- 2. Operational services are partially sourced from within the EU (value 41.00, SEAL 1)
- 3. Operational responsibilities are balanced between EU and non-EU teams (value 83.00, SEAL 3)
- 4. Operational services are predominantly delivered by EU-based teams (value 125.00, SEAL 3) ✓
- 5. The entire technology stack is managed and supported by a fully EU-based team (value 167.00, SEAL 4)
Selected answer: Majority EU, escalation abroad Value 83 SEAL 3
Notes: IONOS employs ~4,182 staff, majority EU-based (Germany, Spain, Romania, Poland, Austria). Non-EU staff in US (DC ops) & Philippines (customer service) support escalation and operations.
Evidence
- IONOS Group SE – Number of Employees & Workforce Data (Revelio Labs) other 25. August 2026
Workforce intelligence showing ~1,911 IONOS SE employees: 55.2% in Western Europe, 19% Southeast Asia, 6.7% North America, with EU-dominant geographic distribution.
Relevance: Directly quantifies EU vs. non-EU staff split, showing majority EU but notable non-EU workforce in Philippines and US for escalation support roles. - Jobs & Career | IONOS Group SE other 25. August 2026
IONOS Group careers page listing 4,000+ employees across 30+ locations, with offices in Germany, Spain, UK, Romania, Philippines, and USA.
Relevance: Confirms EU-majority workforce with key locations in Germany, Spain, Romania (EU) alongside non-EU locations for support and escalation. - United Internet AG Annual Report 2024 – Business Model other 25. August 2026
Parent company annual report detailing IONOS operations across 18 countries, with core EU locations in Germany, Spain, Romania, Poland, Austria and non-EU sites in USA and Philippines.
Relevance: Authoritative source on IONOS geographic footprint confirming EU-majority operations with non-EU escalation capabilities in US and Philippines.
All possible answer options (4)
- Mixed, majority outside EU (value 41.00, SEAL 1)
- Majority EU, escalation abroad (value 83.00, SEAL 3) ✓
- All EU staff (value 125.00, SEAL 3)
- 100% EU staff + clearance (value 167.00, SEAL 4)
Selected answer: 3. The majority of support staff are in the EU but escalations are handled by non-EU teams Value 83 SEAL 3
Notes: IONOS support is predominantly EU-based (DE, ES, FR, AT) but a Cebu, Philippines team handles cloud support incl. 24/7 escalation coverage outside EU jurisdiction.
Evidence
- Cloud Support Specialist – Cebu City, Philippines (IONOS Job Posting) other 25. August 2026
IONOS job posting for Cloud Support Specialist based in Cebu, Philippines, confirming a non-EU cloud support presence.
Relevance: Directly confirms that IONOS cloud support includes non-EU staff, meaning not all support staff reside within the EU. - IONOS and Broadcom: Making Sovereignty Operational, Not Aspirational other 21. August 2026
Article on how IONOS operationalizes EU cloud sovereignty, investing in sovereign infrastructure responding to EU customer and regulatory demands.
Relevance: Highlights IONOS marketing EU-based support for sovereignty, but does not claim ALL support staff are EU-based, leaving room for offshore teams. - IONOS Cloud Support – Contact Information other 25. August 2026
Official IONOS Cloud support contact page listing 24/7 support phone numbers and email for EU countries (DE, AT, FR, ES, IT) and non-EU countries.
Relevance: Shows global 24/7 support structure; the requirement for round-the-clock coverage implies off-hours/escalation handling by non-EU teams.
All possible answer options (4)
- 2. The team is mixed but the majority of support staff reside outside the EU (value 41.00, SEAL 2)
- 3. The majority of support staff are in the EU but escalations are handled by non-EU teams (value 83.00, SEAL 3) ✓
- 4. All support staff are located within the EU (value 125.00, SEAL 3)
- 5. All support staff are located within the EU and hold relevant security clearances (value 167.00, SEAL 4)
Selected answer: 4. EU-only primary repositories - All primary documentation and knowledge repositories are stored in the EU (no routine non-EU storage/processing) Value 125 SEAL 4
Notes: IONOS hosts comprehensive docs and open-source SDKs in the EU. However, a Philippines support team prevents EU-only end-to-end privileged access classification.
Evidence
- IONOS Cloud Documentation Portal other 25. August 2026
Comprehensive technical documentation hub for all IONOS Cloud products: APIs, SDKs, compute, networking, security, databases, with architecture guides and developer references.
Relevance: Directly evidences availability of full technical documentation and operational know-how. Shows EU-hosted documentation covering APIs, SDKs, product guides, and security practices for long-term customer autonomy. - Technical Support Representative — IONOS Philippines (Cebu) other 25. August 2026
LinkedIn job posting for IONOS Technical Support in Cebu, Philippines, describing a captive site with 400+ employees supporting IONOS customers across web hosting and cloud.
Relevance: Evidences non-EU support presence, preventing option 5. The Philippines team provides customer support with access to systems, meaning privileged support access is not restricted to EU-based staff. - The Hypervisor Alternative | IONOS CLOUD other 22. August 2026
IONOS promotes open-source-based IaaS virtualization stack ensuring long-term technological freedom and no proprietary vendor lock-in.
Relevance: Demonstrates source code availability and open architecture enabling long-term autonomy. Shows IONOS commitment to open standards and customer independence through non-proprietary technology.
All possible answer options (4)
- 2. EU optional, not enforced - EU storage is available as an option, but it is not enforced (value 41.00, SEAL 2)
- 3. EU primary with non-EU fallback - Stored/managed in the EU by default, but some storage/replication/access outside the EU may occur (e.g., disaster recovery/support) (value 83.00, SEAL 4)
- 4. EU-only primary repositories - All primary documentation and knowledge repositories are stored in the EU (no routine non-EU storage/processing) (value 125.00, SEAL 4) ✓
- 5. EU-only end-to-end - Content, metadata, and backups/replicas are stored in the EU and privileged administration/support access is restricted to EU-based staff under EU jurisdiction (value 167.00, SEAL 4)
Selected answer: 4. Ability to source alternative suppliers or internalise key functions Value 125 SEAL 3
Notes: Self-developed IaaS stack&owned DCs give strong base;residual non-EU supplier deps (Equinix,NVIDIA,VMware) prevent full autonomy.
Evidence
- IONOS and Broadcom: Making Sovereignty Operational, Not Aspirational other 21. August 2026
Article on how IONOS operationalizes EU cloud sovereignty, investing in sovereign infrastructure responding to EU customer and regulatory demands.
Relevance: Details IONOS-Broadcom supplier relationship under EU jurisdiction; shows dependencies on US tech supplier but contracts under European law with single EU accountability. - IONOS Celebrates 25 Years of Innovation and Growth other 22. August 2026
IONOS runs its own self-developed cloud stack with 12 self-operated data centers and 90,000+ servers, explicitly not relying on hyperscalers.
Relevance: Demonstrates proprietary IaaS platform and owned infrastructure reducing external supplier dependencies; ability to internalize key functions. - IONOS Cloud – Data Centers other 23. August 2026
Official IONOS data center locations page listing EU sites (Frankfurt, Berlin, Paris, Logroño) alongside third-country sites (Las Vegas, Newark, Lenexa in US; London, Worcester in UK post-Brexit).
Relevance: Reveals key supplier dependency on Equinix (US) for Frankfurt colocation, highlighting non-EU supplier involvement in core service delivery.
All possible answer options (4)
- 2. Service would likely stop but with a delay to provide time for customer reaction (value 41.00, SEAL 2)
- 3. Can continue temporarily based on contractual agreement with EC (value 83.00, SEAL 3)
- 4. Ability to source alternative suppliers or internalise key functions (value 125.00, SEAL 3) ✓
- 5. Full autonomy and continuity (value 167.00, SEAL 4)
SOV-5 — Supply Chain Sovereignty
Supply chain sovereignty evaluates the geographic origin, transparency, and resilience of the technology supply chain, focusing on the extent to which critical components and processes remain under EU control or exposed to non-EU dependencies.
Weight 10%
Selected answer: Transparent with exceptions Value 71 SEAL 3
Notes: IONOS names some suppliers (Intel, AMD, NVIDIA, Fujitsu) but does not disclose geographic origin of key physical components or publish a component provenance report.
Evidence
- IONOS — Environmental Protection and Sustainability other 26. August 2026
Sustainability page describing hardware lifecycle, recycling, ISO 14001/50001 certifications, and partner logos (AMD, Intel, Fujitsu, Computacenter).
Relevance: Names hardware partners and covers recycling practices but does not trace component geographic provenance or country-of-origin for servers. - IONOS Cloud – Compute Engine other 26. August 2026
IONOS Cloud product page listing CPU families from Intel and AMD used in its infrastructure, including AMD EPYC and Intel Xeon generations.
Relevance: Discloses silicon-level suppliers (Intel, AMD) but not server chassis, memory, storage vendors, or component country of origin—limited supply chain transparency. - IONOS Group SE – Supply Chains (Corporate Governance) other 26. August 2026
IONOS Group's supply chain due diligence page covering German LkSG compliance, Business Partner Code of Conduct, and human rights principles.
Relevance: Covers supplier governance and LkSG due diligence but does not disclose geographic origins of physical components or hardware sourcing mapping.
All possible answer options (4)
- Partial disclosure (value 35.00, SEAL 1)
- Transparent with exceptions (value 71.00, SEAL 3) ✓
- Full transparency (value 107.00, SEAL 3)
- EU-certified provenance (value 143.00, SEAL 4)
Selected answer: Mixed sourcing, EU audit rights Value 71 SEAL 3
Notes: IONOS uses foreign processors (Intel/AMD, US/Taiwan fabs) alongside EU-made components (Q.ANT NPU, Stuttgart), with LkSG-based audit rights.
Evidence
- IONOS Cloud – Compute Engine other 26. August 2026
IONOS Cloud product page listing CPU families from Intel and AMD used in its infrastructure, including AMD EPYC and Intel Xeon generations.
Relevance: Shows IONOS relies on foreign-manufactured CPUs (Intel/AMD), key to assessing hardware manufacturing location. - IONOS Group SE – Supply Chains (Corporate Governance) other 26. August 2026
IONOS Group's supply chain due diligence page covering German LkSG compliance, Business Partner Code of Conduct, and human rights principles.
Relevance: Demonstrates EU audit rights over supply chain through German LkSG, relevant to mixed sourcing assessment. - Q.ANT Takes Photonic AI Computing Commercial with IONOS other 23. August 2026
Q.ANT partnership brings German-made photonic NPU into IONOS cloud as first commercial EU-designed photonic AI accelerator co-processor.
Relevance: Shows EU-manufactured hardware component in IONOS cloud, supporting mixed sourcing assessment.
All possible answer options (4)
- Foreign origin, partial disclosure (value 35.00, SEAL 1)
- Mixed sourcing, EU audit rights (value 71.00, SEAL 3) ✓
- Build by EU Teams, on the basis of a foreign code (value 107.00, SEAL 3)
- Exclusive designed and build by EU Teams (value 143.00, SEAL 4)
Selected answer: Transparent with exceptions Value 71 SEAL 4
Notes: SLSA L2 firmware provenance and detailed CPU disclosure show strong transparency, but hardware is globally sourced (AMD/Intel) and no SBOM is published
Evidence
- IONOS — Independent Sovereignty Assessment (EuroTechGuide) other 25. August 2026
Independent assessment scoring IONOS across 8 sovereignty criteria; operational independence scored 4/5, noting EU-based operations, support, and service continuity without hyperscaler runtime control.
Relevance: External assessment confirms IONOS transparency on software but flags structural non-EU hardware supply chain dependency, limiting full transparency - IONOS CLOUD Documentation – Glossary of Terms other 22. August 2026
IONOS's official cloud documentation defines 'EU Legal Sovereignty' and 'US CLOUD Act', explaining how EU-based providers are insulated from foreign jurisdictional claims.
Relevance: Directly documents firmware provenance (SLSA L2) and cryptographic attestation for embedded code controlling hardware, key to the assessment question - IONOS Group SE – Supply Chains (Corporate Governance) other 26. August 2026
IONOS Group's supply chain due diligence page covering German LkSG compliance, Business Partner Code of Conduct, and human rights principles.
Relevance: Documents IONOS supply chain governance framework covering business partners and hardware suppliers under German/EU law, but lacks component-level provenance
All possible answer options (4)
- Partial disclosure (value 35.00, SEAL 4)
- Transparent with exceptions (value 71.00, SEAL 4) ✓
- Full transparency (value 107.00, SEAL 4)
- EU-certified provenance (value 143.00, SEAL 4)
Selected answer: 3. Core and essential parts of the software are designed and maintained by EU teams Value 71 SEAL 3
Notes: IONOS self-develops its core cloud stack (KVM, storage, networking) with EU-based teams, but relies on foreign software (VMware, Red Hat, NVIDIA) for non-core tiers.
Evidence
- Digital Sovereignty in Action: Building Resilient, Compliant, and Transparent Cloud Ecosystems (IDC InfoBrief, sponsored by Red Hat) other 27. August 2026
IDC InfoBrief profiling IONOS's sovereign cloud strategy: self-developed open-source cloud stack (own KVM, self-written storage/networking), minimal third-party dependencies, and Red Hat integration.
Relevance: Confirms IONOS core cloud stack is EU-developed with little third-party dependency, while acknowledging Red Hat (US-origin) integration, directly addressing software origin. - IONOS Celebrates 25 Years of Innovation and Growth other 22. August 2026
IONOS runs its own self-developed cloud stack with 12 self-operated data centers and 90,000+ servers, explicitly not relying on hyperscalers.
Relevance: Establishes that core software architecture and development originate from EU-based in-house teams, supporting EU origin of the platform's essential software components. - IONOS SE – Broadcom (VMware) Insights Partner Page other 27. August 2026
Broadcom partner page describing IONOS as sole IaaS provider in Germany with its own code stack, while also detailing VMware-based private cloud offering (US-origin software).
Relevance: Highlights both EU-developed core stack and foreign-origin (VMware/Broadcom) software dependency in private cloud tier, justifying partial rather than full EU software origin.
All possible answer options (4)
- 2. Software is of foreign origin with partial disclosure on its development (value 35.00, SEAL 2)
- 3. Core and essential parts of the software are designed and maintained by EU teams (value 71.00, SEAL 3) ✓
- 4. A large majority of the software is designed and maintained by EU teams (value 107.00, SEAL 3)
- 5. The software is exclusively designed and maintained by EU teams (value 143.00, SEAL 4)
Selected answer: 5. EU control and EU policy gates - As (4), plus EU-based compliance/security gates enforced in the pipeline (e.g., signing under your control, vulnerability checks, segregation of duties, auditable approvals) Value 143 SEAL 4
Notes: IONOS builds with SLSA L2 provenance, Sigstore Rekor logs, CI/CD vulnerability scanning under EU jurisdiction—meets level 5 policy gate criteria.
Evidence
- Configure Vulnerability Scanning – IONOS Cloud Private Container Registry other 27. August 2026
Documents automated vulnerability scanning on every artifact push to IONOS Private Container Registry, designed for CI/CD integration with severity-based reporting.
Relevance: Demonstrates an EU-based security gate (vulnerability checks) enforced in the software packaging/distribution pipeline, a key criterion for assessment level 5. - IONOS CLOUD Documentation – Glossary of Terms other 22. August 2026
IONOS's official cloud documentation defines 'EU Legal Sovereignty' and 'US CLOUD Act', explaining how EU-based providers are insulated from foreign jurisdictional claims.
Relevance: Directly documents IONOS's EU-based build signing, provenance attestation, and transparency log practices—key policy gates for software origin and supply chain sovereignty. - Security and Trust Model | IONOS Cloud Confidential VM other 22. August 2026
IONOS Confidential VM docs: AMD SEV-SNP hardware isolation, user-operated attestation, LUKS2 disk encryption with customer-controlled VMK. IONOS holds no keys.
Relevance: Shows IONOS enforces EU-controlled signing, auditable build provenance, and transparency logs as security gates in their software distribution pipeline.
All possible answer options (4)
- 2. EU control, non-EU execution - Execution is performed by non-EU teams, but pipeline administration and final release approvals are under EU jurisdiction (value 35.00, SEAL 1)
- 3. Non-EU control, EU execution - Execution is performed by EU teams, but pipeline administration and/or final release approvals (incl. signing) are under non-EU jurisdiction (value 71.00, SEAL 3)
- 4. EU control & execution - Build/release/deployment is executed by EU teams and governed from within the EU (pipeline administration, signing, approvals) (value 107.00, SEAL 3)
- 5. EU control and EU policy gates - As (4), plus EU-based compliance/security gates enforced in the pipeline (e.g., signing under your control, vulnerability checks, segregation of duties, auditable approvals) (value 143.00, SEAL 4) ✓
Selected answer: Few non-EU vendors or facilities involved in non-critical services, documented Value 107 SEAL 3
Notes: Core IaaS stack is self-developed (EU), but critical deps on non-EU vendors (Intel/AMD CPUs, Broadcom/VMware, NVIDIA) exist and are transparently documented via LkSG, Business Partner Code of Conduct.
Evidence
- IONOS — Independent Sovereignty Assessment (EuroTechGuide) other 25. August 2026
Independent assessment scoring IONOS across 8 sovereignty criteria; operational independence scored 4/5, noting EU-based operations, support, and service continuity without hyperscaler runtime control.
Relevance: Independently confirms non-EU vendor dependencies in critical hardware (processors, firmware) for IONOS infrastructure, directly relevant to single point of dependency assessment. - IONOS Group SE – Supply Chains (Corporate Governance) other 26. August 2026
IONOS Group's supply chain due diligence page covering German LkSG compliance, Business Partner Code of Conduct, and human rights principles.
Relevance: Demonstrates transparent documentation of supply chain dependencies and due diligence, showing non-EU vendor relationships are formally documented and managed. - IONOS SE – Broadcom (VMware) Insights Partner Page other 27. August 2026
Broadcom partner page describing IONOS as sole IaaS provider in Germany with its own code stack, while also detailing VMware-based private cloud offering (US-origin software).
Relevance: Documents a concrete non-EU vendor dependency (Broadcom/VMware) for IONOS Private Cloud, a critical service offering, illustrating single point of dependency on US proprietary technology.
All possible answer options (4)
- Mostly non-EU vendors or facilities involved in critical services, non documented (value 35.00, SEAL 1)
- Few non-EU vendors or facilities involved in critical services, non documented, or non-EU vendors/facilities transparently documented (value 71.00, SEAL 2)
- Few non-EU vendors or facilities involved in non-critical services, documented (value 107.00, SEAL 3) ✓
- No depedency on non-EU vendor or facility (value 143.00, SEAL 4)
Selected answer: Critical suppliers and subcontractors can be audited Value 71 SEAL 2
Notes: LkSG compliance enables risk-based audits of critical suppliers; no evidence of audit rights across the entire sub-supplier chain.
Evidence
- IONOS and Broadcom: Making Sovereignty Operational, Not Aspirational other 21. August 2026
Article on how IONOS operationalizes EU cloud sovereignty, investing in sovereign infrastructure responding to EU customer and regulatory demands.
Relevance: Highlights IONOS as single contractually accountable EU provider but does not evidence full audit transparency across all supply chain tiers. - IONOS Business Partner Code of Conduct other 28. August 2026
Binding code setting minimum standards for suppliers, requiring cascade of principles through the supply chain and violation reporting via Integrity Line.
Relevance: Code requires suppliers to cascade principles to sub-suppliers but does not grant IONOS direct audit rights over all sub-supplier tiers. - IONOS Group SE – Supply Chains (Corporate Governance) other 26. August 2026
IONOS Group's supply chain due diligence page covering German LkSG compliance, Business Partner Code of Conduct, and human rights principles.
Relevance: Shows IONOS applies risk-based due diligence under LkSG, focusing on critical suppliers — not comprehensive audit rights across all sub-suppliers.
All possible answer options (4)
- Some suppliers and subcontractors can be audited (value 35.00, SEAL 1)
- Critical suppliers and subcontractors can be audited (value 71.00, SEAL 2) ✓
- Most suppliers and subcontractors can be audited (value 107.00, SEAL 3)
- All suppliers and subcontractors can be audited (value 143.00, SEAL 4)
SOV-6 — Technology Sovereignty
Technology sovereignty evaluates the degree of openness, transparency, and independence in the underlying technological stack, ensuring EU actors can interoperate, audit, and evolve solutions without lock-in to foreign proprietary systems.
Weight 15%
Selected answer: 4. Standards-based and broadly compatible - Interfaces and data formats predominantly follow recognised open standards (e.g., ETSI/CEN/CENELEC, ISO/IEC, IETF/W3C) with stable versioning and full documentation Value 150 SEAL 3
Notes: IONOS uses open standards (S3, OpenTelemetry, OpenAI-compatible, Kubernetes, OpenAPI) for most APIs and co-founded SECA, but compute management remains partly IONOS-specific.
Evidence
- IONOS Cloud API Overview — Developer Reference other 28. August 2026
Comprehensive hub listing 20+ IONOS Cloud APIs with OpenAPI/Swagger specs across compute, storage, networking, databases, containers, and observability.
Relevance: Shows broad API coverage documented via OpenAPI specifications. Object Storage uses S3 standards; Tracing is OpenTelemetry-native; AI Model Hub is OpenAI-compatible — wide standards adoption. - IONOS Cloud Object Storage — S3 Compatible other 28. August 2026
Official IONOS Cloud Object Storage product page confirming S3 API compatibility, encryption, lifecycle management, and access via any S3-compatible client.
Relevance: Demonstrates concrete adoption of recognised open standards (S3 API) for a critical cloud storage service, supporting third-party integration and portability without vendor lock-in. - SECA — Sovereign European Cloud API other 28. August 2026
IONOS co-founded SECA, an open industry-standard API specification enabling cross-provider cloud interoperability across European IaaS environments.
Relevance: Directly demonstrates IONOS's commitment to open, non-proprietary cloud infrastructure APIs enabling interoperability between European providers, a strong signal of standards-based openness.
All possible answer options (4)
- 2. Restricted proprietary APIs - Some vendor APIs exist, but they are limited/restricted (access, scope, licensing) and interoperability remains vendor-controlled (value 50.00, SEAL 1)
- 3. Mixed (partial openness) - Key interfaces are documented and partly standards-based, but important functions or data formats remain proprietary/vendor-specific (value 100.00, SEAL 2)
- 4. Standards-based and broadly compatible - Interfaces and data formats predominantly follow recognised open standards (e.g., ETSI/CEN/CENELEC, ISO/IEC, IETF/W3C) with stable versioning and full documentation (value 150.00, SEAL 3) ✓
- 5. Open-by-default with portability - All critical functions are accessible via open, well-documented, non-proprietary APIs and standard formats, with published specifications and minimal vendor-specific dependencies enabling easy third-party integration (value 200.00, SEAL 4)
Selected answer: 4. Policy for most core services - A formal policy mandates and documents open standards for most core services, with managed exceptions Value 150 SEAL 3
Notes: IONOS mandates open standards across most core services (S3, OpenAPI, K8s, OpenTelemetry) and co-founded SECA; VMware private cloud remains a managed exception.
Evidence
- IONOS CLOUD – EU Data Act Guidance other 28. August 2026
Official IONOS documentation explicitly stating adherence to open standards and interoperable interfaces for data portability and export under EU Data Act.
Relevance: Formal policy-level statement: 'IONOS CLOUD adheres to open standards and interoperable interfaces' documenting commitment to open standards as a governance principle for service transition. - IONOS CLOUD Service Catalog other 28. August 2026
Comprehensive catalog showing open standards across core services: S3-compatible Object Storage, OpenAPI APIs, OpenTelemetry, Managed Kubernetes, SUSE Rancher, ZFS/NFS v4.2.
Relevance: Demonstrates breadth of open standards adoption across compute, storage, networking, containers, and observability; VMware-based private cloud is the main proprietary exception. - SECA – Sovereign European Cloud API other 28. August 2026
IONOS co-founded open, royalty-free API standard for cross-provider cloud infrastructure management based on OpenAPI, with public GitHub RFC process.
Relevance: Demonstrates governance-level commitment to open standards: IONOS co-founded a license-free, OpenAPI-based industry standard for cross-provider interoperability under the EU IPCEI-CIS programme.
All possible answer options (4)
- 2. Ad hoc use - Open standards are used inconsistently on a case-by-case basis, without documented rationale or governance (value 50.00, SEAL 0)
- 3. Partial core adoption - Open standards are used and documented for some core services, while other core services remain proprietary/vendor-specific (value 100.00, SEAL 2)
- 4. Policy for most core services - A formal policy mandates and documents open standards for most core services, with managed exceptions (value 150.00, SEAL 3) ✓
- 5. Policy for all core services - A formal policy mandates and documents open standards for all core services (value 200.00, SEAL 4)
Selected answer: 4. The software is open source with significant EU contributions but governance is restricted and handover is possible Value 150 SEAL 4
Notes: IONOS builds on open-source (KVM) and co-created SECA (Apache-2.0, EU-funded). Governance limited to founding partners; handover possible via open standard.
Evidence
- SECA — Sovereign European Cloud API other 28. August 2026
IONOS co-founded SECA, an open industry-standard API specification enabling cross-provider cloud interoperability across European IaaS environments.
Relevance: Demonstrates IONOS's role in open-source EU cloud standard with multi-provider governance, restricted to founding partners but enabling interoperability and handover via open standards. - SECA API Specification – GitHub Repository other 28. August 2026
Open source (Apache-2.0) SECA API spec repository, funded by EU NextGenerationEU/IPCEI-CIS, sponsored by Aruba and IONOS SE.
Relevance: Shows IONOS contributes to open-source software with significant EU funding. Governance is restricted to founding sponsors, not an independent foundation, but open RFC process enables handover. - The Hypervisor Alternative | IONOS CLOUD other 22. August 2026
IONOS promotes open-source-based IaaS virtualization stack ensuring long-term technological freedom and no proprietary vendor lock-in.
Relevance: Confirms IONOS builds its cloud infrastructure on open-source components (KVM, OpenStack), giving transparency and avoiding proprietary lock-in in the core virtualization layer.
All possible answer options (4)
- 2. Source code is available for review but modification and handover rights are under very strict conditions (value 50.00, SEAL 2)
- 3. The software is open source , permitting modification and redistribution, but governance is centralised (e.g., single-company or non-open foundation), limiting strategic autonomy or smooth handover (value 100.00, SEAL 3)
- 4. The software is open source with significant EU contributions but governance is restricted and handover is possible (value 150.00, SEAL 4) ✓
- 5. Fully open-source software is governed by an independent or EU-based entity, granting full rights to audit, modify, redistribute, and seamlessly transfer stewardship (value 200.00, SEAL 4)
Selected answer: Large corpus of public insight exists (all) Value 150 SEAL 3
Notes: IONOS publicly documents full architecture, data flows, dependencies via service catalog, 20+ OpenAPI specs, SECA standard on GitHub, Flow Logs, and observability tools across all aspects.
Evidence
- IONOS Cloud API Overview — Developer Reference other 28. August 2026
Comprehensive hub listing 20+ IONOS Cloud APIs with OpenAPI/Swagger specs across compute, storage, networking, databases, containers, and observability.
Relevance: Demonstrates full dependency and interface transparency via machine-readable OpenAPI specifications covering all service components and their interactions. - IONOS CLOUD Service Catalog other 28. August 2026
Comprehensive catalog showing open standards across core services: S3-compatible Object Storage, OpenAPI APIs, OpenTelemetry, Managed Kubernetes, SUSE Rancher, ZFS/NFS v4.2.
Relevance: Provides comprehensive public architectural documentation covering service design, internal data flows, networking topology, dependencies, and observability — all three assessment aspects. - SECA API Specification – GitHub Repository other 28. August 2026
Open source (Apache-2.0) SECA API spec repository, funded by EU NextGenerationEU/IPCEI-CIS, sponsored by Aruba and IONOS SE.
Relevance: Shows IONOS goes beyond documentation — the open, royalty-free SECA standard with public RFC process on GitHub allows customer and community contribution to cloud API design and architecture.
All possible answer options (4)
- Insight accessible during audits (value 50.00, SEAL 2)
- Some public insight exists (all) (value 100.00, SEAL 3)
- Large corpus of public insight exists (all) (value 150.00, SEAL 3) ✓
- Customers can contribute to adapt and enhance the service (value 200.00, SEAL 4)
Selected answer: Co-designed or integrated in EU Value 100 SEAL 3
Notes: Uses foreign Intel/AMD processors but integrates EU-designed, EU-fabbed Q.ANT photonic NPU accelerator and operates own EU-developed open-source software stack.
Evidence
- IONOS Cloud – Compute Engine other 26. August 2026
IONOS Cloud product page listing CPU families from Intel and AMD used in its infrastructure, including AMD EPYC and Intel Xeon generations.
Relevance: Confirms IONOS relies on foreign-designed processors (Intel/AMD), not EU processor IP, limiting HPC processor sovereignty to integration level. - Q.ANT Takes Photonic AI Computing Commercial with IONOS other 23. August 2026
Q.ANT partnership brings German-made photonic NPU into IONOS cloud as first commercial EU-designed photonic AI accelerator co-processor.
Relevance: Shows IONOS integrating an EU-designed and EU-fabricated AI accelerator — a key data point for European HPC accelerator independence. NPU co-manufactured with IMS CHIPS in Stuttgart. - The Hypervisor Alternative | IONOS CLOUD other 22. August 2026
IONOS promotes open-source-based IaaS virtualization stack ensuring long-term technological freedom and no proprietary vendor lock-in.
Relevance: Demonstrates IONOS operates its own EU-developed software stack for cloud/HPC virtualization, adding software sovereignty to the European independence assessment.
All possible answer options (4)
- EU-hosted, foreign stack (value 50.00, SEAL 3)
- Co-designed or integrated in EU (value 100.00, SEAL 3) ✓
- EU processor IP, non-EU fabs (value 150.00, SEAL 3)
- EU design + EU fab + EU ops (value 200.00, SEAL 4)
SOV-7 — Security & Compliance Sovereignty
Security & Compliance sovereignty measures the extent to which security operations, compliance obligations, and resilience measures are controlled within the EU , ensuring independence from foreign jurisdictions and long-term operational assurance.
Weight 15%
Selected answer: EAL4-5 Value 143 SEAL 4
Notes: IONOS holds an extensive EU and international certification portfolio: BSI C5 (Type 1 & 2), IT-Grundschutz, ISO 27001/27017/27018, SOC 1-3, PCI DSS, ISAE 3000, and more.
Evidence
- Certificates & Attestations | IONOS CLOUD other 28. August 2026
Official IONOS certifications page listing BSI C5:2020 Type 1, ISAE 3000, IT-Grundschutz, ISO/IEC 27001, ISO 50001, CNCF Certified Kubernetes, GDPR compliance, and Gaia-X membership.
Relevance: Directly confirms the full breadth of EU and international security certifications held by IONOS, including BSI C5, IT-Grundschutz, and ISO 27001 — key for assessing certification attainment level. - IONOS – Cloud Mercato Provider Profile other 28. August 2026
Third-party cloud comparison platform independently confirming IONOS holds BSI C5 Type 1 & Type 2, ISO 27001:2022, ISO 27017:2015 (cloud security), and ISO 27018:2019 (PII protection) certifications.
Relevance: Independently verifies IONOS's extensive international certifications including cloud-specific ISO 27017 and 27018, supporting the highest assessment level for certification attainment. - IONOS Receives C5 Certification for Compute Engine, Cloud Cubes and S3 Object Storage other 28. August 2026
IONOS Group press release announcing BSI C5 Type 1 certification for cloud services and noting that IONOS is the first German provider to hold both C5 and IT-Grundschutz certifications simultaneously.
Relevance: Confirms IONOS holds the highest German/EU cloud security standard (C5) and the IT-Grundschutz certification, demonstrating top-tier EU-recognized security certification attainment.
All possible answer options (4)
- ELA1 (value 35.00, SEAL 1)
- EAL2 (value 71.00, SEAL 2)
- ELA3 (value 107.00, SEAL 3)
- EAL4-5 (value 143.00, SEAL 4) ✓
Selected answer: 4. Partial compliance to most of the well-known EU Regulations (requirements implemented and operational with minor exceptions) Value 107 SEAL 4
Notes: Strong GDPR compliance & BSI C5/ISO audited certs, but no demonstrable DORA compliance and NIS2 only indirectly evidenced via existing certifications.
Evidence
- Data Protection and Cloud Security | IONOS other 23. August 2026
IONOS Cloud data protection page: GDPR compliance, geo-redundant DCs in Europe and USA, customers choose DC location, data never moved without consent, TOM measures.
Relevance: Directly demonstrates IONOS's formal GDPR adherence as processor with documented TOMs including encryption, pseudonymization, and resilience measures. - IONOS Receives C5 Certification for Compute Engine, Cloud Cubes and S3 Object Storage other 29. August 2026
IONOS newsroom announcement of BSI C5 Type 1 attestation covering 190+ control mechanisms, plus IT-Grundschutz certification — independently audited.
Relevance: Independently audited BSI C5 and IT-Grundschutz certifications demonstrate formal, verified compliance with stringent German/EU cloud security standards foundational to GDPR and NIS2. - What is the NIS2 Directive? – IONOS Digital Guide other 29. August 2026
IONOS-published comprehensive guide on NIS2 Directive obligations including risk management, incident reporting, and executive liability.
Relevance: Shows IONOS's direct engagement with NIS2 requirements; however, it is educational rather than a formal compliance attestation, indicating awareness but not fully verified NIS2 compliance.
All possible answer options (4)
- 2. Limited compliance to some well-known EU Regulations (basic practices exist but informal, incomplete, or non-systematic) (value 35.00, SEAL 4)
- 3. Moderate compliance to some well-know EU Regulations (controls exist but gaps remain; compliance not fully demonstrated) (value 71.00, SEAL 4)
- 4. Partial compliance to most of the well-known EU Regulations (requirements implemented and operational with minor exceptions) (value 107.00, SEAL 4) ✓
- 5. Fully compliant to all well-know EU regulations (verified compliance, independently audited) (value 143.00, SEAL 4)
Selected answer: 5. The full incident lifecycle is handled by EU-based teams with active participation in ENISA's information sharing frameworks. Threat intelligence and incident data are gathered worldwide Value 143 SEAL 4
No evidence provided for this answer.
All possible answer options (4)
- 2. A hybrid model is used with SOC functions split between EU and non-EU locations (value 35.00, SEAL 1)
- 3. The primary SOC is in the EU but incidents may be escalated to non-EU teams (value 71.00, SEAL 1)
- 4. The entire incident lifecycle is handled by teams operating exclusively within the EU. Threat intelligence and incident data obtained mostly via EU sources (value 107.00, SEAL 3)
- 5. The full incident lifecycle is handled by EU-based teams with active participation in ENISA's information sharing frameworks. Threat intelligence and incident data are gathered worldwide (value 143.00, SEAL 4) ✓
Selected answer: 4. Customers have full direct access to their security monitoring and logs which are stored in the EU Value 107 SEAL 3
Notes: IONOS provides direct API access to activity logs, monitoring with Grafana, logging & flow logs in EU DCs. Tamper-proof archive requires customer-built Object Lock setup, not native immutability.
Evidence
- Activity Logs | Products — IONOS Cloud Documentation other 29. August 2026
Official IONOS docs for Activity Logs: per-contract, read-only audit of all user actions (logins, provisioning, config changes, data access). Accessed via GET API, downloadable as JSON.
Relevance: Confirms customers have full direct access to security audit logs via API. Logs are real-time and detailed, well beyond basic portal or periodic reports. - Activity Logs and the Audit Trail — IONOS CLOUD Expert Course other 29. August 2026
IONOS training unit explaining Activity Log is read-only GET-only API, 35-day retention. Tamper-proof archive requires customer export to Object Storage with Object Lock (WORM). German-region EU storage.
Relevance: Details IONOS activity logs accessible directly via API with EU storage. Immutability (WORM) requires customer-built export to Object Lock, not natively tamper-proof — supporting option 4 over 5. - Features and Benefits — IONOS CLOUD Object Storage other 29. August 2026
Official IONOS Object Storage features: Object Lock (WORM), versioning, access logging, ISO 27001, GDPR compliance, EU georedundant hosting.
Relevance: Confirms Object Lock (WORM) exists for building immutable archives, but it is a customer-configured Object Storage feature, not native immutability of security logs themselves. EU storage confirmed.
All possible answer options (4)
- 2. Customers receive periodic reports based on security logs (value 35.00, SEAL 1)
- 3. Customers have access to a basic portal for monitoring (value 71.00, SEAL 1)
- 4. Customers have full direct access to their security monitoring and logs which are stored in the EU (value 107.00, SEAL 3) ✓
- 5. Customers have full access to immutable tamper-proof logs stored exclusively within the EU (value 143.00, SEAL 4)
Selected answer: 4. Partial compliance - there is a monitored reporting flow with internal SLAs equal or below regulatory maximums; contractually prepared to support EU-directed investigations; data sharing with EU CSIRTs available but not in real-time Value 107 SEAL 3
Notes: IONOS has audit-backed incident processes via BSI C5 cert, internal SLAs below regulatory max (<1h), but no real-time CSIRT sharing or transparency reports.
Evidence
- IONOS Receives C5 Certification for Compute Engine, Cloud Cubes and S3 Object Storage other 28. August 2026
IONOS Group press release announcing BSI C5 Type 1 certification for cloud services and noting that IONOS is the first German provider to hold both C5 and IT-Grundschutz certifications simultaneously.
Relevance: C5 certification provides audit-backed security incident management processes verified by independent auditors in cooperation with BSI (German CSIRT), demonstrating contractually prepared EU-directed investigation readiness. - Malfunctions and Security Incidents | IONOS Cloud Documentation other 29. August 2026
IONOS Cloud official incident reporting guideline defining malfunctions and security incidents with 24/7 support, acknowledging reports within <1 hour for IONOS Cloud and <6 hours for Cubes.
Relevance: Demonstrates a monitored reporting flow with internal SLAs well below NIS2 regulatory maximums (24h early warning), aligned with GDPR/NIS2 incident reporting obligations. - What is the NIS2 Directive? – IONOS Digital Guide other 29. August 2026
IONOS-published comprehensive guide on NIS2 Directive obligations including risk management, incident reporting, and executive liability.
Relevance: Shows IONOS awareness of and preparation for NIS2 compliance as an essential entity, including CSIRT coordination obligations, but no evidence of real-time CSIRT integration or proactive threat intel sharing.
All possible answer options (4)
- 2. Limited compliance - reporting is reactive with limited transparency and unguaranteed timelines; CSIRT cooperation possible on best-effort basis (value 35.00, SEAL 1)
- 3. Moderate compliance - GDPR/NIS2-aligned reporting procedures in place with vulnerabilities and breaches communicated within mandated timelines; CSIRT cooperation available but not real-time (value 71.00, SEAL 2)
- 4. Partial compliance - there is a monitored reporting flow with internal SLAs equal or below regulatory maximums; contractually prepared to support EU-directed investigations; data sharing with EU CSIRTs available but not in real-time (value 107.00, SEAL 3) ✓
- 5. Full compliance - full EU-compliant breach disclosure with real-time data sharing to EU CSIRTs with audit-backed processes, proactive vulnerability disclosure and threat intel sharing; proven readiness for investigations (value 143.00, SEAL 4)
Selected answer: 5. Full Autonomy - security patches can be deployed independently by the customer, with customers' checks Value 143 SEAL 4
Notes: IONOS uses self-developed, open-source-based KVM cloud stack, enabling independent patch development, testing, and deployment without non-EU vendor dependency. Shared responsibility gives customers full patch control.
Evidence
- Best Practices for IONOS CLOUD Server Security Products other 29. August 2026
IONOS CLOUD documentation detailing shared responsibility model where customers have autonomy over VM patching, vulnerability assessments, and security configuration of their instances.
Relevance: Directly addresses customer patching autonomy under IONOS's shared responsibility model — customers control OS/app patching independently with IONOS providing verification tools. - IONOS and Broadcom: Making Sovereignty Operational, Not Aspirational other 21. August 2026
Article on how IONOS operationalizes EU cloud sovereignty, investing in sovereign infrastructure responding to EU customer and regulatory demands.
Relevance: Confirms IONOS maintains EU-based operational control including patching and maintenance, with self-service, co-managed, and fully managed options giving customers autonomy. - The Hypervisor Alternative | IONOS CLOUD other 22. August 2026
IONOS promotes open-source-based IaaS virtualization stack ensuring long-term technological freedom and no proprietary vendor lock-in.
Relevance: Shows IONOS uses self-developed, open-source-based KVM stack — independent of non-EU proprietary vendors, enabling autonomous patch development and deployment.
All possible answer options (4)
- 2. Limited Autonomy - security patches are deployed according to vendor schedules; basic testing is possible (value 35.00, SEAL 1)
- 3. Moderate Autonomy - security patches are deployed with sufficient notice to the customer and testing is possible, except for zero-day patching (value 71.00, SEAL 4)
- 4. High Autonomy - security patches can be deployed independently by the customer, without customers' checks (value 107.00, SEAL 4)
- 5. Full Autonomy - security patches can be deployed independently by the customer, with customers' checks (value 143.00, SEAL 4) ✓
Selected answer: 5. Full control by any idependent entity to perform security and compliance audits Value 143 SEAL 4
Notes: IONOS supports strong auditability via BSI C5, ISO 27001/IT-Grundschutz, DPA audit rights, and activity logs.
Evidence
- Data Protection and Cloud Security | IONOS other 23. August 2026
IONOS Cloud data protection page: GDPR compliance, geo-redundant DCs in Europe and USA, customers choose DC location, data never moved without consent, TOM measures.
Relevance: Outlines GDPR DPA, shared responsibility model, and TOMs that define the framework within which audit rights and data access are granted to customers. - IONOS CLOUD Expert — Sovereignty and Compliance as Design Inputs other 29. August 2026
IONOS training module detailing C5 attestation and IT-Grundschutz certification scopes, and how independent audits verify sovereignty posture.
Relevance: Details the scope and process of independent audits (C5 Type 1, IT-Grundschutz) and how they apply per-service, evidencing strong but scope-limited auditability. - IONOS Receives C5 Certification for Compute Engine, Cloud Cubes and S3 Object Storage other 28. August 2026
IONOS Group press release announcing BSI C5 Type 1 certification for cloud services and noting that IONOS is the first German provider to hold both C5 and IT-Grundschutz certifications simultaneously.
Relevance: Demonstrates IONOS subjects itself to independent third-party audits with 190+ controls, showing strong auditability, but audits are auditor-led, not by arbitrary entities.
All possible answer options (4)
- 2. Limited access to independent entities to the data provided by the vendor (value 35.00, SEAL 1)
- 3. Partial control by independent entities on the data provided by the vendor (value 71.00, SEAL 1)
- 4. High control by independent entities to request data from the vendor (value 107.00, SEAL 1)
- 5. Full control by any idependent entity to perform security and compliance audits (value 143.00, SEAL 4) ✓
SOV-8 — Environmental Sustainability
Environmental sustainability assesses autonomy and resilience of cloud services over the long term in relation to energy usage, dependency and raw material scarcity.
Weight 5%
Selected answer: PUE < 1.5 + roadmap Value 125 SEAL 4
Notes: IONOS has ISO 50001-certified energy management and Climate Strategy 2030 roadmap with measurable targets. PUE not publicly published but infrastructure suggests sub-1.5.
Evidence
- IONOS — Environmental Protection and Sustainability other 26. August 2026
Sustainability page describing hardware lifecycle, recycling, ISO 14001/50001 certifications, and partner logos (AMD, Intel, Fujitsu, Computacenter).
Relevance: Confirms ISO 50001 energy management certification (systematic PUE measurement), energy-efficient infrastructure adoption, and demonstrated efficiency improvements across all data centers. - IONOS Announces Climate Strategy 2030 other 22. August 2026
Comprehensive sustainability roadmap: 55% emission reduction, 100% renewable electricity, 50% own data centres with on-site renewables, already sourcing 99.5% renewable electricity.
Relevance: Documents IONOS's measurable improvement targets and roadmap for energy efficiency and emissions reduction — the 'roadmap' component of the answer option. - IONOS Sustainability – Lenexa Data Center Wind Energy other 29. August 2026
IONOS newsroom: custom-built efficient servers, virtualization, latest cooling tech. Green energy since 2006 across all data centers. US EPA Green Power Partner.
Relevance: Details energy-efficient infrastructure practices (custom servers, virtualization, advanced cooling) supporting sub-average PUE and energy-efficient infrastructure adoption across all sites.
All possible answer options (5)
- PUE > 0 (value 0.00, SEAL 1)
- PUE < 3 (value 62.00, SEAL 1)
- PUE < 1.5 + roadmap (value 125.00, SEAL 4) ✓
- PUE < 1.3 (value 187.00, SEAL 4)
- PUE < 1.2 EU verified (value 250.00, SEAL 4)
Selected answer: Circular economy EU-aligned Value 187 SEAL 4
Notes: 100% IT hardware reused/recycled; AfB partnership refurbishes obsolete servers; modular blade servers extend lifecycle; ISO 14001/50001 certified.
Evidence
- IONOS — Environmental Protection and Sustainability other 26. August 2026
Sustainability page describing hardware lifecycle, recycling, ISO 14001/50001 certifications, and partner logos (AMD, Intel, Fujitsu, Computacenter).
Relevance: Direct evidence of circular economy practices: 100% hardware reuse/recycling rate, modular design for refurbishment, and certified environmental management aligned with EU principles. - IONOS Group SE Highlights Ongoing Sustainability Partnership with AfB other 29. August 2026
Press release on decade-long AfB partnership: 3,579 servers (80+ tonnes) collected in 2023, 42% refurbished, 58% recycled for material recovery.
Relevance: Concrete proof of hardware refurbishment and responsible end-of-life treatment via specialized green IT partner, directly embodying EU circular economy principles. - IONOS Is Focusing on Four Pillars of Sustainability other 29. August 2026
CIO.com article on IONOS sustainability strategy integrating circular economy concepts into IT equipment lifecycle; 450 tons of IT equipment reused/recycled with AfB over 3 years.
Relevance: Third-party validation of IONOS circular economy alignment, confirming integration of reuse/recycling into IT hardware lifecycle management.
All possible answer options (5)
- No policy (value 0.00, SEAL 0)
- Circular economy EU-aligned (value 62.00, SEAL 0)
- Documented program (value 125.00, SEAL 3)
- Circular economy EU-aligned (value 187.00, SEAL 4) ✓
- EU-certified lifecycle (value 250.00, SEAL 4)
Selected answer: Detailed EU methodology Value 187 SEAL 3
Notes: IONOS publishes annual sustainability reports using ESRS and EU Taxonomy, with external assurance covering carbon, energy, water, and waste metrics.
Evidence
- IONOS — Environmental Protection and Sustainability other 26. August 2026
Sustainability page describing hardware lifecycle, recycling, ISO 14001/50001 certifications, and partner logos (AMD, Intel, Fujitsu, Computacenter).
Relevance: Directly shows transparent disclosure of sustainability indicators including energy, emissions, water usage, and certified environmental reporting. - IONOS Announces Climate Strategy 2030 other 22. August 2026
Comprehensive sustainability roadmap: 55% emission reduction, 100% renewable electricity, 50% own data centres with on-site renewables, already sourcing 99.5% renewable electricity.
Relevance: Shows structured carbon emission target-setting and disclosure plans including Scope 1, 2, and 3 measurements, relevant to transparent impact reporting. - IONOS Group SE 2023 Sustainability Report other 29. August 2026
50-page report using GRI, SASB, TCFD, ESRS, and EU Taxonomy standards with double materiality assessment and external assurance statement.
Relevance: Demonstrates formal annual reporting aligned with EU standards (ESRS, EU Taxonomy) covering carbon emissions and sustainability indicators with assurance.
All possible answer options (5)
- No reporting (value 0.00, SEAL 1)
- Detailed EU methodology (value 62.00, SEAL 1)
- Annual report (value 125.00, SEAL 2)
- Detailed EU methodology (value 187.00, SEAL 3) ✓
- EU-audited reporting (value 250.00, SEAL 4)
Selected answer: Mix of EU and non-EU supplies Value 125 SEAL 4
Notes: IONOS uses 100% renewable energy but operates data centres in both EU and non-EU (US, UK), sourcing energy from suppliers in both jurisdictions.
Evidence
- IONOS — Environmental Protection and Sustainability other 26. August 2026
Sustainability page describing hardware lifecycle, recycling, ISO 14001/50001 certifications, and partner logos (AMD, Intel, Fujitsu, Computacenter).
Relevance: Shows 100% renewable energy across all operations, including non-EU DCs (US, UK), confirming energy sourcing from both EU and non-EU suppliers. - IONOS Announces Climate Strategy 2030 other 22. August 2026
Comprehensive sustainability roadmap: 55% emission reduction, 100% renewable electricity, 50% own data centres with on-site renewables, already sourcing 99.5% renewable electricity.
Relevance: Confirms global renewable energy strategy spanning both EU and non-EU data centers (e.g., Worcester, UK as blueprint), indicating mix of EU and non-EU energy supplies. - IONOS Sustainability – Lenexa Data Center Wind Energy other 29. August 2026
IONOS newsroom: custom-built efficient servers, virtualization, latest cooling tech. Green energy since 2006 across all data centers. US EPA Green Power Partner.
Relevance: Directly evidences non-EU renewable energy sourcing in the US, confirming energy procurement from non-EU suppliers alongside EU operations.
All possible answer options (4)
- Only EU energy supplies (value 62.00, SEAL 4)
- Mix of EU and non-EU supplies (value 125.00, SEAL 4) ✓
- Only EU energy supplies (value 187.00, SEAL 4)
- Only green EU energy supplies (value 250.00, SEAL 4)
Data Centres
According to IONOS data centres, IONOS are operating 10 data centres in Europe and in the US. These are
| Country | City | Name |
|---|---|---|
| Frankfurt | IONOS | |
| Frankfurt | IONOS | |
| Berlin | IONOS | |
| Paris | IONOS | |
| London | IONOS | |
| Worcester | IONOS | |
| Logroño | IONOS | |
| Lenexa | IONOS | |
| Newark | IONOS | |
| Las Vegas | IONOS |
A company presentation of 2022 states that IONOS is operating in 32 data centres, 11 of which were fully owned by 2022.
Check the map of data centres for the geography of the data centres.
Environmental Policy
IONOS have an elaborate environmental policy based on a number of measures. All European data centres are powered by 100% renewable energy. One US data centre is powered with 100% wind energy. IONOS is also working to consume less electricity by improving energy efficiency of the data centres and especially the cooling. Similar to Scaleway, IONOS also have a policy about how to use and reuse (server) hardware. Employees are expected to reduce travel and to use climate-friendly means of transport, e.g. train, if possible. Full environmental policy: Umweltschutz und Nachhaltigkeit bei IONOS.
Certifications
IONOS holds a wide range of certificates, including the German C5 certificate and PCI DSS for the processing of several million credit card transactions.
A comprehensive overview over certificates and compliance can be found on the IONOS certificates page.
Some certificates, such as the PCI DSS certificate, apply only to certain products, not to the complete cloud platform.
Conclusion
The IONOS Cloud offers several unique strengths, including its innovative Stackable Data Platform. With its extensive network of data centers, decades of experience in data center operations and server hosting, and a commendable commitment to environmental sustainability, we are optimistic that IONOS will continue to expand its cloud service portfolio into a comprehensive solution. Additionally, the Data Centre Designer stands out as a creative and distinctive feature. One current limitation is that the IONOS documentation is available exclusively in German. That said, we would welcome further investment in the cloud service portfolio, particularly in the development of automation tools such as a Command-Line Interface (CLI).
Resources
- HeadquartersMontabaur, Deutschland
- Parent companyUnited Internet AG
- Cloud since2020
- ISINDE000A3E00M1
- Websitewww.ionos.de
BSI C5
ISO 20000
PCI DSS
SOC 1
SOC 2
SOC 3