OVHcloud – European cloud with a worldwide presence

OVHcloud building

OVHcloud is a large provider of dedicated server, web hosting and (private) cloud solutions operating world-wide and based in Roubaix, France.

OVHcloud is one of the largest OpenStack deployments in the world, with data centres all across the world and around half a million servers in operation.

Next to server hosting, hosted private cloud and cloud platform services, OVHcloud are offering a variety of adjacent services, such as telephony and domain registration.

Features & Services

OVHcloud offers a wide range of services beyond the classic IaaS public cloud services. This includes various options for web hosting, including a CDN (based on the worldwide server presence), managed Exchange Server, a private cloud offering for managed SAP HANA, VMware solutions and many more.

In the public cloud portfolio, OVHcloud has one of the widest product ranges, including for example several services to build a data platform, built on Open Source best-in-class tools, such as Apache Iceberg, Spark, Trino, and Prometheus. A service also worth to highlight is the Managed Rancher Service.

OVHcloud offers 31 different managed AI models, readily consumable behind API endpoints. These range from the classic LLM models of the Llama series, DeepSeek and the Mistral models, over image generation, to voice generation models, named entity recognition, image segmentation, and many more. The complete list is in the AI Endpoints Catalog of Models.

A great addition in our eyes would be serverless options for compute and databases with true scale-to-zero capability.

Developer Experience

There are several options to work with OVHcloud:

REST API

The OVHcloud API lets developers provision and configure every service at OVHcloud. The first steps to get started with the REST API are described in First Steps with OVHcloud APIs.

Command Line Interface (CLI)

OVHcloud do not provide their own, official CLI. There are some community projects, but they do not seem to be actively maintained. A previously official CLI was deprecated in 2019. However, there is a guide on how to manage OVH from shell using a variety of tools, including the OpenStack CLI.

For managing AI services, there is a dedicated CLI, officially maintained by OVH.

Terraform

A well-supported way for managing OVH infrastructure is through the OVHcloud Terraform provider. There is a range of examples for getting started with the public cloud services in the OVHcloud GitHub repository.

Console

The OVHcloud console is very easy to get around. You almost instantly know where to look and where to go – unlike the convoluted monstrosities of AWS, Azure and GCP. On the other hand, the complexity of AWS, Azure and GCP consoles is a consequence of a higher depth of configurability compared to OVHcloud.

OVHcloud Console

Sovereignty Assessment

For the sovereignty assessment, we are following the EU's Cloud Sovereignty Framework. It defines 8 sovereignty objectives and makes sovereignty measurable and quantifiable.

Disclaimer: this assessment is conducted as an outside-in analysis, based on public information and, for some questions, educated guessing. The results may be factually wrong and in no way replace your own due diligence.

Overall Score

78.3 %

SEAL Level

SEAL 1

Sovereignty Assessment

Sovereignty Assessment Details
Provider
OVHcloud
Framework
Initial framework from the Sovereignty assessment calculator annex (v1.0)
Assessment date
7. August 2026
Overall score
78.3 %
SEAL level
SEAL 1

SOV-1 — Strategic Sovereignty

Strategic sovereignty captures the degree to which a cloud provider (or technology actor) is anchored within the European Union/EEA legal, financial, and industrial ecosystem. It assesses ownership stability, governance influence, and alignment with EU strategic priorities.

Weight 20%

Q1. EU/EEA legal entity control - ensuring that ultimate decision-making authority resides within EU jurisdiction.

Selected answer: 4. Entirely within the EU Value 125 SEAL 4

Notes: OVHcloud has a branch in Canada, but decision-making authority is in France.

No evidence provided for this answer.

All possible answer options (4)
  • 1. Entirely outside the EU (value 0.00, SEAL 1)
  • 2. Mostly outside the EU (value 41.00, SEAL 1)
  • 3. Mostly within the EU (value 83.00, SEAL 3)
  • 4. Entirely within the EU (value 125.00, SEAL 4)
Q2. Change of Control Risk - evaluating the likelihood of takeover or transfer to non-sovereign owners

Selected answer: 4. Unlikely takeover by or transfer to a non-EU sovereign entity Value 93 SEAL 4

Notes: Not 'Very unlikely' because stock is publicly traded. A minority strategic investment is more likely than outright change of control

No evidence provided for this answer.

All possible answer options (5)
  • 1. Very likely (value 0.00, SEAL 4)
  • 2. Likely takeover by or transfer to a non-EU sovereign entity (value 31.00, SEAL 4)
  • 3. Somewhat likely takeover by or transfer to a non-EU sovereign entity (value 62.00, SEAL 4)
  • 4. Unlikely takeover by or transfer to a non-EU sovereign entity (value 93.00, SEAL 4)
  • 5. Very unlikely (value 125.00, SEAL 4)
Q3. Control Over Roadmap - measuring the capacity of EU stakeholders to shape the provider’s technological and service evolution.

Selected answer: 3. Governance bodies exist with EU actors participation Value 83 SEAL 3

Notes: OVHcloud is EU-owned and embedded in CISPE, GAIA-X, ENISA; EU actors participate in governance bodies influencing its roadmap and strategic direction.

Evidence

  • DEEP, OVHcloud & Clever Cloud Consortium Selected for Sovereign Cloud for European Institutions other 20. August 2026
    Press release on EC selecting OVHcloud-led consortium for €180M sovereign cloud contract for EU institutions.
    Relevance: Demonstrates structured EU governance influence: the European Commission directly shapes OVHcloud's strategic direction through institutional contracts aligned with EU sovereignty priorities.
  • OVHcloud and Data Sovereignty other 20. August 2026
    Official OVHcloud page on data sovereignty, governance structure, CISPE/GAIA-X founding membership, and EU legal jurisdiction.
    Relevance: Shows OVHcloud's EU ownership, no non-EU dependencies, and active participation in EU governance bodies (CISPE, GAIA-X, ENISA), enabling EU stakeholder influence on roadmap and strategy.
  • Silba Deep Dives – OVHcloud, Europe's Cloud Sovereignty Play other 20. August 2026
    Independent analysis of OVHcloud's ownership structure: Klaba family 81% ownership, SecNumCloud certification, EU regulatory moat.
    Relevance: Confirms EU ownership structure and strategic sovereignty alignment; shows governance is EU-anchored but family-controlled, consistent with governance body influence rather than full EU control.
All possible answer options (4)
  • 1. No influence possible (value 0.00, SEAL 2)
  • 2. Through "voice of the customer" public channels (e.g. feedback portals, online communities) (value 41.00, SEAL 2)
  • 3. Governance bodies exist with EU actors participation (value 83.00, SEAL 3)
  • 4. Full influence of EU actors (value 125.00, SEAL 4)
Q4. Financial independence from non-EU capital - degree to which the provider relies on EU-based financing rather than external capital.

Selected answer: 4. Majority of funding is EU-based Value 93 SEAL 4

Notes: Klaba family (French) owns ~79-81% post-2024 buyback; KKR/TowerBrook largely exited; ~18% free float on Euronext Paris may include non-EU investors.

Evidence

  • OVHcloud FY2024 Annual Results & Share Buyback Announcement other 20. August 2026
    Official OVHcloud press release announcing €350M share buyback at €9/share, increasing Klaba family ownership to ~81%; FY2024 revenue €993M.
    Relevance: Confirms the deliberate strategic move to increase EU family ownership and reduce external/free-float capital via buyback, strengthening financial independence from non-EU sources.
  • OVHcloud Official Investor Relations – Shareholders & Governance other 20. August 2026
    OVHcloud's official IR page showing post-buyback structure: Klaba family 79.0%, free float 18.4%, employees 1.8%, treasury 0.8%.
    Relevance: Directly confirms overwhelming EU family ownership (~79%) with remaining ~18% public float, establishing the degree of EU-based vs non-EU capital reliance.
  • Silba Deep Dives – OVHcloud, Europe's Cloud Sovereignty Play other 20. August 2026
    Independent analysis of OVHcloud's ownership structure: Klaba family 81% ownership, SecNumCloud certification, EU regulatory moat.
    Relevance: Documents the active reduction of non-EU PE capital (KKR/TowerBrook) and consolidation of EU family ownership, directly addressing financial independence from non-EU capital.
All possible answer options (5)
  • 1. Almost entirely relying on non-EU funding (value 0.00, SEAL 4)
  • 2. Mostly relying on non-EU funding (value 31.00, SEAL 4)
  • 3. Balanced mix of EU and non-EU funding (value 62.00, SEAL 4)
  • 4. Majority of funding is EU-based (value 93.00, SEAL 4)
  • 5. Entirely EU-based funding (value 125.00, SEAL 4)
Q5. EU economic contribution - extent of investment, jobs, and value creation within EU/EEA.

Selected answer: 5. Fully in the EU Value 125 SEAL 4

Notes: EU-headquartered, Euronext-listed, ~94% revenue from Europe, ~2,900 EU employees, €200M EIB loan, €700M+ EU capex. Overwhelmingly EU/EEA economic contribution.

Evidence

  • EIB Supports OVHcloud Growth with a €200 Million Loan for European Investments other 20. August 2026
    EIB press release on €200M loan — its first for a pure cloud player — for European expansion including 10+ new EU data centres and R&D investment.
    Relevance: Demonstrates EU institutional financial backing for OVHcloud's European investment, jobs creation, and value generation within EU/EEA.
  • OVHcloud FY2024 Annual Results & Share Buyback Announcement other 20. August 2026
    Official OVHcloud press release announcing €350M share buyback at €9/share, increasing Klaba family ownership to ~81%; FY2024 revenue €993M.
    Relevance: Directly shows EU investment levels, employment footprint, and geographic value concentration — ~94% of revenue generated within Europe.
  • OVHcloud Presents Strategic Plan "Shaping the Future" and FY2026 Targets other 20. August 2026
    Strategic plan detailing €700M cumulative capex (2021-2023), European data center expansion, 2,900 employees across 15 countries, and EU sovereignty positioning.
    Relevance: Shows sustained EU-focused investment strategy, employment growth, and capital deployment plan confirming majority EU/EEA value creation.
All possible answer options (5)
  • 1. Minimal (value 0.00, SEAL 4)
  • 2. Some (value 31.00, SEAL 4)
  • 3. Balanced EU/non-EU (value 62.00, SEAL 4)
  • 4. Majority in the EU (value 93.00, SEAL 4)
  • 5. Fully in the EU (value 125.00, SEAL 4)
Q6. Participation in EU strategic programs - involvement in initiatives such as IPCEI-CIS, Horizon Europe, or Gaia-X.

Selected answer: 2. Active participant in strategic projects Value 62 SEAL 4

Notes: OVHcloud is a founding member of Gaia-X and actively advocated for launching IPCEI-CIS via the Rome Consensus, demonstrating strong strategic project engagement.

Evidence

  • OVHcloud and Data Sovereignty other 20. August 2026
    Official OVHcloud page on data sovereignty, governance structure, CISPE/GAIA-X founding membership, and EU legal jurisdiction.
    Relevance: Confirms OVHcloud as a founding member of Gaia-X, one of the listed EU strategic initiatives in the assessment question.
  • T-Systems and OVHcloud Cooperate for Gaia-X other 20. August 2026
    OVHcloud press release announcing Gaia-X founding partnership with T-Systems to build a sovereign European public cloud offering.
    Relevance: Demonstrates active participation in Gaia-X, building a market-ready sovereign cloud platform following Gaia-X principles.
  • The Rome Consensus: Assert European Digital Sovereignty other 20. August 2026
    OVHcloud-led policy document from 2022 French EU Council Presidency advocating for IPCEI-CIS launch and European digital sovereignty.
    Relevance: Shows OVHcloud's active role in advocating for IPCEI-CIS as a strategic EU initiative, even if not confirmed as a direct consortium member.
All possible answer options (3)
  • 1. No clear participation (value 0.00, SEAL 4)
  • 2. Active participant in strategic projects (value 62.00, SEAL 4)
  • 3. Strategic projects depend on contractor's involvement (value 125.00, SEAL 4)
Q7. Alignment with EU industrial strategies - consistency with digital, green, and industrial sovereignty objectives defined at EU level.

Selected answer: Bold ambition and dedicated means Value 125 SEAL 4

Notes: Bold ambition via Rome Consensus and Gaia-X founding role, backed by €200M EIB loan and €700M capex for EU sovereignty goals.

Evidence

  • EIB Supports OVHcloud Growth with a €200 Million Loan for European Investments other 20. August 2026
    EIB press release on €200M loan — its first for a pure cloud player — for European expansion including 10+ new EU data centres and R&D investment.
    Relevance: EIB's first cloud-sector loan directly ties OVHcloud expansion to EU strategic autonomy in digital tech and green sovereignty objectives, with measurable green targets.
  • OVHcloud and Data Sovereignty other 20. August 2026
    Official OVHcloud page on data sovereignty, governance structure, CISPE/GAIA-X founding membership, and EU legal jurisdiction.
    Relevance: Shows concrete alignment with EU digital and industrial sovereignty objectives through founding roles in CISPE and GAIA-X, plus full EU-based supply chain control.
  • The Rome Consensus: Assert European Digital Sovereignty other 20. August 2026
    OVHcloud-led policy document from 2022 French EU Council Presidency advocating for IPCEI-CIS launch and European digital sovereignty.
    Relevance: Directly demonstrates bold ambition for EU industrial strategy alignment with dedicated governance: proposes IPCEI-CIS, Buy European Tech Act, and concrete policy roadmap.
All possible answer options (3)
  • Existing Action plan (how to measure ambition? Through means linked to the goals? Relative to the size of the company?) (value 41.00, SEAL 4)
  • Already measured achievement and existing dedicated governance (value 83.00, SEAL 4)
  • Bold ambition and dedicated means (value 125.00, SEAL 4)
Q8. Resilience to Cut-off - ability to sustain secure operations even if vendor support is withdrawn or disrupted.

Selected answer: 5. Full autonomy and continuity Value 125 SEAL 4

Notes: OVHcloud has internalised most key functions: own server design/manufacturing, own data centers, open-source OpenStack stack, own network. Can source alternatives for remaining commodity dependencies.

Evidence

  • OVHcloud – Open Source: Shaping the Public Cloud other 20. August 2026
    Details OVHcloud's 100% open-source OpenStack-based public cloud with reversibility, no vendor lock-in, open APIs, and zero egress fees.
    Relevance: Shows OVHcloud avoids proprietary dependencies by using open standards—no single vendor can disrupt its software stack, ensuring continuity even if third-party support is withdrawn.
  • OVHcloud and S2GRUPO Strategic Partnership for European Digital Sovereignty other 20. August 2026
    Press release highlighting OVHcloud's full control over its value chain—from server design to data centre management—ensuring sovereignty by design and cyber resilience.
    Relevance: Confirms OVHcloud's vertical integration across the entire stack, reducing external vendor dependencies and demonstrating ability to internalise key functions for operational continuity.
  • OVHcloud On-Prem Cloud Platform (OPCP) other 20. August 2026
    OVHcloud's on-prem cloud solution runs fully disconnected with open-source tech (OpenStack, Keycloak, Netbox), no external vendor dependency required for operations.
    Relevance: Demonstrates OVHcloud can sustain operations independently using self-managed open-source stack, even fully disconnected—key evidence of internalized key functions and cut-off resilience.
All possible answer options (4)
  • 2. Service would likely stop but with a delay to provide time for customer reaction (value 31.00, SEAL 0)
  • 3. Can continue temporarily based on contractual agreement with EC (value 62.00, SEAL 2)
  • 4. Ability to source alternative suppliers or internalise key functions (value 93.00, SEAL 2)
  • 5. Full autonomy and continuity (value 125.00, SEAL 4)

SOV-2 — Legal & Jurisdictional Sovereignty

Legal & Jurisdictional sovereignty evaluates the legal environment, exposure to foreign authority, and enforceability of rights that govern a technology provider and its services. It determines the extent to which a provider is anchored in European jurisdiction and insulated from external legal claims.

Weight 10%

Q1. Primary Legal Jurisdiction - the national legal system governing the provider’s operations and contracts.

Selected answer: 3. Exclusively EU law Value 167 SEAL 4

Notes: OVH Groupe SAS is incorporated in France, governed by French/EU law exclusively. European entities under exclusive EU jurisdiction; CLOUD Act free; no dependency on non-EU entities.

Evidence

  • OVHcloud and Data Sovereignty other 20. August 2026
    Official OVHcloud page on data sovereignty, governance structure, CISPE/GAIA-X founding membership, and EU legal jurisdiction.
    Relevance: Directly establishes OVHcloud's primary legal identity as French/EU, its data hosted exclusively in EU, and its insulation from non-EU authority for the provider's core operations.
  • OVHcloud Legal and Privacy Security other 20. August 2026
    OVHcloud's official legal page listing applicable legal texts per jurisdiction, GDPR compliance, and EU data hosting with protection against extraterritorial laws.
    Relevance: Details the legal framework governing OVHcloud's EU operations (EU GDPR, e-Privacy Directive, Cybersecurity Regulation), confirming French/EU law as primary governing jurisdiction for EU customers.
  • The CLOUD Act and European Data Sovereignty – OVHcloud Blog other 20. August 2026
    OVHcloud blog post explaining its legal jurisdiction stance: European entities under 'exclusive jurisdiction of EU member states,' no dependency links to non-EU entities, and 'CLOUD Act free' status.
    Relevance: Provides explicit corporate statement that OVH Groupe is governed by French law with no dependency on non-EU jurisdiction entities — directly answers the primary legal jurisdiction question.
All possible answer options (3)
  • 1. Non-EU only (value 0.00, SEAL 1)
  • 2. Mixed EU/non-EU (value 84.00, SEAL 1)
  • 3. Exclusively EU law (value 167.00, SEAL 4)
Q2. Extraterritorial Laws - degree of exposure to non-EU laws with cross-border reach (all).

Selected answer: Legal structures shielding from foreign law Value 125 SEAL 2

Notes: French corporate structure, blocking statute & SecNumCloud shield from foreign law. Not immunity (King v. OVH shows limits), but beyond mere mitigation clauses.

Evidence

  • The CLOUD Act and European Data Sovereignty – OVHcloud Blog other 20. August 2026
    OVHcloud blog post explaining its legal jurisdiction stance: European entities under 'exclusive jurisdiction of EU member states,' no dependency links to non-EU entities, and 'CLOUD Act free' status.
    Relevance: Directly states OVHcloud's legal position on extraterritorial law exposure, French exclusive jurisdiction, and structural independence from non-EU entities.
  • What Canada's King vs. OVH Case Reveals About Cross-Border Data Access other 20. August 2026
    Analysis of King v. OVH case where Ontario court compelled OVHcloud's French parent to produce data despite blocking statute, revealing limits of legal shields.
    Relevance: Documents a real case where a foreign court pierced OVHcloud's legal structures, showing they provide shielding but not verified immunity from non-EU law.
  • White Paper: US CLOUD Act vs European/UK Data Sovereignty – CMS Law other 20. August 2026
    Legal white paper by international law firm CMS analyzing CLOUD Act jurisdiction, blocking statutes, and practical enforcement against EU providers.
    Relevance: Independent legal analysis of CLOUD Act vs European sovereignty, addressing blocking statute effectiveness and whether legal structures genuinely shield EU providers.
All possible answer options (4)
  • Mitigation clauses, exposure remains (value 41.00, SEAL 1)
  • EU subsidiary with contractual protections (value 83.00, SEAL 1)
  • Legal structures shielding from foreign law (value 125.00, SEAL 2)
  • Verified legal immunity, non-EU laws unenforceable (value 167.00, SEAL 4)
Q3. Data Access Pathways - existence of legal, contractual, or technical channels through which non-EU authorities could compel access to data or systems.

Selected answer: 4. Non-EU authorities requests to access data or systems are disputed by the provider and eventually in some cases are accepted with customers being notified Value 125 SEAL 1

Notes: OVHcloud disputes non-EU authority requests citing GDPR Art. 48 & MLAT, but King v. OVH shows some requests succeed via foreign subsidiary jurisdiction. Customer notification is policy.

Evidence

  • OVHcloud and Data Sovereignty other 20. August 2026
    Official OVHcloud page on data sovereignty, governance structure, CISPE/GAIA-X founding membership, and EU legal jurisdiction.
    Relevance: Confirms OVHcloud's sovereignty policy and technical/organizational measures insulating EU data from non-EU access, establishing the dispute baseline.
  • The CLOUD Act and European Data Sovereignty – OVHcloud Blog other 20. August 2026
    OVHcloud blog post explaining its legal jurisdiction stance: European entities under 'exclusive jurisdiction of EU member states,' no dependency links to non-EU entities, and 'CLOUD Act free' status.
    Relevance: Shows OVHcloud's stated policy of disputing all non-EU authority data access requests, which is the first element of option 4.
  • What Canada's King vs. OVH Case Reveals About Cross-Border Data Access other 20. August 2026
    Analysis of King v. OVH case where Ontario court compelled OVHcloud's French parent to produce data despite blocking statute, revealing limits of legal shields.
    Relevance: Proves some non-EU requests are eventually accepted despite OVHcloud's dispute: Canadian court upheld production order and cited prior German data compliance via subsidiary jurisdiction.
All possible answer options (4)
  • 2. Non-EU authorities can compel access to data or systems without customers being notified, in specific cases (value 41.00, SEAL 1)
  • 3. Non-EU authorities can compel access to data or systems with customers being notified in all cases (value 83.00, SEAL 1)
  • 4. Non-EU authorities requests to access data or systems are disputed by the provider and eventually in some cases are accepted with customers being notified (value 125.00, SEAL 1)
  • 5. Non-EU authorities requests to access data or systems are always rejected by the provider (value 167.00, SEAL 4)
Q4. Export Control Restrictions - applicability of international regimes such as ITAR or EAR, which may restrict usage or transfer.

Selected answer: Part of the offer cannot be exposed to restrictions towards EU MSs or international organisations Value 167 SEAL 4

Notes: OVHcloud's core infrastructure is French/EU-based and not subject to US ITAR/EAR. Third-party products may carry export restrictions.

Evidence

  • OVHcloud and Data Sovereignty other 20. August 2026
    Official OVHcloud page on data sovereignty, governance structure, CISPE/GAIA-X founding membership, and EU legal jurisdiction.
    Relevance: Demonstrates OVHcloud's core infrastructure is under French/EU law with no US jurisdictional nexus, meaning ITAR/EAR do not apply to core EU offer.
  • OVHcloud US Terms of Service — Export Compliance Clause other 20. August 2026
    US Terms of Service Section 19(14) places EAR/ITAR compliance solely on US customers; OVHcloud disclaims responsibility.
    Relevance: Shows export controls (ITAR/EAR) apply only to OVHcloud US subsidiary, not the core European offer, confirming partial protection for EU MSs.
  • What is Sovereign Cloud? (OVHcloud) other 20. August 2026
    OVHcloud's article defining sovereign cloud and how it avoids extraterritorial jurisdictional exposure for hosted data.
    Relevance: Explains how sovereign cloud excludes US extraterritorial laws, ensuring part of the offer remains free from ITAR/EAR for EU MSs and intl orgs.
All possible answer options (4)
  • Restrictions exists towards EU citizens or international organisations (value 41.00, SEAL 1)
  • Share of revenues >50% in the EU (value 83.00, SEAL 2)
  • Part of the offer cannot be exposed to restrictions towards EU MSs (value 125.00, SEAL 3)
  • Part of the offer cannot be exposed to restrictions towards EU MSs or international organisations (value 167.00, SEAL 4)
Q5. Origin of IP - location of intellectual property creation, registration, and development (all).

Selected answer: 4. Mostly within the EU Value 125 SEAL 4

Notes: OVHcloud's IP (130+ patent families, server designs, cooling tech) is created, registered, and developed primarily in France/EU, with minor activity in Canada (server factory) and US (subsidiary).

Evidence

  • EIB Supports OVHcloud Growth with a €200 Million Loan for European Investments other 20. August 2026
    EIB press release on €200M loan — its first for a pure cloud player — for European expansion including 10+ new EU data centres and R&D investment.
    Relevance: European institutional financing supporting OVHcloud's R&D and patent development in Europe, confirming IP creation occurs primarily within the EU.
  • How OVHcloud Harmonizes Open Innovation and Patents other 20. August 2026
    OVHcloud article detailing 130+ patent families developed by its R&D engineers in France, covering software, cooling, mechanics, and electronics innovations.
    Relevance: Directly evidences where OVHcloud's IP is created and developed — primarily in France, with a defensive patent strategy and European IP department.
  • Silba Deep Dives – OVHcloud, Europe's Cloud Sovereignty Play other 20. August 2026
    Independent analysis of OVHcloud's ownership structure: Klaba family 81% ownership, SecNumCloud certification, EU regulatory moat.
    Relevance: Documents the location of core IP creation — proprietary server designs and cooling technology developed in France, with a secondary factory in Canada.
All possible answer options (4)
  • 2. Mostly outside the EU (value 41.00, SEAL 4)
  • 3. Mixed within/outside the EU (value 83.00, SEAL 4)
  • 4. Mostly within the EU (value 125.00, SEAL 4)
  • 5. Fully within the EU (value 167.00, SEAL 4)
Q6. IP Holder Jurisdiction - legal jurisdiction where IP rights are owned and enforced.

Selected answer: EU law with exceptions Value 125 SEAL 4

Notes: Core IP (trademarks, patents) owned by OVH SAS/OVH Groupe SA under French/EU law; US subsidiary OVH US LLC operates IP contracts under US law, creating exceptions.

Evidence

  • How OVHcloud Harmonizes Open Innovation and Patents other 20. August 2026
    OVHcloud article detailing 130+ patent families developed by its R&D engineers in France, covering software, cooling, mechanics, and electronics innovations.
    Relevance: Confirms patents are owned by OVHcloud (French entity) and filed in both EP and US jurisdictions, showing primarily EU ownership with US filings as exceptions.
  • OVHcloud and Data Sovereignty other 20. August 2026
    Official OVHcloud page on data sovereignty, governance structure, CISPE/GAIA-X founding membership, and EU legal jurisdiction.
    Relevance: Confirms OVH Groupe SAS is under French/EU law and that European entities oppose non-EU authority requests, establishing EU as primary IP holder jurisdiction.
  • OVHcloud US Terms of Service — Export Compliance Clause other 20. August 2026
    US Terms of Service Section 19(14) places EAR/ITAR compliance solely on US customers; OVHcloud disclaims responsibility.
    Relevance: Reveals the US exception: OVH US LLC IP contracts governed by US state law, while trademark ownership remains with French parent OVH SAS.
All possible answer options (4)
  • non-EU law, mixed non-EU countries (value 41.00, SEAL 3)
  • Mixed law, some EU (value 83.00, SEAL 3)
  • EU law with exceptions (value 125.00, SEAL 4)
  • fully under EU law (value 167.00, SEAL 4)

SOV-3 — Data & AI Sovereignty

Data & AI sovereignty focuses on the protection, control, and independence of data assets and AI services within the EU/EEA. It addresses how data is secured, where it is processed, and the degree of autonomy customers retain over AI capabilities.

Weight 10%

Q1. Customer control over encryption keys

Selected answer: 4. Customer primary control but provider can read the data or some of the data Value 150 SEAL 3

Notes: OVHcloud offers CMK/BYOK where customers control key lifecycle, but keys reside in OVHcloud's KMS/HSM. The provider retains technical capability to perform decryption operations using stored keys.

Evidence

  • OVHcloud Key Management Service (Labs) other 20. August 2026
    OVHcloud's official KMS page describing OMK (provider-managed) and CMK (customer-managed) key models, BYOK support, and FIPS 140-2 certification.
    Relevance: Directly describes OVHcloud's encryption key management offering: CMK lets customers control key lifecycle, but keys are imported into and stored within OVHcloud's KMS infrastructure — not held exclusively by the customer.
  • Using OVHcloud Key Management Service (KMS) — Official Documentation other 20. August 2026
    Technical guide on OVHcloud KMS usage via REST API, covering key creation, encryption/decryption workflows, key sensitivity flags, and regional API endpoints.
    Relevance: Shows KMS performs encrypt/decrypt operations server-side using keys stored in its HSM, confirming the provider's technical capability to decrypt data using customer-managed keys.
All possible answer options (4)
  • 2. Primarily the provider but not exclusively (value 50.00, SEAL 1)
  • 3. Shared - provider has override keys (value 100.00, SEAL 2)
  • 4. Customer primary control but provider can read the data or some of the data (value 150.00, SEAL 3)
  • 5. Customer exclusive control - provider can not read the data (value 200.00, SEAL 4)
Q2. Transparent data flows & access logs - visibility into when, where, and by whom data is accessed, including auditability of AI model usage.

Selected answer: 5. Real-time customer oversight and independent auditability Value 200 SEAL 4

Notes: Real-time log streaming via LDP Live-tail, customer IAM-controlled audit trails, and ISO/SOC independent audits support data and AI access visibility.

Evidence

  • AI Act Explained: EU AI Regulation — OVHcloud Blog other 20. August 2026
    OVHcloud and Ethiqais joint article on EU AI Act compliance, covering traceability, transparency, and logging of AI systems with automated conformity assessment.
    Relevance: Addresses AI model usage auditability requirement — OVHcloud's partnership with Ethiqais and AI Pact signatory status supports independent AI compliance auditing and traceability.
  • Generating OVHcloud Account Logs with Logs Data Platform other 20. August 2026
    Official documentation detailing three audit log types: audit logs (IP, geolocation, MFA, user agent), activity logs (API calls, user identity), and access policy logs (IAM evaluations).
    Relevance: Shows comprehensive audit trail with user identity, timestamps, access type, and IP — directly addressing the visibility requirement for data access logs.
  • OVHcloud Service Logs — Product Page other 20. August 2026
    OVHcloud's managed log service providing real-time log collection, live-tail streaming, IAM-controlled access, and customizable retention (1–10 years).
    Relevance: Demonstrates real-time customer oversight of access logs with IAM-based fine-grained access control, supporting auditability of who, when, and where data is accessed.
All possible answer options (4)
  • 2. Basic logs incomplete (missing date; missing user; missing type of access; missing means of access etc.) (value 50.00, SEAL 1)
  • 3. Logs exist but not real-time or controlled by vendor (vendor is replaced by CUSTOMER in the survey) (value 100.00, SEAL 2)
  • 4. Full customer controlled visibility of log access but not in real time (value 150.00, SEAL 3)
  • 5. Real-time customer oversight and independent auditability (value 200.00, SEAL 4)
Q3. Secure deletion & proof of erasure od data - mechanisms guaranteeing irreversible removal of data, with verifiable evidence.

Selected answer: 4. Deletion is technically verified with access logs Value 150 SEAL 3

Notes: OVHcloud enforces automatic irreversible deletion and offers KMS-based cryptographic erasure, with logging and audit policies. However, no independent proof of erasure per deletion event is provided to customers.

Evidence

  • OVHcloud Data Processing Agreement (DPA) other 20. August 2026
    GDPR-aligned DPA governing data deletion/retrieval post-termination (15-day window), audit rights to third-party examination reports, and Standard Contractual Clauses.
    Relevance: Establishes data deletion procedures and audit rights, showing deletion is policy-driven with some third-party oversight, but no per-event proof of erasure.
  • OVHcloud Data Security & Compliance other 20. August 2026
    Details OVHcloud's ISMS, monitoring/logging policies for storage servers and infrastructure, and annual third-party audits (ISO 27001/27017/27018, SOC 2).
    Relevance: Shows logging and auditing mechanisms that technically verify access and operations, supporting the assessment that deletion is verified via access logs rather than independent proof.
  • OVHcloud Service-Specific Terms for Products and Services other 20. August 2026
    Official legal terms detailing automatic and irreversible deletion of content data on service termination, KMS-based cryptographic key deletion, and shared responsibility for data backup.
    Relevance: Documents OVHcloud's contractual commitment to irreversible deletion and key-based erasure mechanisms, directly addressing the assessment question on secure deletion.
All possible answer options (4)
  • 2. Manual confirmation only (value 50.00, SEAL 1)
  • 3. Internal validation based on policies - no proof of validation left (value 100.00, SEAL 1)
  • 4. Deletion is technically verified with access logs (value 150.00, SEAL 3)
  • 5. Yes, irreversible deletion is systematically enforced and independently verified (value 200.00, SEAL 4)
Q4. Data location strictly in EU/EEA – strict confinement of storage and processing to European jurisdictions, with no fallback to third countries.

Selected answer: 4. Data in the EU by default, tightly controlled exceptions Value 150 SEAL 1

Notes: OVHcloud defaults to EU-only storage and processing for European customers, but DPA includes SCCs and third-country sub-processors; cross-border legal challenges exist.

Evidence

  • OVHcloud and Data Sovereignty other 20. August 2026
    Official OVHcloud page on data sovereignty, governance structure, CISPE/GAIA-X founding membership, and EU legal jurisdiction.
    Relevance: Confirms OVHcloud's default EU-only data hosting stance and its contractual and technical measures to keep European customer data within EU jurisdiction.
  • OVHcloud GDPR FAQ – Your Questions Answered other 20. August 2026
    OVHcloud's GDPR FAQ page stating that data stays within the EU, is never processed in the US, and that these guarantees are contractually enforced via the DPA.
    Relevance: Explicitly confirms EU-only data location guarantee for European customers, supporting the 'EU by default' assessment. Also acknowledges customer responsibility for broader GDPR compliance.
  • The Sovereignty Mirage: Why European Clouds Won't Save Your Data other 20. August 2026
    Critical analysis contrasting BYOK vs HYOK, noting BYOK keys stored in provider HSMs allow compelled decryption — relevant to OVHcloud's CMK/BYOK model.
    Relevance: Highlights that 'no third-country fallback' is not fully achievable — legal mechanisms can compel cross-border data access, justifying a score below 5.
All possible answer options (4)
  • 2. Data partly in the EU, significant reliance on third countries and limited control (value 50.00, SEAL 0)
  • 3. Data mainly in the EU, some third-country use with standard safeguards (value 100.00, SEAL 1)
  • 4. Data in the EU by default, tightly controlled exceptions (value 150.00, SEAL 1)
  • 5. All data exclusively in the EU with no third-country fallback (value 200.00, SEAL 4)
Q5. AI services - extent to which AI models and data pipelines are developed, trained, hosted, and governed under EU control, minimizing dependence on non-EU technology stacks.

Selected answer: Mixed Control with alternatives: Auditable or open source AI, foreign chips Value 100 SEAL 2

Notes: OVHcloud uses open-source AI models on EU sovereign infrastructure, but relies entirely on NVIDIA (US) GPU chips — a mixed control profile.

Evidence

  • OVHcloud AI Training & GPU Services other 20. August 2026
    OVHcloud offers GPU-accelerated AI training with NVIDIA H100, A100, L40S, and L4 chips in European data centers.
    Relevance: Confirms OVHcloud relies entirely on NVIDIA (US) chips for AI accelerators — no EU-origin chip alternatives available in its stack.
  • OVHcloud Data Sovereignty Commitment other 20. August 2026
    OVHcloud's data sovereignty page outlines its European cloud positioning, CLOUD Act protection, and full value chain control.
    Relevance: Establishes that OVHcloud hosting and data processing are EU-sovereign, providing the infrastructure sovereignty layer for AI services.
  • OVHcloud Launches AI Endpoints with 40+ Open-Source Models other 20. August 2026
    OVHcloud AI Endpoints offers 40+ open-source/open-weight AI models hosted on sovereign European cloud, ensuring model transparency and data sovereignty.
    Relevance: Shows OVHcloud uses auditable open-source AI models (Llama, Mixtral, DeepSeek, Qwen) on EU infrastructure, but models originate from both EU and non-EU sources.
All possible answer options (4)
  • Mostly non-EU dependencies: Licensed AI, chip dependency (value 50.00, SEAL 2)
  • Mixed Control with alternatives: Auditable or open source AI, foreign chips (value 100.00, SEAL 2)
  • EU-led AI, foreign accelerators (value 150.00, SEAL 3)
  • EU-origin models and chips - no dependencies from outside EU (value 200.00, SEAL 4)

SOV-4 — Operational Sovereignty

Operational sovereignty measures the practical ability of EU actors to run, support, and evolve a technology independently of foreign control. It focuses on continuity of operations, skill availability, and resilience against external dependencies.

Weight 15%

Q1. Portability & Interoperability - ease of migrating workloads or integrating with alternative EU-controlled solutions without vendor lock-in.

Selected answer: 4. Formal migration services are available to assist with moving data and workloads Value 125 SEAL 4

Notes: OVHcloud offers OMAP migration program with tools, certified partners, and financial incentives, plus OpenStack-based reversibility and documented data export policies.

Evidence

  • OVHcloud – Open Source: Shaping the Public Cloud other 20. August 2026
    Details OVHcloud's 100% open-source OpenStack-based public cloud with reversibility, no vendor lock-in, open APIs, and zero egress fees.
    Relevance: Shows OpenStack-based interoperability, open APIs, and no egress fees — key enablers of workload portability and avoidance of vendor lock-in.
  • OVHcloud Migration Acceleration Program (OMAP) other 20. August 2026
    Structured migration program offering tools, professional services, 100+ certified partners, training, and financial incentives for workload migration with full reversibility.
    Relevance: Demonstrates formal migration services with professional support, certified partners, and tools for moving data and workloads, directly addressing portability and interoperability.
  • Reversibility Policy for the Unified Data Platform other 20. August 2026
    Official documentation defining reversibility policy with standard data export formats (CSV, JSON, Parquet, Avro), open-source tech, and SWIPO IaaS compliance.
    Relevance: Provides documented, standard methods for data export and migration with specific formats and APIs, supporting interoperability and portability claims.
All possible answer options (4)
  • 2. Data export and workload portability is provided on a "best-effort" basis (value 41.00, SEAL 1)
  • 3. Standard documented methods for data export are available (value 83.00, SEAL 4)
  • 4. Formal migration services are available to assist with moving data and workloads (value 125.00, SEAL 4)
  • 5. Solution already deployed on sovereign infrastructure (value 167.00, SEAL 4)
Q2. Ability to Operate Without Foreign Dependencies - capacity for EU operators to manage, maintain, and support the technology without requiring non-EU vendor involvement

Selected answer: 5. The entire technology stack is managed and supported by a fully EU-based team Value 167 SEAL 4

Notes: OVHcloud is EU-headquartered, vertically integrated, and explicitly restricts all EU customer interventions to EU-based entities only.

Evidence

  • OVHcloud and Data Sovereignty other 20. August 2026
    Official OVHcloud page on data sovereignty, governance structure, CISPE/GAIA-X founding membership, and EU legal jurisdiction.
    Relevance: Explicitly states only EU entities can operate on EU customer infrastructures and technology is operated end-to-end by OVHcloud without non-EU vendor involvement.
  • OVHcloud Enterprise Support — EU-Based Support Teams other 21. August 2026
    OVHcloud Enterprise Support page offering a trusted version ensuring all interventions are carried out solely by EU-based teams.
    Relevance: Demonstrates that EU customers can receive full support exclusively from EU-based teams, confirming operational independence from non-EU personnel.
  • Silba Deep Dives – OVHcloud, Europe's Cloud Sovereignty Play other 20. August 2026
    Independent analysis of OVHcloud's ownership structure: Klaba family 81% ownership, SecNumCloud certification, EU regulatory moat.
    Relevance: Details OVHcloud's full-stack vertical integration (servers, data centers, network) eliminating dependency on non-EU vendors for operations and support.
All possible answer options (4)
  • 2. Operational services are partially sourced from within the EU (value 41.00, SEAL 1)
  • 3. Operational responsibilities are balanced between EU and non-EU teams (value 83.00, SEAL 3)
  • 4. Operational services are predominantly delivered by EU-based teams (value 125.00, SEAL 3)
  • 5. The entire technology stack is managed and supported by a fully EU-based team (value 167.00, SEAL 4)
Q3. Skill Availability- existence of an EU-based talent pool with the expertise to operate and sustain the service.

Selected answer: All EU staff Value 125 SEAL 3

Notes: SecNumCloud mandates exclusively EU personnel for sovereign ops. ~67% workforce in Western Europe. Clearance limited to defence workloads.

Evidence

  • OVHcloud Enterprise Support — EU-Based Support Teams other 21. August 2026
    OVHcloud Enterprise Support page offering a trusted version ensuring all interventions are carried out solely by EU-based teams.
    Relevance: Existing evidence already linked; confirms EU-only support staffing for sovereign service operations.
  • OVHcloud Expands Solutions for Defence Players in Europe other 21. August 2026
    Press release on deploying dedicated EU defence teams, hiring cleared military/defence profiles, and upskilling for national security requirements.
    Relevance: Shows EU-based talent pool with cleared personnel for classified workloads, reinforcing operational sovereignty for defence-grade services.
  • OVHcloud SecNumCloud Compliance other 21. August 2026
    Official page detailing ANSSI SecNumCloud certification; states services are operated, maintained and monitored exclusively by EU-based personnel.
    Relevance: Directly confirms that SecNumCloud-qualified services ensure all operations are EU-staffed, satisfying skill availability within the EU.
All possible answer options (4)
  • Mixed, majority outside EU (value 41.00, SEAL 1)
  • Majority EU, escalation abroad (value 83.00, SEAL 3)
  • All EU staff (value 125.00, SEAL 3)
  • 100% EU staff + clearance (value 167.00, SEAL 4)
Q4. Support Channels - assurance that operational support is delivered from within the EU and subject exclusively to EU/EEA legal frameworks

Selected answer: 4. All support staff are located within the EU Value 125 SEAL 3

Notes: OVHcloud provides EU-only support for sovereign/SecNumCloud services; default Enterprise optionally includes Canadian affiliate at extra cost.

Evidence

  • OVHcloud Enterprise Support — EU-Based Support Teams other 21. August 2026
    OVHcloud Enterprise Support page offering a trusted version ensuring all interventions are carried out solely by EU-based teams.
    Relevance: Confirms OVHcloud can guarantee all support interventions by EU-based teams for EU services, directly addressing support channel sovereignty assurance.
All possible answer options (4)
  • 2. The team is mixed but the majority of support staff reside outside the EU (value 41.00, SEAL 2)
  • 3. The majority of support staff are in the EU but escalations are handled by non-EU teams (value 83.00, SEAL 3)
  • 4. All support staff are located within the EU (value 125.00, SEAL 3)
  • 5. All support staff are located within the EU and hold relevant security clearances (value 167.00, SEAL 4)
Q5. Documentation & Knowledge Transfer - availability of full technical documentation, source code, and operational know-how enabling long-term autonomy.

Selected answer: 5. EU-only end-to-end - Content, metadata, and backups/replicas are stored in the EU and privileged administration/support access is restricted to EU-based staff under EU jurisdiction Value 167 SEAL 4

Notes: SecNumCloud certifies EU-only storage, backups, and EU-only staff for privileged admin access. Open-source OpenStack architecture provides reversibility, though proprietary source code access remains limited.

Evidence

  • OVHcloud Data Sovereignty Commitment other 20. August 2026
    OVHcloud's data sovereignty page outlines its European cloud positioning, CLOUD Act protection, and full value chain control.
    Relevance: Confirms EU-only data storage, operations, and documentation with no non-EU subcontractors, supporting end-to-end EU control of documentation and knowledge repositories.
  • OVHcloud SecNumCloud Compliance other 21. August 2026
    Official page detailing ANSSI SecNumCloud certification; states services are operated, maintained and monitored exclusively by EU-based personnel.
    Relevance: SecNumCloud certification guarantees privileged admin/support access restricted to EU-based staff under EU jurisdiction, meeting the Option 5 criteria.
All possible answer options (4)
  • 2. EU optional, not enforced - EU storage is available as an option, but it is not enforced (value 41.00, SEAL 2)
  • 3. EU primary with non-EU fallback - Stored/managed in the EU by default, but some storage/replication/access outside the EU may occur (e.g., disaster recovery/support) (value 83.00, SEAL 4)
  • 4. EU-only primary repositories - All primary documentation and knowledge repositories are stored in the EU (no routine non-EU storage/processing) (value 125.00, SEAL 4)
  • 5. EU-only end-to-end - Content, metadata, and backups/replicas are stored in the EU and privileged administration/support access is restricted to EU-based staff under EU jurisdiction (value 167.00, SEAL 4)
Q6. Subcontractor & Suppliers jurisdiction - location and legal control of critical suppliers or subcontractors involved in service delivery.

Selected answer: 4. Ability to source alternative suppliers or internalise key functions Value 125 SEAL 3

Notes: OVHcloud's vertical integration (in-house server manufacturing, datacenter construction, own dark fibre network) limits supplier dependencies; proven resilience during 2020 crisis.

Evidence

  • OVHcloud and Data Sovereignty other 20. August 2026
    Official OVHcloud page on data sovereignty, governance structure, CISPE/GAIA-X founding membership, and EU legal jurisdiction.
    Relevance: Confirms subcontractors limited to EU/adequate jurisdictions, integrated model avoids stock disruptions—evidencing ability to source alternatives and internalise key functions.
  • OVHcloud Supply Chain (Official Sustainability Page) other 21. August 2026
    OVHcloud's official supply chain page showing vertical integration, in-house server manufacturing in France and Canada, circular economy practices, and a Supplier Code of Conduct with responsible mineral sourcing policies.
    Relevance: Demonstrates OVHcloud internalises critical functions (server production, datacenter construction) reducing dependency on foreign subcontractors, directly addressing supplier jurisdiction concerns.
  • Security and Digital Sovereignty – Press Kit other 21. August 2026
    Corporate press kit outlining three sovereignty pillars (data, technological, operational) with emphasis on integrated value chain control and Gaia-X Level 3 and SecNumCloud qualifications.
    Relevance: Explicitly addresses operational sovereignty pillar; SecNumCloud certifies EU-only personnel operations, confirming continuity against foreign supplier interruptions.
All possible answer options (4)
  • 2. Service would likely stop but with a delay to provide time for customer reaction (value 41.00, SEAL 2)
  • 3. Can continue temporarily based on contractual agreement with EC (value 83.00, SEAL 3)
  • 4. Ability to source alternative suppliers or internalise key functions (value 125.00, SEAL 3)
  • 5. Full autonomy and continuity (value 167.00, SEAL 4)

SOV-5 — Supply Chain Sovereignty

Supply chain sovereignty evaluates the geographic origin, transparency, and resilience of the technology supply chain, focusing on the extent to which critical components and processes remain under EU control or exposed to non-EU dependencies.

Weight 10%

Q1. Origin of Components - geographic source of key physical parts

Selected answer: Transparent with exceptions Value 71 SEAL 3

Notes: OVHcloud manufactures servers in-house (France/Canada) with published supply chain policies and a Supplier Code of Conduct (conflict minerals, UN Global Compact). However, specific named component suppliers and detailed country-of-origin info for individual parts (CPU, GPU, motherboards) are not publicly disclosed.

Evidence

  • OVHcloud and Data Sovereignty other 20. August 2026
    Official OVHcloud page on data sovereignty, governance structure, CISPE/GAIA-X founding membership, and EU legal jurisdiction.
    Relevance: Highlights OVHcloud's server design and manufacturing approach, supporting assessment of component origin controls. Sufficient for understanding endpoints but obviously not all sub-components.
  • OVHcloud Supply Chain (Official Sustainability Page) other 21. August 2026
    OVHcloud's official supply chain page showing vertical integration, in-house server manufacturing in France and Canada, circular economy practices, and a Supplier Code of Conduct with responsible mineral sourcing policies.
    Relevance: Directly relevant: documents supply chain management with component selection, reuse, recycling, and supplier standards. Shows important controls but lacks granular disclosure of component geographic origins or named suppliers.
  • Silba Deep Dives – OVHcloud, Europe's Cloud Sovereignty Play other 20. August 2026
    Independent analysis of OVHcloud's ownership structure: Klaba family 81% ownership, SecNumCloud certification, EU regulatory moat.
    Relevance: Provides third-party confirmation that while OVHcloud builds its own servers, key components still come from external (non-EU) suppliers. Reinforces the exceptions to full transparency on component provenance.
All possible answer options (4)
  • Partial disclosure (value 35.00, SEAL 1)
  • Transparent with exceptions (value 71.00, SEAL 3)
  • Full transparency (value 107.00, SEAL 3)
  • EU-certified provenance (value 143.00, SEAL 4)
Q2. Origin of Components: Manufacturing Location - countries where hardware is manufactured or assembled

Selected answer: Mixed sourcing, EU audit rights Value 71 SEAL 3

Notes: Servers assembled in-house in France by EU teams, but key components (AMD/Intel CPUs, Supermicro boards) are foreign-sourced. Supplier Code of Conduct grants EU audit rights.

Evidence

  • OVHcloud Servers: From Production to Delivery other 21. August 2026
    Official page detailing OVHcloud's 10-step server production process: component supply, assembly (8 components in 15 min), quality testing, all done in-house.
    Relevance: Shows servers are assembled by EU teams in France, but components are externally sourced, confirming mixed sourcing model.
  • OVHcloud Supplier Code of Conduct (Global, Aug 2024) other 21. August 2026
    Group-level Supplier Code requiring responsible mineral sourcing, REACH/RoHS compliance, supply chain mapping to origin, and OVHcloud audit/self-assessment rights.
    Relevance: Establishes EU audit rights over suppliers including origin tracing of components and minerals, directly supporting the 'EU audit rights' assessment.
  • OVHcloud Supply Chain (Official Sustainability Page) other 21. August 2026
    OVHcloud's official supply chain page showing vertical integration, in-house server manufacturing in France and Canada, circular economy practices, and a Supplier Code of Conduct with responsible mineral sourcing policies.
    Relevance: Confirms in-house EU assembly but acknowledges external component suppliers, supporting mixed sourcing with EU-level supply chain oversight.
All possible answer options (4)
  • Foreign origin, partial disclosure (value 35.00, SEAL 1)
  • Mixed sourcing, EU audit rights (value 71.00, SEAL 3)
  • Build by EU Teams, on the basis of a foreign code (value 107.00, SEAL 3)
  • Exclusive designed and build by EU Teams (value 143.00, SEAL 4)
Q3. Origin of Components - jurisdiction and provenance of embedded code controlling hardware, firmwares

Selected answer: Transparent with exceptions Value 71 SEAL 4

Notes: In-house manufacturing and open microcode practices are well documented, but full component supplier lists and firmware (Intel/AMD) provenance are not fully disclosed or EU-certified.

Evidence

  • OVHcloud Supply Chain (Official Sustainability Page) other 21. August 2026
    OVHcloud's official supply chain page showing vertical integration, in-house server manufacturing in France and Canada, circular economy practices, and a Supplier Code of Conduct with responsible mineral sourcing policies.
    Relevance: Shows OVHcloud controls its server manufacturing and component selection, but does not publish individual supplier identities or countries of origin for all components — a transparency exception.
All possible answer options (4)
  • Partial disclosure (value 35.00, SEAL 4)
  • Transparent with exceptions (value 71.00, SEAL 4)
  • Full transparency (value 107.00, SEAL 4)
  • EU-certified provenance (value 143.00, SEAL 4)
Q4. Origin of Software (all) - where and by whom software is architected and programmed

Selected answer: 4. A large majority of the software is designed and maintained by EU teams Value 107 SEAL 3

Notes: OVHcloud develops majority of software in-house by EU teams (1,396 engineers, 70% in France). Core uses open-source OpenStack, not exclusively EU.

Evidence

  • OVHcloud – Open Source: Shaping the Public Cloud other 20. August 2026
    Details OVHcloud's 100% open-source OpenStack-based public cloud with reversibility, no vendor lock-in, open APIs, and zero egress fees.
    Relevance: Shows core platform built on globally-developed OpenStack, preventing assessment from reaching exclusively EU rating.
  • OVHcloud 2023 Non-Financial Performance Statement other 21. August 2026
    Official corporate document detailing 1,396 engineers (69.8% in France), in-house cloud management, AI platform, and OpenStack R&D.
    Relevance: Authoritative source showing majority of engineers in France and extensive in-house software R&D, confirming EU-origin of core software components.
  • Silba Deep Dives – OVHcloud, Europe's Cloud Sovereignty Play other 20. August 2026
    Independent analysis of OVHcloud's ownership structure: Klaba family 81% ownership, SecNumCloud certification, EU regulatory moat.
    Relevance: Details OVHcloud's in-house software development by EU engineering teams with over 60% tech profiles, supporting majority EU-origin assessment.
All possible answer options (4)
  • 2. Software is of foreign origin with partial disclosure on its development (value 35.00, SEAL 2)
  • 3. Core and essential parts of the software are designed and maintained by EU teams (value 71.00, SEAL 3)
  • 4. A large majority of the software is designed and maintained by EU teams (value 107.00, SEAL 3)
  • 5. The software is exclusively designed and maintained by EU teams (value 143.00, SEAL 4)
Q5. Origin of Software (all) - location and jurisdiction governing software packaging, distribution, and updates.

Selected answer: 5. EU control and EU policy gates - As (4), plus EU-based compliance/security gates enforced in the pipeline (e.g., signing under your control, vulnerability checks, segregation of duties, auditable approvals) Value 143 SEAL 4

Notes: OVHcloud runs EU-based software build/deploy pipelines with enforced compliance gates: signing, vulnerability scanning, admission policies—all under EU jurisdiction.

Evidence

  • OVHcloud Presents Strategic Plan "Shaping the Future" and FY2026 Targets other 20. August 2026
    Strategic plan detailing €700M cumulative capex (2021-2023), European data center expansion, 2,900 employees across 15 countries, and EU sovereignty positioning.
    Relevance: Shows in-house software engineering is predominantly EU-based, meaning build/release/deployment execution is under EU control and EU jurisdiction
  • OVHcloud SecNumCloud Compliance other 21. August 2026
    Official page detailing ANSSI SecNumCloud certification; states services are operated, maintained and monitored exclusively by EU-based personnel.
    Relevance: Confirms software operations are exclusively governed by EU jurisdiction with EU-based personnel and auditable processes—SecNumCloud 3.2 requires exclusive application of European law
All possible answer options (4)
  • 2. EU control, non-EU execution - Execution is performed by non-EU teams, but pipeline administration and final release approvals are under EU jurisdiction (value 35.00, SEAL 1)
  • 3. Non-EU control, EU execution - Execution is performed by EU teams, but pipeline administration and/or final release approvals (incl. signing) are under non-EU jurisdiction (value 71.00, SEAL 3)
  • 4. EU control & execution - Build/release/deployment is executed by EU teams and governed from within the EU (pipeline administration, signing, approvals) (value 107.00, SEAL 3)
  • 5. EU control and EU policy gates - As (4), plus EU-based compliance/security gates enforced in the pipeline (e.g., signing under your control, vulnerability checks, segregation of duties, auditable approvals) (value 143.00, SEAL 4)
Q6. Single Point of Dependency - degree of reliance on non-EU vendors, facilities, or proprietary technologies

Selected answer: Few non-EU vendors or facilities involved in critical services, non documented, or non-EU vendors/facilities transparently documented Value 71 SEAL 2

Notes: OVHcloud vertically integrates server assembly in EU but depends on non-EU vendors (Intel, AMD, NVIDIA, Samsung) for critical components; these are transparently documented via supplier code, sustainability reports.

Evidence

  • OVHcloud — An Open Ecosystem, With Several Ways to Contribute other 21. August 2026
    OVHcloud's ecosystem page naming key hardware partners including Intel, AMD, NVIDIA, Samsung, Cisco — predominantly non-EU vendors for critical components.
    Relevance: Explicitly identifies the non-EU vendors (Intel, AMD, NVIDIA, Samsung) that supply critical components (CPUs, GPUs, memory) to OVHcloud's infrastructure, forming key single points of dependency.
  • OVHcloud 2025 Sustainability Statement (Universal Registration Document) other 21. August 2026
    Comprehensive sustainability report confirming upstream value chain includes suppliers in Asia and Africa; 17% IT component reuse rate; 64% emission factors tracked from suppliers.
    Relevance: Transparently documents non-EU supply chain dependencies including raw material/comcomponent sourcing from Asia and Africa, and quantifies component reuse vs. new procurement from external vendors.
  • OVHcloud Supply Chain (Official Sustainability Page) other 21. August 2026
    OVHcloud's official supply chain page showing vertical integration, in-house server manufacturing in France and Canada, circular economy practices, and a Supplier Code of Conduct with responsible mineral sourcing policies.
    Relevance: Shows OVHcloud's vertical integration and supplier governance but confirms it still sources critical electronic components from external (non-EU) suppliers for server production.
All possible answer options (4)
  • Mostly non-EU vendors or facilities involved in critical services, non documented (value 35.00, SEAL 1)
  • Few non-EU vendors or facilities involved in critical services, non documented, or non-EU vendors/facilities transparently documented (value 71.00, SEAL 2)
  • Few non-EU vendors or facilities involved in non-critical services, documented (value 107.00, SEAL 3)
  • No depedency on non-EU vendor or facility (value 143.00, SEAL 4)
Q7. Supply Chain Transparency - visibility into the entire supplier and sub-supplier chain, including audit rights.

Selected answer: Most suppliers and subcontractors can be audited Value 107 SEAL 3

Notes: OVHcloud grants on-site audit rights via third-party auditors for direct suppliers and requires exhaustive subcontractor listings. Vertical integration reduces external dependencies. Full deep sub-supplier auditability is limited for component vendors.

Evidence

  • OVHcloud Supplier Code of Conduct (Global, Aug 2024) other 21. August 2026
    Group-level Supplier Code requiring responsible mineral sourcing, REACH/RoHS compliance, supply chain mapping to origin, and OVHcloud audit/self-assessment rights.
    Relevance: Establishes contractual audit/verification rights and supply chain transparency obligations for suppliers, but audit is primarily evidence-based, not full on-site for all tiers.
  • OVHcloud Supplier Purchasing Terms other 21. August 2026
    Formal purchase order T&Cs with audit rights (on-premises via third-party), subcontractor consent, and exhaustive subcontractor listing requirements.
    Relevance: Directly addresses audit rights for suppliers and subcontractor visibility — includes on-premises compliance assessments and requirement for exhaustive subcontractor listings and subcontract copies.
  • OVHcloud Supply Chain (Official Sustainability Page) other 21. August 2026
    OVHcloud's official supply chain page showing vertical integration, in-house server manufacturing in France and Canada, circular economy practices, and a Supplier Code of Conduct with responsible mineral sourcing policies.
    Relevance: Vertical integration reduces number of external suppliers requiring audit; demonstrates production-chain control. Does not cover deep sub-supplier chains of component vendors.
All possible answer options (4)
  • Some suppliers and subcontractors can be audited (value 35.00, SEAL 1)
  • Critical suppliers and subcontractors can be audited (value 71.00, SEAL 2)
  • Most suppliers and subcontractors can be audited (value 107.00, SEAL 3)
  • All suppliers and subcontractors can be audited (value 143.00, SEAL 4)

SOV-6 — Technology Sovereignty

Technology sovereignty evaluates the degree of openness, transparency, and independence in the underlying technological stack, ensuring EU actors can interoperate, audit, and evolve solutions without lock-in to foreign proprietary systems.

Weight 15%

Q1. Interoperability & Open interfaces - ability to integrate with other technologies through well-documented and non-proprietary APIs or protocols.

Selected answer: 4. Standards-based and broadly compatible - Interfaces and data formats predominantly follow recognised open standards (e.g., ETSI/CEN/CENELEC, ISO/IEC, IETF/W3C) with stable versioning and full documentation Value 150 SEAL 3

Notes: Public Cloud core uses OpenStack APIs (non-proprietary, interoperable), but some services use OVHcloud-specific REST APIs, preventing a full open-by-default rating.

Evidence

  • Open Source: Shaping the Public Cloud — OVHcloud other 21. August 2026
    OVHcloud article detailing its OpenStack-powered Public Cloud, commitment to open APIs, reversibility, and interoperability since 2012.
    Relevance: Confirms OVHcloud uses open-standard OpenStack APIs for compute/storage/network, ensuring hybrid/multi-cloud compatibility and no vendor lock-in.
  • OpenStack — OVHcloud other 21. August 2026
    OVHcloud's OpenStack page detailing membership since 2014, use of core OpenStack components (Nova, Neutron, Cinder, etc.), and API compatibility.
    Relevance: Shows OVHcloud Public Cloud infrastructure is fully accessible via documented, non-proprietary OpenStack APIs compatible with standard tools (Terraform, Ansible).
  • OpenStack Cloud Architecture — Leafcloud other 21. August 2026
    Independent technical resource comparing OpenStack providers (including OVH) against hyperscalers on vendor lock-in and API standardization.
    Relevance: Independent analysis confirms OVHcloud's OpenStack APIs are low vendor-lock-in, standard REST APIs compatible across providers, contrasting with proprietary hyperscaler APIs.
All possible answer options (4)
  • 2. Restricted proprietary APIs - Some vendor APIs exist, but they are limited/restricted (access, scope, licensing) and interoperability remains vendor-controlled (value 50.00, SEAL 1)
  • 3. Mixed (partial openness) - Key interfaces are documented and partly standards-based, but important functions or data formats remain proprietary/vendor-specific (value 100.00, SEAL 2)
  • 4. Standards-based and broadly compatible - Interfaces and data formats predominantly follow recognised open standards (e.g., ETSI/CEN/CENELEC, ISO/IEC, IETF/W3C) with stable versioning and full documentation (value 150.00, SEAL 3)
  • 5. Open-by-default with portability - All critical functions are accessible via open, well-documented, non-proprietary APIs and standard formats, with published specifications and minimal vendor-specific dependencies enabling easy third-party integration (value 200.00, SEAL 4)
Q2. Open Standards Compliance - extent to which the solution adheres to publicly governed and widely adopted standards, reducing dependency on single vendors

Selected answer: 4. Policy for most core services - A formal policy mandates and documents open standards for most core services, with managed exceptions Value 150 SEAL 3

Notes: OVHcloud documents open standards across Public Cloud (100% OpenStack), reversibility (SWIPO), and ISSP, but some services remain proprietary (e.g., vRack, control panel).

Evidence

  • Open Cloud Security Standards - OVHcloud other 21. August 2026
    OVHcloud's security posture page: full supply chain control from hardware to datacenter, in-house server manufacturing, security certifications (ISO 27001, SOC, PCI DSS).
    Relevance: Shows documented corporate policy on open standards adoption across cloud services, including ISO and security certifications built on open standards.
  • OVHcloud – Open Source: Shaping the Public Cloud other 20. August 2026
    Details OVHcloud's 100% open-source OpenStack-based public cloud with reversibility, no vendor lock-in, open APIs, and zero egress fees.
    Relevance: Demonstrates formal adoption of open standards (OpenStack) as core architecture with open APIs for interop and reversibility, evidence of policy-level commitment.
  • OVHcloud Information System Security Policy (ISSP) other 21. August 2026
    Formal documented security policy stating products are built using open-source technologies and established technology standards to facilitate adoption and reversibility.
    Relevance: Formal policy document mandating open-source and established standards for product development, applicable across OVHcloud group — evidence of governance-level open standards policy.
All possible answer options (4)
  • 2. Ad hoc use - Open standards are used inconsistently on a case-by-case basis, without documented rationale or governance (value 50.00, SEAL 0)
  • 3. Partial core adoption - Open standards are used and documented for some core services, while other core services remain proprietary/vendor-specific (value 100.00, SEAL 2)
  • 4. Policy for most core services - A formal policy mandates and documents open standards for most core services, with managed exceptions (value 150.00, SEAL 3)
  • 5. Policy for all core services - A formal policy mandates and documents open standards for all core services (value 200.00, SEAL 4)
Q3. Open Source Availability - whether software is accessible under open licenses, with rights to audit, modify, and redistribute, ensuring transparency and adaptability

Selected answer: 3. The software is open source , permitting modification and redistribution, but governance is centralised (e.g., single-company or non-open foundation), limiting strategic autonomy or smooth handover Value 100 SEAL 3

Notes: OVHcloud uses and contributes to OpenStack (independently governed) but its own 178 GitHub repos are centrally governed by the company, and proprietary management layer limits full autonomy.

No evidence provided for this answer.

All possible answer options (4)
  • 2. Source code is available for review but modification and handover rights are under very strict conditions (value 50.00, SEAL 2)
  • 3. The software is open source , permitting modification and redistribution, but governance is centralised (e.g., single-company or non-open foundation), limiting strategic autonomy or smooth handover (value 100.00, SEAL 3)
  • 4. The software is open source with significant EU contributions but governance is restricted and handover is possible (value 150.00, SEAL 4)
  • 5. Fully open-source software is governed by an independent or EU-based entity, granting full rights to audit, modify, redistribute, and seamlessly transfer stewardship (value 200.00, SEAL 4)
Q4. Service Architecture Transparency - visibility into the design and functioning of the service, including architectural documentation, data flows, and dependencies

Selected answer: Large corpus of public insight exists (all) Value 150 SEAL 3

Notes: OVHcloud publishes extensive architecture docs via OpenStack (open-source), full technical docs portal, public ISSP, and compliance attestations covering all service architecture aspects.

Evidence

  • OpenStack — OVHcloud other 21. August 2026
    OVHcloud's OpenStack page detailing membership since 2014, use of core OpenStack components (Nova, Neutron, Cinder, etc.), and API compatibility.
    Relevance: Publicly documents all architectural components, dependencies, and data flow patterns of OVHcloud's Public Cloud built on open-source OpenStack.
  • OVHcloud – Open Source: Shaping the Public Cloud other 20. August 2026
    Details OVHcloud's 100% open-source OpenStack-based public cloud with reversibility, no vendor lock-in, open APIs, and zero egress fees.
    Relevance: Demonstrates full transparency of service architecture via 100% open-source OpenStack with documented APIs, data flows, and dependencies — no proprietary lock-in.
  • OVHcloud Information System Security Policy (ISSP) other 21. August 2026
    Formal documented security policy stating products are built using open-source technologies and established technology standards to facilitate adoption and reversibility.
    Relevance: Publicly discloses internal security architecture, monitoring data flows (SIEM/CERT), and audit posture — key aspects of service architecture transparency.
All possible answer options (4)
  • Insight accessible during audits (value 50.00, SEAL 2)
  • Some public insight exists (all) (value 100.00, SEAL 3)
  • Large corpus of public insight exists (all) (value 150.00, SEAL 3)
  • Customers can contribute to adapt and enhance the service (value 200.00, SEAL 4)
Q5. HPC Soveriegnty - degree of European independence in high-performance computing capabilities, including processors, accelerators, and software ecosystems.

Selected answer: Co-designed or integrated in EU Value 100 SEAL 3

Notes: OVHcloud designs/assembles HPC servers in EU but uses AMD/Intel processors and NVIDIA accelerators—no European processor IP in its HPC stack.

Evidence

  • OVHcloud Delivers Next-Generation Bare Metal Services with AMD other 21. August 2026
    AMD case study confirming OVHcloud deploys 4th Gen AMD EPYC processors in HPC servers; also describes OVHcloud's in-house server design, manufacturing, and liquid cooling.
    Relevance: Third-party source confirming both foreign processor dependency (AMD) and EU-based server design/assembly, supporting the co-designed/integrated assessment.
  • OVHcloud High Performance Computing on Bare Metal other 21. August 2026
    OVHcloud's official HPC page detailing AMD EPYC, Intel Xeon Gold, and NVIDIA V100S-based server ranges for HPC workloads.
    Relevance: Shows OVHcloud's HPC offerings use exclusively non-EU processors (AMD, Intel) and accelerators (NVIDIA); no European silicon in its computing stack.
  • OVHcloud Servers: From Production to Delivery other 21. August 2026
    Official page detailing OVHcloud's 10-step server production process: component supply, assembly (8 components in 15 min), quality testing, all done in-house.
    Relevance: Demonstrates EU-based server design, assembly, and manufacturing, which is a distinct form of EU co-design and integration beyond mere hosting of a foreign stack.
All possible answer options (4)
  • EU-hosted, foreign stack (value 50.00, SEAL 3)
  • Co-designed or integrated in EU (value 100.00, SEAL 3)
  • EU processor IP, non-EU fabs (value 150.00, SEAL 3)
  • EU design + EU fab + EU ops (value 200.00, SEAL 4)

SOV-7 — Security & Compliance Sovereignty

Security & Compliance sovereignty measures the extent to which security operations, compliance obligations, and resilience measures are controlled within the EU , ensuring independence from foreign jurisdictions and long-term operational assurance.

Weight 15%

Q1. Security Certification - attainment of EU and internationally recognized certifications (all)

Selected answer: EAL4-5 Value 143 SEAL 4

Notes: OVHcloud holds comprehensive EU and international certifications: ISO 27001/27017/27018/27701, SOC 1/2/3, PCI DSS L1, CSA STAR, HDS, and ANSSI SecNumCloud v3.2.

Evidence

  • OVHcloud — Security and Certifications (Corporate) other 21. August 2026
    Corporate overview listing ISO 27001/27017/27018, ISO 27701, SOC 1/2/3, CSA STAR, PCI DSS, and SecNumCloud 3.2 qualification from ANSSI.
    Relevance: Comprehensive list of internationally recognized certifications demonstrating attainment across multiple security domains for all assessment scope.
  • OVHcloud SecNumCloud Compliance other 21. August 2026
    Official page detailing ANSSI SecNumCloud certification; states services are operated, maintained and monitored exclusively by EU-based personnel.
    Relevance: Directly evidences EU-recognized security certification (SecNumCloud is France's highest cloud security standard, protecting against non-EU extraterritorial laws).
All possible answer options (4)
  • ELA1 (value 35.00, SEAL 1)
  • EAL2 (value 71.00, SEAL 2)
  • ELA3 (value 107.00, SEAL 3)
  • EAL4-5 (value 143.00, SEAL 4)
Q2. EU Regulatory compliance - demonstrable adherence to GDPR, NIS2, DORA, and other EU frameworks

Selected answer: 5. Fully compliant to all well-know EU regulations (verified compliance, independently audited) Value 143 SEAL 4

Notes: GDPR fully compliant & independently audited; ISO/SOC/SecNumCloud certifications strong. NIS2 and DORA not explicitly demonstrated, creating minor gaps.

Evidence

  • GDPR-NIS2-DORA Compliant Cloud Architecture: 2026 Integration Guide other 20. August 2026
    Third-party guide recommending OVHcloud as an EU-native provider for GDPR/NIS2/DORA compliance; compares SecNumCloud vs BSI C5 for regulated workloads.
    Relevance: Names OVHcloud among EU-native providers suited for multi-regulation compliance, but highlights that DORA-specific compliance is not yet explicitly demonstrated by OVHcloud.
  • OVHcloud — Security and Certifications (Corporate) other 21. August 2026
    Corporate overview listing ISO 27001/27017/27018, ISO 27701, SOC 1/2/3, CSA STAR, PCI DSS, and SecNumCloud 3.2 qualification from ANSSI.
    Relevance: ndependently audited certifications (ISO, SOC, SecNumCloud) demonstrate systematic compliance with EU-equivalent security frameworks supporting GDPR and NIS requirements.
  • OVHcloud Legal and Privacy Security other 20. August 2026
    OVHcloud's official legal page listing applicable legal texts per jurisdiction, GDPR compliance, and EU data hosting with protection against extraterritorial laws.
    Relevance: Directly demonstrates GDPR adherence and references to NIS Directive (predecessor to NIS2); confirms EU jurisdiction and DPA enforcement.
All possible answer options (4)
  • 2. Limited compliance to some well-known EU Regulations (basic practices exist but informal, incomplete, or non-systematic) (value 35.00, SEAL 4)
  • 3. Moderate compliance to some well-know EU Regulations (controls exist but gaps remain; compliance not fully demonstrated) (value 71.00, SEAL 4)
  • 4. Partial compliance to most of the well-known EU Regulations (requirements implemented and operational with minor exceptions) (value 107.00, SEAL 4)
  • 5. Fully compliant to all well-know EU regulations (verified compliance, independently audited) (value 143.00, SEAL 4)
Q3. EU-based SOC & incident handling - security operations centers and response teams operating exclusively under EU jurisdiction.

Selected answer: 5. The full incident lifecycle is handled by EU-based teams with active participation in ENISA's information sharing frameworks. Threat intelligence and incident data are gathered worldwide Value 143 SEAL 4

Notes: Full incident lifecycle handled by EU-based CSIRT-OVH (France). NIS2 compliance and CSIRT info-sharing align with ENISA frameworks. Threat intelligence gathered worldwide.

Evidence

  • CSIRT-OVH RFC 2350 Charter other 21. August 2026
    OVHcloud's official CSIRT charter defining mission, constituency (EMEA/Canada/APAC, excluding OVH US LLC), incident response lifecycle, and information sharing protocols (TLP v2.0).
    Relevance: Confirms EU-based CSIRT handling full incident lifecycle (prevention–recovery). Excludes US entity. Active info-sharing with CSIRTs/CERTs following NIS2/ENISA-aligned TLP protocols. Worldwide threat intelligence exchange.
  • Open Cloud Security Standards - OVHcloud other 21. August 2026
    OVHcloud's security posture page: full supply chain control from hardware to datacenter, in-house server manufacturing, security certifications (ISO 27001, SOC, PCI DSS).
    Relevance: Describes SOC and CSIRT teams for threat detection and incident response within a European provider context, supporting EU-exclusive security operations.
  • OVHcloud and Data Sovereignty other 20. August 2026
    Official OVHcloud page on data sovereignty, governance structure, CISPE/GAIA-X founding membership, and EU legal jurisdiction.
    Relevance: Confirms no non-EU entity has access to EU customer infrastructure, meaning incident handling for EU customers is exclusively under EU jurisdiction by EU-based teams.
All possible answer options (4)
  • 2. A hybrid model is used with SOC functions split between EU and non-EU locations (value 35.00, SEAL 1)
  • 3. The primary SOC is in the EU but incidents may be escalated to non-EU teams (value 71.00, SEAL 1)
  • 4. The entire incident lifecycle is handled by teams operating exclusively within the EU. Threat intelligence and incident data obtained mostly via EU sources (value 107.00, SEAL 3)
  • 5. The full incident lifecycle is handled by EU-based teams with active participation in ENISA's information sharing frameworks. Threat intelligence and incident data are gathered worldwide (value 143.00, SEAL 4)
Q4. Control over security monitoring/logging - customer or EU authority ability to oversee logs, alerts, and monitoring functions directly.

Selected answer: 5. Customers have full access to immutable tamper-proof logs stored exclusively within the EU Value 143 SEAL 4

Notes: OVHcloud Logs Data Platform offers immutable log streams in EU datacenters, with full customer access via Graylog/OpenSearch. SecNumCloud-certified and EU-headquartered.

Evidence

  • Generating OVHcloud Account Logs with Logs Data Platform other 20. August 2026
    Official documentation detailing three audit log types: audit logs (IP, geolocation, MFA, user agent), activity logs (API calls, user identity), and access policy logs (IAM evaluations).
    Relevance: Confirms direct customer access to security logs and explicitly states 'data stored in a logs stream is immutable,' aligning with option 5's immutability and EU storage requirements.
  • Logs Data Platform – Product Page other 21. August 2026
    OVHcloud's managed log management platform built on OpenSearch ecosystem, supporting Graylog/Grafana, ISO 27001/27017/27701 certified, hosted in EU datacenters.
    Relevance: Demonstrates full customer access to logs via dashboards/API, secure EU-hosted platform, and certifications supporting sovereignty and security monitoring requirements.
All possible answer options (4)
  • 2. Customers receive periodic reports based on security logs (value 35.00, SEAL 1)
  • 3. Customers have access to a basic portal for monitoring (value 71.00, SEAL 1)
  • 4. Customers have full direct access to their security monitoring and logs which are stored in the EU (value 107.00, SEAL 3)
  • 5. Customers have full access to immutable tamper-proof logs stored exclusively within the EU (value 143.00, SEAL 4)
Q5. Disclosure of incidents - transparent, timely, and EU-compliant reporting of breaches or vulnerabilities

Selected answer: 4. Partial compliance - there is a monitored reporting flow with internal SLAs equal or below regulatory maximums; contractually prepared to support EU-directed investigations; data sharing with EU CSIRTs available but not in real-time Value 107 SEAL 3

Notes: Formal CSIRT, GDPR/NIS2-aligned reporting, audit-backed incident management, and CSIRT cooperation — but no evidence of real-time EU CSIRT data sharing.

Evidence

  • CSIRT-OVH RFC 2350 Charter other 21. August 2026
    OVHcloud's official CSIRT charter defining mission, constituency (EMEA/Canada/APAC, excluding OVH US LLC), incident response lifecycle, and information sharing protocols (TLP v2.0).
    Relevance: Demonstrates formal CSIRT with structured incident reporting and cooperation with EU CSIRTs, but does not specify real-time data sharing arrangements.
  • Open Cloud Security Standards - OVHcloud other 21. August 2026
    OVHcloud's security posture page: full supply chain control from hardware to datacenter, in-house server manufacturing, security certifications (ISO 27001, SOC, PCI DSS).
    Relevance: Shows monitored reporting flow, SOC/CSIRT integration, and audit-backed security processes supporting EU-directed investigation readiness.
  • OVHcloud Data Security & Compliance other 20. August 2026
    Details OVHcloud's ISMS, monitoring/logging policies for storage servers and infrastructure, and annual third-party audits (ISO 27001/27017/27018, SOC 2).
    Relevance: Documents formal incident classification, response plans, customer communication procedures, and vulnerability monitoring aligned with GDPR/NIS2 obligations.
All possible answer options (4)
  • 2. Limited compliance - reporting is reactive with limited transparency and unguaranteed timelines; CSIRT cooperation possible on best-effort basis (value 35.00, SEAL 1)
  • 3. Moderate compliance - GDPR/NIS2-aligned reporting procedures in place with vulnerabilities and breaches communicated within mandated timelines; CSIRT cooperation available but not real-time (value 71.00, SEAL 2)
  • 4. Partial compliance - there is a monitored reporting flow with internal SLAs equal or below regulatory maximums; contractually prepared to support EU-directed investigations; data sharing with EU CSIRTs available but not in real-time (value 107.00, SEAL 3)
  • 5. Full compliance - full EU-compliant breach disclosure with real-time data sharing to EU CSIRTs with audit-backed processes, proactive vulnerability disclosure and threat intel sharing; proven readiness for investigations (value 143.00, SEAL 4)
Q6. Maintenance Autonomy - ability to develop, test, and apply security patches independently of non-EU vendors

Selected answer: 4. High Autonomy - security patches can be deployed independently by the customer, without customers' checks Value 107 SEAL 4

Notes: OVHcloud builds own servers & uses open-source OpenStack, enabling independent EU-based patch development and deployment without non-EU vendor dependency.

Evidence

  • OpenStack — OVHcloud other 21. August 2026
    OVHcloud's OpenStack page detailing membership since 2014, use of core OpenStack components (Nova, Neutron, Cinder, etc.), and API compatibility.
    Relevance: Open-source OpenStack platform means OVHcloud can independently develop, test, and apply patches to its cloud infrastructure without dependence on non-EU vendors.
  • OVHcloud Service-Specific Terms for Products and Services other 20. August 2026
    Official legal terms detailing automatic and irreversible deletion of content data on service termination, KMS-based cryptographic key deletion, and shared responsibility for data backup.
    Relevance: Shows OVHcloud applies infrastructure patches independently as an EU provider, while customers independently manage their own workload patching without vendor dependency.
  • VMware on OVHcloud Maintenance Operations other 21. August 2026
    Documentation detailing maintenance operation types (Emergency, Standard, Normal) and customer patching responsibilities for ESXi hosts.
    Relevance: Shows three-tier maintenance with advance notice. Customers can reschedule maintenance and directly administer ESXi patches independently, demonstrating high patching autonomy.
All possible answer options (4)
  • 2. Limited Autonomy - security patches are deployed according to vendor schedules; basic testing is possible (value 35.00, SEAL 1)
  • 3. Moderate Autonomy - security patches are deployed with sufficient notice to the customer and testing is possible, except for zero-day patching (value 71.00, SEAL 4)
  • 4. High Autonomy - security patches can be deployed independently by the customer, without customers' checks (value 107.00, SEAL 4)
  • 5. Full Autonomy - security patches can be deployed independently by the customer, with customers' checks (value 143.00, SEAL 4)
Q7. Auditability - capacity for EU entities to perform independent security and compliance audits with full access.

Selected answer: 4. High control by independent entities to request data from the vendor Value 107 SEAL 1

Notes: OVHcloud offers extensive independent EU-based audits (ANSSI labs, ISO, SOC) but gatekeeps on-site audits via sales; reports under conditions, not unrestricted.

Evidence

  • OVHcloud — Security and Certifications (Corporate) other 21. August 2026
    Corporate overview listing ISO 27001/27017/27018, ISO 27701, SOC 1/2/3, CSA STAR, PCI DSS, and SecNumCloud 3.2 qualification from ANSSI.
    Relevance: Demonstrates broad independent third-party audit coverage enabling EU entities to request compliance data across multiple frameworks.
  • OVHcloud Data Sovereignty other 21. August 2026
    OVHcloud's data sovereignty commitments: GDPR Art. 48 resistance to non-EU requests, EU-only personnel, CISPE/GAIA-X founding membership.
    Relevance: Establishes EU jurisdictional control over audit and compliance data, ensuring independent EU entities can access data free from non-EU interference.
  • OVHcloud SecNumCloud Compliance other 21. August 2026
    Official page detailing ANSSI SecNumCloud certification; states services are operated, maintained and monitored exclusively by EU-based personnel.
    Relevance: Shows independent EU auditors (ANSSI-approved labs) perform security evaluations, but customer-initiated audits are gated through sales, limiting full unrestricted access.
All possible answer options (4)
  • 2. Limited access to independent entities to the data provided by the vendor (value 35.00, SEAL 1)
  • 3. Partial control by independent entities on the data provided by the vendor (value 71.00, SEAL 1)
  • 4. High control by independent entities to request data from the vendor (value 107.00, SEAL 1)
  • 5. Full control by any idependent entity to perform security and compliance audits (value 143.00, SEAL 4)

SOV-8 — Environmental Sustainability

Environmental sustainability assesses autonomy and resilience of cloud services over the long term in relation to energy usage, dependency and raw material scarcity.

Weight 5%

Q1. Energy efficiency - adoption of energy-efficient infrastructure (all) and measurable improvement targets.

Selected answer: PUE < 1.3 Value 187 SEAL 4

Notes: Fleet-wide PUE 1.24-1.26, audited over 12 months (88% coverage), ISO 50001 certified, with NetZero 2030 roadmap and quantified GHG reduction targets.

Evidence

  • OVHcloud Environment & Sustainability other 22. August 2026
    Corporate sustainability page covering ISO 50001 certification, European Code of Conduct participation, audited PUE over 12 months, and GHG reduction targets to FY2030.
    Relevance: Establishes measurable improvement targets (73.4% Scope 1&2 reduction by FY2030), ISO 50001 certification, and audited PUE methodology.
  • OVHcloud Sustainability Press Kit other 22. August 2026
    Press kit summarizing OVHcloud's environmental performance: fleet-wide PUE of 1.24, 100% renewable energy, and AI-driven cooling innovations.
    Relevance: Confirms fleet-average PUE of 1.24, which is below the 1.3 threshold, with audited measurement methodology and improvement targets.
  • OVHcloud White Paper: Building a Sustainable and Responsible Digital Future (2024) other 22. August 2026
    White paper detailing OVHcloud's PUE range of 1.1-1.3 across all sites, water-cooling tech since 2003, NetZero 2030 commitment, ISO/IEC 30134-2 PUE standard adherence.
    Relevance: Shows PUE range 1.1-1.3 across all data centers with detailed energy efficiency roadmap and measurable NetZero 2030 commitment.
All possible answer options (5)
  • PUE > 0 (value 0.00, SEAL 1)
  • PUE < 3 (value 62.00, SEAL 1)
  • PUE < 1.5 + roadmap (value 125.00, SEAL 4)
  • PUE < 1.3 (value 187.00, SEAL 4)
  • PUE < 1.2 EU verified (value 250.00, SEAL 4)
Q2. Hardware reuse & recycling - circular economy practices ensuring reuse, refurbishment, and responsible end-of-life treatment of hardware.

Selected answer: Circular economy EU-aligned Value 187 SEAL 4

Notes: OVHcloud applies full circular economy principles end-to-end: design for disassembly, reverse supply chain with 6 stages, component reuse across server generations, and certified recycling partners—aligned with EU goals.

Evidence

  • OVHcloud — Our Commitment to Green Technology other 22. August 2026
    OVHcloud's green tech page covering circular economy principles applied since founding, servers designed for full disassembly and component reuse, and in-house manufacturing in France and Canada.
    Relevance: Demonstrates long-standing, documented circular economy practices for hardware: servers designed for reuse, recycling, and repair, with second and third lives for components.
  • OVHcloud Supply Chain Sustainability other 22. August 2026
    OVHcloud's corporate page detailing a six-stage reverse supply chain model: Creating, Maintaining, Redistributing, Testing, Reusing, and Recycling, with certified recycling partners for end-of-life.
    Relevance: Directly documents the full circular economy lifecycle for hardware—from design to certified recycling—showing EU-aligned reuse and responsible end-of-life treatment.
  • OVHcloud White Paper: Building a Sustainable and Responsible Digital Future (2024) other 22. August 2026
    White paper detailing OVHcloud's PUE range of 1.1-1.3 across all sites, water-cooling tech since 2003, NetZero 2030 commitment, ISO/IEC 30134-2 PUE standard adherence.
    Relevance: Provides quantified evidence (45% reused components, ECO range, zero-waste goal) of a formally documented circular economy program aligned with EU sustainability objectives.
All possible answer options (5)
  • No policy (value 0.00, SEAL 0)
  • Circular economy EU-aligned (value 62.00, SEAL 0)
  • Documented program (value 125.00, SEAL 3)
  • Circular economy EU-aligned (value 187.00, SEAL 4)
  • EU-certified lifecycle (value 250.00, SEAL 4)
Q3. Environmental impact reporting - transparent measurement and disclosure of carbon emissions, water usage, and other sustainability indicators.

Selected answer: EU-audited reporting Value 250 SEAL 4

Notes: CSRD-compliant, third-party audited reporting (KPMG/IJO) covering Scope 1-3 emissions, PUE/WUE, EU Taxonomy, per EU frameworks.

Evidence

  • OVHcloud 2025 Sustainability Statement (Universal Registration Document) other 21. August 2026
    Comprehensive sustainability report confirming upstream value chain includes suppliers in Asia and Africa; 17% IT component reuse rate; 64% emission factors tracked from suppliers.
    Relevance: Confirms compliance with EU's mandatory sustainability reporting framework (CSRD), which requires standardized disclosure and third-party assurance of environmental indicators including carbon and water.
  • OVHcloud Environmental Impact Tracker Methodology (PDF) other 22. August 2026
    25-page methodology document detailing per-server GHG calculations using GHG Protocol and Bilan Carbone®, audited by IJO and Cost House with Limited Assurance Statement.
    Relevance: Shows detailed, third-party-audited methodology for measuring carbon emissions at server level, with site-specific PUE/WUE values and plans to expand to water, abiotic resources, and land use.
  • OVHcloud Non-Financial Performance Statement FY2024 (DPEF) other 22. August 2026
    Comprehensive ESG disclosure for FY2024 audited by KPMG (COFRAC-accredited), covering Scope 1-3 emissions, PUE/WUE/CUE/REF, EU Taxonomy alignment (66% revenue).
    Relevance: Demonstrates EU-regulated, independently audited environmental reporting including carbon emissions, water usage (WUE), and EU Taxonomy alignment — directly relevant to transparent sustainability disclosure.
All possible answer options (5)
  • No reporting (value 0.00, SEAL 1)
  • Detailed EU methodology (value 62.00, SEAL 1)
  • Annual report (value 125.00, SEAL 2)
  • Detailed EU methodology (value 187.00, SEAL 3)
  • EU-audited reporting (value 250.00, SEAL 4)
Q4. Energy supplies - sourcing of renewable or low-carbon energy to power infrastructure and operations

Selected answer: Mix of EU and non-EU supplies Value 125 SEAL 4

Notes: OVHcloud operates data centers in EU and non-EU countries; 92% renewable energy via EU PPAs but non-EU sites use local grids and nuclear included in low-carbon mix.

Evidence

  • OVHcloud — Our Datacenter Locations other 22. August 2026
    OVHcloud's official data center locations page listing 46 data centers across 9 countries on 4 continents, including EU and non-EU sites.
    Relevance: Shows OVHcloud operates data centers in both EU (France, Germany, Italy, Poland) and non-EU countries (USA, Canada, Australia, Singapore, India, UK), confirming mixed energy supply origins.
  • OVHcloud Environment & Sustainability other 22. August 2026
    Corporate sustainability page covering ISO 50001 certification, European Code of Conduct participation, audited PUE over 12 months, and GHG reduction targets to FY2030.
    Relevance: Details OVHcloud's energy sourcing commitments including renewable energy ratio and transition to 100% low-carbon (not 100% green) energy by 2025.
  • OVHcloud signs 10-year PPA with Sunnic Lighthouse to power German data center other 22. August 2026
    Article reporting OVHcloud's 10-year solar PPA with Sunnic Lighthouse for its German data center, increasing renewable share to 92%.
    Relevance: Confirms EU-specific renewable PPA and 100% low-carbon (not exclusively green) target by 2025, while non-EU sites rely on local grid energy.
All possible answer options (4)
  • Only EU energy supplies (value 62.00, SEAL 4)
  • Mix of EU and non-EU supplies (value 125.00, SEAL 4)
  • Only EU energy supplies (value 187.00, SEAL 4)
  • Only green EU energy supplies (value 250.00, SEAL 4)

Data Centres

OVHcloud is operating 43 data centres in 9 countries with more than 450.000 servers. Outside of Europe, OVHcloud have data centres in Australia, India, Singapore, United States and Canada. In Europe, OVHcloud are operating 4 data centres in France, one in Germany, one in Poland and one in the United Kingdom.

NameCityCountry
GRAGravelinesFrance
EU-WEST-PARParisFrance
RBX-ARoubaixFrance
SBGStrasbougFrance
DE1FrankfurtGermany
WAW1WarsawPoland
UK1LondonUnited Kingdom
EU-SOUTH-MILMilanItaly
BHS5BeauharnoisCanada
SYD1SydneyAustralia
SGP1SingaporeSingapore
AP-SOUTH-MUM-1MumbaiIndia

For the geographical location of all European data centres check the Data Centre Map.

Environmental Policy

OVHcloud has a very distinct and holistic environmental policy, based on several pillars:

  • Energy: OVHcloud’s policy regarding energy consumption is twofold: the data centers are designed use as minimal electricity as possible. OVHcloud claim to have an average Power Usage Efficiency (PUE) of 1,26 (compared to ~1,5 industry average). Furthermore, the company strives to use renewable or low-carbon energy. 92% of energy comes from renewable sources in 2025.
  • Water consumption: the data centers are designed to minimize water consumption for cooling.
  • Circular economy: OVHcloud claims to disassemle all servers after use, thus reusing 27% of components.
  • Measurement & Transparency: the company is measuring its own environmental footprint and is being transparent about it. Furthermore, cloud users can check their carbon footprint in the OVHcloud console. OVHcloud are calculating the carbon footprint by considering the CO2 equivalent of server production, energy consumption and operation.

Read more about OVHcloud environmental policy.

Certifications

Being an “older” European player, OVHcloud have accumulated a large set of certifications – both regional/national certifications as well as international standards. These include ISO27001, SOC 1, SOC 2, SOC 3, the strict SecNumCloud certification, and the German C5 (Cloud Computing Compliance Criteria Catalogue) of BSI.

NameDescription
BSI C5German cloud security catalogue
CSA STARCloud Security Alliance Assurance Registry
ISO 27001World's best-known standard for information security management systems (ISMS)
ISO 27017Information security controls for cloud services
ISO 27018Guidance for protecting PII data in public clouds
ISO 27701Requirements for Privacy Information Management System
ISO 50001Standard for Energy Management System
PCI DSSStandard regulating protection of payment account data
SecNumCloudFrench certification framework for cloud service providers. Recognized as one of the most demanding qualification frameworks in Europe.
SOC 1Validation of internal controls over financial reporting
SOC 2Controls for security, availability, processing integrity, confidentiality, or privacy
SOC 3Controls for security, availability, integrity, confidentiality and privacy for distribution

A full list of OVHcloud certifications can be found on the OVHcloud website on Security and Certifications.

Conclusion

OVHcloud is a very large European cloud provider with the largest number of data centres by far. Also, the product portfolio is one of the widest, with special solutions for the enterprise, e.g. for disaster recovery, managed SAP HANA, a completly packaged data platform, managed Kafka, and many more services. With the maturity of the OVHcloud platform after over 25 years in business, OVHcloud is a very solid choice for almost any type of workload and project.

Resources

To top