Sovereignty Profile
How sovereign is your SaaS? Check it, then prove it.
Public-sector and regulated buyers now ask about sovereignty in tenders. Answer once, with evidence, mapped to the EU Cloud Sovereignty Framework and BSI C3A.
- Finds the providers in your data path and who controls them
- Mapped to the EU Cloud Sovereignty Framework and BSI C3A
- Evidence corrects claims it contradicts
- Tender-ready PDF, public page and badge
"Hosted in the EU" is no longer the answer
Buyers have yardsticks now
The European Commission scores cloud offers against its Cloud Sovereignty Framework, and the BSI published the C3A criteria in April 2026.
Jurisdiction beats location
A Frankfurt region of a US provider is still reachable by US law. What counts is who controls each provider in your data path.
Your stack answers for you
Hosting, CDN, email, support and analytics tools all count as dependencies. Most of them are visible from the outside.
What we check, and what you declare
Checked from public signals
- Network operator behind your domain, www, app, api and any subdomains you add (IP-to-ASN lookup)
- CDN and platform providers from DNS aliases and response headers
- DNS provider (name servers)
- Inbound email provider (MX) and email-sending services (SPF includes)
- Tools that verify your domain (TXT records such as Google, Microsoft, Atlassian, Stripe)
- Third-party scripts and embeds on your home page
Checked with WardBee (optional)
- Regions of your cloud resources, from the last WardBee inventory sync
- Whether you run in the AWS European Sovereign Cloud partition
- Provider-proprietary services in use (for example Lambda, DynamoDB, Cognito)
- Whether your source code is hosted on GitHub
Declared by you
- Ownership and control of your company
- Governing law, venue and handling of foreign government requests
- Encryption key control and AI processing location
- Where admins, support and incident response sit
- Subprocessor transparency, exit plan and data export
- Certifications, security logging and energy footprint
Evidence beats claims
Answer "every provider in our data path is EU-controlled" while your DNS points to a US hyperscaler, and the profile marks the answer as contradicted and counts it as SEAL-1. Evidence can only lower an answer, never raise it.
Eight objectives, weighted like the EU framework
Background: EU Cloud Sovereignty Framework and SEAL levels · BSI C3A for SaaS vendors
What you get
Score and objective levels
SEAL 0–4 for each of the eight objectives, weighted to 0–100.
Answer-by-answer evidence
Checked, contradicted or self-declared, with what we saw.
Next steps
The changes that raise your score most, starting with the heaviest objectives.
PDF with authenticity check
SHA-256 hash and a QR code to a ScanComb verification page.
Public page and badge
Opt-in. Levels and providers only, never your individual answers.
Frequently asked questions
Is this a certification or a C3A attestation?
No. It is a self-assessment mapped to the EU Cloud Sovereignty Framework and the BSI C3A domains. C3A conformity requires BSI C5 and an audit. What we add is evidence: where public signals or your cloud inventory show less than you claim, the lower level counts and the claim is marked as contradicted.
What is checked automatically?
From public DNS and one request to your home page: hosting networks, CDN, DNS and email providers, email-sending services, tools that verify your domain, and third-party scripts. With a WardBee workspace linked: the regions of your cloud resources, the AWS partition, proprietary managed services and GitHub as code host.
We host on AWS in Frankfurt. Are we sovereign?
Partly. EU data residency helps, but Amazon is a US company, so US law such as the CLOUD Act can still reach the data. The profile marks that as jurisdictional (SEAL-1) for foreign-law exposure and shows the steps that raise it: customer-held keys, an EU-operated sovereign partition, or EU-controlled providers.
How is the score calculated?
Each answer maps to a SEAL level from 0 to 4. An objective takes the level of its weakest answer. The score is the weighted sum across the eight objectives, using the weights of the EU Cloud Sovereignty Framework, from 0 to 100.
What can buyers see?
Only what you publish. The public page shows the objective levels, detected providers and dates, never your individual answers. The PDF carries a SHA-256 hash and a QR code to an authenticity page.
How long is a profile valid?
90 days from the oldest evidence it rests on. After that the badge and public page show it as not current until you issue a new report. Nothing re-scans in the background; you rerun the check when you want.
What does it cost?
The check and the profile are free while in early access.
Where is my data stored?
In the EU (AWS eu-central-1, Frankfurt).
Prove data location and portability, not just declare them
Connect your AWS account in WardBee and link it to the profile. The regions of your resources and the managed services you depend on then check your data-location and portability answers.


