Skip to content

Sovereignty Profile

How sovereign is your SaaS? Check it, then prove it.

Public-sector and regulated buyers now ask about sovereignty in tenders. Answer once, with evidence, mapped to the EU Cloud Sovereignty Framework and BSI C3A.

  • Finds the providers in your data path and who controls them
  • Mapped to the EU Cloud Sovereignty Framework and BSI C3A
  • Evidence corrects claims it contradicts
  • Tender-ready PDF, public page and badge

Must belong to the domain. No free-mail addresses.

We only read public DNS records and load your home page once.

"Hosted in the EU" is no longer the answer

Buyers have yardsticks now

The European Commission scores cloud offers against its Cloud Sovereignty Framework, and the BSI published the C3A criteria in April 2026.

Jurisdiction beats location

A Frankfurt region of a US provider is still reachable by US law. What counts is who controls each provider in your data path.

Your stack answers for you

Hosting, CDN, email, support and analytics tools all count as dependencies. Most of them are visible from the outside.

What we check, and what you declare

Checked from public signals

  • Network operator behind your domain, www, app, api and any subdomains you add (IP-to-ASN lookup)
  • CDN and platform providers from DNS aliases and response headers
  • DNS provider (name servers)
  • Inbound email provider (MX) and email-sending services (SPF includes)
  • Tools that verify your domain (TXT records such as Google, Microsoft, Atlassian, Stripe)
  • Third-party scripts and embeds on your home page

Checked with WardBee (optional)

  • Regions of your cloud resources, from the last WardBee inventory sync
  • Whether you run in the AWS European Sovereign Cloud partition
  • Provider-proprietary services in use (for example Lambda, DynamoDB, Cognito)
  • Whether your source code is hosted on GitHub

Declared by you

  • Ownership and control of your company
  • Governing law, venue and handling of foreign government requests
  • Encryption key control and AI processing location
  • Where admins, support and incident response sit
  • Subprocessor transparency, exit plan and data export
  • Certifications, security logging and energy footprint

Evidence beats claims

Answer "every provider in our data path is EU-controlled" while your DNS points to a US hyperscaler, and the profile marks the answer as contradicted and counts it as SEAL-1. Evidence can only lower an answer, never raise it.

Eight objectives, weighted like the EU framework

SOV-1 Strategic15 % · C3A: Strategic sovereignty
SOV-2 Legal & jurisdictional10 % · C3A: Legal sovereignty
SOV-3 Data & AI10 % · C3A: Data sovereignty
SOV-4 Operational15 % · C3A: Operational sovereignty
SOV-5 Supply chain20 % · C3A: Supply-chain sovereignty
SOV-6 Technology15 % · C3A: Technology sovereignty
SOV-7 Security & compliance10 % · not in C3A
SOV-8 Environmental5 % · not in C3A

Background: EU Cloud Sovereignty Framework and SEAL levels · BSI C3A for SaaS vendors

What you get

  1. Score and objective levels

    SEAL 0–4 for each of the eight objectives, weighted to 0–100.

  2. Answer-by-answer evidence

    Checked, contradicted or self-declared, with what we saw.

  3. Next steps

    The changes that raise your score most, starting with the heaviest objectives.

  4. PDF with authenticity check

    SHA-256 hash and a QR code to a ScanComb verification page.

  5. Public page and badge

    Opt-in. Levels and providers only, never your individual answers.

Frequently asked questions

Is this a certification or a C3A attestation?

No. It is a self-assessment mapped to the EU Cloud Sovereignty Framework and the BSI C3A domains. C3A conformity requires BSI C5 and an audit. What we add is evidence: where public signals or your cloud inventory show less than you claim, the lower level counts and the claim is marked as contradicted.

What is checked automatically?

From public DNS and one request to your home page: hosting networks, CDN, DNS and email providers, email-sending services, tools that verify your domain, and third-party scripts. With a WardBee workspace linked: the regions of your cloud resources, the AWS partition, proprietary managed services and GitHub as code host.

We host on AWS in Frankfurt. Are we sovereign?

Partly. EU data residency helps, but Amazon is a US company, so US law such as the CLOUD Act can still reach the data. The profile marks that as jurisdictional (SEAL-1) for foreign-law exposure and shows the steps that raise it: customer-held keys, an EU-operated sovereign partition, or EU-controlled providers.

How is the score calculated?

Each answer maps to a SEAL level from 0 to 4. An objective takes the level of its weakest answer. The score is the weighted sum across the eight objectives, using the weights of the EU Cloud Sovereignty Framework, from 0 to 100.

What can buyers see?

Only what you publish. The public page shows the objective levels, detected providers and dates, never your individual answers. The PDF carries a SHA-256 hash and a QR code to an authenticity page.

How long is a profile valid?

90 days from the oldest evidence it rests on. After that the badge and public page show it as not current until you issue a new report. Nothing re-scans in the background; you rerun the check when you want.

What does it cost?

The check and the profile are free while in early access.

Where is my data stored?

In the EU (AWS eu-central-1, Frankfurt).

Prove data location and portability, not just declare them

Connect your AWS account in WardBee and link it to the profile. The regions of your resources and the managed services you depend on then check your data-location and portability answers.