Sovereignty
Sovereign cloud: the digital sovereignty guide
What SecNumCloud, the SEAL levels, the CLOUD Act and the new European rules actually cover, and how to assess the sovereignty of an AI phone system without trusting logos.
Digital sovereignty: three dimensions behind one word
“Sovereign” is not a binary state. European frameworks break sovereignty into three dimensions that must be assessed separately, because a provider can be strong on one and exposed on another.
Hosting data in France or Europe is necessary, but it is the first level of every European grid, not the last. A datacentre in France operated by a company subject to a non-European law remains exposed to extraterritorial access requests.
The useful question is therefore not “sovereign or not”, but: at which level, on which dimension, and with what trajectory. That is exactly the reasoning behind the Commission's Cloud Sovereignty Framework and the French ANSSI's SecNumCloud qualification.
Legal
Which law applies to the provider and which law can compel it to disclose data.
Operational
Who operates, supports, updates, holds the encryption keys and can shut the service down.
Technological
What the stack is made of (hardware, software, IdP, DNS): open, auditable, substitutable or not.
Extraterritorial risk, concretely
At the heart of the sovereignty debate is the possibility of access to data by a non-European authority, even when that data is stored in Europe.
The CLOUD Act (United States, 2018) lets US authorities compel a provider subject to US law to hand over data it controls, wherever it is stored, including in a European region. Surveillance under FISA section 702 is the origin of the Court of Justice of the European Union's Schrems I and Schrems II rulings.
Add to that the risk of service suspension for political reasons or sanctions, and the invisible dependencies: even on a European cloud, the IdP, DNS, CDN, transactional email or AI model APIs are often non-European by default.
A chain is only as strong as its weakest link
For an AI phone system, the voice chain — telecom, speech recognition, language model, speech synthesis, hosting, identity — is the dependency to document first. Hosting in France behind a chain operated outside Europe does not make a sovereign service, and that must be said honestly.
The standards, from SecNumCloud to the Cloud Sovereignty Framework
Several standards coexist. None is universal: they answer different questions and do not carry the same legal weight.
With SecNumCloud (ANSSI), France has a demanding qualification that combines a security audit and extraterritorial-immunity criteria. The European EUCS scheme had its sovereignty criteria removed in March 2024. The Commission changed method in 2025-2026 with a scoring grid, the Cloud Sovereignty Framework and its SEAL levels, then a draft regulation, the Cloud and AI Development Act (CADA).
ISO 27001 certifies an information security management system but says nothing about sovereignty: a non-European hyperscaler can obtain it. HDS governs the hosting of health data. Each standard should be read for what it proves, not for the logo it lets you display.
SecNumCloud
ANSSI qualification, per offer, by audit, with extraterritorial-immunity criteria. Detail on the dedicated page.
SEAL & CSF
SEAL-0 to SEAL-4 levels of the Cloud Sovereignty Framework measure sovereignty objective by objective.
CADA & EU texts
CADA, the Data Act, NIS2 and DORA set the regulatory framework taking shape for the cloud.
Seven questions to ask an AI phone system provider
This checklist adapts the eight sovereignty objectives of the Cloud Sovereignty Framework to the voice chain. It applies to the provider and to each of its subcontractors.
1. Who owns and controls the provider?
Shareholding, headquarters, non-European subsidiaries and their effective separation.
2. Where are the data AND the operations?
Hosting regions, but also where the operations, support and on-call teams are located.
3. Who holds the keys?
Encryption at rest, signing keys, KMS, and the ability to bring your own keys (BYOK/HYOK).
4. What hidden dependencies?
Telecom, speech recognition and synthesis, language model, IdP, DNS, email, downstream subcontractors.
5. What reversibility?
Full export, open formats, exit lead time, fees, and whether reversibility has actually been tested.
6. What declared level, with what proof?
SecNumCloud, HDS, ISO 27001, SEAL level per objective: ask for the audit reports, not the logos.
7. What plan if the provider disappears?
Multi-region, multi-cloud, externalised backups, documented RTO and RPO.
Glossary
The terms that recur in a sovereignty review, one sentence each. Detailed, sourced definitions are on the dedicated pages.
SecNumCloud
The French ANSSI's security qualification for cloud providers, per offer, valid for three years.
HDS
French certification required to host personal health data.
EUCS
European cloud certification scheme (ENISA); its sovereignty criteria were removed in 2024.
SEAL / CSF
Assurance levels (0 to 4) of the European Commission's Cloud Sovereignty Framework.
CLOUD Act
US law of 2018 allowing extraterritorial access to data held by a provider subject to US law.
CADA
Draft European regulation (Cloud and AI Development Act) of 3 June 2026, not adopted.
Data Act
EU regulation that eases switching cloud providers; end of exit fees on 12 January 2027.
NIS2 / DORA
Cybersecurity directive (NIS2) and financial regulation (DORA) governing the use of third-party cloud providers.
Where Natalia stands
Natalia applies this guide's own rule: verifiable facts rather than logos. Here is its position, as published, without superlatives.
Natalia's information security management system is aligned with ISO 27001 requirements and incorporates SOC 2 controls; ISO 27001 certification is in progress. Availability is covered by a 99.9% contractual SLA. Data is hosted in France.
For organisations that require nothing to leave their network, the on-premise edition of Natalia Analytics deploys in strict disconnected mode: the appliance stays in the customer's datacentre, calls and their metadata are processed on site, with no outbound connection.
Evidence on request
Audit reports and RFP documentation are available under a confidentiality agreement. The detail of the security posture is presented on the security page.
Frequently asked questions
What is a sovereign cloud?
Is hosting data in France enough to be sovereign?
How do I assess the sovereignty of an AI phone system?
Is a provider without SecNumCloud disqualified?
Primary sources
Each dated fact links to its primary source. Statuses change: check the source before relying on a specific point.
- European Commission — Cloud Sovereignty Framework (explainer) 1 Jun 2026
- European Commission — Tech Sovereignty package and CADA proposal 3 Jun 2026
- ANSSI — SecNumCloud for cloud service providers accessed 2 Oct 2026
- EUR-Lex — GDPR, Data Act, NIS2, DORA accessed 2 Oct 2026
- Natalia — security and compliance accessed 2 Oct 2026
Go deeper on each standard
SecNumCloud explained
The ANSSI qualification: what it proves, the official list, the observed timelines.
SEAL levels 0 to 4 and the CSF
The European Commission grid, objective by objective.
CLOUD Act
What the US law changes for a European company.
CADA, Data Act, NIS2, DORA
The European regulatory framework that concerns your provider.
Sovereignty overview
Natalia's positioning and its three angles.
On-Premise edition
The appliance deployed in your datacentre, in strict disconnected mode.
Assess the sovereignty of your telephony
A demo on your own environment. We start from your network architecture and your real constraints.