---
title: "Sovereign Cloud: The Digital Sovereignty Guide | Natalia"
description: "Sovereign cloud: SecNumCloud, SEAL levels and the CLOUD Act explained, plus 7 questions to assess the sovereignty of an AI phone system."
url: https://getnatalia.com/en/sovereignty/sovereign-cloud-guide
lang: en
---

Sovereignty

# Sovereign cloud: the digital sovereignty guide

What SecNumCloud, the SEAL levels, the CLOUD Act and the new European rules actually cover, and how to assess the sovereignty of an AI phone system without trusting logos.

October 2, 2026 12 min

## Contents

1.  [Three dimensions behind one word](https://getnatalia.com/en/sovereignty/sovereign-cloud-guide#section-0)
2.  [Extraterritorial risk, concretely](https://getnatalia.com/en/sovereignty/sovereign-cloud-guide#section-1)
3.  [The standards, from SecNumCloud to the CSF](https://getnatalia.com/en/sovereignty/sovereign-cloud-guide#section-2)
4.  [Seven questions for an AI phone system](https://getnatalia.com/en/sovereignty/sovereign-cloud-guide#section-3)
5.  [Glossary](https://getnatalia.com/en/sovereignty/sovereign-cloud-guide#section-4)
6.  [Where Natalia stands](https://getnatalia.com/en/sovereignty/sovereign-cloud-guide#section-5)
7.  [FAQ](https://getnatalia.com/en/sovereignty/sovereign-cloud-guide#section-6)

## Digital sovereignty: three dimensions behind one word

“Sovereign” is not a binary state. European frameworks break sovereignty into three dimensions that must be assessed separately, because a provider can be strong on one and exposed on another.

Hosting data in France or Europe is necessary, but it is the first level of every European grid, not the last. A datacentre in France operated by a company subject to a non-European law remains exposed to extraterritorial access requests.

The useful question is therefore not “sovereign or not”, but: at which level, on which dimension, and with what trajectory. That is exactly the reasoning behind the Commission's Cloud Sovereignty Framework and the French ANSSI's SecNumCloud qualification.

### Legal

Which law applies to the provider and which law can compel it to disclose data.

### Operational

Who operates, supports, updates, holds the encryption keys and can shut the service down.

### Technological

What the stack is made of (hardware, software, IdP, DNS): open, auditable, substitutable or not.

## Extraterritorial risk, concretely

At the heart of the sovereignty debate is the possibility of access to data by a non-European authority, even when that data is stored in Europe.

The CLOUD Act (United States, 2018) lets US authorities compel a provider subject to US law to hand over data it controls, wherever it is stored, including in a European region. Surveillance under FISA section 702 is the origin of the Court of Justice of the European Union's Schrems I and Schrems II rulings.

Add to that the risk of service suspension for political reasons or sanctions, and the invisible dependencies: even on a European cloud, the IdP, DNS, CDN, transactional email or AI model APIs are often non-European by default.

### A chain is only as strong as its weakest link

For an AI phone system, the voice chain — telecom, speech recognition, language model, speech synthesis, hosting, identity — is the dependency to document first. Hosting in France behind a chain operated outside Europe does not make a sovereign service, and that must be said honestly.

## The standards, from SecNumCloud to the Cloud Sovereignty Framework

Several standards coexist. None is universal: they answer different questions and do not carry the same legal weight.

With SecNumCloud (ANSSI), France has a demanding qualification that combines a security audit and extraterritorial-immunity criteria. The European EUCS scheme had its sovereignty criteria removed in March 2024. The Commission changed method in 2025-2026 with a scoring grid, the Cloud Sovereignty Framework and its SEAL levels, then a draft regulation, the Cloud and AI Development Act (CADA).

ISO 27001 certifies an information security management system but says nothing about sovereignty: a non-European hyperscaler can obtain it. HDS governs the hosting of health data. Each standard should be read for what it proves, not for the logo it lets you display.

### SecNumCloud

ANSSI qualification, per offer, by audit, with extraterritorial-immunity criteria. Detail on the dedicated page.

### SEAL & CSF

SEAL-0 to SEAL-4 levels of the Cloud Sovereignty Framework measure sovereignty objective by objective.

### CADA & EU texts

CADA, the Data Act, NIS2 and DORA set the regulatory framework taking shape for the cloud.

## Seven questions to ask an AI phone system provider

This checklist adapts the eight sovereignty objectives of the Cloud Sovereignty Framework to the voice chain. It applies to the provider and to each of its subcontractors.

### 1\. Who owns and controls the provider?

Shareholding, headquarters, non-European subsidiaries and their effective separation.

### 2\. Where are the data AND the operations?

Hosting regions, but also where the operations, support and on-call teams are located.

### 3\. Who holds the keys?

Encryption at rest, signing keys, KMS, and the ability to bring your own keys (BYOK/HYOK).

### 4\. What hidden dependencies?

Telecom, speech recognition and synthesis, language model, IdP, DNS, email, downstream subcontractors.

### 5\. What reversibility?

Full export, open formats, exit lead time, fees, and whether reversibility has actually been tested.

### 6\. What declared level, with what proof?

SecNumCloud, HDS, ISO 27001, SEAL level per objective: ask for the audit reports, not the logos.

### 7\. What plan if the provider disappears?

Multi-region, multi-cloud, externalised backups, documented RTO and RPO.

## Glossary

The terms that recur in a sovereignty review, one sentence each. Detailed, sourced definitions are on the dedicated pages.

### SecNumCloud

The French ANSSI's security qualification for cloud providers, per offer, valid for three years.

### HDS

French certification required to host personal health data.

### EUCS

European cloud certification scheme (ENISA); its sovereignty criteria were removed in 2024.

### SEAL / CSF

Assurance levels (0 to 4) of the European Commission's Cloud Sovereignty Framework.

### CLOUD Act

US law of 2018 allowing extraterritorial access to data held by a provider subject to US law.

### CADA

Draft European regulation (Cloud and AI Development Act) of 3 June 2026, not adopted.

### Data Act

EU regulation that eases switching cloud providers; end of exit fees on 12 January 2027.

### NIS2 / DORA

Cybersecurity directive (NIS2) and financial regulation (DORA) governing the use of third-party cloud providers.

## Where Natalia stands

Natalia applies this guide's own rule: verifiable facts rather than logos. Here is its position, as published, without superlatives.

Natalia's information security management system is aligned with ISO 27001 requirements and incorporates SOC 2 controls; ISO 27001 certification is in progress. Availability is covered by a 99.9% contractual SLA. Data is hosted in France.

For organisations that require nothing to leave their network, the on-premise edition of Natalia Analytics deploys in strict disconnected mode: the appliance stays in the customer's datacentre, calls and their metadata are processed on site, with no outbound connection.

### Evidence on request

Audit reports and RFP documentation are available under a confidentiality agreement. The detail of the security posture is presented on the security page.

## Frequently asked questions

### What is a sovereign cloud?

A cloud whose provider is not subject to an extraterritorial law that could compel it to disclose data, and whose operations, keys and technology stack remain under European control. Hosting data in Europe is its first level, necessary but not sufficient.

### Is hosting data in France enough to be sovereign?

No. That is the first level of every European grid. A datacentre in France operated by a company subject to a non-European law remains exposed to access requests. Sovereignty is also measured on operations, encryption keys and the hidden dependencies of the chain.

### How do I assess the sovereignty of an AI phone system?

By following the voice chain link by link: telecom, speech recognition, language model, speech synthesis, hosting and identity. For each link, ask the guide's seven questions and request audit reports rather than logos. The real level is that of the weakest link.

### Is a provider without SecNumCloud disqualified?

Not necessarily. SecNumCloud is mandatory for certain state data and recommended for sensitive data. For many private use cases it is a strong signal but not an obligation. What matters is assessing real sovereignty across the three dimensions, with evidence, rather than stopping at a label.

## Primary sources

Each dated fact links to its primary source. Statuses change: check the source before relying on a specific point.

-   [European Commission — Cloud Sovereignty Framework (explainer)](https://commission.europa.eu/news-and-media/news/sovereign-cloud-framework-explained-2026-06-01_en) 1 Jun 2026
-   [European Commission — Tech Sovereignty package and CADA proposal](https://digital-strategy.ec.europa.eu/en/library/proposal-cloud-and-ai-development-act-cada) 3 Jun 2026
-   [ANSSI — SecNumCloud for cloud service providers](https://cyber.gouv.fr/secnumcloud-pour-les-fournisseurs-de-services-cloud) accessed 2 Oct 2026
-   [EUR-Lex — GDPR, Data Act, NIS2, DORA](https://eur-lex.europa.eu/homepage.html) accessed 2 Oct 2026
-   [Natalia — security and compliance](https://getnatalia.com/en/security) accessed 2 Oct 2026

## Go deeper on each standard

-   ### SecNumCloud explained

    The ANSSI qualification: what it proves, the official list, the observed timelines.

    <https://getnatalia.com/en/sovereignty/secnumcloud>

-   ### SEAL levels 0 to 4 and the CSF

    The European Commission grid, objective by objective.

    <https://getnatalia.com/en/sovereignty/seal-levels>

-   ### CLOUD Act

    What the US law changes for a European company.

    <https://getnatalia.com/en/sovereignty/cloud-act>

-   ### CADA, Data Act, NIS2, DORA

    The European regulatory framework that concerns your provider.

    <https://getnatalia.com/en/sovereignty/cada-data-act-nis2-dora>

-   ### Sovereignty overview

    Natalia's positioning and its three angles.

    <https://getnatalia.com/en/sovereignty>

-   ### On-Premise edition

    The appliance deployed in your datacentre, in strict disconnected mode.

    <https://getnatalia.com/en/analytics-on-premise>

## Assess the sovereignty of your telephony

A demo on your own environment. We start from your network architecture and your real constraints.

[Request a demo](https://getnatalia.com/en/contact)
