Methodology
Scoring methodology
The Saveran Sovereignty Score is a deterministic, rule-based 0–100 assessment of a vendor's digital sovereignty. It is computed by versioned rules over evidence-backed facts — never by a model, and never from opinion. Current ruleset: 2026.06.3.
The one idea behind the score
Residency is not sovereignty. Where data physically sits and who can lawfully compel access to it are different questions. A US hyperscaler's Frankfurt region is EU-resident, yet its operator remains subject to the US CLOUD Act. The score measures that delta.
Four dimensions, equally weighted
Corporate Ownership (25%)
Who ultimately controls the provider and which jurisdictions can compel that owner.
Data Residency (25%)
Where data is stored and who can reach it, including support access.
Technology Stack (25%)
Jurisdiction over the infrastructure operators the service runs on.
Regulatory Compliance (25%)
EU and national attestations (SecNumCloud, C5, ENS, ISO 27001) and transparency artefacts.
How facts become a score
- Every fact carries a source URL and a verbatim quote from that source.
- Confidence (0–100) is computed from how the fact was obtained — registries score higher than model extraction. Score and confidence are reported separately, never blended.
- Each dimension starts at 50; deterministic rules add or remove points, and exposure caps bound the result (e.g. hosting on a US hyperscaler caps Technology Stack at 35 — even in EU regions).
- The full rule trace is published on every profile under “Why this score”.
Relationship to the EU Cloud Sovereignty Framework
The score is aligned toward the European Commission's Cloud Sovereignty Framework (SEAL levels, SOV objectives) but is Saveran's own model — we never claim a CSF assessment or SEAL level on a vendor's behalf.
Versioning & disputes
Rule changes always ship with a ruleset version bump; every published score records the version that produced it. Vendors can dispute any assessment at disputes@saveran.eu.
