Keystone Sovereign

Sovereignty posture management

Every sovereignty assessment asks you the same 48 questions.
We read the answers out of your cloud.

Europe's cloud procurement is now scored across eight sovereignty objectives — and missing any single floor disqualifies you outright, whatever your average. Keystone connects to your AWS accounts and computes your position continuously, with tamper-evident evidence your regulator will accept.

Runs inside your own tenancy. We never hold your data — which is rather the point.

Read the argumentOn 12 January 2027, switching your cloud provider becomes free. Nobody can prove they can do it. →
$ keystone sovereignty scan --estate prod
discovering ...................... 1,847 resources / 12 accounts
jurisdiction map ................. 4 regions · 2 partitions
cross-partition trust paths ...... 31 will break
non-EU privileged access (90d) ... 17 sessions
SOV-1 strategic ownership ...... SEAL-2 PASS
SOV-2 non-EU law exposure ...... SEAL-1 FAIL (floor: 2)
SOV-4 EU operational capability SEAL-1 FAIL (floor: 3)
SOV-5 supply chain transparency SEAL-3 PASS
weighted score .................. 68%
procurement outcome ............. DISQUALIFIED

Illustrative output. Two failed floors disqualify the bid — the 68% is irrelevant.

A 70% that misses one floor loses to a 55% that clears them all.

The European Commission's Cloud Sovereignty Framework does not score you on a total. It sets a minimum SEAL level for each of eight objectives, and a bid has to clear every one of them.

Miss a single floor and the bid is eliminated — not marked down. A strong average across seven objectives buys you nothing if the eighth sits below its required level.

Every free self-assessment tool on the market outputs one number: a weighted average. That is the wrong answer to the actual procurement mechanic, and it is the number that tells buyers they are fine right up until they are disqualified.

ObjectiveFocusWeight
SOV-1Strategic ownership; decision-making authority15%
SOV-2Exposure to non-EU law (CLOUD Act, FISA 702)10%
SOV-3Data access control and AI independence10%
SOV-4EU operational capability without non-EU involvement15%
SOV-5Hardware and software supply chain transparency20%
SOV-6Open standards, auditability, freedom from lock-in15%
SOV-7EU-controlled security and regulatory alignment10%
SOV-8Energy efficiency and sustainability reporting5%

EU Cloud Sovereignty Framework v1.2.1, European Commission, published 20 October 2025; implementation guidance 1 June 2026. Tenders that miss the required minimum level on any single objective are rejected.

Three dates that are already on your calendar.

12 Sep 2025

EU Data Act applies.

Your provider must publish the jurisdiction its infrastructure is subject to, and describe how it prevents foreign governmental access. Your contracts must already carry the Article 25 exit terms.

12 Jan 2027

Switching charges go to zero.

Article 29 removes egress and switching fees entirely. Every exit plan that was never tested becomes a question someone has to answer.

17 Jan 2025

DORA has been in force for over a year.

Register of Information, contractual data-location terms, concentration risk, and exit strategies that are tested — not documented.

And on 18 November 2025, the European Supervisory Authorities designated 19 Critical ICT Third-Party Providers under DORA — among them Amazon Web Services EMEA, Microsoft Ireland Operations, Google Cloud EMEA, IBM and Oracle Nederland — placing them under direct supervision.

Computed, not self-reported.

1

Connect

A read-only cross-account IAM role. No agents, no data leaves your accounts. Keystone can run entirely inside your own tenancy, in your own region.

2

Discover

Every resource, region, partition, key, trust relationship and privileged access path across your estate. Including the parts nobody put in the inventory — Keystone reports coverage, so you know what fraction of your estate is even in scope.

3

Prove

A per-objective SEAL position with the floors modelled correctly, a jurisdiction map, an access register, and a hash-chained evidence bundle dated to the period under review.

The Partition & Sovereignty Exposure Report.

One connection. One hour. Here is what comes back.

jurisdiction_map

Jurisdiction map

Every resource, its region, partition, operating legal entity, and whether any non-EU personnel hold a path to it. Computed from your estate, not from a form.

partition_breakage

Partition breakage list

Everything that stops working at the aws → aws-eusc boundary. Cross-account trust, ARN literals, managed policy references, unsupported services, non-Nitro AMIs, non-transferable reservations.

remote_access

Remote access register

Privileged and support sessions by non-EU personnel over the review period: who, when, what they touched. This is where "EU data boundary" claims are actually tested.

key_custody

Key custody evidence

Who holds which keys, where the HSMs sit, whether your provider can technically decrypt without you, and what happens on revocation.

concentration

Concentration register

DORA Article 29 substitutability, third-country provider exposure, and the documented alternative you are supposed to already have.

seal_scorecard

SEAL scorecard

Per objective, with floors. Not an average. Includes exactly which floors you miss and what it would take to clear them.

This is machine-checkable. Almost nobody is checking it by machine.

module.data_platform.aws_iam_role.etl
- arn:aws:iam::aws:policy/AmazonS3FullAccess
+ arn:aws-eusc:iam::aws:policy/AmazonS3FullAccess
module.networking.tgw_attachment.shared_services
! cross-partition Transit Gateway attachment — not supported
! 6 downstream VPCs affected
module.compute.asg_batch → m5.4xlarge (Xen)
! not Nitro — AMI will not boot in eusc-de-east-1
scripts/tag_enforcer.py:41
! region regex ^[a-z]{2}-[a-z]+-\d$ does not match eusc-de-east-1

AWS Organizations cannot span partitions, and AWS states that IAM credentials from one partition cannot act on resources in another. Landing Zone Accelerator needs a separate deployment per partition.

AWS published its first cross-partition migration procedure — S3 via DataSync Enhanced mode — on 18 August 2026.

Everyone else scopes this in a workshop. Two consultants, a whiteboard, and an estimate. It is a list, and lists should be computed.

We are not a European vendor. That is why this works.

Keystone is not an EU-domiciled company and we are not going to pretend otherwise. Under the framework above, that would put us in SOV-1, SOV-2 and SOV-4 — 40% of the weighting — on the wrong side.

So we do not host your data. Keystone deploys inside your own tenancy, in your own region, under your own keys. What you buy is software with a published SBOM and verifiable provenance. That is a supply-chain question under SOV-5, and it is one we can answer with a document rather than a nationality.

We run Keystone against Keystone and publish the result, including the parts we fail. Ask for it in the form below and it comes with your report.

Who this is for.

Financial entities in DORA scope

You already owe a Register of Information, contractual data-location terms, and an exit strategy that has actually been tested.

Integrators and MSPs building ESC practices

You need the breakage list as engagement input, across every client estate, in one console. Multi-tenant from day one.

ISVs selling into European public sector

SEAL questions are appearing in your RFPs now, and "we're working on it" is not a scoring answer.

Questions people actually ask.

Request your Exposure Report.

One read-only role. Same-day turnaround. No obligation, and no sales sequence.

We reply from a real address. We do not sell or share this.

Keystone Sovereign

A product of hireken.io

Regulatory references current as of 20 August 2026.