CloudCompass

Digital sovereignty · resilience roadmap

Digital sovereignty:
where do you start?

It's not read on a flag — it's in your architecture. CloudCompass maps the services you depend on and hands back a prioritized resilience roadmap: what to act on now, what to make portable, what to switch.

FreeEU-hosted~5 minutesSaved & tracked over time
cloudcompass.eu / roadmap

Your sovereignty roadmap

9 dependencies need action

across 14 mapped dependencies

  • Act now3
  • Build an exit option2
  • Switch — easy win4
  • Watch5
Act now3 dependencies
SalesforceCRM

Start an exit programme now; it will take time, so begin early.

United States · CLOUD ActSensitive dataHard to leave

Reachable by the US CLOUD Act (listed on a US market) — authorities can compel disclosure regardless of where the data is hosted.

Operated by Gravitek — an EU companyData hosted in the EU, under EU jurisdictionInspired by the EU Cloud Sovereignty Framework

~70% of Europe's cloud runs on US hyperscalers — the real risk is the sensitive data inside that share

Not a score — a plan

A score tells you where you stand. A roadmap tells you what to do.

Each dependency is weighed on three things: whose law can reach it, how sensitive its data is, and how hard it would be to leave. It's not about ripping out every non-EU service — it's about spotting the ones that carry real risk, and moving just those.

Act now

These run sensitive data under non-EU jurisdiction — the combination that carries real exposure today. Easy-to-leave ones are quick wins; locked-in ones need an exit plan you should start now, even if it takes time.

Build an exit option

Hard to leave, and you may not have a full alternative yet (frontier AI is the classic case). You're not necessarily leaving — but make sure you could: prefer portable formats, agnostic approaches, avoid deepening the lock-in.

Switch — easy win

Low lock-in, and a mature European alternative exists. These are the cheapest sovereignty gains available to you.

Watch

Low stakes and low lock-in. No action needed now — we list them so nothing is invisible.

The goal isn't zero foreign tech — it's informed choices. Keep an exposed tool for public, low-stakes workloads; move the sensitive data to a sovereign option. It's a to-do list, not a score: the four tracks run in parallel, and there's no single finish line.

Identify → Assess → Act

Your roadmap in about five minutes.

No long survey. You recognize your tools from a list; we do the analysis.

01

Pick what you use

Walk a short list — email, cloud, identity, CRM — and choose your providers. Recognition, not a blank page. Start with the vital few and add more later.

02

We map the exposure

Each provider's effective jurisdiction and lock-in are derived from our catalogue; you confirm only what's sensitive. We state the facts — like the US CLOUD Act — and never grade a provider; that call is yours.

03

Get a prioritized roadmap

A board-ready plan: fix first, make portable, switch. Save it, re-assess as you act, and watch your exposure shrink over time.

Shared · tracked · benchmarked

One roadmap, your whole team, tracked over time.

Sovereignty is a journey, not a one-off score. Your assessment is saved to your organization — invite colleagues to work on it together, and re-run it to see progress as you act.

Work as a team

Invite colleagues into the same organization and build one shared roadmap — everyone works from the same picture.

Ownership shared across your team.

Track over time

Re-assess as you act. See each dependency move down the roadmap and your exposure shrink, quarter over quarter.

Progress you can show your board.

Benchmark your sector

See how your posture compares to peers your size, in your industry. Anonymized and opt-in.

See exactly where you stand among peers.

What your roadmap covers

The domains of your stack, mapped for sovereignty.

Nine functional domains — from identity and data to AI and infrastructure. It's inspired by the EU Cloud Sovereignty Framework — the reference the European Commission used to award its €180M sovereign-cloud tender — from which we borrow the category taxonomy, keeping only what an enterprise needs to act.

Learn about the framework
Identity & AccessSSO, MFA, directories, and identity management.
Comms & CollaborationEmail, messaging, video conferencing, and team communication.
Productivity & OfficeOffice suites, file storage, and document collaboration.
Business AppsCRM, ERP, HRIS, billing, and business-critical applications.
Data & AnalyticsDatabases, data warehouses, BI tools, and ETL pipelines.
AI & MLLLMs, AI agents, ML pipelines, and vector databases.
Infrastructure & ComputeCloud IaaS/PaaS, Kubernetes, VMs, CDN, and networking.
Security & ComplianceSIEM, EDR, backup, DLP, and vulnerability management.
Dev & OpsCI/CD, source control, observability, and incident management.

Start free

Map your dependencies. Get your roadmap.

Free, EU-hosted, about five minutes — and it's yours to keep, so you can track progress as you act.