Sovereign Cloud Compass
Blackbox exposure (ops/control plane)

Blackbox exposure (ops/control plane)

Why important?

The larger the operational black box, the more limited classic auditability becomes, and the more compensating controls and verification matter.

How measured?

Scale 0–5 + N/A:
  • (higher = less black box / more transparency):
  • 0 = Highly opaque (control plane/ops not traceable)
  • 1 = Little transparency, few information/artefacts
  • 2 = Partial transparency, important areas remain a black box
  • 3 = Transparency for core areas, but relevant gaps (ops/control plane) remain
  • 4 = High transparency (documentation, access concept, artefacts) with few gaps
  • 5 = Very high transparency + verifiable artefacts (audit/evidence) also for ops/control plane
  • N/A = no reliable evidence

Validation questions (RFP)

  • Which parts cannot be verified technically (support tools, control plane)? Which technical controls compensate for this (customer keys, PAM, complete audit logs)?

Scores comparison

Providers Score
noris Sovereign Cloud 4.0
SysEleven OpenStack Cloud 4.0
STACKIT 3.0
OVHcloud Public Cloud (inkl. SecNumCloud) 3.0
T Cloud Public 3.0
Oracle EU Sovereign Cloud 3.0
pluscloud open 3.0
Cloud Temple Trusted Cloud 3.0 Console provides metrics/logs/monitoring. SecNumCloud requires transparency. GraphQL API for monitoring. Grafana dashboard available. Control plane internal, but documented.
AWS European Sovereign Cloud 2.0
IONOS Cloud 2.0
UpCloud 2.0
Exoscale 2.0
Hetzner Cloud 2.0
Scaleway 2.0
Delos Cloud 2.0
Microsoft Sovereign Cloud 2.0
Infomaniak Public Cloud 2.0 Infomaniak Manager + OpenStack Horizon dashboard. API access. Monitoring via console. Control plane transparency through OpenStack open source. No dedicated audit logs / transparency reports.