How it works
How your roadmap is built
The engine that prioritises your dependencies is not a black box. Here are its principles, its rules, the parameters it uses, and a complete worked example.
Four principles
We classify your dependencies, not your providers
No provider is rated good or bad. What lands on the roadmap is your use of one — the same product can be a priority for you and a non-issue for the company next door.
The goal is informed choices, not zero foreign technology
Keeping an exposed tool for public, low-stakes work is a perfectly good decision. What matters is that it is a decision.
Same inputs, same roadmap
The engine is deterministic. No case-by-case judgment, no hidden weighting: two organizations that map the same dependencies get the same prioritisation.
Facts first, prioritisation second
We establish where a service is governed, how sensitive its data is, and how hard it would be to leave. Only then do we sort.
The three factors
Every dependency is weighed on three things — and each one is established differently.
Jurisdiction — whose law can reach the data
It follows how you deploy, not the logo on the box. A SaaS product is governed by its editor; a product you self-host is governed by the infrastructure it runs on; a product on your own premises is governed by your own country. Haven't chosen a host yet? We treat it as unknown rather than assume it is safe.
Four outcomes: governed in the EU or EEA; reachable by non-EU law; operated in Europe on non-EU technology, with residual exposure; or not yet known.
Sensitivity — what the data is worth
You declare it, dependency by dependency. We never guess it: only you know what actually flows through a given tool.
Reversibility — how hard it would be to leave
A default per function, because leaving object storage is nothing like leaving an identity provider. One rule raises it: open-source software you host yourself has no editor lock-in, so it counts as easy to leave.
The four levels
The levels are parallel tracks, not a ladder. There is no single finish line — you decide what matters most.
Act now
These run sensitive data under non-EU jurisdiction — the combination that carries real exposure today. Easy-to-leave ones are quick wins; locked-in ones need an exit plan you should start now, even if it takes time.
Build an exit option
Hard to leave, and you may not have a full alternative yet (frontier AI is the classic case). You're not necessarily leaving — but make sure you could: prefer portable formats, agnostic approaches, avoid deepening the lock-in.
Switch — easy win
Low lock-in, and a mature European alternative exists. These are the cheapest sovereignty gains available to you.
Watch
Low stakes and low lock-in. No action needed now — we list them so nothing is invisible.
The rules
The engine walks these in order and stops at the first match, so every dependency lands on exactly one level. This list is generated from the engine itself.
Rule 1
Reachable by non-EU law, sensitive data, a mature European alternative exists — and it is easy to leave.
Result — Act now · quick exit
Rule 2
Reachable by non-EU law, sensitive data, a mature European alternative exists — but leaving takes work.
Result — Act now · long programme
Rule 3
Reachable by non-EU law, sensitive data, and no mature European alternative yet. Telling you to leave would point nowhere, so the work is to stay able to leave.
Result — Build an exit option
Rule 4
Sensitive data on a service operated in Europe on non-EU technology, or whose jurisdiction we cannot establish yet.
Result — Build an exit option
Rule 5
Hard to leave, whatever the jurisdiction. Lock-in is a risk on its own.
Result — Build an exit option
Rule 6
Easy to leave, a mature European alternative exists, and switching would actually reduce exposure.
Result — Switch — easy win
Rule 7
Everything else: low stakes, low lock-in, or already governed in Europe.
Result — Watch
A complete example
Seven dependencies of a fictional 120-person European company. The levels below are computed by the engine as this page loads — they are not written by hand.
| Dependency | Jurisdiction | Sensitivity | Reversibility | Level | Rule |
|---|---|---|---|---|---|
| Corporate mailboxes, from a US-headquartered editor | Reachable by non-EU law | Sensitive data | Moderate lock-in | Act now · long programme | Rule 2 |
| Transactional email for the product, from a US-headquartered editor | Reachable by non-EU law | Sensitive data | Easy to leave | Act now · quick exit | Rule 1 |
| Generative AI assistant used on internal documents | Reachable by non-EU law | Sensitive data | Hard to leave | Build an exit option | Rule 3 |
| Single sign-on, operated in Europe on non-EU technology | EU-operated, non-EU technology | Sensitive data | Moderate lock-in | Build an exit option | Rule 4 |
| Managed data warehouse holding aggregated public data | Reachable by non-EU law | Non-sensitive data | Hard to leave | Build an exit option | Rule 5 |
| Object storage for public assets | Reachable by non-EU law | Non-sensitive data | Easy to leave | Switch — easy win | Rule 6 |
| DNS, with a European provider | EU / EEA | Non-sensitive data | Easy to leave | Watch | Rule 7 |
The nine domains
Dependencies are grouped into nine functional domains. They are how your roadmap reports coverage — which parts of your stack you have mapped, and which are still blank. Each domain is mapped onto the objectives of the EU Cloud Sovereignty Framework, a correspondence we maintain for solution evaluation by their editors. The prioritisation of your roadmap rests on our own rules.
- Identity & Access
- Comms & Collaboration
- Productivity & Office
- Business Apps
- Data & Analytics
- AI & ML
- Infrastructure & Compute
- Security & Compliance
- Dev & Ops
Engine version
Every report carries the version of the engine that produced it. When the rules change, older reports are flagged so you can re-run them and see what moved.
Current version: 2.0.0
2.0.0 · 2026-07-10
Dependencies that are exposed and sensitive but have no mature European alternative now route to "Build an exit option" instead of "Act now": leaving has to have a destination. Frontier AI is the typical case.
1.0.0 · 2026-07-10
First public version: routing on the three factors, jurisdiction resolved from the deployment, and the "switch — easy win" level for dependencies that are cheap to replace.
Parameters, in full
Everything the engine reads, published. These are editorial values: they evolve, and we welcome argued disagreement.
What this method does not do
It does not rate providers
You will find no ranking and no verdict here. A dependency's level says something about your use of a service, not about the company behind it.
It is not legal advice
The roadmap is a working tool for prioritising. Whether a given exposure is acceptable for your organization is a call only you — and where relevant, your counsel — can make.
It does not judge cost, quality or security maturity
Three factors, deliberately. A tool can be excellent, cheap, well secured, and still sit at the top of your roadmap — and the reverse.
Its parameters are ours, and they move
The per-function defaults and the rules on this page are editorial choices. We revise them as the European market changes, and the engine version tells you which set produced a given report.
Where the jurisdiction facts come from
We gather them from public sources — company registration and ownership, published hosting arrangements, contractual terms — and keep them under regular review. They can still be incomplete or out of date for a specific product, region or contract. If something looks wrong for your situation, tell us and we will correct it.
What we build on
CloudCompass did not appear from nowhere. Here is what we owe to each of these, and where our own work starts.
EU Cloud Sovereignty Framework
The European Commission's framework gives us the vocabulary of sovereignty, the lens for reading jurisdictional exposure, and the eight objectives our nine domains are mapped onto. The routing rules and the per-function parameters on this page are our own work.
Read the frameworkaDRI — Indice de Résilience Numérique
The closest enterprise-oriented work to ours, and an inspiration at the level of ideas: measuring an organization's digital dependency rather than grading a product. Our method is built independently of it — different factors, different rules.
Visit aDRIEuropean Alternatives
A reminder that the practical question is rarely "is this exposed?" but "is there a mature European option today?" — which our engine carries as a per-function parameter.
Browse European AlternativesEU-Score
For the discipline of publishing criteria rather than only a score. This page exists partly because that norm should be the norm.
Visit EU-Score