How it works

How your roadmap is built

The engine that prioritises your dependencies is not a black box. Here are its principles, its rules, the parameters it uses, and a complete worked example.

Four principles

  • We classify your dependencies, not your providers

    No provider is rated good or bad. What lands on the roadmap is your use of one — the same product can be a priority for you and a non-issue for the company next door.

  • The goal is informed choices, not zero foreign technology

    Keeping an exposed tool for public, low-stakes work is a perfectly good decision. What matters is that it is a decision.

  • Same inputs, same roadmap

    The engine is deterministic. No case-by-case judgment, no hidden weighting: two organizations that map the same dependencies get the same prioritisation.

  • Facts first, prioritisation second

    We establish where a service is governed, how sensitive its data is, and how hard it would be to leave. Only then do we sort.

The three factors

Every dependency is weighed on three things — and each one is established differently.

  • Jurisdiction — whose law can reach the data

    It follows how you deploy, not the logo on the box. A SaaS product is governed by its editor; a product you self-host is governed by the infrastructure it runs on; a product on your own premises is governed by your own country. Haven't chosen a host yet? We treat it as unknown rather than assume it is safe.

    Four outcomes: governed in the EU or EEA; reachable by non-EU law; operated in Europe on non-EU technology, with residual exposure; or not yet known.

  • Sensitivity — what the data is worth

    You declare it, dependency by dependency. We never guess it: only you know what actually flows through a given tool.

  • Reversibility — how hard it would be to leave

    A default per function, because leaving object storage is nothing like leaving an identity provider. One rule raises it: open-source software you host yourself has no editor lock-in, so it counts as easy to leave.

The four levels

The levels are parallel tracks, not a ladder. There is no single finish line — you decide what matters most.

  • Act now

    These run sensitive data under non-EU jurisdiction — the combination that carries real exposure today. Easy-to-leave ones are quick wins; locked-in ones need an exit plan you should start now, even if it takes time.

  • Build an exit option

    Hard to leave, and you may not have a full alternative yet (frontier AI is the classic case). You're not necessarily leaving — but make sure you could: prefer portable formats, agnostic approaches, avoid deepening the lock-in.

  • Switch — easy win

    Low lock-in, and a mature European alternative exists. These are the cheapest sovereignty gains available to you.

  • Watch

    Low stakes and low lock-in. No action needed now — we list them so nothing is invisible.

The rules

The engine walks these in order and stops at the first match, so every dependency lands on exactly one level. This list is generated from the engine itself.

  1. Rule 1

    Reachable by non-EU law, sensitive data, a mature European alternative exists — and it is easy to leave.

    ResultAct now · quick exit

  2. Rule 2

    Reachable by non-EU law, sensitive data, a mature European alternative exists — but leaving takes work.

    ResultAct now · long programme

  3. Rule 3

    Reachable by non-EU law, sensitive data, and no mature European alternative yet. Telling you to leave would point nowhere, so the work is to stay able to leave.

    ResultBuild an exit option

  4. Rule 4

    Sensitive data on a service operated in Europe on non-EU technology, or whose jurisdiction we cannot establish yet.

    ResultBuild an exit option

  5. Rule 5

    Hard to leave, whatever the jurisdiction. Lock-in is a risk on its own.

    ResultBuild an exit option

  6. Rule 6

    Easy to leave, a mature European alternative exists, and switching would actually reduce exposure.

    ResultSwitch — easy win

  7. Rule 7

    Everything else: low stakes, low lock-in, or already governed in Europe.

    ResultWatch

A complete example

Seven dependencies of a fictional 120-person European company. The levels below are computed by the engine as this page loads — they are not written by hand.

DependencyJurisdictionSensitivityReversibilityLevelRule
Corporate mailboxes, from a US-headquartered editorReachable by non-EU lawSensitive dataModerate lock-inAct now · long programmeRule 2
Transactional email for the product, from a US-headquartered editorReachable by non-EU lawSensitive dataEasy to leaveAct now · quick exitRule 1
Generative AI assistant used on internal documentsReachable by non-EU lawSensitive dataHard to leaveBuild an exit optionRule 3
Single sign-on, operated in Europe on non-EU technologyEU-operated, non-EU technologySensitive dataModerate lock-inBuild an exit optionRule 4
Managed data warehouse holding aggregated public dataReachable by non-EU lawNon-sensitive dataHard to leaveBuild an exit optionRule 5
Object storage for public assetsReachable by non-EU lawNon-sensitive dataEasy to leaveSwitch — easy winRule 6
DNS, with a European providerEU / EEANon-sensitive dataEasy to leaveWatchRule 7

The nine domains

Dependencies are grouped into nine functional domains. They are how your roadmap reports coverage — which parts of your stack you have mapped, and which are still blank. Each domain is mapped onto the objectives of the EU Cloud Sovereignty Framework, a correspondence we maintain for solution evaluation by their editors. The prioritisation of your roadmap rests on our own rules.

  • Identity & Access
  • Comms & Collaboration
  • Productivity & Office
  • Business Apps
  • Data & Analytics
  • AI & ML
  • Infrastructure & Compute
  • Security & Compliance
  • Dev & Ops

Engine version

Every report carries the version of the engine that produced it. When the rules change, older reports are flagged so you can re-run them and see what moved.

Current version: 2.0.0

  • 2.0.0 · 2026-07-10

    Dependencies that are exposed and sensitive but have no mature European alternative now route to "Build an exit option" instead of "Act now": leaving has to have a destination. Frontier AI is the typical case.

  • 1.0.0 · 2026-07-10

    First public version: routing on the three factors, jurisdiction resolved from the deployment, and the "switch — easy win" level for dependencies that are cheap to replace.

Parameters, in full

Everything the engine reads, published. These are editorial values: they evolve, and we welcome argued disagreement.

What this method does not do

  • It does not rate providers

    You will find no ranking and no verdict here. A dependency's level says something about your use of a service, not about the company behind it.

  • It is not legal advice

    The roadmap is a working tool for prioritising. Whether a given exposure is acceptable for your organization is a call only you — and where relevant, your counsel — can make.

  • It does not judge cost, quality or security maturity

    Three factors, deliberately. A tool can be excellent, cheap, well secured, and still sit at the top of your roadmap — and the reverse.

  • Its parameters are ours, and they move

    The per-function defaults and the rules on this page are editorial choices. We revise them as the European market changes, and the engine version tells you which set produced a given report.

Where the jurisdiction facts come from

We gather them from public sources — company registration and ownership, published hosting arrangements, contractual terms — and keep them under regular review. They can still be incomplete or out of date for a specific product, region or contract. If something looks wrong for your situation, tell us and we will correct it.

Report an error

What we build on

CloudCompass did not appear from nowhere. Here is what we owe to each of these, and where our own work starts.

  • EU Cloud Sovereignty Framework

    The European Commission's framework gives us the vocabulary of sovereignty, the lens for reading jurisdictional exposure, and the eight objectives our nine domains are mapped onto. The routing rules and the per-function parameters on this page are our own work.

    Read the framework
  • aDRI — Indice de Résilience Numérique

    The closest enterprise-oriented work to ours, and an inspiration at the level of ideas: measuring an organization's digital dependency rather than grading a product. Our method is built independently of it — different factors, different rules.

    Visit aDRI
  • European Alternatives

    A reminder that the practical question is rarely "is this exposed?" but "is there a mature European option today?" — which our engine carries as a per-function parameter.

    Browse European Alternatives
  • EU-Score

    For the discipline of publishing criteria rather than only a score. This page exists partly because that norm should be the norm.

    Visit EU-Score

See it on your own dependencies

Map what you use, and the same rules produce your roadmap. Free, EU-hosted, about five minutes.