Sovereignty

French sovereign cloud: control first

Why a cloud hosted in France, operated under French law and designed zero trust, better protects companies, employees, and sensitive data.

7 min readThe UltiSuite team
French flag behind a cloud protected by a shield and zero trust controls

Friday evening, cloud becomes political

Banal scene: Friday, 6:42 p.m. The executive committee finishes a video call on a possible acquisition. In drive, there is the tax memo. In mail, exchanges with the lawyer. In calendar, meetings with two banks. In CRM, clients who must not learn the news before signing.

On paper, these are files. In reality, it is a complete power map: who negotiates, who finances, who hesitates, who depends on whom.

Sensitive data does not need to be published to do harm. It is enough for a third party to threaten access, block it, or deliver it at the wrong moment.

Sovereign cloud starts there. Not anti-American reflex. Not a blue-white-red logo. A colder question: who holds the lever when things tighten?

The real risk: losing the lever

A French company does not only store documents in its cloud. It puts negotiations, patents, disputes, payroll, sensitive clients, political address books. That data tells the strategy before it is public.

When that cloud depends on foreign law, a foreign parent, or an opaque admin chain, the risk does not always look like a spy movie. It can take a very administrative form:

  • a court order addressed to the provider;
  • support access hard to audit;
  • account suspension at the worst moment;
  • diplomatic pressure on an actor with more to lose in Washington, London, or Berlin than in Paris;
  • a data transfer covered by a contract nobody rereads after signing.

CNIL is clear: for sensitive processing, the topic is not only server location. You must also avoid exposure to extra-European laws. SecNumCloud ANSSI qualification exists to materialize that trust level, with technical, operational, and legal requirements.

Alstom, Gemplus, Gemalto: precedent exists

The Alstom case remains what many executives keep in mind. Frédéric Pierucci, a group executive, was arrested in the United States in 2013 in an FCPA procedure. A year later, Alstom sold its energy division to General Electric. Pierucci sees an economic warfare tool; others see corruption first.

We do not need to settle the whole case to keep the useful lesson: an American legal lever weighed on a strategic French industrial asset. When the asset touches turbines, energy, international contracts, judicial procedure is no longer only judicial. It becomes a negotiation parameter.

Gemplus tells another fragility, closer to digital. French smart card champion, the company carried cryptography and mobile security know-how. Early 2000s, arrival of American fund TPG then Alex Mandl, linked to In-Q-Tel, triggered strong internal industrial espionage fears. The battle played in governance, not a datacenter.

Gemalto, heir to that sector, returns in Snowden revelations. NSA and GCHQ allegedly targeted SIM encryption keys. Gemalto acknowledged sophisticated intrusions probably linked to the operation, while disputing massive key leak. Nuance matters. But the signal stays heavy: allies collect too when strategic interest is sufficient.

Crypto AG pushes further. Per the 2020 Washington Post/ZDF/SRF investigation, CIA and German BND controlled for decades a Swiss company selling encryption machines to 120+ countries. Clients thought they bought confidentiality; some bought a back door.

Digital sovereignty begins when the trust chain no longer rests on another state's goodwill.

Ransomware does not ask for your passport

Hostile threat no longer needs a state. In its 2025 panorama, ANSSI records 1,366 incidents brought to its attention, 128 ransomware compromises, and a clear rise in data exfiltration. Attackers encrypt less systematically; they steal, then negotiate.

That detail changes everything. Backup restores a server. It does not cancel publication of an HR file, defense client list, acquisition negotiation, or prefecture exchange. Sovereign cloud is therefore not only availability. It is possible blackmail.

A foreign provider does not create ransomware. But the longer the chain, the fuzzier dependencies: outsourced support, subprocessors, admin consoles, encryption keys, connected APIs, automatic exports. The attacker seeks where control is weakest.

Zero trust: useful only if it bites

Zero trust avoids the classic trap: "it is ours, so it is safe." No. Even hosted in France, a service must verify every access, limit every role, trace every sensitive action.

The good test is simple: if an administrator, subcontractor, or compromised account tries to export 40 GB of mail at 2 a.m., who sees it, who blocks, who explains?

A serious sovereign cloud should prove at minimum:

ControlWhat we expect
IdentityMandatory MFA, controlled SSO, separate admin accounts
RightsLeast privilege, access expiry, regular review
IsolationSeparate tenants, segmented network, isolated secrets
EncryptionTLS, encryption at rest, client-controllable keys
LoggingExploitable access logs, alerts on exports and admin
ResilienceOffline or immutable backups, tested restore
OperationsTeams and subcontractors under French or European law

The hard point is often the last. Many "trusted cloud" offers reduce risk but do not remove it if technology, license, support, or parent company remain exposed to another jurisdiction.

Made in France is not enough, but it matters

"Made in France" is not magic. A French suite can be poorly coded. A local host can miss backups. A team can plug an American LLM on all inbound mail and recreate the transfer it wanted to avoid.

But when software, hosting, operations, and governance stay under French or European control, decisions become negotiable locally. The CIO can audit. The DPO can document. The executive knows which court decides. The state does not discover in crisis that a critical SI piece depends on a foreign arbitration.

This point is less glamorous than generative AI news. It matters more: know how to say no, cut, migrate, audit, and restore without asking permission from an out-of-reach actor.

That is why we build UltiSuite as a France-hosted suite, with on-premise option for organizations that require it: mail, files, identity, and automation under your control. Our article on productivity suite telemetry details data-side risk. UltiSuite vs Google Workspace comparison also covers cost from €6/seat in cloud, and progressive migration.

Simple criterion to decide

Ask before choosing a cloud: if tomorrow a provider, allied state, or attacker uses your data as leverage, can you resist without begging?

If the answer is no, your cloud is not sovereign enough. Not yet.

Sources consulted

Related articles

More reading in the Sovereignty category.