Your subcontractors' digital sovereignty,
visible in one scan
A supplier can host its data in France and still be under US jurisdiction. Conitiv analyzes ASN jurisdiction and GeoIP location for each digital asset — Web, Mail and DNS — without relying on third-party cooperation.
Supplier A — IT Services & Systems Integration
Information systems · Automatic analysis
3
surfaces analysées
2
dimensions de score
Cloud Act: when your data remains under US jurisdiction
Cloud Act — 18 U.S.C. § 2523 (2018)
"US-based electronic service providers must disclose data stored on their servers, wherever they are located worldwide, upon request from US federal authorities."
Hosted in France ≠ French jurisdiction
Azure France-North physically hosts data in France, but the ASN operator is Microsoft Corp. (US). The Cloud Act applies regardless of the geographic location of the servers.
Microsoft 365: the invisible email risk
More than 90% of French IT service companies and SMEs use Microsoft 365 or Google Workspace. Their mail servers are 100% under US jurisdiction, even when mailboxes are hosted in Europe.
NIS2 and DORA require this verification
Article 21 of NIS2 and the DORA RTS require assessment of risks related to the digital supply chain, including dependence on extra-European cloud operators.
Liability comes back to you
In the event of a requisition by US authorities concerning data processed by a subcontractor, the data controller is exposed if they have not previously documented and qualified this risk.
The distinction between physical location and jurisdiction is crucial: a third party can advertise 'data hosted in France' while being entirely exposed to the Cloud Act. Conitiv independently analyzes both dimensions for each of the supplier's digital assets.
3 surfaces, 2 dimensions
Each asset is assessed on two independent dimensions: its physical location (GeoIP) and the jurisdiction of its network operator (ASN). A score is calculated for each.
du score
Web
IP location of web servers, hosting provider ASN, presence of US CDNs (Cloudflare, Fastly, Akamai)
du score
MX records, identification of Microsoft 365 / Google Workspace, jurisdiction of mail relays
du score
DNS
Authoritative nameserver operators, location and jurisdiction of DNS resolvers
Jurisdiction (ASN) measures the nationality of the network operator. Location (GeoIP) measures the physical location of the servers. A score is calculated for each, out of 1,000 points.
Criteria are technically verified by domain scan, DNS resolution and ARIN/RIPE/APNIC registry lookup. Results available in under one minute.
Same location, two risk levels
The sovereignty rating reveals unexpected situations: a supplier located in France can remain entirely under US jurisdiction.
Supplier A — IT Services & Systems Integration
Information systems · Automatic analysis
Jurisdiction (ASN)
Location (GeoIP)
Exemplary location (100% EU), but jurisdiction compromised by Microsoft 365 (mail) and Azure. Physical servers are in France, the ASN operator is American.
Breakdown by operator
Supplier B — Financial Advisory
Capital management · Automatic analysis
Jurisdiction (ASN)
Location (GeoIP)
Double exposure: website hosted in the United States (Cloudflare) and email under US jurisdiction (Microsoft 365). Only DNS is sovereign (OVH).
Breakdown by operator
The most discriminating signals
Microsoft 365 & Exchange Online
The most decisive email operator. Present in more than 90% of subcontractors, it automatically places all professional communications under US jurisdiction, even when mailboxes are hosted in Ireland.
US CDNs (Cloudflare, Akamai, Fastly)
A US CDN in front of the website is sufficient to create Cloud Act exposure on web traffic. Cloudflare (AS13335, US) is present at most suppliers and is the second most frequent risk factor.
Azure / AWS / GCP hosted 'in France'
These operators are US companies regardless of the region chosen. Azure France-North, AWS eu-west-3 and GCP europe-west9 remain under US jurisdiction. The physical location of data is not sufficient to guarantee sovereignty.
From declaration to real mapping
Cloud dependency mapping
Precisely identify which operators (Azure, AWS, Cloudflare…) run each third party's infrastructure, and what fraction is under US jurisdiction.
Prioritization by exposed service
Email is often the highest-risk vector. The rating segments exposure by surface (Web, Mail, DNS) to target remediation plans.
Sovereignty due diligence proof
Produce a dated and exportable proof for each supplier. Essential in public procurement and NIS2/DORA audits requiring digital supply chain assessment.
Integrated into Conitiv's 360° score
The sovereignty rating is added to Cyber, RSE, GDPR and Solvency ratings in the global risk score. Procurement, CISO and DPO teams work on the same view.
Without relying on the supplier
The analysis relies on public data: DNS resolution, ASN registries (RIPE, ARIN, APNIC) and GeoIP. No third-party cooperation is required.
Continuous monitoring, cloud migration alerts
Schedule periodic updates. If a migration to an unqualified US operator occurs, you receive an alert before the contract is renewed.
Map the digital sovereignty of your third-party portfolio
A 30-minute demonstration with your suppliers handling the most sensitive data and a live scan.
Request a demo →expert Conitiv