New · Sovereignty Rating

Your subcontractors' digital sovereignty,
visible in one scan

A supplier can host its data in France and still be under US jurisdiction. Conitiv analyzes ASN jurisdiction and GeoIP location for each digital asset — Web, Mail and DNS — without relying on third-party cooperation.

Request a demo
JS

Supplier A — IT Services & Systems Integration

Information systems · Automatic analysis

475/1 000
At riskJurisdiction
640/1 000
PartialLocation
⚠ Cloud Act applicable

3

surfaces analysées

2

dimensions de score

ASN jurisdiction analyzed
GeoIP location
Web · Mail · DNS
Updatable on demand
The challenge

Cloud Act: when your data remains under US jurisdiction

Cloud Act — 18 U.S.C. § 2523 (2018)

"US-based electronic service providers must disclose data stored on their servers, wherever they are located worldwide, upon request from US federal authorities."

🏢

Hosted in France ≠ French jurisdiction

Azure France-North physically hosts data in France, but the ASN operator is Microsoft Corp. (US). The Cloud Act applies regardless of the geographic location of the servers.

📧

Microsoft 365: the invisible email risk

More than 90% of French IT service companies and SMEs use Microsoft 365 or Google Workspace. Their mail servers are 100% under US jurisdiction, even when mailboxes are hosted in Europe.

📋

NIS2 and DORA require this verification

Article 21 of NIS2 and the DORA RTS require assessment of risks related to the digital supply chain, including dependence on extra-European cloud operators.

⚠️

Liability comes back to you

In the event of a requisition by US authorities concerning data processed by a subcontractor, the data controller is exposed if they have not previously documented and qualified this risk.

The distinction between physical location and jurisdiction is crucial: a third party can advertise 'data hosted in France' while being entirely exposed to the Cloud Act. Conitiv independently analyzes both dimensions for each of the supplier's digital assets.

What Conitiv analyzes

3 surfaces, 2 dimensions

Each asset is assessed on two independent dimensions: its physical location (GeoIP) and the jurisdiction of its network operator (ASN). A score is calculated for each.

Jurisdiction (ASN)
Location (GeoIP)
45%

du score

Web

IP location of web servers, hosting provider ASN, presence of US CDNs (Cloudflare, Fastly, Akamai)

45%

du score

Mail

MX records, identification of Microsoft 365 / Google Workspace, jurisdiction of mail relays

10%

du score

DNS

Authoritative nameserver operators, location and jurisdiction of DNS resolvers

Jurisdiction (ASN) measures the nationality of the network operator. Location (GeoIP) measures the physical location of the servers. A score is calculated for each, out of 1,000 points.

Criteria are technically verified by domain scan, DNS resolution and ARIN/RIPE/APNIC registry lookup. Results available in under one minute.

Result examples

Same location, two risk levels

The sovereignty rating reveals unexpected situations: a supplier located in France can remain entirely under US jurisdiction.

S1

Supplier A — IT Services & Systems Integration

Information systems · Automatic analysis

16 assets analyzed

Jurisdiction (ASN)

475/1 000
At risk

Location (GeoIP)

1,000/1 000
Sovereign
⚠ Cloud Act applicable

Exemplary location (100% EU), but jurisdiction compromised by Microsoft 365 (mail) and Azure. Physical servers are in France, the ASN operator is American.

Breakdown by operator

USMicrosoft Azure
25%
UEGandi SAS
19%
UENetsyst SAS
19%
UEScaleway / Online
6%
—Others
31%
Web — Location100% EU
Web — JurisdictionUnknown 50% · US 25%
Mail — Jurisdiction100% US (MS 365)
DNS — Location100% EU
DNS — Jurisdiction100% EU
S2

Supplier B — Financial Advisory

Capital management · Automatic analysis

7 assets analyzed

Jurisdiction (ASN)

415/1 000
At risk

Location (GeoIP)

640/1 000
Partial
⚠ Cloud Act applicable

Double exposure: website hosted in the United States (Cloudflare) and email under US jurisdiction (Microsoft 365). Only DNS is sovereign (OVH).

Breakdown by operator

USMicrosoft Azure
57%
UEOVH
29%
USCloudflare
14%
Web — Location100% US
Web — JurisdictionUnknown 100%
Mail — Jurisdiction100% US (MS 365)
DNS — Location100% EU
DNS — Jurisdiction100% EU (OVH)
What the scan reveals

The most discriminating signals

📧

Microsoft 365 & Exchange Online

The most decisive email operator. Present in more than 90% of subcontractors, it automatically places all professional communications under US jurisdiction, even when mailboxes are hosted in Ireland.

⚠ Identified in more than 9 out of 10 suppliers in our analyses
☁️

US CDNs (Cloudflare, Akamai, Fastly)

A US CDN in front of the website is sufficient to create Cloud Act exposure on web traffic. Cloudflare (AS13335, US) is present at most suppliers and is the second most frequent risk factor.

⚠ Cloudflare detected in more than 60% of analyses
🌐

Azure / AWS / GCP hosted 'in France'

These operators are US companies regardless of the region chosen. Azure France-North, AWS eu-west-3 and GCP europe-west9 remain under US jurisdiction. The physical location of data is not sufficient to guarantee sovereignty.

⚠ Location / jurisdiction confusion in 80% of cases
What you gain

From declaration to real mapping

Cloud dependency mapping

Precisely identify which operators (Azure, AWS, Cloudflare…) run each third party's infrastructure, and what fraction is under US jurisdiction.

Prioritization by exposed service

Email is often the highest-risk vector. The rating segments exposure by surface (Web, Mail, DNS) to target remediation plans.

Sovereignty due diligence proof

Produce a dated and exportable proof for each supplier. Essential in public procurement and NIS2/DORA audits requiring digital supply chain assessment.

Integrated into Conitiv's 360° score

The sovereignty rating is added to Cyber, RSE, GDPR and Solvency ratings in the global risk score. Procurement, CISO and DPO teams work on the same view.

Without relying on the supplier

The analysis relies on public data: DNS resolution, ASN registries (RIPE, ARIN, APNIC) and GeoIP. No third-party cooperation is required.

Continuous monitoring, cloud migration alerts

Schedule periodic updates. If a migration to an unqualified US operator occurs, you receive an alert before the contract is renewed.

Take action

Map the digital sovereignty of your third-party portfolio

A 30-minute demonstration with your suppliers handling the most sensitive data and a live scan.

Request a demo →
Parlez à un
expert Conitiv