Data and Process Sovereignty Survey

Find your Data and Process Sovereignty Score

Twenty questions across four areas: cloud security posture, cost visibility, data control, and process control. We score each answer on a 1 to 10 scale and send back a PDF with your composite score and section breakdown. Higher scores indicate a stronger sovereign posture. Lower scores indicate a greater need for sovereign infrastructure.

Organization Profile

1

Cloud Data Security Posture

Authentication and Access. How consistently does your organization enforce strong MFA and least-privilege access across all users, service accounts, and AI systems?

5 / 10
1510

Encryption Standards. How completely is your data encrypted at rest and in transit across every cloud environment you use?

5 / 10
1510

Incident Resilience. How prepared is your organization to keep operating and protect data during a long-term cloud outage or major security incident?

5 / 10
1510

Monitoring and Auditing. How mature is your program for continuous cloud risk monitoring, control testing, and audit evidence collection?

5 / 10
1510

Third-Party Risk. How rigorously do you assess SaaS applications and AI agents for security and data-handling risk before they are integrated into critical workflows?

5 / 10
1510
2

Security and Visibility of Cloud Costs

Budgetary Adequacy. How well is your cybersecurity and AI-risk budget scaled to meet the current threat landscape, including AI-generated attacks?

5 / 10
1510

Breach Absorption. How confident are you that your organization could absorb the financial impact of a major cloud data breach without material harm?

5 / 10
1510

Shadow IT Visibility. How much visibility do you have into unauthorized cloud apps and AI tools running inside your organization?

5 / 10
1510

Security-Enabled Velocity. How well do your current security policies enable innovation teams to move quickly without compromising posture?

5 / 10
1510

Cost Predictability. How accurately can you forecast your AI and cloud compute spend twelve months out, including egress, inference, and lock-in costs?

5 / 10
1510
3

Data Sovereignty and Control

Geographic Sovereignty. How well does your current infrastructure guarantee that regulated data stays within required jurisdictions?

5 / 10
1510

Physical Control. How confident are you in your ability to physically inspect, seize, or reclaim your data and infrastructure on demand?

5 / 10
1510

Regulatory Compliance. How confident are you that your current setup meets all regulatory mandates applicable to your industry (GDPR, HIPAA, DORA, CMMC, and equivalents)?

5 / 10
1510

Provider Exit Readiness. How ready is your documented exit strategy to move workloads if your cloud provider changes terms, pricing, or availability?

5 / 10
1510

AI Data Containment. How well have you contained the risk of data leaks and intellectual property loss from generative AI tools used inside your organization?

5 / 10
1510
4

Process Sovereignty

Model Control. How much of your mission-critical AI can you run on infrastructure you own, without a third-party inference API in the path?

5 / 10
1510

Workflow Portability. If your primary cloud AI provider changed terms tomorrow, how quickly could you cut production workflows over to an alternative?

5 / 10
1510

Determinism and Audit. How reliably can you reproduce the exact inputs, model weights, and decision path for an AI-generated output six months after the fact for a regulator?

5 / 10
1510

Automation Independence. How portable are your CI/CD, orchestration, and MLOps stacks across environments, versus being locked to a single provider?

5 / 10
1510

Human-in-the-Loop Authority. How well can you enforce which AI-driven decisions require human review, consistently across every AI system in your organization?

5 / 10
1510

By submitting, you agree to receive your PDF report by email. We will not share your responses with any third party.