Measuring Digital Sovereignty: SovereigntyMap Put to the Test

🇫🇷 Lire en français : Mesurer sa souveraineté numérique : SovereigntyMap à l'épreuve
Testing SovereigntyMap — the new independent digital-sovereignty observatory launched by engineer Sylvain Rutten — kimoun.com scored 100/100: “sovereign”, gold label, when the French average sits around 54/100. Good news. But what really interests me isn’t the score: it’s what a measurement tool reveals when you handle it from the Caribbean, where digital sovereignty isn’t a conference topic but daily life.
An observatory that makes sovereignty measurable

Tip
A sovereignty observatory doesn’t judge your intentions: it measures technical facts — where your site is hosted, who runs your DNS, which jurisdiction your email falls under.
We talk a lot about digital sovereignty, and almost always without criteria. Which dependencies should you analyse? Which guarantees should you compare? How do you tell a concrete commitment from a marketing pitch? That’s exactly the gap SovereigntyMap fills: mapping an organisation’s cloud dependency the way Electricity Maps maps the carbon footprint of electricity — making an otherwise abstract issue visible, comparable and debatable.
The timing is apt. On 26 January 2026, the French state launched its own Digital Sovereignty Observatory, entrusted to the High Commission for Strategy and Planning — an institutional body whose first findings are expected in spring. SovereigntyMap, by contrast, is an independent, open project that waits for no one’s permission to measure. The two don’t compete: they light up the same blind spot. The backdrop is well known — according to CIGREF, 80% of European spending on software and professional storage goes to US companies.
100/100, gold label: what SovereigntyMap measures

A 100/100 doesn’t fall from the sky, and it puts kimoun.com well ahead: at the time of writing, across the 681 French organisations the tool tracks, the average sits around 54/100. The tool then breaks the score down by category, and that’s where it gets instructive. On kimoun.com’s profile: front-end hosting 100/100, DNS 100/100, email 100/100. Three building blocks flagged low-risk — European host and DNS, email under European jurisdiction.

A nice detail: the tool correctly saw that my email runs at OVH, the very place where it got the hosting wrong (more on that below). Proof that sovereign email is as detectable as it is deliberate.
This score is no accident; it’s a string of choices. Hosting on European infrastructure, keeping a controlled DNS, email that doesn’t hand your exchanges to a non-European jurisdiction: these are the same principles I apply to the projects we host — reversibility, no lock-in, the client owning their code and their access. Sovereignty isn’t proclaimed, it’s built block by block. A tool that makes it visible suits me just fine.

What I flagged to the author — and he’s already fixing

Note
On kimoun.com, the crawler placed the hosting at Gandi. But the server has run at OVH for more than ten years. An old redirect from
wwwto the apex, still sitting at Gandi, threw the detection off.
A good tool deserves serious testing. So I went looking for where it might slip. The crawler treated www as the main site — except that on kimoun.com, www is only a 301 redirect to the apex, which itself points to OVH. Result: hosting attributed to Gandi. To check, I cross-referenced with the free version of
ip-api.com (country, region, ASN, organisation), which returned the right data centre.
I flagged the case to Sylvain. His reply, the same day: 301 redirects will be taken into account, “we’ll code that”. This is exactly how an open project moves forward — through real cases. Other first-version rough edges show on my profile: the cloud stays classed “unknown”, the trackers display 0/100, and the “overall risk” block keeps generic text that jars a little with a 100/100. Nothing serious: youthful details that get fixed quickly when the author is responsive — and he is.
Warning
An automated score is still a surface snapshot: it reads what it detects (IP, ASN, DNS, headers), not your contracts, your backups or your recovery plan. 100/100 on the map doesn’t replace a real resilience audit.
Measure, yes — but who maps the overseas territories?

My one real regret comes down to a map. The overseas territories aren’t on it. And that’s a shame, because to my mind they’re precisely the most interesting angle of the subject.
The outermost regions are Europe — and its most exposed frontier on the question of digital sovereignty. Here, insularity and distance quickly turn “make or buy” into “make or die”: when the cable strains or a distant provider goes down, it isn’t a budget line, it’s the business that stops. There’s even a delicious paradox: France’s centralised model has recreated ultra-periphery on a network that is, by nature, a-peripheral. That’s the whole subject I dig into, from the submarine cable to the click, through to the day the Internet stops for 72 hours — and to how economic value drains off the territory via distant platforms.
Mapping sovereignty without the overseas territories is mapping only what we already see. I shared the point with Sylvain, who noted it at once: the overseas dimension is coming to the map. Good. Because to talk seriously about sovereignty, you also have to be willing to look where it plays out the hardest.