Automated sovereignty scoring for your vendor supply chain

sovscan produces auditor-ready Sovereignty Scores for any domain — replacing weeks of manual evidence collection with structured, timestamped results in under 5 minutes.
Physical location is not legal reach. A server in Frankfurt running on a US-operated network is still CLOUD Act-exposed. sovscan resolves every asset to the jurisdiction of the network operator that controls it — not just where the IP sits.

NIS2 Art. 21(2)(e) · BSI C5 Supply Chain · SecNumCloud

Try it on your own domain

Enter the root domain only, not a full URL.

One free scan per domain every 7 days. No account required.

Manual vendor assessment doesn't scale

  • Weeks per vendor
    DNS, WHOIS, TLS, corporate ownership chains, questionnaires — weeks of work per assessment.
  • Stale the moment it's printed
    Infrastructure changes continuously; last month's assessment is today's liability.
  • Location is not legal reach
    A Frankfurt server owned by a US parent is still CLOUD Act-exposed — most assessments miss this entirely.

Evidence in minutes, not weeks

  • 1
    Enter a domain
    Submit any vendor domain.
  • 2
    sovscan audits the full stack
    DNS records, subdomains via Certificate Transparency, ASN ownership, CDN edges, third-party script dependencies.
  • 3
    Get auditor-ready evidence
    A timestamped Sovereignty Score with full asset breakdown, exportable for regulators and auditors.

Built for regulated EU suppliers

  • BSI C5 certified suppliers
    Your NIS2 Art. 21(2)(e) supply chain obligation means your vendors need to meet the same bar. sovscan automates that assessment.
  • SecNumCloud qualified providers
    Demonstrate supply chain sovereignty posture to ANSSI auditors with structured, timestamped evidence.
  • Vendor risk and GRC teams
    Replace questionnaire-based assessment with automated scoring across your entire vendor portfolio.

Looking for 3–5 design partners

We're working with a small group of EU-based organizations to validate the scoring model. If you manage vendor risk for a BSI C5 supplier, a SecNumCloud-qualified provider, or a NIS2 essential entity, we'd like to hear from you.

© 2026 sovscan

Hosted on Hetzner, Nuremberg