Automated sovereignty scoring for your vendor supply chain
sovscan produces auditor-ready Sovereignty Scores for any domain — replacing weeks of manual evidence collection with structured, timestamped results in under 5 minutes.
Physical location is not legal reach. A server in Frankfurt running on a US-operated network is still CLOUD Act-exposed. sovscan resolves every asset to the jurisdiction of the network operator that controls it — not just where the IP sits.
NIS2 Art. 21(2)(e) · BSI C5 Supply Chain · SecNumCloud
Try it on your own domain
Manual vendor assessment doesn't scale
- Weeks per vendorDNS, WHOIS, TLS, corporate ownership chains, questionnaires — weeks of work per assessment.
- Stale the moment it's printedInfrastructure changes continuously; last month's assessment is today's liability.
- Location is not legal reachA Frankfurt server owned by a US parent is still CLOUD Act-exposed — most assessments miss this entirely.
Evidence in minutes, not weeks
- 1Enter a domainSubmit any vendor domain.
- 2sovscan audits the full stackDNS records, subdomains via Certificate Transparency, ASN ownership, CDN edges, third-party script dependencies.
- 3Get auditor-ready evidenceA timestamped Sovereignty Score with full asset breakdown, exportable for regulators and auditors.
Built for regulated EU suppliers
- BSI C5 certified suppliersYour NIS2 Art. 21(2)(e) supply chain obligation means your vendors need to meet the same bar. sovscan automates that assessment.
- SecNumCloud qualified providersDemonstrate supply chain sovereignty posture to ANSSI auditors with structured, timestamped evidence.
- Vendor risk and GRC teamsReplace questionnaire-based assessment with automated scoring across your entire vendor portfolio.
Looking for 3–5 design partners
We're working with a small group of EU-based organizations to validate the scoring model. If you manage vendor risk for a BSI C5 supplier, a SecNumCloud-qualified provider, or a NIS2 essential entity, we'd like to hear from you.