Shebaka شبكة

Shebaka Provenance

The provenance record.

Every provider carrying a Shebaka workload has been through a written screen: ownership traced to natural persons, jurisdiction, the whole upstream supply chain, energy, labour, and what happens contractually when any of it stops being true. This page publishes the results, including the parts that are inconvenient for us.

Framework Shebaka Ethical Sourcing Framework Cadence Annual re-audit · quarterly upstream re-checks Onboarding threshold ≥ 3.5 / 5.0 weighted

What we screen

Seven criteria, weighted. Each is scored 0–5 with evidence attached. Some are weighted; some are hard gates, where a single failure disqualifies a provider no matter how well it scores elsewhere.

25%

Ownership & jurisdiction

The ultimate beneficial owner traced to natural persons or state entities via corporate registry extracts. Which legal jurisdiction governs customer data, and what extraterritorial disclosure regimes reach it regardless of where the machines physically sit.

Hard gate: a UBO on the divestment list, or ownership that goes opaque past two layers.

20%

Divestment screen: direct

The provider itself, screened against a maintained divestment list, sanctions and complicity databases, with board and investor review.

Hard gate: the provider is a flagged entity, or is majority-owned or controlled by one.

15%

Divestment screen: upstream supply chain

The criterion that catches what marketing pages hide. Many "independent" clouds quietly resell hyperscaler capacity, so we require a written declaration of the full delivery chain and then verify it technically rather than taking it on trust.

Hard gate: any capacity, colocation, or transit in the delivery chain turns out to be resold AWS, GCP, Azure, or flagged-entity infrastructure.

15%

Energy & environment

Grid mix and renewable share, and specifically the instrument behind a renewables claim. An unbundled certificate and a power purchase agreement are very different promises. Measured PUE rather than design PUE (we prefer ≤ 1.4 measured and flag above 1.6), plus water use and source, which matters most exactly where cooling is cheapest to claim and hardest to sustain.

Hard gate: no measurement capability at all: a provider that cannot state its PUE or its energy sources.

10%

Labour practices & conduct

Direct and contractor labour conditions, grievance mechanisms, safety record, anti-corruption posture. For Gulf facilities, recruitment-fee and passport-retention screening are named questions rather than implied ones. This criterion is never resolvable from a marketing page.

Hard gate: credible evidence of forced labour, or construction and operations labour violations left unremediated.

10%

Operational & security maturity

Certifications such as ISO 27001 or SOC 2, with the scope verified rather than just the badge, plus incident history, disclosure practice, and how the provider actually responded to us during evaluation.

Hard gate: no physical access control, or a single non-redundant power path with no roadmap.

5%

Contractual alignment

Willingness to sign attestation, audit, exit and egress clauses, and to price transparently. The smallest weight and frequently the hardest criterion: high-volume providers on standardised terms have untested appetite for bespoke attestation.

Hard gate: refuses the exit and egress terms, or refuses annual re-audit rights.

How the upstream check actually runs

This is where screens usually go wrong, so it gets its own procedure. A provider can be independently owned, honestly run, and still be delivering your workload on rented hyperscaler capacity.

  1. Supply-chain declaration. The provider names every facility with its owner and its operator, every upstream capacity supplier, and every transit and exchange relationship in the path to Shebaka customers.
  2. Technical verification. ASN ownership lookups, IP allocation against RIR records, traceroutes run from inside capacity we have actually provisioned, and TLS or BGP fingerprinting where it helps. For GPU capacity, hardware attestation of where the machine really is versus where it is claimed to be.
  3. Warranty in the contract. The declaration is warranted in the MSA. Discovering undeclared hyperscaler or flagged-entity resale is a material breach that triggers the exit clause, not a renegotiation.
  4. Quarterly re-checks. Automated ASN and IP drift monitoring between the annual audits, because a supply chain can change without anyone telling us.

The providers

Three screened. Two carrying workloads. One of those two comes with a jurisdiction caveat we will not bury.

Hetzner

Germany · Falkenstein, Nuremberg, Helsinki Passed

Hetzner Online GmbH, headquartered in Gunzenhausen, Bavaria. Privately held and founder/family-owned, with a short ownership chain that terminates in natural persons rather than in a holding structure. It builds and operates its own data centre parks and runs its own backbone, AS24940.

That last part is the reason it is here. The most common failure mode among providers marketing themselves as independent is the quiet resale of hyperscaler capacity somewhere in the delivery chain, and Hetzner's chain does not contain any: its own hardware, in its own facilities, on its own network.

Ownership
Private German GmbH, founder/family-owned
Jurisdiction
Germany / EU (GDPR), no extraterritorial parent
Facilities
Owned and operated by Hetzner
Energy
100% renewable claimed for DE and FI: hydro, wind
Scope in service
EU and Finland campuses only
Role
Default placement for new workloads

DigitalOcean

United States parent · Singapore, Bangalore and other regions Conditional

Own hardware and a public company (NYSE: DOCN), not a reseller, so the upstream criterion passes. Ownership is a public float, so the beneficial-owner check becomes a divestment screen of major holders, which is tractable.

It is on the platform because it brings jurisdictional and regional diversity that the European providers cannot: without a second, structurally different provider, the failover story is a slide rather than a capability.

Ownership
Public float (NYSE: DOCN)
Jurisdiction
US parent (see the caveat below)
Facilities
Leased third-party colocation
Energy
Thin public disclosure, an open audit item
Role
Failover target, APAC presence, provider diversity

The caveat, stated plainly. A US parent means CLOUD Act reach regardless of which country the facility sits in. DigitalOcean regions are labelled accordingly and are excluded from sovereign-residency claims. If data residency under a non-US jurisdiction is your requirement, this is not the provider for that workload, and we would rather tell you here than in a support ticket. Its facilities are also leased colocation, which means the colocation operators join the upstream screen in their own right.

Scaleway

France · Paris region, Amsterdam, Warsaw Passed

Scaleway SAS, a subsidiary of the iliad group. The chain to a natural person is short but runs through a large telecom group, so the screen had to map the whole holding structure rather than stop at the first parent. It operates its own hardware in group-operated facilities, and it publishes more environmental data (energy, PUE and WUE figures, per-service footprint) than almost anyone at its scale, which is itself a positive signal about measurement capability.

Screened and cleared, but not currently carrying workloads. It is listed here because a provenance record that only shows the providers we happen to be using is a smaller claim than one that shows the bench too.

Ownership
iliad group subsidiary; control traceable
Jurisdiction
France / EU (GDPR), no extraterritorial parent
Facilities
Group-operated, Paris region
Energy
Publishes PUE, WUE and footprint data
Status
Cleared, not in service
Role
Third provider; the designated GPU supply path

Re-audit and what happens on a failure

A screen that only runs once is a press release. Every provider is re-scored annually from the anniversary of onboarding, and the upstream criterion additionally gets quarterly technical re-checks.

A re-audit also fires immediately, outside the annual cycle, on any of these triggers: an ownership change, M&A activity, a new facility or upstream supplier, a credible public allegation on any criterion, or an update to the divestment list itself.

Pass · ≥ 3.5 Renewed. This page is updated with the audit date and outcome.
Conditional · 3.0–3.5 A remediation plan with a 90-day limit. No new Shebaka capacity is placed with that provider in the meantime.
Fail · < 3.0 The exit clause is invoked and migration off the provider begins immediately. This is survivable precisely because a second provider is always already live.

What every provider contract has to contain

  1. Termination for screening failure. Without penalty, on a failed re-audit or a breached attestation.
  2. A 90-day wind-down. Capacity stays available at contracted rates after termination notice, so workloads migrate calmly rather than under duress.
  3. Egress at no more than cost during wind-down, with no throttling below contracted bandwidth. Expensive exit egress is how lock-in is enforced in practice.
  4. Data destruction. Cryptographic erasure within 30 days of migration, certified in writing, with media-destruction attestation for bare metal.
  5. No lock-in primitives. No proprietary APIs in the delivery path, no exclusivity, and no minimum-commit clauses that outlive a failed re-audit.
  6. Audit rights. Annual re-audit access to records and facilities, for-cause audit on the trigger list, and the right to audit the provider's own supplier list.
  7. Attestation warranty. The supply-chain declaration is a continuing warranty, and the provider must notify us of any upstream change within 30 days.

Screening work is never finished, and this record will get longer rather than cleaner. If something here is out of date or you think we have got a provider wrong, tell us. We would rather correct it than defend it.

Deploy on infrastructure you can account for.

The screen exists so that "where does this actually run?" has an answer you can hand to a board.