Evolix

France · www.evolix.com · 4 vendors

Evolix is a company specializing in hosting and outsourcing Open Source infrastructures based on dedicated servers under Linux and BSD. They provide IT managed services and support, including cloud services and DevOps expertise, with offices in Marseille, Paris, and Montreal.

Resilience scores

Technology vendors

Services catalogue

5 services in catalogue across 2 categories; runs on 4 sub-vendors.

Insights

Last updated 2026-08-11 · revision 1

4 direct vendors, 43 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Evolix exhibits very high migration readiness, driven by its deep expertise in modern, portable technologies and its internal service offerings. The company's tech stack is heavily based on open-source software (Linux, KVM, Docker, LXC, Ansible, various databases), which inherently reduces proprietary vendor lock-in and facilitates portability to diverse cloud environments. Evolix's proficiency in virtualization (KVM) and containerization (LXC, Docker) is a significant advantage, as these are foundational for cloud-native architectures. The use of Ansible for automation is crucial for efficient and repeatable infrastructure deployments during migration. Furthermore, Evolix's own offerings of Private & Public Cloud solutions, coupled with its IT Consulting, infrastructure audit, architecture recommendations, and migration planning services, demonstrate strong internal capabilities and a strategic focus on cloud adoption and migration. They also provide technical training on key migration technologies. While specific data residency requirements, regulatory environment details, and financial stability information are not provided, which could introduce unforeseen complexities, Evolix's technical foundation and service portfolio position it exceptionally well for migration.

Compliance

7 in-scope frameworks identified; showing 3.

SOC 2 (source) — Assessment Required

SOC 2 is an AICPA framework for service organizations (particularly cloud and technology providers) that store, process, or transmit customer data. Evolix is a cloud and managed hosting provider — exactly the type of organization for which SOC 2 is designed. While SOC 2 is not legally mandated, it is increasingly required by enterprise customers as a contractual prerequisite, particularly for US-facing clients. Evolix has a Montréal office serving Canadian/North American clients, increasing the likelihood that SOC 2 may be commercially required. Risk is Medium because: (1) without SOC 2, Evolix may lose enterprise customers who require it; (2) the absence of SOC 2 may indicate gaps in security controls documentation; (3) however, as a small French company (~20 employees), SOC 2 is not legally mandated and many European SMEs rely on ISO 27001 instead. No SOC 2 report or certification was found publicly.

Evidence: https://evolix.com/hebergement.html, https://evolix.com/infogerance.html, https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services

NIS2 (source) — Assessment Required

NIS2 (EU Directive 2022/2555, transposed into French law) is highly likely to apply to Evolix as a digital infrastructure and ICT service provider operating in France. Evolix provides managed hosting, cloud computing, dedicated server infrastructure, and SaaS services — activities that fall under NIS2's 'digital infrastructure' and 'managed service providers' (MSP) categories, which are classified as Important Entities or potentially Essential Entities. The size threshold for NIS2 is medium enterprises (50+ employees OR €10M+ annual turnover). Evolix has ~20 employees and ~€1.365M revenue (2020), which is below both thresholds, potentially exempting them from NIS2 as a small enterprise. However, France may apply NIS2 to smaller digital infrastructure providers at national discretion, and Evolix's role as a critical infrastructure operator (RIPE NCC member, AS197696, ARCEP licence L33.1) may trigger specific national obligations. Risk is Medium because: (1) if size thresholds are not met, NIS2 may not formally apply, but (2) as a network operator with ARCEP licence, French national cybersecurity obligations (ANSSI) may still apply independently. The risk of non-compliance if NIS2 does apply is significant given ANSSI enforcement powers. Missing information: Exact current employee count and revenue needed to confirm size threshold; French NIS2 transposition specifics for small digital operators.

Evidence: https://evolix.com/presentation.html, https://www.legifrance.gouv.fr/jorf/id/JORFTEXT000047866733, https://www.anssi.gouv.fr/fr/actualites/nis-2-la-directive-europeenne-sur-la-cybersecurite, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.arcep.fr/

GDPR (source) — Partially Compliant

Evolix is a French company headquartered in Marseille, EU, making GDPR universally applicable. As a managed hosting and cloud services provider, Evolix processes personal data both as a Data Controller (employee data, customer contact data, billing data) and as a Data Processor (sub-processor for customer-hosted data). Their CGV was updated in November 2018 to include GDPR compliance provisions and a data processing annex (Article 13 and a dedicated personal data annex), demonstrating proactive compliance steps. However, no independent GDPR audit, DPO appointment disclosure, or CNIL registration evidence was found publicly. Risk is Medium rather than High because they have taken documented compliance steps (contractual DPA provisions), operate in a well-regulated French environment with CNIL oversight, and are a relatively small company (~20 employees, ~€1.365M revenue). The risk of a major enforcement action is moderate given their size, but non-compliance with processor obligations (Art. 28 GDPR) could expose both Evolix and their clients to regulatory action. Missing information: No public DPO appointment, no CNIL audit record found, no Records of Processing Activities (RoPA) publicly disclosed.

Evidence: https://evolix.com/conditions-generales.html, https://evolix.com/cgvs/conditions-generales-de-vente-et-service-evolix.pdf, https://www.cnil.fr/fr/rgpd-de-quoi-parle-t-on, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679

Financials

Three-year financials

Financial Resilience Score: 6/10

Evolix is a small, long-established French SARL with a deliberately conservative, self-financed growth model. The company has operated continuously since 2004, growing from €50K in first-year revenue to €1.365M by 2020, with headcount expanding from 2 to approximately 20 employees. Its recurring revenue model based on multi-year managed hosting and infogérance contracts provides good cash flow visibility, and its status as a declared network operator (RIPE AS 197696, ARCEP L33.1) offers technical differentiation versus resellers. However, its small absolute size (~€1.4M revenue, ~20 FTEs) provides limited buffer against loss of key customers or technical staff. The company faces significant competitive pressure from hyperscalers (AWS, GCP, Azure) and larger French managed-hosting players (OVHcloud, Scaleway, Ikoula, Claranet), as well as datacenter operating cost inflation (electricity/cooling) that weighed on the sector in 2022-2024. Limited public financial transparency—likely due to the confidentiality option available to small French SARLs—makes external assessment of liquidity, margins, and leverage difficult. Overall, the company appears financially stable but constrained by its niche positioning and small scale.

Key strengths: Explicit conservative growth model with no venture funding, Recurring revenue base from multi-year managed hosting contracts, 20+ year continuous operating track record, Owned network/operator status (AS 197696, ARCEP L33.1), Diversified customer base of 100+ clients, Multi-site resilience across Marseille, Paris, and Montréal

Risk factors: Small absolute size (~€1.4M revenue, ~20 FTEs) limits buffer against customer/staff loss, Competitive pressure from hyperscalers and larger French hosting players, Datacenter operating cost inflation (electricity/cooling) in 2022-2024, Concentration on Debian/Linux niche narrows addressable market, Limited public financial transparency due to SME confidentiality filing option

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report