A Warrant Doesn't Need a Visa
Pillar 02 · Legal
A Warrant Doesn't Need a Visa
BBD published a data sovereignty primer this week. It defines residency, sovereignty and localisation correctly, which in this industry puts it in roughly the top decile of things written about data sovereignty. It names the right risks. The taxonomy is genuinely sound.
Then it reaches the part where you're supposed to do something, and the wheels come off. Quietly. With excellent alignment to industry best practice.
The piece lists foreign-jurisdiction compelled disclosure as a risk: governments can legally order a provider to hand over data.
Correct.
Then, a few lines later, it prescribes the cure. Region-specific deployments. Customer-managed keys. Zero-trust access.
None of those survive the risk it just named.
Geography is not jurisdiction
Region-specific deployment answers the wrong question.
Where the bytes sit is a residency fact.
Who can compel them is a sovereignty fact.
The article's own definitions make this distinction, two paragraphs before forgetting it.
The CLOUD Act reaches data held by a US-controlled provider regardless of where it is stored. Your data in Frankfurt is not beyond a US warrant because it is in Frankfurt. Warrants are not deterred by scenery. FISA 702 does not check postal codes either. Moving the disk to a compliant region relocates the problem, at considerable expense, to somewhere with better data centre certifications and identical legal exposure.
"Customer-managed" is doing a lot of work in that sentence
Encrypt everything, the piece says. At rest, in transit, in use, with customer-managed keys. Fine words. Let's look at what's under them.
In most hyperscaler configurations, "customer-managed" means the customer selects the key while the provider operates the HSM that holds it.
Managed by you.
Held by them.
This is the cryptographic equivalent of owning a safe that lives in someone else's house, to which they retain a key, and which they are legally required to open when asked nicely by their government. But the safe has your name on it, which is lovely.
A key the provider can be compelled to use does nothing to protect you from the provider being compelled. And "in use" is where the quiet part lives: plaintext still materialises in memory during processing, inside infrastructure the provider operates. Every architecture that leaves plaintext reachable by the custodian has simply chosen not to look at that part. A remarkable share of the sovereignty industry runs on choosing not to look at that part.
What actually survives a subpoena
A subpoena is answered by whoever holds a reconstructable copy.
So the mechanism is straightforward, if inconvenient:
Arrange for that person not to exist.
The provider never sees plaintext and never sees keys. Zero-knowledge, without the asterisk that usually comes with zero-trust. The data is erasure-coded into shards distributed across jurisdictions such that no single custodian, and no single legal order, can compel reconstruction. Compliance stops being a property of the data centre's address and becomes a property of the data structure itself.
Under that arrangement the compelled-disclosure risk doesn't get mitigated. It gets answered honestly: we cannot produce it, because no one party can. That is a sentence a lawyer can defend. "It's encrypted with customer-managed keys" is a sentence a prosecutor frames and hangs on the wall.
Don't take the region's word for it. Run the stopwatch.
There's also a way to test the article's favourite remedy, and nobody uses it. I made this argument at length in The Speed of Light Doesn't Sign NDAs, so the short version: latency is more than a user-experience number. It is a physical measurement of where your data actually is, taken by an instrument that has never once been influenced by a marketing department.
Light in fibre moves at roughly 200,000 km/s, about one millisecond of round trip per 100 kilometres, before a single router gets involved. That floor is not a setting. So if a probe in Johannesburg gets a 5ms response to data that is contractually resident in Frankfurt, the contract is wrong. A copy is in Johannesburg. The speed of light was not consulted on the residency addendum.
The asymmetry is the useful part:
Low latency proves proximity.
A fast response is physical evidence that a copy sits near the measurement. Which means every provider promising local residency and global performance is promising two things physics won't let coexist, unless a copy quietly lives near every fast user. The performance you were sold is the evidence the residency you were sold is leaking. Region-specific deployment fails against compelled disclosure, and on top of that it's frequently untrue in the plain factual sense. You can check from your desk with a tool that ships free with every operating system since 1983.
But doesn't sharding across jurisdictions destroy performance?
The obvious objection is the same physics pointed the other way:
Spread the data across borders and every read pays a distance tax.
It would, if placement and reconstruction were the same decision. They aren't. They answer to different masters, and the masters don't attend the same meetings.
Placement is governed by policy:
Jurisdiction, classification, accreditation. Never latency.
Reconstruction is governed by physics. With erasure coding you need only a subset of shards to rebuild, so every read is a race. The fastest-responding policy-eligible nodes win, and a slow or dead node gets skipped rather than waited for, like a group project.
Sovereignty decides where shards may live.
The speed of light decides which of them answer first.
The apparent trade-off between sovereignty and performance is an artifact of architectures that made one decision where there should have been two.
Keep the hyperscalers. Just demote them.
None of this is an argument for abandoning hyperscale infrastructure. That would be trading one problem for a worse one. The hyperscalers have spent two decades and several hundred billion dollars building the best storage substrate on earth: global footprint, eleven-nines durability, elastic scale, uptime your own data centre will never match no matter how much you love it. Walking away from all that to run sovereign tin in a basement gets you a maintenance contract and a martyr complex, and your data still isn't safe.
The move is subtler. Use them, but demote them. When data is client-side encrypted and erasure-coded into shards before it ever leaves your control, each hyperscaler becomes a dumb, interchangeable shard bucket. It contributes availability zones, replication, and global reach. It reads nothing. Its geographic spread stops being a jurisdictional liability and becomes a performance fabric, with shards geocached near where reads happen, reconstruction racing the fastest eligible nodes, and an entire slow region failed past without anyone noticing. Its redundancy finally starts protecting you rather than its own SLA. Lose a whole provider to an outage, an acquisition, or a court order, and the erasure coding rebuilds from the survivors while the lawyers are still finding the meeting room.
You inherit everything the hyperscalers are genuinely good at, scale and uptime and proximity, while the one thing they can be compelled to produce, reconstructable plaintext, never exists on their side of the wire. The subpoena arrives at a warehouse of ciphertext fragments that assemble into precisely nothing. The hyperscaler keeps its revenue. It just loses its leverage. Everyone stays friends, in the way you stay friends with someone once they can no longer testify against you.
The African fragmentation is an argument for this, not against it
The piece is right that Africa's landscape is fragmented. Thirty-five-plus regimes, each with its own residency and transfer rules, no unifying adequacy layer. It frames this as a burden, and it is one.
But you cannot paper thirty-five adequacy assessments and keep them current. That's not a compliance program. That's a subscription to full employment for lawyers. You can, however, build so the question never arises, with sovereignty enforced by cryptography and shard distribution rather than by negotiating a fresh treaty with every border your data crosses. Fragmentation makes the geographic approach unscalable, which makes it a reason to stop leading with geography rather than a reason to buy more of it.
And a note on the European end of this
The article leans on the EU regime as the mature benchmark. Fair enough. But the transatlantic half of it, the Data Privacy Framework adequacy that lets EU data touch US providers at all, rests on the independence of US oversight bodies.
That independence just got structurally weaker.
On 29 June the US Supreme Court overruled Humphrey's Executor in Trump v. Slaughter, weakening for-cause removal protections for the heads of independent agencies. The DPF's adequacy assumed those bodies were insulated from the executive. That assumption is now a live question, which is a polite way of saying it's on fire.
Which is the whole point. If your compliance posture depends on the continued good behaviour of a foreign executive branch, you don't have a sovereignty architecture. You have a subscription to someone else's politics, and the renewal terms are not in your favour.
Residency is table stakes.
Sovereignty is a design decision.
Most cloud architectures decline to make it, and the certifications look great.
https://techcentral.co.za/the-data-sovereignty-rules-african-and-eu-firms-cant-ignore/283328/
Bias declaration: I run SkyeConnex, which builds Raidr.cloud, a zero-knowledge, erasure-coded, multi-jurisdictional sharding architecture. I have a direct commercial interest in every argument above, which you should weigh accordingly. Then check the mechanism yourself. The mechanism is the part that doesn't care who's making the claim.
More from the blog
CBC and CTV Say Canada's Cloud Market Is "Broken." They're Half Right.
A Better Question Doesn't Survive a Subpoena
Bergson Lopes Rego published a piece in CDO Magazine called "The Data Sovereignty Illusion." Read it. The diagnosis is…
Read → Commentary · 5 min readHave You Ever Wondered Where Your Data Goes in the Cloud?
You upload the quarterly numbers. A little spinner turns. "Saved to the cloud." Reassuring phrase, the cloud. Sounds…
Read → Regulation · 3 min readThe Kill Switch Has a Loyalty Program - Microsoft is in the Trump trap
Three weeks before Brad Smith promised Europe that Microsoft would protect it from Washington, Microsoft had already…
Read →