Data Sovereignty Is Five Questions. Your Vendor Brought a Map.
Pillar 03 · Residency
Ask a cloud provider what data sovereignty means and you will get an answer about geography. The data is here. In this country, in this region, behind this flag. There will be a map. There is always a map. Sometimes the map has a maple leaf on it, at which point the sales cycle is considered complete.
The map answers one question. Sovereignty is five.
The industry has a name for selling you the map and calling it the territory. I've been using two. Flag-washing, when the pitch is a domestic logo over foreign exposure. Sovereignty theatre, when the pitch is a compliance ritual over an unchanged threat model. Both are thriving product categories with excellent margins. Neither is sovereignty.
Data sovereignty, as we define it at SkyeConnex, is what survives five distinct failure modes. Each one is a question an adversary will eventually ask of your data: a hacker, a court, a regulator, a vendor, a rival. If your architecture doesn't have an answer built in, your contract is the answer. And contracts are a genre of fiction adversaries don't read. They don't even skim.
01 — The Hacker. What do they get?
The first question is the oldest. Someone gets in. Into your provider, or into you. What do they walk out with?
The honest answer, for nearly every architecture on the market, is everything they can reach. Encryption at rest helps until the keys live next to the data, which they usually do, because that's convenient, and convenience is undefeated.
Our answer: fragments, not files. Data is erasure-coded into shards below the reconstruction threshold, encrypted per file, named opaquely, keyed in a hierarchy we cannot see into. A breach of any provider, or of SkyeConnex itself, yields fragments that reconstruct into nothing. Not "encrypted data we hope stays encrypted." Nothing. The attackers still get to write a press release. It's just a press release about confetti.
This also disposes of the industry's other favourite disease: shadow data. The copies, snapshots, exports, and forgotten buckets that an entire product category now exists to hunt for. Shadow data is a symptom of possession-based storage. You can only mislay a copy of something that exists whole somewhere. When no whole object exists anywhere, there is nothing to copy, nothing to export, nothing to forget in a bucket named temp-final-v2-DO-NOT-DELETE. The DSPM vendors sell you an annual subscription to a flashlight, so you can discover where your storage architecture failed you this quarter, tidy up, and book the same discovery for next quarter. That's a gym membership. We removed the failure mode instead.
The breach question also has a time dimension nobody prices in. "What does a hacker get" really means "what does a hacker get eventually," because the patient ones are harvesting ciphertext today to decrypt when a cryptographically relevant quantum computer arrives. Your current encryption is a promise about your adversary's current hardware, which is a strange thing to bet a decade of secrets on. Ours is ML-KEM-1024 and ML-DSA-87, the post-quantum standards, in production. What gets harvested today is fragments, below threshold, under encryption designed for the computer that doesn't exist yet. Steal it now, decrypt it never. Enjoy the storage costs.
02 — The Court. What does a subpoena get?
The second question is the one the map was supposed to answer, and doesn't. Data residency tells you which country's courts have the easiest claim on your data. It says nothing about which countries have a claim. The CLOUD Act does not care where the server is. It cares who operates it. A warrant doesn't need a visa, and it has never once been stopped at customs.
Our answer: one order is incomplete. Shards are spread across a customer-selected mix of jurisdictions, five-of-seven threshold, held as objects no single provider can link to each other or to you. Compelled disclosure against any one jurisdiction retrieves less than threshold from objects it cannot correlate. The subpoena executes flawlessly. Everyone complies. The paperwork is immaculate. The yield is confetti. Somewhere a very expensive lawyer bills eleven hours explaining why.
This is the difference between sovereignty by promise and sovereignty by architecture. A promise is a legal posture that holds until a bigger legal posture arrives, and there is always a bigger legal posture. An architecture doesn't have a posture. It has math.
03 — The Regulator. Can you prove where it is, right now?
Residency still matters, as the third question rather than the whole exam. And it matters in a form the industry doesn't sell: proof.
The standard product is an annual attestation about a data centre. A PDF, dated last fiscal year, about a building. Your data has moved eleven times since breakfast. The PDF has not.
Our answer: shard-level proof, live. Every shard's location, demonstrated on demand instead of asserted annually. Sovereignty scoring, signed reports, deletion certificates, custody timelines. The mechanism underneath is the inversion of shadow data. Every object in custody casts exactly one shadow, engineered on purpose: a Merkle-anchored, post-quantum-signed fingerprint recording every custody event. The shadow proves existence, location, lineage, integrity, and policy state without exposing a byte of content. Auditors query shadows. Regulators receive shadows. The substance stays fragmented and dark while the shadow does all the talking. You get to demonstrate control over data you provably cannot read, the sentence every compliance officer has been waiting their whole career to say out loud, ideally to a regulator, slowly.
And here's the part I enjoy. You can audit anyone's residency claim yourself, from your desk, with a stopwatch. Light in fibre covers about 100 kilometres per millisecond of round trip, and that number is not negotiable, because physics doesn't take meetings. If data contractually resident in Frankfurt answers a Johannesburg probe in 5ms, the contract is wrong and a copy is local. The speed of light was not consulted on the residency addendum. It never is. It keeps testifying anyway.
04 — The Vendor. What does leaving cost?
Nobody asks the fourth question at signing, because at signing everyone is in love. What does it cost to leave?
If any provider holds your data whole, the answer is whatever they decide it costs, at the exact moment you have the least leverage. Egress fees are not a pricing model. They are a hostage negotiation with a rate card, and you'll notice the hostage paid for the room.
Our answer: providers become components. When no provider holds anything whole, no provider holds anything over you. Any one of them swaps out without a migration project, because there is nothing whole to migrate, just fragments to re-place. The S3-compatible gateway on top means your tooling doesn't know or care which components sit underneath. Providers compete for your shards the way disks compete for your RAID array. Which is to say: silently, replaceably, and without a customer success manager.
This is what failure looks like under the model, and it's boring, which is the point. A provider goes down, gets acquired, cuts you off, or discovers a sudden enthusiasm for raising prices? The erasure coding rebuilds that provider's portion from the surviving shards and reconstitutes it onto a replacement. Different provider, different jurisdiction, whatever policy prefers. No outage on your side, no migration project, no farewell call where everyone promises to stay in touch. The provider that just tripled its rates isn't a crisis. It's a failing disk. You hot-swap failing disks. You do not write them a cheque.
None of which is an argument for abandoning the hyperscalers. They spent several hundred billion dollars building the best storage substrate on earth, and walking away from that to run sovereign tin in a basement gets you a maintenance contract, a martyr complex, and a pager. Use them. Demote them. Each one becomes a dumb, interchangeable shard bucket that contributes availability zones, eleven-nines durability, and global reach, and reads nothing. Their geographic footprint stops being a jurisdictional liability and becomes a performance fabric: shards geocached near where reads actually happen, reconstruction racing the fastest policy-eligible nodes, an entire slow region failed past without anyone noticing or filing a ticket. You inherit everything they're genuinely good at. They keep their revenue. They just lose their leverage. Nobody has explained this to their sales teams, and I'd rather we didn't.
05 — The Model. Who gets the weights?
The fifth question looks different from the first four, and it should, because it isn't a new threat. It's the first four threats coming back for a second pass.
Everything your enterprise knows is now being distilled into model weights. Trained on your data, encoding your operations and your pricing logic and your customer patterns, the most concentrated asset you have ever produced, currently stored with roughly the diligence of a shared drive named models_old. Concentration cuts both ways. A breach of the weights is a breach of everything they learned. A subpoena for the model is a subpoena for its training corpus, pre-summarized for the court's convenience. Weights have residency exposure. And your AI vendor holds them with more lock-in leverage than any storage provider ever dreamed of, which is saying something, because storage providers dream big.
So the fifth pillar is the threat model applied to where your data is going. Plus one failure mode that genuinely is new: release. Data mostly needs to stay put. Models need to deploy, to inference hardware, to partners, to the edge, and every deployment is a custody handoff. Today most of those handoffs are governed by nothing sturdier than an admin having a good week.
Our answer: keys release by ceremony. Model IP and enterprise intelligence are custody objects with the same four guarantees as everything above. Fragmented, unlinkable, provably placed, provider-independent, and released only under verifiable conditions. Opaque tokens, client-side reconstruction, hardware-attested release. The weights leave custody when the ceremony completes, and not before. The admin's week is no longer load-bearing.
The question under all five: is it fast?
There's a sixth question buyers ask, and it deserves an answer even though it isn't a pillar. Doesn't all this sovereignty cost you speed?
It's the right worry pointed at the wrong architecture. The model that pays the latency tax is the naive sovereign fix: one flag, one domestic data centre, everything inside. That buys you residency at the cost of everything else. Your mission-critical data is now exactly as fast, and exactly as available, as one building. If that building is far from your users, or busy, or down, your data is sovereign the way a sealed vault is sovereign. Technically yours. Practically elsewhere. Very secure, in the way of things nobody can use.
The sharded model doesn't make that trade, because placement and reconstruction are two decisions, not one. Placement is governed by policy: jurisdiction, classification, accreditation, never latency. Reconstruction is governed by physics. You only need a subset of shards to rebuild, so every read is a race, won by the fastest-responding policy-eligible nodes, with slow or dead nodes skipped rather than waited for. Shards sit geocached near where reads happen. Sovereignty decides where they may live. The speed of light decides which of them answer first.
The sovereignty-versus-performance trade-off is an artifact of architectures that made one decision where there should have been two, not a law of nature. And for the customers whose policy layer tightens to accredited domestic or air-gapped nodes only, the same race converts into something better than speed: survivability, with reads routing around whatever the bad day took out.
One thesis under all five
Here is the through-line, and it is short enough to be a design principle rather than a slogan: nothing assembles the whole. No single cloud, country, provider, operator, or subpoena can put the complete picture together. Not because they promised not to. Because they can't. The difference between those two sentences is the entire industry.
Everything else we build, the file UX, the admin console, the billing, exists to serve those five answers. Nothing in the product introduces a sixth claim, because a sixth claim would be marketing, and the first five are load-bearing.
So the next time a vendor shows you the map, ask the other questions. Ask what a hacker gets, what a subpoena gets, what proof looks like on a Tuesday, what leaving costs. Then ask all four again about your models, because that's where your data is going and where the answers matter most. Watch how quickly the conversation returns to the map. There will be a laser pointer.
The map is one-fifth of an answer. Physics and math are the other four-fifths, and neither of them signs NDAs.
Bias declaration: I run SkyeConnex, which builds Raidr.cloud, a zero-knowledge, erasure-coded, multi-jurisdictional custody architecture. I have a direct commercial interest in every argument above. Read it as such, and check the mechanisms yourself. The mechanisms are the part that doesn't care who's making the claim.
More from the blog
CBC and CTV Say Canada's Cloud Market Is "Broken." They're Half Right.
A Better Question Doesn't Survive a Subpoena
Bergson Lopes Rego published a piece in CDO Magazine called "The Data Sovereignty Illusion." Read it. The diagnosis is…
Read → Commentary · 5 min readHave You Ever Wondered Where Your Data Goes in the Cloud?
You upload the quarterly numbers. A little spinner turns. "Saved to the cloud." Reassuring phrase, the cloud. Sounds…
Read → Regulation · 3 min readThe Kill Switch Has a Loyalty Program - Microsoft is in the Trump trap
Three weeks before Brad Smith promised Europe that Microsoft would protect it from Washington, Microsoft had already…
Read →