Threat · 4 min read

Storm-2949 Didn't Break In. They Logged In.

Microsoft's threat intelligence team published a 20-minute read on May 18 about a threat actor called Storm-2949. It's worth your time. Not…

2026-06-11 Read
Threat · 2 min read

The Watermark Said "Do Not Duplicate." It Duplicated.

Sony's second trailer for Spider-Man: Brand New Day leaked this week, days ahead of its June 17 debut. Every frame carried a big red X and a…

2026-06-11 Read
Commentary · 6 min read

Canada's Sovereignty Posture vs. Reality

Canada spent the week announcing sovereignty. It spent the decade buying the opposite. The gap is sitting in your inbox, unread.

2026-06-05 Read
Commentary · 5 min read

Sovereign Compute, Borrowed Data

Canada released its national AI strategy last week. AI for All. Six pillars, nearly $200 billion in projected productivity, up to 250,000 new…

2026-06-05 Read
Commentary · 3 min read

CBC and CTV Say Canada's Cloud Market Is "Broken." They're Half Right.

Bias Declaration: I founded SkyeConnex, a Canadian data-sovereignty company. I compete directly with the providers this piece concerns, and I…

2026-06-02 Read
Threat · 2 min read

A Better Question Doesn't Survive a Subpoena

Bergson Lopes Rego published a piece in CDO Magazine called "The Data Sovereignty Illusion." Read it. The diagnosis is correct, which makes it…

2026-06-01 Read
Commentary · 5 min read

Have You Ever Wondered Where Your Data Goes in the Cloud?

You upload the quarterly numbers. A little spinner turns. "Saved to the cloud." Reassuring phrase, the cloud. Sounds like the sky. Soft…

2026-06-01 Read
Regulation · 3 min read

The Kill Switch Has a Loyalty Program - Microsoft is in the Trump trap

Three weeks before Brad Smith promised Europe that Microsoft would protect it from Washington, Microsoft had already locked the Chief Prosecutor…

2026-06-01 Read
Regulation · 6 min read

Europe Built a €180M Sovereign Cloud. It Runs on Google. — June 3 it's law

The EU's Tech Sovereignty Package arrives June 3. Probably. It was due in March, then April, then late May, and has now been rescheduled more…

2026-05-30 Read
Commentary · 4 min read

Your Grocery Bill Now Comes With a Browser History

There was a time when shopping was simple.

2026-05-28 Read
Architecture · 2 min read

SkyeConnex - SkyeBucket (S4)

Every sovereign cloud pitch eventually asks you to do the same thing: rip out your stack and adopt theirs.

2026-05-25 Read
Commentary · 2 min read

89% Say Sovereignty Matters. 10% Paid For It.

BARC's Data Sovereignty 2026 is out. The headline: 89% of organizations rate data sovereignty as important. 51% say "very important." Only 2%…

2026-05-24 Read
Architecture · 2 min read

Canada Needs a Sovereign Dependency Test, Because “Trust Us” Is Not an Architecture

Canada has become very good at buying platforms from other countries and then convincing ourselves we are in control because the invoice has a…

2026-05-20 Read
Threat · 4 min read

Germany, Palantir, and the Moment “Very Impressive” Still Means “No”

Palantir just ran into a very German problem.

2026-05-20 Read
Commentary · 3 min read

Sovereignty Is Not a Postal Code - CTV News

CTV ran a piece this week about Canadian companies building data sovereignty. The reporting is solid and the people quoted are right about the…

2026-05-20 Read
Commentary · 4 min read

Reassurance Is a Fine Product. It Shouldn't Cost the Same as Proof

Four Questions Every Data Sovereignty Vendor Should Answer (And Sign)

2026-05-12 Read
Commentary · 4 min read

Data Sovereignty 2026: Reality, Relevance, and the Bit Where You Find a Budget

BARC just published their second annual Data Sovereignty survey. 320 enterprises across Europe, North America, and the rest of the world. Two…

2026-05-06 Read
Regulation · 2 min read

Europe Has the Cards. It Has Always Had the Cards.

There is a Thierry Breton op-ed about European digital sovereignty roughly every eighteen months. The metaphor changes — wallets, pillars, now…

2026-05-05 Read
Commentary · 4 min read

Sovereignty is not a configuration option

A new paper in Media, Culture & Society makes a clean argument: Microsoft, AWS, and Google have rebranded themselves as stewards of digital…

2026-05-04 Read
Commentary · 2 min read

Telegram Drive: The Market Just Winked at SkyeConnex

Every once in a while, something appears on GitHub that makes you laugh and then quietly say:

2026-04-29 Read
Architecture · 7 min read

The Next Cloud Pivot: Decoupling Storage From Elasticity and Collaboration

For fifteen years, cloud strategy has been sold as a package deal.

2026-04-27 Read
Commentary · 2 min read

Canada Brought a Lumberjack to an API Fight

On Ottawa's sovereignty-shaped blind spot, and why the architecture has to do the job the treaty won't.

2026-04-24 Read
Threat · 2 min read

Canada Life breach was not the surprise. The architecture was.

There is something almost touching about how predictably these breach stories arrive now.

2026-04-23 Read
Threat · 3 min read

Your healthcare data breach is not over when the letter arrives. That is when the damage gets personal.

I do not need a white paper to explain what happens when sensitive information ends up in the wrong hands.

2026-04-20 Read
Commentary · 2 min read

Digital sovereignty, now available from the same people you were trying to be sovereign from. Act now and we’ll throw in a free maple leaf meme coin.

Microsoft’s Digital Sovereignty Summit was a nice reminder that the market is finally catching up to what should have been obvious a while ago:

2026-04-18 Read
Commentary · 4 min read

“Stored in Canada” is not a guarantee of sovereignty. It’s a Jedi mind trick.

Canada is finally starting to have the right conversation about data sovereignty.

2026-04-15 Read
Threat · 3 min read

Free cloud drives. Free email. One subpoena. Fun math.

Most people still think the biggest problem with free cloud storage is advertising. As if the real threat is Google scanning your spreadsheet…

2026-04-12 Read
Commentary · 4 min read

Canada keeps talking about sovereignty like it’s a set of hockey cards

Canada has developed a very modern habit. We take an important word, stretch it until it covers everything, and then act surprised when it stops…

2026-04-11 Read
Commentary · 3 min read

Canada’s digital sovereignty push is making the U.S. uncomfortable. Funny how that happens when leverage starts slipping.

The Globe and Mail piece gets at something important: the moment Canada starts treating digital sovereignty like an actual policy objective…

2026-04-09 Read
Regulation · 4 min read

Sovereign cloud: same dependency, different accent, premium price

There is a pattern in the data sovereignty market that deserves a name.

2026-04-09 Read
Regulation · 4 min read

SkyeConnex: Data Sovereignty as a Service for Europe

When no single provider holds the whole file, no single provider holds the power. For Europe’s sovereignty test — from AI architecture to cloud…

2026-03-31 Read
Regulation · 4 min read

Europe Is Not Building Another Office Suite. It Is Building an Exit Strategy. SkyeConnex Just Happens to Offer One.

Europe's new EuroOffice initiative is being described as a software story.

2026-03-30 Read
Commentary · 3 min read

When Microsoft can switch you off, this is no longer a software story. It is a sovereignty story.

Reuters reported that Nayara Energy, an Indian refiner sanctioned by the EU, has taken Microsoft to court after what it says was the abrupt…

2026-03-30 Read
Commentary · 2 min read

The Cloud Does Not Need a Divorce. It Needs Boundaries.

There's a peculiar habit in cloud strategy discussions where every decision collapses into one of two options.

2026-03-26 Read
Commentary · 2 min read

Can Canada ever have true digital sovereignty?

By now, Canada has had enough discussions about digital sovereignty to build a very impressive stack of panels, roundtables, and policy decks…

2026-03-25 Read
Regulation · 2 min read

Europe Isn’t Banning Microsoft. It’s Finally Asking the Right Question.

A German state is moving off Microsoft Teams, Office, and eventually Windows.

2026-03-24 Read
Commentary · 2 min read

Useful Until It Isn’t

Everyone wants utility.

2026-03-22 Read
Commentary · 2 min read

Data governance isn't failing because it's too slow. It's failing because we keep building the roof before the foundation.

Every few years, the data industry discovers the same problem wearing a new outfit.

2026-03-19 Read
Commentary · 2 min read

The Government of Canada just published an AI Readiness Scorecard. Most departments should read it twice — and be honest the second time.

The Canada School of Public Service recently released a job aid to help public servants assess whether a problem is a strong candidate for an…

2026-03-19 Read
Commentary · 2 min read

"Our data never leaves the country" is a great start and a terrible finish.

Every enterprise tech vendor has a sovereignty story now. It usually involves a slide with a map of Canada, some flags, and the phrase "your…

2026-03-18 Read
Commentary · 2 min read

Sovereignty Is the Wrong Word. Here Is the Right One.

John Miedema wrote something worth reading this week.

2026-03-16 Read
Commentary · 3 min read

Data Sovereignty as a Service Doesn't Exist. Except It Does.

Wikipedia has a definition for data sovereignty.

2026-03-15 Read
Commentary · 2 min read

Indigenous Communities Got Data Sovereignty Right. The Cloud Industry Got a Logo.

They did not have a booth. They did not have a lanyard. They were not handing out branded socks or explaining their platform's compliance…

2026-03-15 Read
Commentary · 5 min read

A Flag on the Rack Does Not Change Who Holds the Power

My perspective comes from both sides: I founded AssetMetrix, an early SaaS company that became part of the foundation of Microsoft’s management…

2026-03-09 Read
Commentary · 4 min read

Canada Is Still Asking the Wrong AI Question

Geoffrey Hinton’s appearance before the Senate’s Standing Committee on Social Affairs, Science and Technology should have been a prompt for a…

2026-03-08 Read
Commentary · 2 min read

“Keep It in Canada” Won’t Save You

I read Osler’s piece and had a bit of a grim chuckle—because it’s basically the same conversation I’ve heard (and lived) in the CDO world…

2026-03-03 Read
Commentary · 2 min read

What Should a CDO Office Be Doing? Use Data Sovereignty as the Lens.

Data sovereignty is the perfect way to explain what a CDO office is for —because it exposes the real issue.

2026-03-03 Read
Regulation · 8 min read

The CLOUD Act and why data residency isn't enough

The CLOUD Act extends US legal reach to data held by US-controlled cloud providers anywhere in the world. Choosing a Frankfurt or Toronto region does not change that. Here's what does.

2026-05-22 Read
Cryptography · 6 min read

Post-quantum cryptography: SkyeConnex already ships both halves

ML-KEM-1024 (FIPS 203) addresses the key-encapsulation half of post-quantum migration. ML-DSA-87 (FIPS 204) addresses the signature half. SkyeConnex ships both today, in production.

2026-04-14 Read
Architecture · 7 min read

Why multi-cloud RAID beats multi-cloud sync

Most multi-cloud storage products replicate your file inside each provider. SkyeConnex erasure-codes it across them. That distinction is the difference between provider lock-in and provider independence.

2026-03-08 Read
Regulation · 9 min read

Schrems II two years on: what actually changed for EU-US data transfers

The 2020 CJEU ruling invalidated Privacy Shield. Five years and one EU-US Data Privacy Framework later, the underlying problem remains. Here's what's changed — and what hasn't.

2026-06-04 Read
Regulation · 8 min read

What a CLOUD Act subpoena actually looks like in practice

Most board conversations about the CLOUD Act stay abstract. Here's a concrete walkthrough of how the mechanism works — and why architectural sovereignty defeats it.

2026-05-30 Read
Architecture · 10 min read

Reed-Solomon erasure coding for storage: a practical primer

Reed-Solomon codes are decades old. They're suddenly central to sovereign cloud architecture. Here's what they do, the math you need, and the engineering trade-offs.

2026-05-15 Read
Cryptography · 7 min read

Why customer-managed keys aren't zero-knowledge

Customer-managed keys (CMK) are hyperscalers' answer to the sovereignty question. They're better than provider-managed keys. They don't deliver zero-knowledge. Here's the difference.

2026-05-08 Read
AI & Sovereignty · 8 min read

Sovereign AI: running RAG on regulated data without OpenAI exposure

Retrieval-augmented generation over regulated documents is a board-level win — if you can do it without sending those documents to OpenAI or Azure OpenAI. Here's how the architecture should work.

2026-04-30 Read
Cryptography · 7 min read

FIPS 203 and FIPS 204 explained: what NIST's PQ standards mean for procurement

NIST finalised both post-quantum standards in August 2024. ML-KEM-1024 (FIPS 203) and ML-DSA-87 (FIPS 204). Here's what procurement teams should now demand from cloud vendors.

2026-04-21 Read
Regulation · 8 min read

Bill C-26 explained: what Canadian critical infrastructure needs to know

Canada's Bill C-26 — the Critical Cyber Systems Protection Act — quietly reshapes obligations for designated operators. Here's what changes for cloud storage.

2026-04-12 Read
Procurement · 10 min read

How to evaluate a sovereign cloud vendor: a 12-point checklist

Most sovereign cloud claims don't survive technical scrutiny. Here's the checklist procurement teams should use — and what good answers look like.

2026-04-02 Read
Threat · 8 min read

Ransomware in 2026: why your backup target is the new attack surface

The 2020s ransomware playbook shifted when crews started encrypting backup targets. Your recovery story dies the moment your backup destination is compromised. Here's the architectural fix.

2026-03-25 Read
Cryptography · 7 min read

Quantum 'harvest now, decrypt later': the timeline that actually matters

'We'll worry about quantum when it happens' is the wrong frame. Adversaries are harvesting encrypted traffic today, betting on decryption tomorrow. Here's the timeline that matters.

2026-03-18 Read
Regulation · Canada · 7 min read

PIPEDA and cloud storage: what most providers get wrong

PIPEDA predates the cloud. Applying it to multi-cloud workloads requires architectural thinking that most providers don't do. Here's the gap, and how to close it.

2026-03-10 Read
Industry · Healthcare · 9 min read

Healthcare data residency: PIPEDA + HIPAA + provincial — a survival guide

Healthcare data in 2026 must satisfy PIPEDA, HIPAA, provincial health acts, and emerging AI compliance — often simultaneously. The architectural answer compounds across all four.

2026-02-28 Read
Regulation · 6 min read

Why 'Canadian-flag cloud' is not Canadian sovereignty

A US-headquartered hyperscaler with a Canadian holding company is still subject to US legal process. Sovereignty by corporate paperwork is flag-washing — and buyers know it.

2026-02-19 Read
Practical · 10 min read

Migrating from hyperscaler to sovereign storage: the runbook

Most 'we should be sovereign' conversations stall at 'where do we start?' Here's the practical runbook from audit to pilot to expansion to decommission.

2026-02-09 Read
Threat · 7 min read

Insider threat in cloud storage: the trust topology problem

Most insider-threat discussions focus on customer-side admin compromise. The provider-side question — what your cloud's own admins can see — matters more, and is rarely addressed.

2026-01-29 Read

Want the whitepaper next?

The v1.2 SkyeConnex whitepaper is the consolidated technical and commercial reference. 36 pages. NDA-distributed.