Bias declaration up front: I'm the founder of SkyeConnex. We just shipped the four reports I'm about to describe, and I have a commercial interest in you thinking they're useful. I've tried to write this so the framework holds even if you swap our name out — but you should read it knowing I built the thing.

For a long time, "data sovereignty" has meant a PDF.

A PDF with a flag on it. A clause in a Data Processing Agreement. A regional badge on a marketing page. A footnote about "ring-fenced infrastructure" with no way to test the claim. The entire category runs on a single instruction to the buyer: trust us.

This is a strange way to handle an asset class where the failure mode is regulatory, legal, or geopolitical — three categories of risk where trust is precisely the thing you should not be paying for.

The BARC Data Sovereignty 2026 report makes a similar observation in more measured language: sovereignty claims have outpaced sovereignty proofs. The market has accepted contractual assurance as a substitute for cryptographic verification, and the gap is widening as cross-border legal pressure increases.

So instead of writing another brochure, we shipped four reports that any SkyeConnex customer can generate on demand. Each one answers a different question about their data. Each one is signed with HMAC-SHA256. Each one is verifiable by POSTing the JSON back to our endpoint — tamper with any field, the signature breaks.

Here they are, framed as the four questions the category has been avoiding.

1. Where is my data right now?

The Sovereignty Audit maps every shard of your data to a jurisdiction and a regulatory framework. Not as a forecast. Not as a target state. As of the moment you generated the report.

A sample output: 2,023 shards, 77.6% under PIPEDA (Canada), 12.5% under UK-GDPR, 9.9% under SOC2 (United States). Each provider named. Each shard count attributable. Each framework explicit. Sovereignty Integrity Score: 100%.

This is the report most "sovereign" vendors cannot produce — because their sovereignty story relies on you not asking the question with this much precision

2. What format is my data sitting in?

Sovereignty over location is necessary but insufficient. If your files are in proprietary, vendor-controlled formats, you have a different dependency — format lock-in — that survives any geographic relocation.

The Storage Standards report scores your file portfolio against open standards (ISO/IEC, W3C, IETF, OASIS) versus vendor-controlled formats. It names the format-controlling vendors. It ranks them by share. It runs a Herfindahl-Hirschman Index on format concentration, because that's actually the correct measure.

It also tells you something most enterprises will not want to hear: the typical enterprise format mix is roughly 30% open. The bar, again, is on the floor. A 94% open posture is achievable, and the report shows you exactly which files are pulling the number down.

3. What happens if a jurisdiction cuts me off tomorrow?

This is the report no one else in the category will run, because no one else can.

The Threat Simulator lets you select a set of jurisdictions, simulate them blocking access today, and compute a per-file recoverability outcome. RS(5,2) erasure coding tolerates two shard losses per file; the third loss makes the file unrecoverable. The report does the math file by file.

In one test scenario — five jurisdictions blocked, including the US and UK — 151 of 151 files become unrecoverable. The Sovereignty Integrity Score drops from 100% to 0%. That is exactly the result you want to see in simulation, because it tells you where your concentration risk actually sits and what posture would survive the scenario.

Most sovereignty claims in this market would not survive being run against this report. That is the point of the report.

4. What is my financial exposure under my current posture?

The Resilience Report models exposure as V·A + ∫C(t)dt — value at risk times threat factor, plus integrated downtime cost over recovery time. It compares your actual SkyeConnex posture to a single-vendor baseline of your choosing (Dropbox, OneDrive, S3 — pick one). It quantifies the delta and projects it across a 10-year horizon.

In one customer scenario, the year-one delta is $3.06M. Across ten years, $30.7M.

You should be skeptical of single-point dollar figures in vendor reports. You should be more skeptical of vendors who refuse to produce one because their architecture cannot support the calculation.

The signature is the point

Each of these reports is signed with HMAC-SHA256. The signature covers the entire report content. Any field altered after signing — a jurisdiction, a shard count, a score — breaks verification.

A SkyeConnex customer can hand a signed sovereignty audit to a regulator, an auditor, or a board, and the regulator/auditor/board can verify it themselves. They do not need to trust SkyeConnex. They need to trust SHA-256, which has held up under more scrutiny than any DPA ever written.

The reports are not the product. The product is the architecture that makes the reports computable. The reports are what verifiable sovereignty looks like when you actually have the architecture under it.

What this changes

If you accept the framing — that sovereignty should be auditable rather than contractual — most of the data sovereignty market is mispriced. Vendors who cannot produce a per-shard jurisdictional map, a format-openness score, a jurisdictional blockade simulation, and a signed exposure model are selling something other than sovereignty. They are selling reassurance.

Reassurance is a fine product. It just shouldn't cost the same as proof.

The BARC Data Sovereignty 2026 report is the most rigorous independent assessment of the category to date.

Data Sovereignty 2026: Reality, Relevance, Roadmap


Originally published by Ross Norrie, founder of SkyeConnex, on LinkedIn.

Published May 12, 2026 · More from the SkyeConnex blog