That's No Moon. That's a Compliance Framework.
Pillar 02 · Legal
We've spent the last three years arguing about where data lives. The CLOUD Act, Bill C-26, DGSI 100-8, the endless debate over whether a hyperscaler's Canadian region is actually Canadian. Important arguments. I've made most of them myself.
But there's a version of the sovereignty question that residency can't answer, and it happens to be the version that matters most to the people whose job is National Defence.
Ask a defence planner what they need from data and you won't hear "jurisdiction." You'll hear four things: it has to arrive in time, it has to survive attack, it has to be provably untampered, and it has to be shared with allies without being surrendered to them.
Latency. Resilience. Integrity. Disclosure.
Now run the country-bound sovereignty model against those four requirements.
A national data enclave, however well secured, is a fixed strategic target. Concentrating the crown jewels in one heavily fortified facility doesn't protect them. It publishes the target list. We've all seen the movie where someone builds the ultimate secure installation and bets everything on it. There's always an exhaust port.
It imposes a latency penalty on exactly the users who can least afford one. A deployed task force operating on denied, disrupted, intermittent bandwidth doesn't get faster access because the authoritative copy sits in a certified facility back home. It gets a round trip.
It does nothing for integrity. Jurisdiction is a legal property, not a cryptographic one. Once an adversary is inside the enclave, the fact that Canadian law governs the building is not a control.
And it handles disclosure by promise. We share with allies by trusting their legal systems and their operational security. When one of those allies is compelled by its own courts, or a forward node is simply captured, the residency model has nothing to say.
Residency, in other words, is a compliance construct built for peacetime. It answers "whose laws apply?" It has no answer to "does the data survive contact?"
There's a different way to hold the problem. Stop treating sovereignty as a property of location and start treating it as a property of custody.
Fragment the data mathematically so that no single site holds anything usable. With threshold erasure coding, an object encrypted and split into seven fragments reconstructs from any five. Put those fragments forward: coalition nodes, tactical clouds, allied infrastructure. The edge reads from whichever fragments are nearest and alive. No round trip to a sovereign enclave, because no single location is authoritative.
Lose any two sites to a strike, a cyberattack, or a cut cable, and the data still reconstructs. Better than that: no individual site is worth striking for the data it holds. The payload is encrypted before it's ever fragmented, so every shard is a slice of ciphertext — indistinguishable from noise without the keys. A seized site yields nothing.
Bind every access and mutation to an append-only, cryptographically verifiable ledger, signed with post-quantum algorithms, so provenance is proven rather than assumed. In a targeting chain, that isn't a compliance feature. It's the difference between trusting a coordinate and being able to prove where it came from.
And make disclosure a quorum act instead of a jurisdictional promise. An allied node compelled by a foreign court can hand over everything it physically holds and yield nothing. Coalition sharing becomes cryptographic policy: grant reconstruction rights for a mission window, revoke them when it closes. You don't have to trust another country's legal system to hold. You hold the keys.
None of this makes residency irrelevant. For regulated civilian workloads, Protected B, health data, financial records, jurisdiction still matters and Canadian custody infrastructure should be the default. I've argued that position publicly and I'll keep arguing it.
But we should be honest that residency and survivability are different problems, and the second one is where the harder thinking needs to happen. A sovereignty strategy that only works when nobody is shooting at it is not a defence strategy. It's a procurement policy.
The question Canada should be asking isn't "where does the data live?" It's "does the data arrive in time, survive the fight, prove itself, and disclose only by design?"
Location can't answer that. Custody can.
And if your sovereignty strategy depends on one big, impressive, fully operational installation — that's no moon.
Ross Norrie is the founder of SkyeConnex, an Ottawa-based sovereign data infrastructure company.
More from the blog
CBC and CTV Say Canada's Cloud Market Is "Broken." They're Half Right.
A Better Question Doesn't Survive a Subpoena
Bergson Lopes Rego published a piece in CDO Magazine called "The Data Sovereignty Illusion." Read it. The diagnosis is…
Read → Commentary · 5 min readHave You Ever Wondered Where Your Data Goes in the Cloud?
You upload the quarterly numbers. A little spinner turns. "Saved to the cloud." Reassuring phrase, the cloud. Sounds…
Read → Regulation · 3 min readThe Kill Switch Has a Loyalty Program - Microsoft is in the Trump trap
Three weeks before Brad Smith promised Europe that Microsoft would protect it from Washington, Microsoft had already…
Read →