The Speed of Light Doesn't Sign NDAs
Pillar 03 · Residency
Everyone arguing about data sovereignty is arguing about law. Jurisdiction, the CLOUD Act, who can serve a warrant on whom. Worth arguing about. I've done my share.
But there's a second instrument in the room that nobody points at the problem, and it doesn't take depositions or read marketing copy. It just measures.
Latency.
We treat latency as a user-experience number. A figure on a dashboard. The thing that makes the spinner spin. It is also — and almost no one says this out loud — a physical measurement of where your data actually is, and a continuous, un-fakeable audit of whether your provider's sovereignty claims are true.
Here's the physics, because it's the whole argument. Light in optical fibre travels at roughly two-thirds of its vacuum speed — about 200,000 kilometres per second. That works out to a hard floor of roughly one millisecond of round-trip time per 100 kilometres of fibre, before you add a single switch or router. This floor is not negotiable. It is not a setting. No CDN, no TCP tuning, no vendor SLA edits the refractive index of glass.
Which means round-trip time tells you something a contract cannot: a maximum distance. If a probe in Sydney gets a 5-millisecond response to your "EU-resident" data, the data — or a copy of it — is not in Frankfurt. It is in Sydney. The speed of light says so, and the speed of light was not consulted on your data residency addendum.
Note the asymmetry, because it's the useful part. Low latency proves proximity. A fast response is physical evidence that a copy of your data sits near the thing measuring it. High latency proves nothing — slow routing is easy to produce. So latency is specifically a replication detector. It cannot tell you your data is safely far away. It can absolutely tell you a copy is somewhere it shouldn't be.
Now hold that next to the pitch every "sovereign cloud" makes: local residency and hyperscale performance and global availability. Pick two. You cannot serve a Singapore user in sub-20ms from a data centre in Frankfurt. Physics forbids it. So when a provider promises both, they are not bending physics. They are quietly keeping a copy near Singapore. The performance you were sold is the proof that the sovereignty you were sold is leaking.
This is the part no one connects. The optimisation is the breach. The CDN edge node, the read replica, the "regional cache for resiliency," the disaster-recovery copy, the support team's snapshot — every one of them is a latency win and a jurisdiction you didn't authorise. Your sovereign data has a shadow. Switching on the global accelerator for speed is the same action as distributing regulated data into N legal regimes. The dashboard celebrates it as a green number.
So the first thing latency gives you is forensic. You can audit a residency claim from the outside, with nothing but probes and a stopwatch, and the vendor cannot lie to a stopwatch. Constraint-based geolocation — triangulating physical position from round-trip times against known vantage points — has existed in the research literature for twenty years. Almost no compliance team uses it to check whether the sovereign region is actually sovereign. They read the certificate instead. The certificate is policy. The latency is physics. Audit the one that can't be edited.
Here's the second thing, and it's where the conventional wisdom has it backwards. The assumption is that sovereign distribution must cost latency — that spreading data across jurisdictions drags every read across an ocean. That's only true if you distribute the way hyperscalers replicate: whole copies, location chosen for speed, one slow reach at a time.
Separate the two decisions and the problem dissolves. Placement is one decision. Reconstruction is another. They answer to different masters.
Placement answers to policy. A policy layer decides where shards may live — by jurisdiction, residency, classification, accreditation. Not by latency. Commercial policy might permit a wide spread across many providers and regions. Defence policy might confine every shard to accredited domestic nodes, or to an air-gapped enclave with no egress at all. Either way, sovereignty is enforced here, at placement, by rule — never by whichever node happened to answer fastest.
Reconstruction answers to physics. Encode the data into n shards where any k rebuild the whole. On read, you request from the shards policy already placed and assemble from the first k to respond. A slow node isn't waited on; it drops to the back and the next in line is pulled. You need any k of n, so a laggard, a congested link, or a dead node never stalls the read. The fastest bits win the reconstruction. Policy already won the placement.
That separation is the whole trick — and it's why the sovereign-cloud trilemma was never real. Local performance and sovereignty were never in conflict. They were two different decisions everyone insisted on making at once.
It's also why one architecture serves a marketing team and a battlespace without changing shape. Change the policy, not the primitive. Loosen placement and the next-in-line race buys proximity: you ride the hyperscalers' global footprint while no single one of them holds k shards. Tighten placement to accredited nodes and the identical race buys survivability: lose up to n − k nodes to an outage, a cut cable, or an adversary, and you still reconstruct from whatever k you can still reach. In a denied or degraded network you don't need every node. You need any k you can talk to.
Same maths. Commercial spends it on speed. Defence spends it on staying alive when the network doesn't.
So: stop reading latency as a UX metric. It's a forensic instrument and an honesty check. Point it at your own provider. Measure the round-trip from three continents to the data you were promised never leaves one.
Then count how many time zones your sovereign data is actually awake in.
Bias Declaration: I run SkyeConnex. CloudRAID disperses client-side-encrypted shards by policy — jurisdiction, classification, accreditation — and reconstructs each read from the fastest k nodes to respond, promoting the next in line when one lags. The fastest bits win the read; policy wins the placement; no single provider ever holds enough to be worth a warrant. I have a commercial stake in you measuring latency honestly. So measure mine too. The physics is identical on both sides of the pitch — which is the entire reason to trust physics over pitches.
More from the blog
CBC and CTV Say Canada's Cloud Market Is "Broken." They're Half Right.
A Better Question Doesn't Survive a Subpoena
Bergson Lopes Rego published a piece in CDO Magazine called "The Data Sovereignty Illusion." Read it. The diagnosis is…
Read → Commentary · 5 min readHave You Ever Wondered Where Your Data Goes in the Cloud?
You upload the quarterly numbers. A little spinner turns. "Saved to the cloud." Reassuring phrase, the cloud. Sounds…
Read → Regulation · 3 min readThe Kill Switch Has a Loyalty Program - Microsoft is in the Trump trap
Three weeks before Brad Smith promised Europe that Microsoft would protect it from Washington, Microsoft had already…
Read →