Sovereignty enforced at the data layer — not the contract layer
Three reinforcing layers

Sovereignty, enforced in depth.

Each ring is an independent guarantee. No single layer is asked to be trustworthy on its own — and no single party, including SkyeConnex, can collapse all three.

  1. 01
    Core · Cryptographic isolation

    The key never leaves the device.

    Encryption keys are derived client-side. The cloud operator stores ciphertext it can never unwrap — sovereignty that holds even if the provider is compromised.

  2. 02
    Distribution · Geometric

    No provider holds the whole.

    Encrypted shards are spread across multiple providers in jurisdictions you choose. Reconstructing the data requires every party to cooperate at once.

  3. 03
    Boundary · Jurisdictional policy

    Residency enforced in real time.

    Placement, access, and retention are governed by policy that runs on every request — and fails closed. Compliance becomes structural, not contractual.

What's driving the conversation

Why this sector is rethinking cloud now.

CLOUD Act exposure

Every US-headquartered cloud provider is reachable by a US National Security Letter, regardless of where the data physically sits. Canadian and EU public-sector data is in scope today.

Bill C-26 & critical infrastructure

Canada's cyber-security legislation increasingly treats provider concentration as a national-resilience issue. Single-cloud dependencies are now a board-level risk.

DGSI 100-8 readiness

The Standards Council of Canada's Technical Committee on Data Sovereignty is drafting the Canadian sovereign-cloud standard. SkyeConnex sits as a reference implementation of the Sovereign / Defence tier.

How it lands

What SkyeConnex actually does here.

  1. USE 01

    Citizen-record storage

    Encrypted citizen records distributed across allow-listed Canadian providers, with per-file SkyeMap evidence for FOI-type audits.

  2. USE 02

    Inter-agency secure transfer

    Replace email-attachment workflows with audited, expiring share links — every external access identity-captured.

  3. USE 03

    Sovereign-cloud reference architecture

    Deploy SkyeConnex as a sovereign-cloud reference for departments evaluating cloud migration paths under emerging GC guidance.

Regulatory deep-dive for government & public sector

PIPEDA and federal data-handling

The Personal Information Protection and Electronic Documents Act sets the federal floor for personal information handling. For government agencies, PIPEDA pairs with the Privacy Act and Directive on Service and Digital. The Office of the Privacy Commissioner has been consistent: cross-border transfer to providers under foreign legal regimes carries residual risk that contracts cannot fully mitigate. Architectures that enforce residency and zero-knowledge at the data layer answer this concern structurally.

Bill C-26 — Critical Cyber Systems Protection Act

C-26 designates operators in finance, energy, transportation, and telecommunications as subject to cyber-security obligations. The Act doesn't dictate technical controls but requires 'reasonable steps' to protect critical cyber systems — interpreted by emerging guidance as including supply-chain risk mitigation. A US-controlled hyperscaler holding critical operational data is a supply-chain risk under this framing. Multi-cloud RAID inverts that dependency.

DGSI 100-8 — Canadian sovereign-cloud standard

The Standards Council of Canada's Technical Committee on Data Sovereignty is drafting the Canadian sovereign-cloud standard series. SkyeConnex's architecture functions as a reference implementation of the Sovereign / Defence tier. Our gap analysis against the draft DGSI 100-8:2026 specification identifies zero Critical and zero Material indicators outstanding at the Sovereign / Defence tier.

What good looks like

For organisations in government & public sector that are serious about sovereignty, the architectural baseline includes:

  • Encryption keys derived on the client device; the cloud operator never holds the unwrapped key.
  • Data spread across multiple providers in customer-chosen jurisdictions — no single provider can decrypt.
  • Per-file evidence of residency, exportable as signed JSON for audit.
  • Compliance preset packs that bundle encryption, geo, retention, and audit policy in one selection.
  • Audit log dual-signed for legal-evidentiary value, verifiable offline against a published issuer key.
  • Optional on-prem or air-gap deployment for the most sensitive workloads.

SkyeConnex delivers all of the above by default — see the architecture and the cryptographic posture.

Regulatory frameworks SkyeConnex addresses for this sector

PIPEDA · Bill C-26 · DGSI 100-8 · Treasury Board cloud guidance

Compliance preset packs encode each framework's expectations into one cascade — encryption posture, allow-list, retention, audit treatment — so the pack itself is the documentation of what was applied.

FAQ

Common questions in government & public sector

Does SkyeConnex meet Canadian government residency requirements?

Yes. The geo-policy engine supports allow-listing Canadian-resident providers (AWS ca-central-1, Azure canadacentral, on-prem MinIO, OVH Beauharnois) and blocking placement elsewhere. The strict-mode hook fails uploads that violate policy rather than degrading silently.

Is SkyeConnex used by any federal agencies today?

A 90-day pilot proposal is active with the Honourable David McGuinty, Minister of National Defence. Executive engagement is in train at Treasury Board, Health Canada, and the federal cyber team. Specific customer relationships are subject to NDA.

How does SkyeConnex map to DGSI 100-8?

SkyeConnex sits as a reference implementation of the Sovereign / Defence tier. Our gap analysis against the draft 2026 specification identifies zero Critical and zero Material indicators outstanding. We're engaged with the SCC's Technical Committee through ongoing standards work.

Can we deploy SkyeConnex air-gapped for classified workloads?

Yes, on the Sovereign tier. The same code that runs at app.skyeconnex.com runs in a customer VPC or air-gapped environment, including the SkyeGXU on-prem GPU embedding subsystem for sovereign AI workloads.

Government-sector posture
$15M
CCSPA penalty
Maximum administrative monetary penalty per organisation per violation under Bill C-26.
Zero
Material gaps
Critical or Material indicators outstanding against DGSI 100-8 Sovereign / Defence tier.
90-day
DND pilot
Active pilot proposal with the Honourable David McGuinty, Minister of National Defence.

See it on your data.

Book a sector-specific briefing. We'll bring the relevant compliance packs pre-configured.