Per-record residency

One record. Six jurisdictions. No single point of compulsion.

🇨🇦 CANADA AWS ca-central-1 🇩🇪 GERMANY Azure DE central 🇫🇷 FRANCE OVH gra 🇨🇭 SWITZERLAND Sovereign on-prem 🇮🇪 IRELAND Backblaze eu 🇸🇪 SWEDEN Wasabi eu ENCRYPTED RECORD
Per-record residency across PHIPA, PIPEDA, HIPAA, and GDPR jurisdictions
Sovereign clinical AI

Your data never leaves the envelope.

YOUR SOVEREIGNTY ENVELOPE DOCS CloudRAID multi-cloud SKYEGXU on-prem GPU /v1/embeddings /v1/search ANSWER Grounded in your corpus EXTERNAL AI never reached no egress
Sovereign clinical AI: embeddings on your GPU, never a third-party model
What's driving the conversation

Why this sector is rethinking cloud now.

Cross-border patient data risk

Cloud-resident PHI is reachable by foreign authorities the moment it crosses a hyperscaler boundary. Provincial residency policy is not satisfied by 'we have a region here.'

AI without leakage

Clinical RAG, document Q&A, semantic search — most implementations involve sending records to OpenAI or Azure OpenAI. That breaches the data-handling agreement before it leaves the building.

Multi-framework compliance

PIPEDA, GDPR, HIPAA-BAA, HITRUST, provincial — at the same time. The cost of reconciling them per-system is enormous.

How it lands

What SkyeConnex actually does here.

  1. USE 01

    PHI storage with provincial residency

    Allow-list Ontario, Quebec, BC providers as your jurisdiction set. Records distributed exclusively within. Per-file SkyeMap evidence for audit.

  2. USE 02

    Sovereign clinical RAG

    SkyeGXU runs OpenAI-compatible embeddings on your own GPU. Semantic search and the Barrista assistant grounded in patient records — without records ever reaching OpenAI.

  3. USE 03

    Research-data sharing

    Audited, expiring share links with external identity capture for inter-institutional research data exchange. Every access in the audit log.

Regulatory deep-dive for healthcare & life sciences

Provincial health-information acts

Ontario's PHIPA, Quebec's health regime under Law 25, British Columbia's E-HIA, and Alberta's HIA each impose residency expectations that overlap but do not perfectly align. PHIPA in particular emphasises in-province residency where operationally feasible. For organisations operating across provinces, the combined obligation is the intersection — and that intersection often cannot be met by hyperscaler regional storage alone.

HIPAA and the BAA-able architecture

HIPAA requires Business Associate Agreements with any third party handling PHI. The architecture must support the safeguards required by the Security Rule: access controls, audit controls, integrity controls, and transmission security. SkyeConnex's zero-knowledge architecture exceeds these by construction — the storage operator cannot access PHI in any operational mode.

AI compliance overlay

Quebec's framework leads in formality for AI governance. Federal AIDA (Artificial Intelligence and Data Act) provisions, expected to come into force in stages, will add national obligations. For RAG-style clinical decision support, the practical implication is that the embedding and inference layers must remain within the same residency envelope as the underlying records.

What good looks like

For organisations in healthcare & life sciences that are serious about sovereignty, the architectural baseline includes:

  • EHRs distributed across in-province providers with per-record residency evidence.
  • Sovereign clinical RAG: embeddings on customer GPUs (SkyeGXU), records never leave the network.
  • BAA-able architecture with healthcare-grade encryption, audit, breach detection.
  • Audited inter-institutional research-data sharing with external identity capture.
  • Compliance preset packs that bundle PHIPA, PIPEDA, HIPAA, and Quebec Law 25 expectations.
  • Cryptographic erasure for patient withdrawal requests (right to deletion).

SkyeConnex delivers all of the above by default — see the architecture and the cryptographic posture.

Regulatory frameworks SkyeConnex addresses for this sector

PIPEDA · GDPR · UK-GDPR / DPA 2018 · HIPAA-BAA-able

Compliance preset packs for HIPAA-BAA and GDPR write encryption posture, geo allow-list, retention policy, and audit treatment in one action.

FAQ

Common questions in healthcare & life sciences

Can we use SkyeConnex for clinical decision support without OpenAI exposure?

Yes. SkyeGXU on the Sovereign tier runs OpenAI-compatible embeddings on customer GPUs. Existing RAG stacks change one endpoint and inherit sovereignty — documents, embeddings, queries, and retrieved chunks never reach OpenAI, Anthropic, or Azure OpenAI.

How does SkyeConnex handle a patient's right to deletion under PHIPA / PIPEDA?

Deletion is a cryptographic operation: the customer rotates the wrap key for the affected records. Previous shards remain in storage briefly but cannot be decrypted; once garbage-collected they're gone permanently. The deletion event is dual-signed in the audit log for regulator review.

Are signed compliance reports acceptable to provincial privacy commissioners?

Reports are dual-signed with HMAC-SHA-256 and ML-DSA-87 (FIPS 204). The issuer public key is published at /security for offline verification. This makes reports cryptographically verifiable evidence rather than 'trust us' attestations — which is what regulators increasingly expect.

Can we host SkyeConnex within our existing hospital data centre?

Yes, on the Sovereign tier. Includes SkyeGXU for on-prem AI. The platform integrates with existing storage via plugin SDK — your existing on-prem NAS or sovereign cloud can be one of the seven shard targets.

PHI handling at a glance
4
Frameworks
PHIPA, PIPEDA, HIPAA, GDPR simultaneously — per-record residency configuration.
Sovereign
Clinical AI
SkyeGXU runs OpenAI-compatible embeddings on your GPU; PHI never reaches OpenAI.
Crypto
Erasure
Patient withdrawal handled as a single wrap-key rotation; signed in the audit log.

See it on your data.

Book a sector-specific briefing. We'll bring the relevant compliance packs pre-configured.