THE SKYECONNEX PLATFORM MAP Six surfaces · one substrate · eleven jurisdictions. CLIENT SURFACES WEB APP browser-native MOBILE iOS · Android (Flutter) OUTLOOK add-in GMAIL marketplace add-on SkyeXplore Windows virtual drive SkyeBucket S3 gateway PLATFORM CORE 400+ HTTP ENDPOINTS CRYPTO STACK AES + ML-KEM-1024 9 NIST primitives PQ-READY RS(5,2) ENCODER Reed-Solomon 7 shards / file LOSE 2 OK GEO-POLICY ENGINE Allow + block + strict enforced at upload 11 FRAMEWORKS SkyeGXU Sovereign on-prem AI OpenAI-compatible AIR-GAP OK SkyeMap 94 / 100 SOVEREIGN PROVIDER CONSTELLATION 14 PROVIDERS · 11 JURISDICTIONS CA EU UK US AU NZ JP CH IE SE BR + Wasabi · Backblaze · AWS · Azure · OVH · Hetzner · Linode · IDrive · Storj · IDC Frontier · MinIO · Catalyst 400+ ENDPOINTS 14 PROVIDERS 11 JURISDICTIONS 7 SHARDS / FILE FIPS 203 + 204
The whole platform on one canvas — ingress, substrate, egress.
14
Provider plugins
7
Shards per file · RS(5,2)
400+
Production endpoints
11
Privacy regimes
9
NIST primitives
6
Client surfaces
5
Pricing tiers
Ø
Proprietary algorithms

The category

Data Sovereignty as a Service. The first productised, operationally proven, architecturally enforceable sovereign-cloud primitive. Where every other "sovereign cloud" answers the residency question with a regional dropdown, SkyeConnex answers it with mathematics — a cryptographic and topological construction in which no single provider, court, or operator can read your data, by design rather than by contract. Read more →

The thesis

Mathematics, not promises. Three reinforcing layers — cryptographic isolation, geometric distribution, jurisdictional policy — none of which depends on any single party behaving honestly. A subpoena to any single provider yields ciphertext. Compelling five providers across multiple jurisdictions is the operational coordination problem that the topology makes practically impossible. The architecture composes naturally: ransomware resistance, post-quantum readiness, and multi-cloud durability are emergent properties of the same substrate. Read the architecture →

What's shipped, in production today

Multi-cloud RAID with Reed-Solomon RS(5,2). Post-quantum hybrid key wrap (ML-KEM-1024, FIPS 203). Post-quantum signatures (ML-DSA-87, FIPS 204) on every signed report. Six client surfaces: SkyeBucket (S3 gateway), SkyeGXU (sovereign on-prem AI), Outlook & Gmail add-ins, Windows virtual drive, mobile, web. SkyeMap for real-time sovereignty visualisation. SkyeVault for password and secret storage on every tier — including Free. Full feature inventory →

Who it's for

Government, defence, healthcare, financial services, legal, research, media, real estate, SaaS. Anywhere data residency, compelled-disclosure resistance, and post-quantum protection are board-level concerns. We are typically the chosen architecture when the choice is between verifiable sovereignty (provable, signed, per-file) and contractual sovereignty (a clause in an MSA). By industry →

What it costs

Five tiers from Free to Sovereign. Pricing flexes within tier; the matrix is the capability matrix as enforced in code. Tier changes are recovery-neutral by construction — both wrapped UMK variants (password and PQ-hybrid) are unwrap-attempted on every login, so moving between tiers never affects recoverability of previously encrypted files. Compare tiers →

Where it fits

How SkyeConnex compares to the alternatives.

Three categories of incumbent. One architecture that subsumes them.

Hyperscaler with "sovereign" SKU

AWS Sovereign Cloud, Azure for Sovereignty, GCP Sovereign Controls. Architecturally still reachable by the parent jurisdiction's legal process. Sovereignty by contract clause.

SOVEREIGNTY: contractual · ENFORCEMENT: provider plane

Regional sovereign cloud

OVH Sovereign Cloud, T-Systems, S3NS, Capgemini Bleu. National-flag holding companies that resell hyperscaler infrastructure or operate single-region clouds. Better than residency-only, but still a single provider plane.

SOVEREIGNTY: jurisdictional · ENFORCEMENT: single operator

SkyeConnex — sovereignty by architecture

Encrypt client-side. RS(5,2) erasure-code into 7 shards. Scatter across providers and jurisdictions you choose. Compelling decryption requires 5 of 7 providers simultaneously across multiple jurisdictions — the topology compounds the coordination problem.

SOVEREIGNTY: architectural · ENFORCEMENT: data layer

Proof points

Operational, not aspirational.

BARC operational reference

Recognised by BARC analysts (May 2026) as the first and only operational implementation of the data-sovereignty architecture their research describes. "SkyeConnex is the gap-closer."

SCC engagement

Engaged with the Standards Council of Canada Technical Committee on Data Sovereignty as reference implementation for DGSI 100-8. Gap analysis: zero Critical or Material indicators outstanding at the Sovereign / Defence tier.

Patent filed

39 claims covering the multi-cloud RAID + hybrid PQ wrap construction. Counsel: Perley-Robertson, Hill & McDougall LLP.

Post-quantum in production

Both halves of the NIST PQ migration are shipping today: ML-KEM-1024 (FIPS 203) for key encapsulation, ML-DSA-87 (FIPS 204) for signatures.

S3-compatible drop-in

SkyeBucket exposes the SkyeConnex substrate as a standard S3 endpoint. Veeam, AWS Backup, Bacula, boto3, awscli, rclone all retarget with a single endpoint change.

Built in Ottawa

Headquartered in Ottawa, Canada. Sovereign by jurisdiction. Patent-protected by IP strategy. Production-validated at petabyte scale.

FAQ

The executive's questions, answered.

How is SkyeConnex different from a sovereign hyperscaler SKU?

Sovereign hyperscaler offerings (AWS Sovereign Cloud, Azure for Sovereignty, GCP Sovereign Controls) provide regional isolation, customer-managed keys, and contractual data-handling commitments — but the data plane is still operated by the parent company, which means it is still reachable by the parent jurisdiction's legal process. SkyeConnex inverts that by encrypting client-side and distributing shards across your chosen providers and jurisdictions; no single provider plane can satisfy a subpoena, by construction.

What does "production today" actually mean?

The platform runs at app.skyeconnex.com with more than 400 HTTP API endpoints, 14 provider plugins, and six shipping client surfaces. Both NIST post-quantum primitives (ML-KEM-1024 and ML-DSA-87) are in production. Customers can sign up to the Free tier today and use SkyeVault for encrypted secret storage without paying anything.

How long does an evaluation take?

A typical evaluation is a 45-minute live briefing, a 1-2 week sandbox period using your own representative dataset, and a procurement track that varies by sector. For regulated buyers we ship the compliance pack (signed reports, certification posture, framework alignment) for the procurement team in parallel with the technical sandbox.

What does it cost?

Five tiers. The Free tier includes encrypted secret storage (SkyeVault) and a small storage allocation. Paid tiers scale with storage, throughput, provider selection breadth, and tier-specific capabilities (Sovereign tier includes split-authority decryption, air-gap deployment, and PQ-hybrid wrap by default). See the full pricing matrix.

Can I bring my own storage providers?

Yes. The provider plugin SDK lets you ship a new provider plugin in under 500 lines of code. SkyeConnex includes 14 production plugins out of the box (Wasabi, Backblaze, AWS, Azure, OVH, Hetzner, Linode, IDrive, Storj, IDC Frontier, MinIO, Catalyst Cloud, and others). On-prem MinIO and air-gapped storage are first-class targets.

How do auditors verify a signed sovereignty report?

Every report is dual-signed with HMAC-SHA-256 and ML-DSA-87 (FIPS 204). The ML-DSA-87 verification key is published at /security as a SHA-256 fingerprint for pinning. Once pinned, any FIPS 204 verifier — Python pqcrypto, Open Quantum Safe liboqs, AWS-LC — can verify the signed report offline without contacting SkyeConnex.

What happens if SkyeConnex goes away?

The customer holds the wrap key. The customer holds the connexion credentials. The data is in standard providers under standard accounts. Worst-case escrow recovery is reading shards from each provider directly and decoding offline using the documented RS(5,2) format — no SkyeConnex dependency required for recovery.

Five minutes was enough.

The next step is a 45-minute live briefing on a configuration relevant to your use case — with the SkyeMap, Threat Simulator, and a signed-report verification walked through end-to-end.