Capabilities

The sovereignty surface, made operational.

Account-wide score

A single number summarising the account's sovereignty posture against your selected frameworks. Drops in real time as policy or topology changes.

Per-folder roll-up

Folders inherit a score from their contents. Top-level navigation surfaces the weakest folder in red — making remediation an ordered list, not a scavenger hunt.

Per-file drill-down

Click any file — see the seven jurisdictions holding its shards, each with confidence grade. Per-file evidence for an auditor, not aggregate reassurance.

Confidence-graded pins

Probed, declared, observed, country-only, unknown. Each grade renders differently — so visible evidence is never confused with operator-typed claims.

11 frameworks tracked

PIPEDA, GDPR, UK-GDPR, SOC 2, FedRAMP, APP, APPI, MAS, LGPD, POPIA, PDPL. Each adds its own residency, transfer, and cryptographic-standard constraints to the score.

Threat Simulator

Click-to-block any country. The score recomputes live. Built-in presets: Five Eyes, CLOUD Act bloc, China, Russia. Make scenario planning a five-second task.

Confidence grading

Evidence and claims, visually distinct.

Probed

The endpoint reported its region through an authenticated API call within the last refresh window. Highest confidence — this is what we know, not what we've been told.

Declared

The operator typed the region. Used when the provider doesn't expose a region API or hasn't been probed yet. Lower confidence; flagged for the audit log.

Observed

The endpoint's last credible network hop suggested the region. Useful for legacy or self-hosted endpoints where neither probe nor declaration is available.

Country-only

The endpoint resolved to a country but not a region. Plotted at the country centroid with a warning pin. The customer is told they have less precision than usual.

Unknown

No reliable location signal. Pin is not plotted; the shard is logged as in-flight against an unverified endpoint. The score reflects the unknown.

Refresh cadence

Probed endpoints re-verify on a sliding window (typically hourly). Declared endpoints lose confidence over time until re-declared. Confidence has a half-life by construction.

Why a real-time map matters

Sovereignty posture is not a snapshot — it is a continuous state that changes whenever a connexion is added, a provider region rotates, a UMK is re-keyed, or a policy is edited. A point-in-time PDF report is the wrong abstraction. The SkyeMap is the right one: it is always now.

The board-level question is not "what was our posture at the audit?" but "what is our posture as of this minute?" The SkyeMap answers that question with evidence per file, not aggregates per region.

How it ties to the signed report

When the auditor wants the snapshot, the SkyeMap renders an account-wide or per-folder report as dual-signed JSON. HMAC-SHA-256 with a customer-derived key and ML-DSA-87 with the SkyeConnex issuer key. Both verifiable offline. The report is a frozen view of the SkyeMap state at the moment of generation — complete with per-file evidence, confidence grades, and framework alignment.

Eleven frameworks at the same time

Most regulated organisations are subject to more than one regulatory regime. Healthcare touches PIPEDA, HIPAA, GDPR, and provincial frameworks. Financial services touches SOC 2, FedRAMP, ISO 27001, and PCI. SkyeMap evaluates the account against all eleven supported frameworks simultaneously — per-framework pass/fail and per-file evidence supporting each pass.

The currently-tracked frameworks: PIPEDA (Canada), GDPR (EU), UK-GDPR / DPA 2018 (UK), SOC 2 (US, attestation), FedRAMP (US, federal), APP (Australia), APPI (Japan), MAS (Singapore), LGPD (Brazil), POPIA (South Africa), PDPL (Saudi Arabia).

See your data's residency now.

Book a session. We'll log in to a tenant with a representative dataset and walk the SkyeMap top-down, account → folder → file.