Sovereign storage for federal-grant research
Tri-Council, NIH, Horizon Europe, and DARPA funding increasingly include data-handling clauses that hyperscaler regional storage can't fully satisfy. SkyeConnex makes residency a configuration.
The challenge
Research data under federal grants in 2026 sits at the intersection of multiple data-handling regimes. Canadian Tri-Council funding increasingly references TCPS2 risk-mitigation; Horizon Europe terms include explicit cross-border clauses post-Schrems II; NIH genomic-data sharing (GDS) policy specifies access-controlled storage; DARPA and DoD funding lines reference CMMC, CNSA 2.0, and ITAR-aligned protections.
For research groups with grants from multiple funders, the architecture has to satisfy the union of all applicable terms. Hyperscaler regional storage (ca-central-1, eu-west-1, etc.) addresses residency but not the parent-jurisdiction question. NIH's GDS policy explicitly requires access-controlled storage with audit — most cloud configurations satisfy this nominally but not architecturally.
The AI overlay makes this acute. Increasingly, federally-funded research involves AI-grounded analysis of the corpus — and routing research data to OpenAI or Azure OpenAI typically violates the grant's data-handling clause without explicit waiver.
The architectural answer
SkyeConnex's per-project compliance preset packs map each major funder's expectations to platform configuration:
- TCPS2 — risk-mitigation patterns with per-study allow-list configuration and REB-quality access evidence.
- Horizon Europe — EU residency allow-list, signed transfer impact assessment artefacts, cross-border consent capture.
- NIH GDS — access-controlled per-investigator scoping with cryptographic audit. Per-collaborator identity capture.
- DARPA / CMMC-aligned — Sovereign tier with split-authority decryption, PQ hybrid wrap, and air-gap deployment for the most sensitive workloads.
For RAG over research corpora, SkyeGXU keeps embeddings on the institution's own GPUs. The Barrista in-app assistant grounds answers in the corpus without sending records to OpenAI or Azure OpenAI.
How it works in practice
Grant setup
The PI's research administrator configures a project tenant with the appropriate compliance pack. For multi-funder projects, the cascade combines the strictest requirements of each funder. Storage allow-list is set to the union of acceptable jurisdictions per funder.
Data capture and analysis
Researchers upload via standard SkyeConnex clients. Multi-TB datasets stream through the resumable chunked upload protocol. SkyeBucket handles legacy tooling integration (R / Python scripts targeting S3, HPC batch systems, instrument data exporters).
Collaborator access
Inter-institutional collaborators access through revocable share links with external identity capture. Per-collaborator audit trails support the access-control requirements in NIH GDS and similar policies.
Sovereign AI for analysis
SkyeGXU on customer GPUs lets researchers deploy RAG and semantic search over the project corpus without breaching grant data-handling terms. The Barrista assistant grounds answers in the project's documents.
Audit and reporting
Sponsor audit cycles produce signed sovereignty reports verifiable offline. REB inspections receive the per-record residency map. Grant-closeout archival continues under the same residency policy, with cryptographic erasure support for participant withdrawals.
Common questions
How does SkyeConnex handle multi-funder projects?
The effective-policy cascade combines requirements: Tri-Council + Horizon Europe + NIH for a single project produces an intersection allow-list with the strictest retention and audit requirements applied. Compliance preset packs cover each major funder; you select the relevant ones.
Can we run sovereign RAG over project documents?
Yes, on the Sovereign tier via SkyeGXU. Embeddings run on your institution's GPU. Documents and queries never reach OpenAI or Azure OpenAI. The Barrista in-app assistant grounds answers in your project corpus.
Does this satisfy NIH Genomic Data Sharing policy?
The access-control infrastructure satisfies GDS's controlled-access expectations. Per-collaborator scoping and dual-signed audit logs provide the access-tracking required. Specific compliance with each Data Access Committee's requirements depends on study-specific terms; we provide architecture documentation.
How does this affect grant-related procurement?
Sovereign architecture is increasingly part of competitive grant proposal review. Demonstrating per-record residency, signed audit, and sovereign AI in the proposal phase substantially differentiates from generic 'we use AWS' positioning.
Read deeper
Sovereign AI: running RAG on regulated data without OpenAI exposure
Retrieval-augmented generation over regulated documents is a board-level win — if you can do it without sending those documents to OpenAI or…
Read → Regulation · 9 min readSchrems II two years on: what actually changed for EU-US data transfers
The 2020 CJEU ruling invalidated Privacy Shield. Five years and one EU-US Data Privacy Framework later, the underlying problem remains. Here…
Read → Regulation · Canada · 7 min readPIPEDA and cloud storage: what most providers get wrong
PIPEDA predates the cloud. Applying it to multi-cloud workloads requires architectural thinking that most providers don't do. Here's the gap…
Read →See it on your data.
Book a 45-minute briefing. We'll walk through the architecture configured for this exact use case — compliance preset packs, connexion set, residency policy — live.