ATTACKER compromises 1-2 Shard 1 — encrypted by attacker Shard 2 — encrypted by attacker Shard 3 — intact Shard 4 — intact Shards 5–7 — intact RECOVERED 5 of 7 is enough
Backup topology that survives attacks on the MSP's central management

The challenge

MSPs serving regulated customers in 2026 face a procurement question that's getting harder to answer: 'How sovereign is our customer data on your backup infrastructure?' The standard answer — 'we use Veeam writing to AWS / Azure / Wasabi' — increasingly fails customer compliance review.

The pressure is compounding. Customers in healthcare, finance, legal, and government are pushing residency requirements down to their MSPs. Cyber-insurance underwriters distinguish well-architected vs. concentrated cloud postures in MSP underwriting. And ransomware crews routinely target MSPs as a high-leverage attack — encrypt one MSP and you potentially encrypt dozens of downstream customers.

MSPs need backup infrastructure that does three things at once: handles per-customer residency policy, survives ransomware targeting the MSP itself, and integrates cleanly with the customer's existing audit expectations.

The architectural answer

SkyeConnex's multi-tenancy model — Reseller → Company → Account — was designed for exactly this. MSPs operate as resellers; each downstream customer is a Company; each customer has Accounts under it. Per-customer geo-policy, branding, support contact, and compliance preset packs all cascade through the model.

  • Per-customer residency — each Company under the MSP reseller can have its own allow-list. Healthcare customers get PHIPA-aligned Canadian-only configuration; financial-services customers get SOC 2 / FedRAMP-amenable US-only configuration; SaaS customers get their region of choice.
  • Multi-cloud RAID for ransomware resilience — each customer's backups are Reed-Solomon spread across seven providers. An attacker compromising the MSP's central management cannot encrypt or delete backups; would have to compromise five providers in five jurisdictions simultaneously.
  • White-label — customer-facing surfaces (web app, email-from, support) carry the MSP's brand. The customer experiences the MSP, not SkyeConnex.
  • Veeam / AWS Backup retargeting — existing customer backup tooling re-points at SkyeBucket. The MSP doesn't change tooling; the architectural sovereignty is inherited.

How it works in practice

MSP onboarding

The MSP signs a reseller agreement. White-label assets (logo, brand colours, email-from) are loaded into the Reseller tenant. The MSP's standard compliance preset packs are configured at the reseller level. All downstream customers inherit by default.

Customer onboarding

The MSP creates a Company tenant per customer. The customer's specific compliance pack is selected (PIPEDA, HIPAA-BAA, GDPR, etc.). The customer's preferred jurisdictions are configured as the allow-list. Existing customer Veeam, AWS Backup, or Bacula configuration is re-pointed at the customer-specific SkyeBucket endpoint.

Ongoing operations

Backups run on existing schedules through existing tooling. The Stream Pipeline encrypts client-side, frames into 5 MB chunks, Reed-Solomon-encodes into seven shards, scatters across the seven providers in the customer's allow-list. The MSP's central management console shows per-customer health, throughput, and policy compliance.

Ransomware event response

If the MSP's central management is compromised, the attacker cannot encrypt or delete customer backups — five providers in five jurisdictions would have to be compromised simultaneously. Recovery proceeds normally; clients restore from the same Reed-Solomon shards.

Customer audit support

Customer audits receive signed sovereignty reports verifiable offline against the published issuer key. The MSP doesn't need to vouch for the architecture; the customer's auditor verifies cryptographically.

FAQ

Common questions

Can each of our customers have a different geo-policy?

Yes. The effective-policy cascade lets each Company tenant under the MSP reseller have its own allow-list. Healthcare customers get Canadian-only; financial-services customers get US-only; etc. Cross-customer configuration is fully isolated.

Does our brand show through to customers?

Full white-label: logo, brand name, email-from, support contact. The customer-facing experience is your MSP brand. Per-tenant overrides let you customise per customer where needed.

How does this affect our cyber-insurance underwriting?

Most underwriters in 2026 view multi-cloud RAID with zero-knowledge encryption favourably because it demonstrably reduces breach blast-radius and is structurally ransomware-resilient. Architecture documentation suitable for sharing with your broker is available.

Can we integrate with existing customer backup tooling?

Yes. SkyeBucket exposes an S3-compatible API at s3.skyeconnex.com. Veeam, AWS Backup, Bacula, and most S3-targeting backup tools retarget by changing one endpoint configuration. No customer-side workflow change.

See it on your data.

Book a 45-minute briefing. We'll walk through the architecture configured for this exact use case — compliance preset packs, connexion set, residency policy — live.