For what it's worth — Google says it doesn't use content from Gmail, Drive, or Photos for personalized ads. Microsoft says the same about email, Teams, and your personal files. Fine. Great. Gold star for not doing the thing everyone was worried about ten years ago.

But "we don't mine your inbox to sell you camping gear" is not the same as "you are in control." Both companies still collect and use account, activity, and service data to run, secure, improve, and personalize their platforms. They're not reading your files to target ads. They're just operating the entire control plane around your data. Subtle difference.

And here's where the cloud marketing deck usually develops selective amnesia.

The issue was never just ads. It's control. Specifically: who controls the provider that controls your data.

Under 18 U.S.C. § 2713 — as amended by the CLOUD Act — a U.S.-headquartered provider must preserve, back up, or disclose covered records within its "possession, custody, or control," regardless of where that data is physically stored. Not a fringe reading. That's the text.

So when a U.S. provider tells you your data lives in Canada, or Europe, or wherever the brochure feels most patriotic that quarter — that may be true in a storage sense. But it doesn't answer the legal question of who can be compelled.

Data residency is about where the bytes sleep. Sovereignty is about who gets woken up by a court order.

That's exactly why I built SkyeConnex.

SkyeConnex isn't built on the bold modern strategy of handing everything to one giant provider and hoping their legal team has solved geopolitics. We reduce single-provider exposure by splitting and protecting data across environments — so no one provider holds the whole file, the whole dependency, and the whole leverage position.

That changes the architecture in ways that matter:

One provider has an outage → that shouldn't be your outage.

One provider is breached → that shouldn't be your full exposure.

One provider gets a court order → that shouldn't mean one provider can hand over the complete usable object.

This is the architectural point that "sovereign cloud" conversations politely skip, because it's inconvenient to the business model. A local region is not local control. A national flag on the rack doesn't change who holds the power.

In 2026, the risk isn't that someone is using your inbox to sell you loafers. The risk is that your entire data model is structurally dependent on a single provider who remains the central point of access, control, and legal exposure.

We're not selling a nicer way to feel comfortable about concentration risk. We're reducing the concentration risk itself.

"Our data is stored locally" is a sentence your compliance team can put in a deck.

"Our provider cannot unilaterally reconstruct the whole thing" is the sentence that actually holds up when someone who isn't on your org chart decides they'd like a look.

In a world where sovereignty has become a branding exercise and "secure cloud" means a nicer logo on the same legal exposure — that distinction isn't a feature. It's the whole point. And if you're still betting on a single provider's goodwill, their uptime SLA, and their relationship with U.S. federal courts to protect your data — I genuinely hope the brochure was worth it.

#SkyeConnex#CloudSecurity#DataSovereignty#CLOUDAct#EnterpriseArchitecture


Originally published by Ross Norrie, founder of SkyeConnex, on LinkedIn.

Published April 12, 2026 · More from the SkyeConnex blog