Public-sector sovereignty, enforced at the data layer.
Government data is reachable by foreign authorities the moment it sits with a hyperscaler whose parent is in another jurisdiction. SkyeConnex makes that mathematically impossible — and it's already in conversation with Treasury Board, Health Canada, and the federal cyber team.
Sovereignty, enforced in depth.
Each ring is an independent guarantee. No single layer is asked to be trustworthy on its own — and no single party, including SkyeConnex, can collapse all three.
-
01Core · Cryptographic isolation
The key never leaves the device.
Encryption keys are derived client-side. The cloud operator stores ciphertext it can never unwrap — sovereignty that holds even if the provider is compromised.
-
02Distribution · Geometric
No provider holds the whole.
Encrypted shards are spread across multiple providers in jurisdictions you choose. Reconstructing the data requires every party to cooperate at once.
-
03Boundary · Jurisdictional policy
Residency enforced in real time.
Placement, access, and retention are governed by policy that runs on every request — and fails closed. Compliance becomes structural, not contractual.
Why this sector is rethinking cloud now.
CLOUD Act exposure
Every US-headquartered cloud provider is reachable by a US National Security Letter, regardless of where the data physically sits. Canadian and EU public-sector data is in scope today.
Bill C-26 & critical infrastructure
Canada's cyber-security legislation increasingly treats provider concentration as a national-resilience issue. Single-cloud dependencies are now a board-level risk.
DGSI 100-8 readiness
The Standards Council of Canada's Technical Committee on Data Sovereignty is drafting the Canadian sovereign-cloud standard. SkyeConnex sits as a reference implementation of the Sovereign / Defence tier.
What SkyeConnex actually does here.
-
USE 01
Citizen-record storage
Encrypted citizen records distributed across allow-listed Canadian providers, with per-file SkyeMap evidence for FOI-type audits.
-
USE 02
Inter-agency secure transfer
Replace email-attachment workflows with audited, expiring share links — every external access identity-captured.
-
USE 03
Sovereign-cloud reference architecture
Deploy SkyeConnex as a sovereign-cloud reference for departments evaluating cloud migration paths under emerging GC guidance.
Regulatory deep-dive for government & public sector
PIPEDA and federal data-handling
The Personal Information Protection and Electronic Documents Act sets the federal floor for personal information handling. For government agencies, PIPEDA pairs with the Privacy Act and Directive on Service and Digital. The Office of the Privacy Commissioner has been consistent: cross-border transfer to providers under foreign legal regimes carries residual risk that contracts cannot fully mitigate. Architectures that enforce residency and zero-knowledge at the data layer answer this concern structurally.
Bill C-26 — Critical Cyber Systems Protection Act
C-26 designates operators in finance, energy, transportation, and telecommunications as subject to cyber-security obligations. The Act doesn't dictate technical controls but requires 'reasonable steps' to protect critical cyber systems — interpreted by emerging guidance as including supply-chain risk mitigation. A US-controlled hyperscaler holding critical operational data is a supply-chain risk under this framing. Multi-cloud RAID inverts that dependency.
DGSI 100-8 — Canadian sovereign-cloud standard
The Standards Council of Canada's Technical Committee on Data Sovereignty is drafting the Canadian sovereign-cloud standard series. SkyeConnex's architecture functions as a reference implementation of the Sovereign / Defence tier. Our gap analysis against the draft DGSI 100-8:2026 specification identifies zero Critical and zero Material indicators outstanding at the Sovereign / Defence tier.
What good looks like
For organisations in government & public sector that are serious about sovereignty, the architectural baseline includes:
- Encryption keys derived on the client device; the cloud operator never holds the unwrapped key.
- Data spread across multiple providers in customer-chosen jurisdictions — no single provider can decrypt.
- Per-file evidence of residency, exportable as signed JSON for audit.
- Compliance preset packs that bundle encryption, geo, retention, and audit policy in one selection.
- Audit log dual-signed for legal-evidentiary value, verifiable offline against a published issuer key.
- Optional on-prem or air-gap deployment for the most sensitive workloads.
SkyeConnex delivers all of the above by default — see the architecture and the cryptographic posture.
Regulatory frameworks SkyeConnex addresses for this sector
PIPEDA · Bill C-26 · DGSI 100-8 · Treasury Board cloud guidance
Compliance preset packs encode each framework's expectations into one cascade — encryption posture, allow-list, retention, audit treatment — so the pack itself is the documentation of what was applied.
Sovereignty thinking for government & public sector
The CLOUD Act and why data residency isn't enough
The CLOUD Act extends US legal reach to data held by US-controlled cloud providers anywhere in the world. Choosing a Frankfurt or Toronto re…
Read → Regulation · 6 min readWhy 'Canadian-flag cloud' is not Canadian sovereignty
A US-headquartered hyperscaler with a Canadian holding company is still subject to US legal process. Sovereignty by corporate paperwork is f…
Read → Regulation · 9 min readSchrems II two years on: what actually changed for EU-US data transfers
The 2020 CJEU ruling invalidated Privacy Shield. Five years and one EU-US Data Privacy Framework later, the underlying problem remains. Here…
Read →Common questions in government & public sector
Does SkyeConnex meet Canadian government residency requirements?
Yes. The geo-policy engine supports allow-listing Canadian-resident providers (AWS ca-central-1, Azure canadacentral, on-prem MinIO, OVH Beauharnois) and blocking placement elsewhere. The strict-mode hook fails uploads that violate policy rather than degrading silently.
Is SkyeConnex used by any federal agencies today?
A 90-day pilot proposal is active with the Honourable David McGuinty, Minister of National Defence. Executive engagement is in train at Treasury Board, Health Canada, and the federal cyber team. Specific customer relationships are subject to NDA.
How does SkyeConnex map to DGSI 100-8?
SkyeConnex sits as a reference implementation of the Sovereign / Defence tier. Our gap analysis against the draft 2026 specification identifies zero Critical and zero Material indicators outstanding. We're engaged with the SCC's Technical Committee through ongoing standards work.
Can we deploy SkyeConnex air-gapped for classified workloads?
Yes, on the Sovereign tier. The same code that runs at app.skyeconnex.com runs in a customer VPC or air-gapped environment, including the SkyeGXU on-prem GPU embedding subsystem for sovereign AI workloads.
See it on your data.
Book a sector-specific briefing. We'll bring the relevant compliance packs pre-configured.