Privilege, evidence, and non-repudiation — built in.
Legal practice produces artefacts whose evidentiary value depends on chain-of-custody. SkyeConnex makes that chain cryptographic — and verifiable by an auditor who has never spoken to us.
Why this sector is rethinking cloud now.
Privileged-document exposure
A subpoena to a hyperscaler holding privileged documents triggers a fight you'd rather avoid. SkyeConnex's topology makes the question moot — there is no plaintext in any one provider to compel.
Non-repudiation in evidence
HMAC-signed reports require the verifier to call back to the platform. That's 'trust us.' Dual-signed reports (ML-DSA-87 + HMAC) let an auditor verify offline against a published issuer key. That's evidence.
Audited disclosure trails
Every share-link access — including external recipients — identity-captured into a signed audit log. CSV streamable, JSON exportable, append-only.
What SkyeConnex actually does here.
-
USE 01
Privileged-document storage
Privileged documents distributed across allow-listed jurisdictions, with split-authority decryption available for the most sensitive scopes.
-
USE 02
Discovery exchange
Audited, expiring share links for inter-firm document exchange — external identity captured, expiry enforced, access in the audit log.
-
USE 03
Evidence non-repudiation
Per-file Integrity Certificates dual-signed with HMAC-SHA-256 and ML-DSA-87. An opposing party's expert can verify without contacting us.
Regulatory deep-dive for legal & professional services
Solicitor-client privilege under multi-cloud topology
Privilege exists in the document, not the storage. But operational security of privileged documents has implications under provincial Law Society rules and the Federation of Law Societies of Canada Model Code. A US-controlled hyperscaler holding privileged documents is reachable by US legal process — and that reachability is a privilege risk in itself, before any actual subpoena. Multi-cloud RAID makes the reachability moot: no single jurisdiction holds enough of any document to read it.
Chain-of-custody and evidentiary weight
Documents intended for evidentiary use need a credible chain of custody. SkyeConnex's per-file provenance chain — every read, write, and access cryptographically chained — produces evidentiary-quality custody records. Dual-signed integrity certificates with offline ML-DSA-87 verification mean opposing counsel can verify document integrity independently.
E-discovery and retention
Litigation hold requires retention beyond normal cycles. SkyeConnex's retention policy supports hold tags that override automatic purge. Audit-log retention windows are independently configurable. Compliance preset packs include legal-hold patterns.
What good looks like
For organisations in legal & professional services that are serious about sovereignty, the architectural baseline includes:
- Privileged documents distributed across allow-listed jurisdictions; no single party can decrypt.
- Per-file dual-signed integrity certificates for non-repudiation in evidence.
- Audited share links for inter-firm discovery exchange with external identity capture.
- Split-Authority Decryption for the most sensitive privileged scopes.
- Cryptographic chain of custody from intake through every read.
- Retention-hold tagging that overrides automatic purge during litigation.
SkyeConnex delivers all of the above by default — see the architecture and the cryptographic posture.
Regulatory frameworks SkyeConnex addresses for this sector
PIPEDA · GDPR · Provincial Law Society rules
Every signed report and integrity certificate carries an embedded ML-DSA-87 (FIPS 204) public key alongside the HMAC signature, with a published SHA-256 fingerprint at /security.
Sovereignty thinking for legal & professional services
Schrems II two years on: what actually changed for EU-US data transfers
The 2020 CJEU ruling invalidated Privacy Shield. Five years and one EU-US Data Privacy Framework later, the underlying problem remains. Here…
Read → Regulation · 8 min readWhat a CLOUD Act subpoena actually looks like in practice
Most board conversations about the CLOUD Act stay abstract. Here's a concrete walkthrough of how the mechanism works — and why architectural…
Read → Regulation · 8 min readThe CLOUD Act and why data residency isn't enough
The CLOUD Act extends US legal reach to data held by US-controlled cloud providers anywhere in the world. Choosing a Frankfurt or Toronto re…
Read →Common questions in legal & professional services
Is SkyeConnex compliant with provincial Law Society rules on cloud storage?
Provincial Law Societies generally require lawyers to evaluate cloud storage for confidentiality and competence. SkyeConnex's zero-knowledge architecture and multi-jurisdictional sharding directly address the confidentiality dimension — the cloud operator cannot read privileged documents. Documentation aligned with the Federation of Law Societies' Model Code is available.
Can opposing counsel verify a SkyeConnex integrity certificate?
Yes — that's the point. The issuer public key is published at /security. Opposing counsel's technical expert can verify a certificate offline using any FIPS 204 verifier (Python pqcrypto, Open Quantum Safe liboqs). The platform's involvement is not required — and that's what makes the certificate credible in evidence.
How are audit logs handled for legal hold?
Audit logs are append-only and dual-signed. Retention can be extended for matters under hold. Per-document custody chains are exportable as signed JSON for offering to court.
Can clients access documents we share without an account?
Yes, via revocable share links with optional password, expiry, and view limits. Every access — including by external recipients — is identity-captured into the audit log.
See it on your data.
Book a sector-specific briefing. We'll bring the relevant compliance packs pre-configured.