Defence-grade by construction. Sovereign by mathematics.
Defence workloads need stronger guarantees than 'trust the provider.' Split-Authority Decryption, post-quantum signatures, and air-gap-capable on-prem deployment make SkyeConnex viable where classified-handling rules govern.
Why this sector is rethinking cloud now.
Compelled disclosure under foreign law
Defence data on US-controlled clouds is reachable by US legal process. Coalition data on US-controlled clouds is reachable by US legal process. The entire premise of sovereign defence storage requires architectural enforcement.
Post-quantum migration mandate
Both Canada's Cyber Centre PQC guidance and the NSA CNSA 2.0 profile call out KEM and signature halves separately. SkyeConnex ships both — ML-KEM-1024 and ML-DSA-87 — in production today.
Air-gap and disconnected operations
Field deployments need reliability primitives — resumable chunked upload, async scatter, mobile resume across battery cycles — that hyperscaler clients don't ship.
What SkyeConnex actually does here.
-
USE 01
Shamir M-of-N custodian quorum
Split-Authority Decryption requires multiple custodians to unlock the most sensitive scopes. No single insider can compel access.
-
USE 02
Air-gap deployment
The same code that runs app.skyeconnex.com runs in a customer's own VPC, on-prem, or air-gapped. Provider plugin SDK lets you bring sovereign storage in fewer than 500 lines.
-
USE 03
Field reliability
Mobile clients persist in-flight upload_ids to local storage. An OS-killed app or backgrounded session resumes on next launch. Field upload survives a dead battery.
Regulatory deep-dive for military & defence
CCCS PQC migration guidance
The Canadian Centre for Cyber Security publishes guidance on the post-quantum migration. The 2025 update emphasises that both key-encapsulation and signature algorithms must migrate independently — and that hybrid constructions are recommended during the transition window. SkyeConnex ships ML-KEM-1024 (FIPS 203) hybrid wrap and ML-DSA-87 (FIPS 204) signatures in production today on the Sovereign tier.
NSA CNSA 2.0
The NSA's Commercial National Security Algorithm Suite version 2.0 specifies the post-quantum primitives required for protecting National Security Systems. ML-KEM and ML-DSA are both named explicitly. SkyeConnex's defence-grade configuration aligns with CNSA 2.0 — making the architecture suitable for coalition defence workloads where cross-border interoperability matters.
DGSI 100-8 Sovereign / Defence tier
The Standards Council of Canada's draft sovereign-cloud standard defines a Sovereign / Defence tier with the most stringent requirements: split-authority decryption, jurisdiction-locked shards, mandatory PQ-hybrid wrap, dual-signed audit log, optional air-gap deployment. SkyeConnex's defence configuration satisfies all of these.
What good looks like
For organisations in military & defence that are serious about sovereignty, the architectural baseline includes:
- Shamir M-of-N custodian quorum for unlocking the most sensitive scopes (no single insider can compel access).
- Post-quantum hybrid key wrap (ML-KEM-1024 + AES Key Wrap) so harvest-now-decrypt-later attacks fail.
- Post-quantum signatures (ML-DSA-87) on every audit-log entry, offline-verifiable.
- Jurisdiction-locked shards: data physically restricted to nominated countries by policy.
- Optional fully air-gapped deployment with no platform telemetry leaving the customer network.
- Field-grade reliability primitives: resumable chunked upload, async scatter, mobile resume across battery cycles.
SkyeConnex delivers all of the above by default — see the architecture and the cryptographic posture.
Regulatory frameworks SkyeConnex addresses for this sector
DGSI 100-8 (Sovereign/Defence) · CCCS PQC guidance · NSA CNSA 2.0
Patent filed — 39 claims, DGSI-aligned. Corporate counsel: Perley-Robertson, Hill & McDougall LLP.
Sovereignty thinking for military & defence
FIPS 203 and FIPS 204 explained: what NIST's PQ standards mean for procurement
NIST finalised both post-quantum standards in August 2024. ML-KEM-1024 (FIPS 203) and ML-DSA-87 (FIPS 204). Here's what procurement teams sh…
Read → Cryptography · 6 min readPost-quantum cryptography: SkyeConnex already ships both halves
ML-KEM-1024 (FIPS 203) addresses the key-encapsulation half of post-quantum migration. ML-DSA-87 (FIPS 204) addresses the signature half. Sk…
Read → Cryptography · 7 min readQuantum 'harvest now, decrypt later': the timeline that actually matters
'We'll worry about quantum when it happens' is the wrong frame. Adversaries are harvesting encrypted traffic today, betting on decryption to…
Read →Common questions in military & defence
Is SkyeConnex suitable for classified workloads?
On the Sovereign tier with Split-Authority Decryption configured and air-gap deployment, SkyeConnex is architecturally suitable for classified-handling. Final accreditation depends on the customer's own evaluation programme — we provide architecture documentation aligned with DGSI 100-8 Sovereign / Defence tier requirements.
How does Split-Authority Decryption work in practice?
Shamir Secret Sharing splits the decryption secret among M-of-N custodians. To unlock the most sensitive scopes, M custodians must independently authorise the unwrap. No single custodian can compel access — including the customer's own administrators.
Can SkyeConnex run in a fully air-gapped environment?
Yes. The platform code, including SkyeGXU on-prem AI, runs without network access to app.skyeconnex.com. License verification falls back to a 24-hour grace period in absence of connectivity, and an offline licence-renewal flow handles longer disconnections.
Does SkyeConnex support coalition / cross-jurisdictional defence operations?
Yes. Allow-list policy can be configured to admit Five Eyes jurisdictions while blocking others. Per-file evidence of residency makes coalition data-sharing arrangements auditable. CNSA 2.0 alignment ensures interoperability with US National Security Systems.
See it on your data.
Book a sector-specific briefing. We'll bring the relevant compliance packs pre-configured.