PolicyWorking Paper

Capability Today, Sovereignty Always: A Control-First Model for Canada's Digital State

Canada's digital sovereignty debate fixates on who owns the vendor and where the data sits — overweighting postal codes and underweighting what actually decides access: keys, policy, attestation, and exit. This paper argues sovereignty is an enforceable control problem, not a place, and that narrowing the vendor pool imposes a compounding capability tax. It proposes a 'Capability today, sovereignty always' model with 20 concrete recommendations for control-first, capability-maximizing procurement.

Richard St-Pierre·November 1, 2025·20 min read
digital-sovereigntydata-sovereigntyprocurementconfidential-computingencryptiongovernment-policycanadacybersecurity

Key finding: Sovereignty is not a place; it is an enforceable control problem. A database can sit in Ottawa under a Canadian-controlled vendor and still be Canadian in name only — what decides access is who holds the keys, what policy is enforced in real time, whether the system can attest to those controls, and whether the Crown can exit at will.

Canada's federal conversation about digital sovereignty has been anchored in corporate locus and geography: who owns the vendor and where the data sits, including insistence on absolute in-Canada residency — even "in-transit." This framing is understandable, but incomplete. It overweights postal codes and underweights the only things that actually decide whether data can be accessed, decrypted, or compelled: who controls the keys; what policies are enforced in real time; whether the system can produce trustworthy evidence (attestation) that those controls are in place; and whether the government can walk away at will (exit). Taken together, sovereignty is not a place; it is an enforceable control problem. At the very moment global data and AI capabilities are compounding, narrowing the eligible vendor ecosystem imposes a hidden "capability tax" on Canada's economy, services, and security posture. The country should neither buy only domestic technologies and accept a capability gap, nor rely uncritically on foreign technologies and accept strategic dependence. The right path is a "Capability today, sovereignty always" model: mandate enforceable control over data, keys, and operations; procure best-of-world capabilities; and surround their use with tiered guardrails and domestic economic multipliers that grow Canadian capacity without sacrificing performance.

1. The Policy Problem in Plain Terms

The current working definition of digital sovereignty in federal practice often reduces to two questions: is the provider Canadian-controlled, and is the data in Canada — at rest, in use, and even in transit? This has the benefit of being easy to verify on paper. It maps neatly to procurement checklists and architectural diagrams. Yet it ignores the more difficult reality that access to data is ultimately determined by cryptographic possession and policy enforcement, not by postal code. A database can sit in Ottawa and a vendor can be Canadian-controlled; if a third party can compel or silently obtain decryption keys, inject privileged operational access, or bypass logging and attestation, the data is Canadian in name only. Conversely, a workload could run on global infrastructure but be cryptographically isolated behind keys the Crown controls, protected by verified hardware enclaves, and governed by operational processes that prevent unilateral vendor access. Geography is not irrelevant; it is simply not decisive.

Sovereignty, understood operationally, is the government's sustained ability to decide who can access, process, or move its data under any circumstances, backed by mechanisms that make those decisions technically and legally enforceable. That ability must survive the ordinary frictions of cloud operations and the extraordinary pressures of crisis, legal compulsion, insider threat, or vendor failure. A policy that elevates corporate ownership and routing constraints above enforceable control misallocates attention and creates a false sense of safety. It pushes leaders to celebrate the address of the data centre and the nationality of a contractor while overlooking the power of a privileged session, a forgotten break-glass account, or an unverified enclave.

This misalignment is costly. Every time the eligible pool of technologies is narrowed by formalistic criteria, Canada pays a capability tax: fewer best-of-breed options today and, more importantly, a widening performance gap tomorrow as global AI and data services improve. In a race defined by compounding learning curves, forgoing frontier capabilities does not merely slow progress; it compounds disadvantage. The cost is not abstract. It shows up as slower service delivery, weaker fraud detection, poorer health outcomes, lagging productivity across regulated industries, and a constrained defence posture. When control mechanisms can keep world-class capabilities under Canadian, irrevocable control, trading away performance is unnecessary and strategically harmful.

2. From Postal Codes to Enforceable Control

The practical definition of sovereignty for digital government reduces to four enforceable pillars: keys, policy, attestation, and exit. Together they transform sovereignty from a pledge into a property of the system.

Keys are the ultimate arbiters of access. If the Crown (or a Canadian escrowed custodian subject solely to Canadian jurisdiction) holds the master encryption material, with split control and verifiable custody, data remains inaccessible to others by design. Hold-Your-Own-Key and Customer-Managed-Key patterns only matter when they are real — meaning the vendor cannot silently use a shadow copy; hardware security modules are anchored in Canadian custody; keys are generated, rotated, and destroyed on Canadian terms; and cryptographic operations are auditable. The difference between "we can prove we alone can decrypt" and "we asked the vendor to promise not to look" is the difference between sovereignty and trust.

Policy is how authority becomes action. Sovereign systems embed policy as code — identity-centric, least-privilege, just-in-time, and continuously evaluated. They constrain privileged operations to observable, approved workflows; bind elevated access to Canadian oversight; and require multi-party approvals for any control-plane change that could expose data. Policy is not a PDF binder; it is the runtime fabric that gates every access decision, with evidence emitted for every decision taken.

Attestation is the ability to verify the integrity of the platform and the enforcement of policy. It is not enough to say a workload runs in a secure environment; the government must be able to obtain cryptographic proof of the environment's state — measured boot chains, verified firmware, trusted execution environments — and tie that proof to the release of keys. If the attestation is wrong, or missing, keys do not flow and data cannot decrypt. Attestation extends beyond hardware. It encompasses supply chain verifications of images, signed builds, and policy bundles, as well as continuous posture monitoring that makes drift visible in minutes, not in annual audits.

Exit is the ultimate backstop. Sovereignty requires credible, low-friction portability of data, configurations, and operational runbooks. It demands contracts and architectures that make migration feasible without punitive switching costs, and that mandate termination assistance, escrow of critical artifacts, and portability of logs in usable formats. Exit is more than a contingency; it is an ever-present forcing function that disciplines vendors and protects the Crown from strategic dependence.

When these four pillars are real, geography becomes an additional control — not the cornerstone. In-country residency, including in-transit routing constraints, can reduce latency and jurisdictional risk, but they do not define sovereignty. They are one layer of a multi-layer control stack.

3. The Compounding Capability Tax

Canada's instinct to narrow the eligible ecosystem to domestically owned vendors or to demand absolute in-country residency for every byte and packet creates a compounding capability tax. The first-order effect is obvious: fewer choices. The second-order effect is less visible but more damaging: weaker competition among remaining suppliers, slower feature velocity, and a widening performance gap as global platforms race ahead. In AI, where model quality and tooling improve monthly, the cost of lag compounds. A department that cannot access state-of-the-art language models for fraud analytics or service triage leaves measurable value on the table. A regulator without modern anomaly detection or secure data exchange tools enforces more slowly and with less precision. A defence agency constrained to tools a generation behind its peers faces higher operational risk.

The capability tax also shows up as talent tax. World-class engineers and data scientists want to work with world-class tools. If the federal technology stack excludes frontier capabilities, retaining and attracting the people who can bend those tools to the public good becomes harder. Procurement that treats sovereignty as address verification rather than enforceable control can thus deplete both the toolset and the talent willing to use it.

4. The False Binary

The choice is not "buy only domestic" versus "outsource sovereignty." Buying only Canadian technologies is insufficient to fix sovereignty; it only shrinks the toolbox. Conversely, relying uncritically on foreign technologies invites strategic dependence. The path forward is to combine best-of-world capabilities with Canadian, irrevocable control. That means accepting the global nature of innovation while refusing to outsource the levers that decide access. It means building a Canadian control plane over a heterogeneous substrate of domestic and global services, with the Crown — or trusted Canadian custodians — holding the keys, authoring policy, verifying attestation, and preserving exit options.

This hybrid posture has another benefit: it grows Canadian capacity through use, not through isolation. By engaging global platforms under Canadian control, the federal government can demand domestic economic multipliers — training, secondments, research partnerships, and supply-chain localization — without forgoing performance. It can set the conditions under which Canadian firms scale into global markets by building to verifiable, sovereignty-grade standards at home.

5. A Pragmatist Model

"Capability today, sovereignty always" is a principled, implementable framing. It commits to two non-negotiables — enforceable sovereignty over data, keys, and operations; and access to best-of-world capability — and reconciles them with tiered guardrails and economic multipliers. The guardrails scale by data criticality and mission risk. The multipliers convert federal spend into Canadian skills, IP, and jobs. The result is a system that performs at the frontier while remaining sovereign by design.

This model recognizes that not all workloads are equal. The controls necessary for public web content are not the same as those necessary for national security data or sensitive citizen records. A tiered regime ensures the Crown does not pay for maximum control where it is unnecessary, but never under-protects where it matters most. Meanwhile, economic multipliers ensure procurement dollars compound domestically — in training cohorts, apprenticeship programs, research chairs, sovereign cryptographic infrastructure, and partnerships that give Canadian SMEs meaningful roles in delivery.

The balance is not rhetorical. It shows up in architectures that bind key release to Canadian attestation authorities; in contracts that make operational sovereignty provable; in observability stacks that feed Canadian-controlled security operations centres; and in open standards that keep exit credible. With that frame set, the following recommendations translate principles into enforceable practice without prescribing a stepwise roadmap.

Recommendations for a Control-First, Capability-Maximizing Sovereignty Regime

Recommendation 1: Define sovereignty in operational terms and require Evidence-of-Control. Federal policy should redefine digital sovereignty as "enforceable control over access, processing, and movement of government data, evidenced continuously by cryptographic, operational, and legal mechanisms within Canadian jurisdiction." This definition should be tied to an Evidence-of-Control regime whereby departments must obtain and retain machine-verifiable proofs that keys are under Canadian custody, that policy is enforced as code, that platform integrity is attested before keys are released, and that exit paths are tested. Evidence, not assurances, must be the coin of the realm.

Recommendation 2: Establish a Government of Canada Key Custody Authority anchored in Canadian HSM infrastructure. Create a central, service-oriented key management authority that generates, stores, and uses cryptographic material within certified hardware security modules physically located in Canada and operated by the Crown or Canadian custodians subject exclusively to Canadian law. Keys should be split using multi-party controls so that no single entity — vendor or custodian — can act unilaterally. All cloud and SaaS providers used for sensitive workloads would integrate to this authority via standardized interfaces. Key generation and rotation events should be logged immutably, and key release should be conditional on validated attestation and policy checks.

Recommendation 3: Mandate confidential computing and remote attestation for sensitive workloads. Require that processing of designated data classes occur within trusted execution environments that support remote attestation. Tie the release of decryption keys to attestation evidence that verifies measured boot, firmware state, and workload identity, with an allow-list maintained by the Crown. Where confidential computing is not yet viable, enforce compensating controls such as threshold cryptography, robust data minimization, and architecture patterns that externalize decryption to sovereign services while keeping plaintext exposure narrow, time-bounded, and observable.

Recommendation 4: Embed policy as code with Canadian oversight of privileged operations. Adopt an identity-centric, least-privilege model across all environments, with just-in-time elevation and multi-party approvals for any action that could expose data or alter control-plane configurations. Privileged sessions should be brokered through Canadian-controlled systems, recorded by default, and subject to conditional access based on device health and location. Administrative actions must emit tamper-evident logs to a Canadian-controlled observability layer. Vendors should be contractually barred from establishing out-of-band access paths and required to disclose all administrative tooling used in support.

Recommendation 5: Treat in-country residency and in-transit controls as complementary, not defining. Continue to favour in-Canada data residency and domestic routing where they provide latency and jurisdictional benefits, but do not treat them as sufficient or defining conditions for sovereignty. Where in-transit domestic routing is mandated, use private connectivity and geofenced peering with enforceable routing policies, while acknowledging that routing guarantees are a complement to, not a substitute for, cryptographic control. Make residency a layer in the stack, not the stack itself.

Recommendation 6: Require contractual challenge and transparency obligations against foreign legal compulsion. All vendors should be bound to notify the Crown of any legal demands that could affect Canadian data or operations, to challenge such demands where legally permissible, and to cooperate with the Crown's legal response. Crucially, design systems so that, even under compulsion, vendors cannot access plaintext because they do not control keys or unilateral privileged access. Create consequences for breach of these obligations and require regular reporting on requests received and responses made, with independent audit rights.

Recommendation 7: Make exit and reversibility real through architecture and contract. Structure contracts to require export of data, configurations, logs, and model artifacts in open, documented formats at the Crown's request, with termination assistance priced and pre-negotiated. Architect workloads with portability in mind: modular service boundaries, infrastructure-as-code stored in Crown repositories, and data schemas that minimize provider-specific lock-in. Test exit annually for designated systems, not as a paper exercise but as a dry run that validates timelines, costs, and data integrity.

Recommendation 8: Create a tiered guardrail regime aligned to data criticality and mission risk. Publish a clear classification and control mapping that scales from low-risk public information to highly sensitive national security workloads. For each tier, specify key custody requirements, attestation strength, operational sovereignty expectations, observability depth, and exit testing frequency. Allow providers to meet higher tiers through a combination of native capabilities and Canadian overlays, but require cryptographic proofs and independent attestation at the top tiers. This ensures the Crown does not overpay for maximal control where it is unnecessary while never under-protecting where it is essential.

Recommendation 9: Build a sovereign observability and incident response fabric. Centralize log collection, metrics, traces, and security events for federal workloads into Canadian-controlled systems with scalable analytics and clear retention rules. Require providers to stream detailed, high-fidelity logs — including administrative actions and control-plane events — into this fabric in near-real time. Incident response should be led by Canadian authorities with vendor support, and playbooks should include rapid key rotation, forced session termination, policy redeployment, and attestation re-verification. Make post-incident evidence collection automatic and tamper-evident.

Recommendation 10: Set procurement to reward capability under control and require domestic multipliers. Update evaluation frameworks so that best-of-world capability under enforceable control wins. Price, performance, and control evidence should drive awards. At the same time, require domestic economic multipliers: commitments to train Canadian civil servants and SMEs; funded research partnerships with Canadian universities and labs; local SRE teams for designated systems; and open contributions that benefit Canadian ecosystems. Condition renewals on delivery of these multipliers and on demonstrable control evidence, not on marketing claims.

Recommendation 11: Govern AI with model-level and data-level sovereignty. For AI systems that handle sensitive data or make consequential decisions, require data lineage, consent tracking, and usage constraints enforced as code. Demand access to model cards, evaluation reports, and red-team findings. Where fine-tuning or domain adaptation occurs on Crown data, keep training corpora and resulting weights under Canadian key custody, with cryptographically controlled access for inference. For hosted frontier models, enforce inference through attested, isolated endpoints with strict input/output filtering governed by Canadian policy. Preserve the right to move to alternative models if performance or control declines.

Recommendation 12: Separate duties across independent Canadian custodians. Design separation of duties so that no single party can compromise sovereignty. Key custody, attestation authority, observability, and incident command should be held by distinct Canadian entities, with M-of-N approvals required for exceptional actions. This reduces insider risk and creates structural checks. Where a provider offers integrated capabilities, overlay Canadian controls to break potential single-party dominance over access or evidence.

Recommendation 13: Invest in a national cryptographic backbone and trust services. Fund a Canadian HSM grid, time-stamping authority, code-signing service, and attestation verification service that federal, provincial, and critical infrastructure partners can consume. Standardize APIs so providers integrate once and serve many public bodies. Extend services to SMEs delivering into government to raise the control floor across the domestic supply chain. These investments compound: every workload that binds to national trust services becomes easier to govern and easier to move.

Recommendation 14: Institutionalize continuous control monitoring. Move from periodic audits to continuous verification. Require dashboards that show, in near real time, key custody status, attestation pass/fail, privileged access events, policy drifts, and exit readiness metrics. Make these dashboards accessible to departmental CIOs, security authorities, and central agencies. Embed automated guardrails that block deployments lacking valid attestation or that force key rotation when anomalies are detected. Treat control health as a first-class SLO alongside uptime and latency.

Recommendation 15: Calibrate in-transit constraints to risk, and encrypt everywhere. Maintain end-to-end encryption with forward secrecy for all traffic, and prefer private connectivity for sensitive tiers. Where policy requires in-transit domestic routing, ensure routes are pinned and monitored, with cryptographic session metadata logged to the sovereign observability platform. Recognize that even perfect routing is not a control if keys can be compelled; insist that encryption keys are released only under Canadian control and attestation. Avoid turning routing policy into a ritual substitute for real control.

Recommendation 16: Make people part of sovereignty by design. Operational sovereignty depends on human process as much as on code. Build talent programs for cryptography, cloud security, SRE, and AI safety within the public service, and create secondment paths with providers that transfer know-how into government rather than draw it out. Require vendors to staff critical support roles in Canada and to train Canadian teams for hands-on-keyboard operations, while keeping privileged access under Canadian oversight and recording.

Recommendation 17: Align liability and incentives with control reality. Contracts should align liability with the locus of control. If the Crown holds the keys and enforces policy, it assumes certain responsibilities; vendors remain liable for platform integrity, attestation fidelity, and any deviation from agreed operational constraints. Introduce performance credits not only for uptime but also for control SLOs — timely attestation, log quality, key-release latency, and exit support responsiveness. Link renewals and expansions to proven control performance over time.

Recommendation 18: Expand sovereign patterns across intergovernmental and sectoral boundaries. Develop reusable blueprints — reference architectures, contract clauses, and control mappings — that provinces, municipalities, and regulated sectors can adopt. This federates the control paradigm across Canada's public sector while respecting jurisdictional differences. Encourage cross-sector exercises that test incident response, key rotation across domains, and coordinated exit for shared platforms.

Recommendation 19: Treat data minimization and purpose limitation as control multipliers. Reduce the blast radius of any compromise by collecting and retaining only what is necessary, segmenting data by purpose, and tokenizing or anonymizing wherever possible. Sovereignty is easier to guarantee when there is less sensitive data in scope, and when the data that must exist is partitioned so that no single compromise yields systemic exposure. Bake these principles into design reviews and procurement deliverables.

Recommendation 20: Communicate sovereignty and performance transparently. Publish an annual, independent report on the state of federal digital sovereignty and capability, with system-level scorecards that balance control evidence and service outcomes. Transparency disciplines the ecosystem and builds public trust. It also helps the market understand what the Crown values: real control plus measurable performance, not branding or promises.

6. Addressing Common Objections

One objection to a control-first model is that it is harder to procure and harder to verify than address-based rules. In practice, it is different rather than harder. It shifts effort from one-time checklist compliance to continuous assurance — exactly where effort should be in systems that change daily. The tools exist: modern key management, confidential computing, signed supply chains, and continuous monitoring are maturing rapidly. The Crown's role is to codify expectations, consolidate demand, and make integration with Canadian trust services the default path for suppliers who want to serve public missions.

Another objection is that control can never be absolute, so geography and corporate ownership offer necessary belt-and-suspenders protections. The answer is yes — and. Geography is a belt; corporate locus may be a suspenders; neither is the pants. A Canadian data centre operated by a Canadian company is a sensible preference where it does not force a capability trade. But when that preference crowds out frontier capabilities that can be brought under Canadian control, the policy becomes self-defeating. The government should preserve geography as a valuable layer, not elevate it to dogma.

A third objection is that demanding cryptographic control and attestation will scare away suppliers. In reality, it will sort the market. Providers that can operate at the frontier while meeting sovereignty-grade controls will win business. Those that cannot will adapt or exit. The result is a healthier ecosystem calibrated to public needs. And because control standards will be published and reusable, Canadian SMEs can build offerings that snap into the same trust fabric, multiplying domestic participation rather than throttling it.

7. The Economic Logic of Multipliers

Domestic economic multipliers are often misread as a tax on capability. They need not be. When tied to real training, research, and local delivery, multipliers translate federal spend into Canadian capacity that persists beyond any single contract. A provider that commits to train a cohort of Canadian SREs and cryptographers, to fund joint research chairs in verifiable systems, and to build incident response teams in Canada is not merely writing a cheque; it is growing the pool of people and institutions that make sovereignty sustainable. When those commitments are tracked and enforced alongside technical controls, they become part of a coherent strategy: global tools under Canadian hands, doing Canadian work, producing Canadian knowledge, and strengthening Canadian firms.

Multipliers also help address a practical constraint: the global scarcity of specialized skills. The federal government can use procurement to create predictable demand for training and to structure secondments that transfer operating knowledge into the public service. Over time, this reduces dependence on any single provider and makes exit less daunting. The capability gained is not just in tools; it is in teams.

8. What Success Looks Like

A successful "Capability today, sovereignty always" regime would feel different to executives and engineers alike. Executives would see dashboards that report not only on the availability of systems but on the health of sovereignty controls: which keys are where, which attestations passed, where privileged access occurred, how quickly exits were tested and validated. They would see procurement outcomes where best-of-world capability wins because it submits to Canadian control, and where domestic multipliers are visible in trained cohorts, new labs, and SMEs delivering critical components.

Engineers would experience a platform that defaults to control: deploying a workload automatically binds it to Canadian key custody; policy gates are obvious and enforced; attestation failures halt key release; logs flow to a sovereign observability plane; and privileged access requires Canadian approval and leaves a trail. They would have access to modern AI and data tooling, wrapped in guardrails that make safe use the easiest path. Incident response would be faster because the building blocks — rotation, revocation, attestation re-checks — are integrated and rehearsed.

Citizens would encounter services that are faster, more reliable, and demonstrably private. The government would be able to show, not merely say, that sensitive data remained under Canadian control, that decisions were taken by systems and people accountable to Canadian institutions, and that reliance on global technologies did not compromise sovereignty but, rather, increased capability under enforceable Canadian terms.

9. Conclusion

Canada's digital sovereignty challenge is not a paradox to be endured; it is a design problem to be solved. The current emphasis on corporate locus and geography, including absolute in-Canada residency for data at rest and in transit, focuses on where data sits and who owns the vendor instead of who can actually access, decrypt, or compel the data. In practice, sovereignty lives or dies on the question of enforceable control: keys under Canadian custody; policy enforced as code with Canadian oversight; attestation that binds truth to the release of secrets; and exit that keeps the Crown free. When those pillars are real, geography becomes a useful layer rather than a misplaced foundation.

The alternative — confining procurement to domestic providers in the hope that ownership equals control — imposes a capability tax that compounds year after year as global AI and data capabilities accelerate. Canada should not trade away frontier capabilities when control mechanisms can keep those capabilities under irrevocable Canadian control. Nor should it accept strategic dependence by trusting foreign technologies without enforceable constraints. A "Capability today, sovereignty always" model resolves the false binary. It mandates sovereignty as an operational property and insists on performance that matches the world's best, wrapped in tiered guardrails and multiplied by domestic investments that build Canadian skills, IP, and firms.

The test of this model is simple. If a vendor disappeared tomorrow, could the government continue? If a foreign authority knocked, could the vendor comply without Canadian consent? If a platform's integrity drifted, would keys withhold themselves until truth returned? If the answer to these questions is yes, sovereignty is a press release; if the answer is no, sovereignty is a property. Canada can choose the latter. By adopting enforceable control as the core, demanding evidence rather than promises, calibrating guardrails to risk, and directing spend to build domestic capacity, the federal government can deliver capability today and sovereignty always — confidently, measurably, and durably in the national interest.

← Back to all essays

Stay informed

New essays on digital sovereignty, AI governance, and national strategy — delivered when published.