MeetingCanary LogoMeetingCanary

Why data sovereignty matters so much

Why data sovereignty matters so much

I’ve been a huge fan of Software as a Service (SaaS) for as long as I can remember, for most people in the workforce today it is hard to even comprehend what happened before Amazon pioneered the cloud revolution 30 years ago.

Without SaaS my modest business success would have simply been impossible. My first IPO was only 5 years after the cloud was born – the alternative would have been extraordinarily difficult – in effect I would have had to build a data centre – and become my own ISP. I know how hard this is, as the company I floated on the London Stock Exchange way back when, did exactly that. We were so nervous (and had raised enough cash to do it) about the new cloud universe that we built own web servers network, purchased a hideously expensive data connection and even spent around £100k on a massive UPS (Uninterruptible Power Supply) – which looked rather like a jet engine and is probably still in our old offices in Oxford…..

So everything is fine right?

Well no it’s actually not.

SaaS and Cloud are vulnerable, cables can be cut, data can be stolen in transit (and don’t think encryption in transit helps – because bad actors can steal the encrypted data, ‘bank it’ and wait for Quantum Computing to decode…). But there is something more worrying still. Because companies want to ‘protect’ themselves, they require their suppliers to gain compliance with frameworks like SOC 2 and ISO 27001 – however AI is debasing the validity of such standards – as numerous consultancies are popping up saying ‘we can help you comply’ for a 20th of what my last company spent on compliance. How? By using LLMs to write all the policies and procedures the principles and controls. Is that secure? Is it? Well no, I’d argue that it’s not in the spirit of ‘secure’.

Is there a solution?

Let’s go back to a time before cloud. What did us old chaps and chappeses do then? Well there was a big old computer called a main frame, lots of ‘dumb’ terminals on desks with bright screens of green or yellow with pixels that you could actually see, a building full of miles of Cat 5 and a team of engineers – often in sweating profusely in the large main frame cave keeping it working. Was it secure? Well in so much as there was no external access to speak of, yes it was. I mean people could print data out and take it home, but it was a safer time as no one could be arsed to type it back in and anyway there were no PCs to type on, because, as a CEO of the huge IT company DEC said at the time “There is no reason anyone would want a computer in their home”. BTW that quote is often tributed to Bill Gates, instead he was supposed to have said ‘640K of memory ought to be enough for anybody’ which he also denies.

Anyway, as systems evolved software began to emerge which could be loaded into the computer cave by the computer cavemen, and people could access said software. This became known later as ‘on premise’, it was ugly to maintain as the software was often configured to be unique to the company, so after the first few 1000 installations firms had to employ 100s of engineers to go to the ‘premise’ and fix the software when it inevitably went wrong.

But was it secure? Well again it was probably more secure because it was within the company network rather than outside.

So we’re in a bind, SaaS and Cloud are perhaps not as secure as you imagine, standards are becoming farcical fig leaves, probably mainly used for insurance purposes, and Q Day – when Quantum compute may break encryption is a very few years away (Google say 2029, yup, that’s 30 months away).

In the world of Meeting Canary this is a worry, especially given that the content of internal and external meetings is the very essence of what a company does and therefore highly sensitive. Our approach is terribly pragmatic – we do not hold transcripts, and any content that relates to the actual meeting is posted into the clients own Teams chat instance – and even we can’t reach it.

But there is actually more that could be done…

While our cloud SaaS version offers robust security, certain organisations, particularly those in highly regulated sectors like finance, healthcare, or government, operate under strict compliance mandates that forbid third-party data processing. Providing a self-hosted, private version of Meeting Canary answers this need directly. By deploying the monitoring architecture entirely within their own cloud infrastructure, companies retain absolute ownership of their network traffic. Audio streams, video feeds, and real-time analytics never leave their security perimeter, eliminating the risk of third-party data leaks, satisfying rigorous data sovereignty laws, and allowing internal security teams to maintain full control over encryption keys and access logs.

So those how say that ‘the past is a foreign country; they do things differently there’ are wrong, the past is the place we learned things, and sometimes a revisit is not a bad idea at all.