All posts

Why digital sovereignty matters for Canadian tech

Ross Hill · September 17, 2026

Most arguments for Canadian infrastructure get made one company at a time. Where does our data sit, whose law reaches it, what does the contract say. Those are the right questions for a buyer, and we have answered them elsewhere. This post asks a different one. What does it cost the Canadian technology sector, in aggregate, that nearly all of its infrastructure is rented from a small number of foreign companies?

This is an opinion piece. Dependence at this scale is a strategic exposure, not a matter of taste. Residency and sovereignty are separate ideas with separate consequences, and we define both in data residency vs data sovereignty. What follows takes those definitions as read and builds on them.

Start with how much of the stack is rented

Cloud computing is now the ordinary way Canadian businesses run software. In Statistics Canada's 2023 Survey of Digital Technology and Internet Use, cloud computing was the most commonly used information and communications technology at 48 percent of businesses, up three points from 2021. In the information and cultural industries, the figure was 81 percent. That is the substrate the sector builds on, and most of it is rented from providers that answer to another country's law.

The federal government is direct about this. Canada's 2026 national AI strategy, AI for All, states that "sovereign compute capacity is nascent, leaving Canadian organizations reliant on foreign providers for the infrastructure that increasingly underpins economic, scientific, and public-sector activity," and that "Canadian companies store sensitive data in foreign jurisdictions." That is the government's own description of the dependency.

How concentrated that spending is in Canada has been estimated rather than officially measured. The advocacy group Canadian Anti-Monopoly Project, in its June 2026 report Parting Clouds, estimates Amazon, Microsoft and Alphabet at roughly 85 percent of the Canadian cloud market. The most detailed public accounting comes from the United Kingdom, where the Competition and Markets Authority ran a market investigation into cloud infrastructure services. Its final decision report, published in July 2025, found AWS and Microsoft holding a combined 60 to 80 percent of UK cloud spending and concluded that competition was not working well.

The UK is not Canada, and its numbers are not ours. But the suppliers are the same companies, so the findings are worth reading from here.

What dependence actually costs

The costs are easier to describe than to total.

Foreign law follows the company, not the server. This is the part most people already know, and the part we have written about at length. A US-incorporated provider generally stays reachable by US legal process wherever its data centres are. A Toronto region does not change that. For one company, that is a compliance question. For the sector, it means the rules governing most of the stack are written in another country and can change on that country's schedule.

Switching costs set the real price. The CMA's final decision identified data egress fees, barriers to interoperability, and the licensing of Microsoft's business software on the cloud as the features restricting switching and multi-cloud use. This is the part of dependence that never appears on a pricing page. When leaving is expensive, the list price is not the price you are actually paying. Lock-in is not unique to foreign providers, but it is what makes the jurisdiction exposure durable. If leaving were cheap, hosting under foreign law would be a decision you could revisit next quarter. Priced as it is, it is a position you are held in.

Terms improve when somebody has bargaining power, and it does not have to be you. In March 2024, AWS announced it would waive data transfer out charges for customers moving off AWS, one of the egress fees the CMA would later flag. AWS applied the change to customers everywhere and described it as following "the direction set by the European Data Act." The Data Act entered into force in January 2024 and became applicable in September 2025, and it includes rules on switching between providers of data processing services.

The improvement was real, it benefited Canadian customers, and no Canadian had any part in producing it. Europe wrote a rule and the terms moved. Canada currently has no comparable rule and no comparable weight, so the terms move for us only when they move for someone else.

What a healthier domestic layer looks like

Not a national champion. One Canadian hyperscaler subsidised into existence would reproduce the problem with a different flag on it. The useful version is duller and more achievable.

  • More than one credible option per layer. Compute, storage, DNS, email, payments. A layer with a single Canadian provider is a dependency too, just a closer one.
  • Buyers who actually buy. Supply follows demand. A Canadian option that gets asked about but never bought does not stay in the market long.
  • Portability as a design rule. Containers, standard databases, open formats, configuration you can read. A stack you cannot move is a lock-in, whoever is hosting it.
  • Public money aimed at what private capital will not fund. The Canadian Sovereign AI Compute Strategy commits $2 billion over five years starting in fiscal year 2024-2025 for domestic compute. The logic is sound: build capacity where the market will not, then let companies use it.

The supply side is thinner than the demand side right now. When we assembled our own stack we found real gaps, particularly in payments, and we wrote up what we chose and where we had to compromise. We also keep a running catalogue of Canadian and non-US alternatives by category, which is a more useful contribution than another opinion about sovereignty.

The honest limits

Canada is not going to build a full domestic replacement for the global cloud, and it should not try. The federal strategy says as much: it commits to a "build-partner-buy" approach for AI infrastructure, "building its key sovereign capabilities domestically whenever possible, while partnering with trusted allies or buying existing market solutions when appropriate." That is a realistic limit to set. Autarky in software would be expensive, slow, and worse for Canadian companies than the thing it replaced.

The Canadian managed-service ecosystem is smaller, community resources are thinner, and some unit costs are higher. We covered the practical version of this in our guide to building a SaaS on Canadian infrastructure. Plenty of teams have no data obligation and no jurisdictional preference. For them, US infrastructure is a reasonable default and we are not going to pretend otherwise.

The goal is choice, not self-sufficiency. A market with real alternatives disciplines the incumbents even for buyers who never switch, because the option to leave is what gives a negotiation any content at all. Right now, for a lot of Canadian teams, that option does not meaningfully exist. That is the exposure, and it is fixable by ordinary commercial means rather than by anything dramatic.

Where we fit

MapleDeploy is one layer of this. We run managed Coolify, a deployment platform, on dedicated VMs in Toronto, priced in Canadian dollars. It is open source and runs on a standard server, so the exit path is an ordinary migration rather than a negotiation with us. That is deliberate. An argument about dependence is not worth much from a provider who makes leaving hard.

If jurisdiction matters to what you are building, our Canadian hosting page has the specifics.

Put your stack on Canadian infrastructure

A dedicated Coolify server in Toronto, flat pricing in Canadian dollars. Try Starter or Pro free for 30 days.