Your SaaS stack is probably exposed. We can fix that.

For Canadian organizations that need to document, remediate, or defend their data sovereignty posture — led by the person who built the 755-tool Sovereignty Index.

Book a Free Call →

Data sovereignty consulting

When your stack is complex, your regulatory environment is layered (PIPEDA, Law 25, FIPPA, PIPA), or you’re ready to actually migrate. Every engagement is led by Joshua van Es — the person who built the Sovereignty Index and researched every tool page on this site.

Sovereignty Assessment
$5,000+
2–3 weeks
Full audit of your SaaS stack against Canadian sovereignty requirements.
  • Complete SaaS inventory and jurisdiction mapping
  • CLOUD Act exposure analysis per tool
  • Transfer Impact Assessments (Law 25, FIPPA)
  • Subprocessor chain analysis
  • Prioritized remediation plan
  • Board-ready summary report
  • 60-minute walkthrough with your team
Book a Call →
Strategy & Migration
$15,000+
4–8 weeks
Assessment plus hands-on support choosing alternatives and planning the move.
  • Everything in Sovereignty Assessment
  • Canadian alternative evaluation and shortlisting
  • Migration sequencing and risk assessment
  • Vendor negotiation support
  • Procurement language for RFPs
  • DPA review and recommendations
  • Implementation oversight
Book a Call →
Ongoing Advisory
$2,000+
per month
Continuous monitoring as your stack and regulatory environment evolve.
  • New tool sovereignty evaluation before adoption
  • Quarterly compliance review and update
  • Regulatory change monitoring and alerts
  • Vendor DPA and contract review
  • Board reporting on sovereignty posture
  • Priority access to new research
  • Direct line to Joshua van Es
Book a Call →

Every engagement starts with a 30-minute call. No cost, no commitment.

Book a Free Call →

Not sure you need consulting? Start with a $99 compliance report or a free HarbourScan.

Frequently asked questions

What is a data sovereignty audit?

We map every SaaS tool your organization uses to its parent jurisdiction, CLOUD Act exposure, data residency options, and encryption posture. The result is a prioritized remediation plan showing which tools create compliance risk and what to do about each one.

Do I need a Transfer Impact Assessment under Law 25?

If your organization processes personal information of Quebec residents and uses any SaaS tool that stores or processes data outside Quebec, you likely need a TIA for each tool. This includes most US-owned SaaS even if they offer Canadian data residency.

How much does a privacy impact assessment cost?

Industry-specific assessments start at $99 for self-serve reports covering 18–24 common tools. Custom assessments for your exact stack are $500. Full compliance packages are $2,500. Consulting engagements for complex organizations start at $5,000.

How is this different from a privacy consultant?

Privacy consultants do broad compliance work. We specialize exclusively in technology sovereignty — which tools are exposed, what the jurisdictional risks are, and what alternatives exist. We have the deepest dataset on SaaS vendor jurisdictions in Canada (755+ tools mapped).

Can I start with a $99 report and upgrade later?

Yes. Many consulting clients start with a self-serve assessment, then engage consulting when they need hands-on help. The $99 report gives us a baseline to work from.