<

Blog

>

What does sovereign technology mean in 2026?

Security Journal UK hears exclusively from Daniel Clarke, Chief Technology Officer of StirlingX about sovereign technology.

Plenty of companies describe their technology as sovereign, when in reality, almost none of it is.

Given globalisation, true sovereignty is close to impossible. Take a software library used for object detection in computer vision applications.

We would struggle to build that in a purely sovereign way, because we rely on libraries developed and built up over decades.

We cannot trace every line of that code and check it does exactly what it claims and only what it claims.

We can have good confidence, but without huge cost, we cannot have certainty.

Hardware is no different as a motor or a battery depends on lithium and magnets, and there are very few sources for those minerals in the West.

Manufacturing a component in the UK does not make it sovereign if the raw materials came from somewhere we don’t control.

So this version of sovereignty falls apart on contact.

A more useful definition starts with the dictionary. Sovereignty is supreme power and authority: the authority to govern oneself.

Applied to a state, means self-government. Applied to a technology company such as StirlingX, it means the authority to govern our own technology stack.

That distinction matters because “we are a sovereign tech company” says very little when an unnamed group wrote the linear algebra library inside your computer vision model twenty years ago.

At StirlingX, we break sovereignty down into three engineering principles: security, resilience, and robustness. Hardware, avionics, and software each carry different amounts of each.

Security

Security matters most in software.

You want code with no security flaws that let someone else exploit it, and no inbuilt zero-days that quietly push information out to a competitor or an adversary.

Every component in our stack is vetted to remove adversary-sourced elements.

Data is encrypted end to end, from the point of collection through to processing.

Our secure development lifecycle, our certifications (ISO 27001, SOC 2 Type II) and our work with Second Front Systems let us deploy into the highest-level government environments.

Security also shapes how we handle failure.

Assume a zero-day exploit exists and tries to send data outward, if the stack is built correctly, we catch that data before it leaves our servers.

The information that matters stays protected even when something goes wrong.

Resilience

Resilience lives in the supply chain.

For example, with batteries, I can buy them from China, from Europe or from the UK, and depending on cost, I can sometimes trace the minerals back to source: a lithium mine in Cornwall, or one in West Africa.

None of those routes is sovereign on its own.

What makes the system resilient is having more than one of them.

If a supplier disappears or a region becomes inaccessible, there’s another route to the same component.

That’s the benefit in practice.

You’re not locked into one supplier or one region and when a requirement changes, you adapt the supply, not the whole system.

Robustness

Robustness is what lets resilience work.

If we develop the system well, we can swap out one battery for another and it still functions the way we and the end users expect.

The same goes for cameras, motors and communications. Components change. Behaviour does not.

In software, robustness has a specific meaning.

The software has to do what you expect it to do and not do the things you expect it not to do.

We build for austere, contested conditions rather than laboratory ones: sustained throughput, degraded connectivity, imperfect data.

That is the reality of field operations, and the system has to hold up in it.

Why this matters in 2026

For a customer, all of this comes down to risk.

The most widely deployed data-capture systems on the market are technically very capable and extremely prolific.

This is where the problem lies as we do not know the likelihood of a cybersecurity incident involving them, and we cannot prove where their data goes.

We have a risk with an unknown likelihood and a serious impact: an authoritarian adversary gaining high-resolution mapping of our critical national infrastructure.

You cannot measure that risk, so unless you are comfortable with the consequence, you have to address it.

Defence and civil infrastructure used to be treated as separate worlds.

They are not anymore.

When General Sir Nick Carter launched the Integrated Operating Concept in 2020, he said our adversaries want to win without going to war.

The way they do that is to go after civil infrastructure rather than defence infrastructure: the power, gas, internet, and communications a society depends on, and the critical points within them.

That is the gap the Cyber Security and Resilience Bill is trying to close as it moves through Parliament.

For our purposes it works as a handrail.

Governance and compliance set out how you build the technology.

Incident reporting sets out how you respond when something happens, and eventually something will happen so every organisation should plan on that.

Sovereign technology is about minimising the likelihood of a security risk being realised, then minimising the impact when it is.

Our technology gives customers the capability to do both if they choose to use it. If they choose not to, they are choosing to accept a risk they may not understand.

Share this post

StirlingX brand mark

Ready to see what’s possible?

Experience secure autonomy in action. Partner with StirlingX and transform the way you monitor, manage and protect your assets.