Outages are partial before they are total. Sovex keeps settlement moving through the failures a real nation experiences — a severed region, a lost data center, a saturated link — degrading in defined steps rather than collapsing.
The system moves between named states with documented guarantees so behavior under stress is known in advance.
Operation steps through named modes — full settlement, constrained settlement, store-and-forward, local-only — each with stated guarantees.
Mode changes are triggered by measured conditions such as quorum loss or link saturation, and every transition is recorded for audit.
Participants are told which mode is in force, so downstream systems and operators act on known guarantees rather than guesses.
A network partition should not freeze commerce inside the cut-off area, so regions can act within delegated authority.
Regional nodes continue authorizing local transactions when cut off from the national core, within pre-delegated limits.
The central bank can grant regions bounded settlement authority so an isolated area keeps functioning without the core.
When the partition heals, regional activity reconciles into the national hash-chain through the same deterministic replay used for offline transfers.
When bandwidth is scarce, the system protects the settlement path by shedding everything that is not settlement.
Under bandwidth pressure, settlement traffic is prioritized above telemetry and analytics so payments clear while noise waits.
Transactions accepted during a link outage are durably queued and forwarded in order once a path recovers.
The system throttles intake and sheds non-critical load to protect the integrity of the core path rather than accepting corruption.
When machines go dark, consensus adapts within pre-authorized bounds instead of stalling entirely.
Consensus can proceed on a smaller, pre-authorized quorum when nodes are unreachable, with the reduction written into the ledger.
When write consensus is unavailable, balance inquiries and validations continue, keeping the system useful while it heals.
Where a choice is forced, the system refuses to fork the authoritative ledger; it degrades what it offers before it compromises what it records.
Recovery is a reconciliation event that produces proof, not a best-effort catch-up that hides what happened.
Queued and regional transactions are replayed in causal order, and the hash-chain makes any gap or tamper immediately visible.
Each recovery produces a verifiable record of what was accepted, deferred, or rejected during the degraded window.
Throughout, operators see the current tier, backlog depth, and reconciliation progress, so central-bank staff retain situational command.
Talk to us about degraded-mode operation in a sovereign deployment.