SOVEX
CBDC Data Centers Sovereign AI Tokenization Deep Tech Architecture About Team Request access
Security & Post-Quantum / Key custody / Key recovery and governance

Key recovery and governance.

An institution must survive the loss of a custodian without ever concentrating power in one. Recovery and governance turn key custody from a single point of failure into a controlled, auditable institutional process.

Authority is split so that no individual is a single point of failure

Recovery capability is distributed across custodians by design.

01

Threshold custody

Recovery secrets are split into shares under an M-of-N scheme, so reconstituting a key requires a quorum and no lone actor can do it.

02

Distributed shareholders

Shares are held by separated custodians — across departments, sites, or institutions — so compromise of one holder does not yield the key.

03

No full-secret assembly

Where supported, shares combine inside protected hardware so the complete secret is never materialized in one place even during recovery.

04

Configurable thresholds

The owner sets quorum sizes per key according to its authority, applying stricter thresholds to monetary roots than to routine operational keys.

Loss of a custodian is a procedure, not a catastrophe

Recovery is a rehearsed, authorized ceremony with a defined chain of control.

01

Authorized triggers

Recovery can only begin under defined conditions — lost custodian, failed module, succession — each requiring documented authorization before shares are touched.

02

Witnessed ceremony

Reconstitution follows a scripted ceremony with multiple witnesses and recorded roles, so the act of recovery is itself governed and observable.

03

Recover into hardware

A recovered key is restored directly into an HSM rather than exposed to general systems, preserving the hardware custody boundary through the event.

04

Rotate after recovery

Because recovery necessarily involves more exposure, policy can require rotating to a fresh key afterward and retiring the recovered one.

Institutions outlive the people who hold their keys

Governance defines how authority passes across time and personnel.

01

Custodian onboarding

Adding a custodian re-issues shares under quorum, so membership in the recovery set changes only with collective authorization.

02

Custodian revocation

Departing custodians are removed by re-sharing to a new set, invalidating their old shares without exposing the underlying key.

03

Delegation certificates

Operational authority flows through owner-signed certificates with scope and expiry, so day-to-day signers can change without moving the root.

04

Continuity of authority

Roots persist across administrations and staff turnover, so a sovereign owner's control is institutional rather than tied to any individual's tenure.

Every governed action leaves a tamper-evident trace

Governance is only real if it is enforced and recorded.

01

Policy-as-signed-rules

Quorum sizes, roles, and permitted operations are expressed as owner-signed policy that the platform enforces, not as informal convention.

02

Hash-chained audit trail

Recovery events, custodian changes, and delegations are appended to the tamper-evident ledger, giving regulators an immutable record of who did what.

03

Separation of duties

Proposing, approving, and executing a governance action are held by different roles, so no one person can both authorize and carry out a change.

04

Fail-closed governance

If quorum or policy conditions are not met, the action does not proceed; the system withholds authority rather than granting a weaker form of it.

Recovery and governance are designed to be tested, not assumed

An owner should be able to prove the process works before they need it.

01

Rehearsable ceremonies

Recovery and rotation ceremonies can be exercised on non-production keys so custodians are practiced and the runbooks are proven.

02

Owner-defined runbooks

The procedures, participants, and thresholds are documented and owned by the institution, so governance reflects the owner's mandate rather than the vendor's defaults.

03

Independent review

The recovery and governance controls are part of the production hardening and external audit underway across the platform's security engines.

04

Non-custody preserved

Throughout recovery and succession, Sovex never becomes a shareholder or backdoor, so zero-custody survives every governance event.

Build it sovereign.

Talk to us about key recovery and governance in a sovereign deployment.