An institution must survive the loss of a custodian without ever concentrating power in one. Recovery and governance turn key custody from a single point of failure into a controlled, auditable institutional process.
Recovery capability is distributed across custodians by design.
Recovery secrets are split into shares under an M-of-N scheme, so reconstituting a key requires a quorum and no lone actor can do it.
Shares are held by separated custodians — across departments, sites, or institutions — so compromise of one holder does not yield the key.
Where supported, shares combine inside protected hardware so the complete secret is never materialized in one place even during recovery.
The owner sets quorum sizes per key according to its authority, applying stricter thresholds to monetary roots than to routine operational keys.
Recovery is a rehearsed, authorized ceremony with a defined chain of control.
Recovery can only begin under defined conditions — lost custodian, failed module, succession — each requiring documented authorization before shares are touched.
Reconstitution follows a scripted ceremony with multiple witnesses and recorded roles, so the act of recovery is itself governed and observable.
A recovered key is restored directly into an HSM rather than exposed to general systems, preserving the hardware custody boundary through the event.
Because recovery necessarily involves more exposure, policy can require rotating to a fresh key afterward and retiring the recovered one.
Governance defines how authority passes across time and personnel.
Adding a custodian re-issues shares under quorum, so membership in the recovery set changes only with collective authorization.
Departing custodians are removed by re-sharing to a new set, invalidating their old shares without exposing the underlying key.
Operational authority flows through owner-signed certificates with scope and expiry, so day-to-day signers can change without moving the root.
Roots persist across administrations and staff turnover, so a sovereign owner's control is institutional rather than tied to any individual's tenure.
Governance is only real if it is enforced and recorded.
Quorum sizes, roles, and permitted operations are expressed as owner-signed policy that the platform enforces, not as informal convention.
Recovery events, custodian changes, and delegations are appended to the tamper-evident ledger, giving regulators an immutable record of who did what.
Proposing, approving, and executing a governance action are held by different roles, so no one person can both authorize and carry out a change.
If quorum or policy conditions are not met, the action does not proceed; the system withholds authority rather than granting a weaker form of it.
An owner should be able to prove the process works before they need it.
Recovery and rotation ceremonies can be exercised on non-production keys so custodians are practiced and the runbooks are proven.
The procedures, participants, and thresholds are documented and owned by the institution, so governance reflects the owner's mandate rather than the vendor's defaults.
The recovery and governance controls are part of the production hardening and external audit underway across the platform's security engines.
Throughout recovery and succession, Sovex never becomes a shareholder or backdoor, so zero-custody survives every governance event.
Talk to us about key recovery and governance in a sovereign deployment.