SOVEX
CBDC Data Centers Sovereign AI Tokenization Deep Tech Architecture About Team Request access
Sovereign AI / Sovereign models / Owner-held weights

Owner-held weights.

The nation holds the model weights. There is no external licence to renew, no remote flag that can disable the model, and no provider positioned to read or throttle what the state runs.

The owner physically and cryptographically holds the weights

Custody means the weight files live under sovereign control, not merely accessible through someone else's platform.

01

Weights on owner storage

The checkpoint files reside in the owner's in-nation storage under the owner's keys, rather than being held by a vendor and exposed only through an API.

02

Keys held by the state

Consistent with the core principle that owners hold the keys and weights, decryption and export of the model are controlled by keys the nation holds, not by Sovex.

03

Exportable artifact

The owner can move, back up, or archive the weights on its own terms, because it possesses the actual files and the means to decrypt them.

04

No custodial middle party

There is no arrangement in which a third party holds the true weights on the nation's behalf and mediates access; custody is direct.

Nothing external can disable a model the nation owns

A sovereign model must keep working regardless of any provider's status, intent, or jurisdiction.

01

No licence check

The model does not phone home to validate a licence before it runs, so it cannot be switched off by an expiry, a billing dispute, or a policy change abroad.

02

No remote disablement

There is no vendor-held flag, token, or entitlement server that gates inference; the ability to run is a property of possessing the weights.

03

Offline-capable

Because there is no authorization dependency, the model can serve even if external connectivity is cut, which matters for infrastructure a state relies on.

04

Continuity under sanction

Ownership of the weights means capability the nation has built cannot be revoked as leverage by any external party.

The owner can prove the weights are authentic and unaltered

Holding the weights is paired with the ability to verify exactly what one holds.

01

Post-quantum attestation

Checkpoints are signed with ML-DSA-65 (FIPS 204), so the owner can verify a weight file is the genuine artifact and detect tampering under post-quantum assumptions.

02

Hash-chained releases

Model releases are recorded in a tamper-evident hash chain, making any silent swap of a deployed checkpoint detectable against the recorded lineage.

03

Served weights match held weights

The owner can confirm that the model answering in production is the same signed artifact it holds, closing the door on an undisclosed substitution.

04

Independent verification

Verification uses the owner's own keys and standard cryptographic checks, so the state need not trust Sovex's assertion to confirm authenticity.

Weight custody is a governance instrument, not just a technical fact

Owning the weights lets the state set its own rules for how the model is changed and used.

01

Owner-set change control

Updates, fine-tunes, and rollbacks happen on the owner's authority and schedule, because no external party controls the artifact being changed.

02

Accountable lineage

Every version the state runs is tied to a signed, hash-chained record, so governance bodies can account for which model was in force at any time.

03

Confidential by construction

Since the weights are not held or observed by a provider, the model's internals and the queries it serves stay confidential to the owner.

04

Succession-proof

Ownership persists independent of any commercial relationship, so a change of vendor or contract does not put the model itself at risk.

Build it sovereign.

Talk to us about owner-held weights in a sovereign deployment.