Sovereign assets must survive lost officers, rotated keys, and contested authority. Recovery and governance make control durable without ever creating a backdoor the operator could use.
Recovery is designed as a threshold operation among parties the owner designates, so no single loss is fatal and no operator can impersonate the owner.
Signing authority can be reconstituted only when a defined quorum of owner-designated guardians cooperates. A single lost or compromised guardian neither blocks recovery nor enables it alone.
The platform holds no share, escrow, or master key capable of recovering owner control. Recovery is a capability of the owner's governance set, not a service the operator can perform.
Recovery shares are distributed across independent custodians or jurisdictions the owner chooses. Compromising recovery requires colluding across boundaries the owner deliberately separated.
Every recovery is written to the hash-chained ledger with the participating quorum and the new key binding. A recovery cannot happen silently or be denied after the fact.
Control can move to new keys or new custody tiers while the history signed under old keys remains valid and verifiable.
A rotation is a transition signed by the outgoing authority (or the recovery quorum) that names the incoming key. Successor authority is provable back to the party that granted it.
Entries signed under a retired key remain verifiable under that key. Rotation changes who may authorize future transitions, not the validity of the past.
An owner can move from self-custody to an HSM or qualified custodian, or back, as a governed rotation. The asset's identity and history are continuous across the change.
On suspected compromise, a key can be revoked and succeeded under governance so that no further transitions authorize against the exposed key, bounding the loss to what already committed.
Who may authorize, approve, recover, and rotate is encoded as policy the ledger enforces rather than convention the operator interprets.
Owners define the signing keys, quorum thresholds, and approver roles that constitute valid authority for each asset. The ledger accepts only transitions that satisfy those declared rules.
Changes to the governance set itself require the owner's governance quorum. The operator cannot alter who holds authority, and no minority of officers can seize it.
Owners can define freeze conditions that halt transitions on an asset pending review. The freeze is an owner-governed action, not an operator override, and is itself recorded.
Recovery guardians, approvers, and custodians can be split across institutions or jurisdictions so that concentrated control requires collusion the governance design forbids.
The point of recovery and governance is durable, provable control — so every act that changes authority is preserved and independently checkable.
Every grant, rotation, recovery, and freeze commits into the hash-chained ledger. The full lineage of who held authority over an asset is reconstructable and cannot be silently edited.
Governance transitions are themselves ML-DSA-65 signed, so the record of who changed control survives the same long horizon as the assets being governed.
With the public governance keys and the chain, an auditor can confirm that every change of authority followed the owner's declared rules, without trusting the platform's account of events.
Because authority, history, and evidence are all owner-held and in-nation, control persists through personnel change, custody migration, and operator transition without dependence on any single party.
Talk to us about recovery and governance in a sovereign deployment.