SOVEX
CBDC Data Centers Sovereign AI Tokenization Deep Tech Architecture About Team Request access
Tokenization / Custody & keys / Recovery and governance

Recovery and governance.

Sovereign assets must survive lost officers, rotated keys, and contested authority. Recovery and governance make control durable without ever creating a backdoor the operator could use.

Lost keys are recoverable by the owner, never by the platform

Recovery is designed as a threshold operation among parties the owner designates, so no single loss is fatal and no operator can impersonate the owner.

01

Threshold recovery

Signing authority can be reconstituted only when a defined quorum of owner-designated guardians cooperates. A single lost or compromised guardian neither blocks recovery nor enables it alone.

02

No operator recovery path

The platform holds no share, escrow, or master key capable of recovering owner control. Recovery is a capability of the owner's governance set, not a service the operator can perform.

03

Distributed guardian shares

Recovery shares are distributed across independent custodians or jurisdictions the owner chooses. Compromising recovery requires colluding across boundaries the owner deliberately separated.

04

Recorded recovery events

Every recovery is written to the hash-chained ledger with the participating quorum and the new key binding. A recovery cannot happen silently or be denied after the fact.

Keys change without rewriting who owned what

Control can move to new keys or new custody tiers while the history signed under old keys remains valid and verifiable.

01

Signed key succession

A rotation is a transition signed by the outgoing authority (or the recovery quorum) that names the incoming key. Successor authority is provable back to the party that granted it.

02

History stays valid

Entries signed under a retired key remain verifiable under that key. Rotation changes who may authorize future transitions, not the validity of the past.

03

Custody-tier migration

An owner can move from self-custody to an HSM or qualified custodian, or back, as a governed rotation. The asset's identity and history are continuous across the change.

04

Compromise containment

On suspected compromise, a key can be revoked and succeeded under governance so that no further transitions authorize against the exposed key, bounding the loss to what already committed.

Authority is expressed as explicit, verifiable rules

Who may authorize, approve, recover, and rotate is encoded as policy the ledger enforces rather than convention the operator interprets.

01

Codified authority sets

Owners define the signing keys, quorum thresholds, and approver roles that constitute valid authority for each asset. The ledger accepts only transitions that satisfy those declared rules.

02

Quorum-gated changes

Changes to the governance set itself require the owner's governance quorum. The operator cannot alter who holds authority, and no minority of officers can seize it.

03

Emergency freeze under mandate

Owners can define freeze conditions that halt transitions on an asset pending review. The freeze is an owner-governed action, not an operator override, and is itself recorded.

04

Jurisdictional separation of powers

Recovery guardians, approvers, and custodians can be split across institutions or jurisdictions so that concentrated control requires collusion the governance design forbids.

Governance leaves a chain that outlives any operator

The point of recovery and governance is durable, provable control — so every act that changes authority is preserved and independently checkable.

01

Tamper-evident authority trail

Every grant, rotation, recovery, and freeze commits into the hash-chained ledger. The full lineage of who held authority over an asset is reconstructable and cannot be silently edited.

02

Post-quantum provenance

Governance transitions are themselves ML-DSA-65 signed, so the record of who changed control survives the same long horizon as the assets being governed.

03

Operator-independent verification

With the public governance keys and the chain, an auditor can confirm that every change of authority followed the owner's declared rules, without trusting the platform's account of events.

04

Continuity across succession

Because authority, history, and evidence are all owner-held and in-nation, control persists through personnel change, custody migration, and operator transition without dependence on any single party.

Build it sovereign.

Talk to us about recovery and governance in a sovereign deployment.