SOVEX
CBDC Data Centers Sovereign AI Tokenization Deep Tech Architecture About Team Request access
Sovereign AI / Data sovereignty / Right to retire

Right to retire.

Data and the weights derived from it can be revoked and retired on the owner's terms. Sovereignty that cannot compel forgetting is not sovereignty.

Retirement begins with an authorized, recorded decision

Withdrawing data or a model is a deliberate sovereign act with a clear origin.

01

Owner-initiated revocation

An authorized officer can order a source, a class of data, or an entire model retired. The order is signed and written to the hash-chained ledger as the start of record.

02

Legal-basis expiry

When consent lapses, a license ends, or a court compels removal, the affected data is flagged automatically and enters the retirement workflow.

03

Scoped or total

Retirement can target a single document, a data category, a jurisdiction's subset, or a whole model lineage. The scope is explicit and enforced, not approximate.

04

Effective-date semantics

An order specifies when the retirement takes effect and whether it applies to future models only or to models already in service, removing ambiguity about reach.

Retirement follows the lineage graph to every affected artifact

Because provenance is complete, revocation reaches every place the data went.

01

Impact resolution

The lineage graph identifies every corpus snapshot, checkpoint, and deployed model touched by the retired data before any deletion occurs, so nothing is missed and nothing extra is destroyed.

02

Corpus purge

The data is removed from active storage and from every snapshot slated for future training, and its admission record is marked retired rather than erased from history.

03

Derived-weight handling

Models built on the data are flagged for remediation — retraining, fine-tune reversal where feasible, or withdrawal from service — according to the order's scope.

04

Cascade to downstream

Fine-tunes and derivatives of an affected model inherit the retirement status, so a revocation does not stop at the first model it reaches.

Retirement ends with verifiable destruction, not a status flag

The owner receives cryptographic proof that the data and its keys are gone.

01

Cryptographic erasure

Where data is encrypted per-source, destroying the owner-held keys renders it unrecoverable across all copies at once, including backups, without hunting every replica.

02

Media sanitization

For plaintext or cached copies, storage is sanitized to a defined standard and decommissioned media is destroyed under owner custody in-nation.

03

Backup and replica reach

Retirement policy accounts for snapshots and replicas so that a retired item does not silently survive in a backup, with residual-copy handling defined up front.

04

Certificate of destruction

Each retirement produces a signed, ledger-anchored record of what was destroyed, when, and by whose authority — usable as evidence to a regulator or claimant.

Retirement is designed to be provable to a third party

The owner can demonstrate that forgetting actually happened, not merely that it was requested.

01

Before-and-after lineage

The lineage graph shows the retired artifact present before the order and absent after, with the transition itself recorded as a tamper-evident event.

02

Independent verification

An auditor can confirm that no active model or corpus snapshot still references the retired data, using the same content-addressed identifiers that tracked it in.

03

Continuity of the record

The fact of retirement is preserved even though the data is gone, so the audit trail remains complete and the destruction stays accountable over time.

04

No operator override

Sovex cannot reverse or bypass a retirement, because destruction of owner-held keys and media is outside operator control by design.

Build it sovereign.

Talk to us about right to retire in a sovereign deployment.