The keys and the weights belong to the sovereign owner. Our job is to make sure that in every layer — concrete, silicon, and code — that ownership cannot be quietly subverted.
Access is defended in depth from the perimeter to the individual rack, with residency enforced by geography as well as policy.
The facility is divided into concentric zones — perimeter, building, data hall, and cage — each with its own authentication. Credentials that admit someone to the building do not admit them to a settlement rack.
Entry to the most sensitive zones requires more than one factor, and the most sensitive operations require more than one person. No single individual can unlock and act on critical infrastructure alone.
Data and the systems that hold it remain physically inside the owning nation's territory. Residency is a property of where the concrete and the disks are, enforced by siting and jurisdiction, not only by contract.
Racks, key-management modules, and console access are physically sealed and monitored so that unauthorized physical contact leaves evidence. Tampering may not always be preventable, but it is always detectable.
Segmentation, least privilege, and post-quantum cryptography are built in rather than bolted on.
Signatures use ML-DSA-65 under FIPS 204, so ledger entries and settlement instructions remain verifiable against an adversary with a quantum computer. Cryptographic agility is designed in for future standard transitions.
Production, management, and out-of-band networks are separated so that a compromise in one plane does not grant the run of the others. Lateral movement is a design failure we architect against.
Access to keys, weights, and control systems is granted by role, scoped to task, and time-bound. Standing administrative privilege is minimized because an unused credential is still an attack surface.
The sovereign owner holds the signing keys and, for Sovereign AI, the model weights. The operator runs the machinery but cannot unilaterally sign, mint, or exfiltrate — custody and operation are deliberately separated.
The ledger and the operational logs are built to be reconstructed and defended, not merely stored.
The settlement ledger is tamper-evident: each entry is cryptographically chained to its predecessor, so any retroactive edit breaks the chain and is detectable. History is provable, not just recorded.
Administrative access, configuration changes, and key operations are logged with actor, time, and outcome. The record answers not only what changed but who changed it and under what authorization.
An auditor can independently recompute the chain and confirm that the ledger's stated history matches its cryptographic evidence. Trust in the record does not depend on trusting the operator.
Audit records are retained under defined policy and held within the owning nation's jurisdiction, so the evidentiary trail is subject to the sovereign's own law rather than a foreign operator's.
Security is treated as a property to be re-proven over time, not a certificate earned once.
The engines are proven end-to-end, and production hardening with external audit is in progress. We describe design intent and demonstrated capability; independent validation is the mechanism that turns intent into assurance.
Security posture is monitored continuously — configuration drift, access anomalies, and integrity of the hash chain are checked as ongoing conditions rather than periodic snapshots.
Roles are structured so that no single person can develop, deploy, and approve the same sensitive change. The controls that protect owners from outsiders also protect them from insiders.
The underlying methods — non-custodial custody, post-quantum settlement, and tamper-evident accounting — are the subject of six filed patents in the US and Canada, reflecting original design rather than assembled components.