A nation cannot re-tender its payment rails every few years. We commit to availability today and to the disciplined stewardship that keeps the platform sovereign for decades.
What we commit to is backed by concurrently maintainable infrastructure and measured against agreed definitions.
Availability rests on redundant power, cooling, and network paths so that any single failure is absorbed rather than passed to the workload. The commitment reflects the architecture, not a hope about the year ahead.
Availability is measured against a written definition of what counts as available — settlement finality and ledger liveness, not merely a machine responding to ping. Both sides agree on what is being measured before it is promised.
Delivery-versus-payment is atomic: the asset and the payment move together or neither moves. There is no interim state in which one leg has settled and the other is exposed, which removes a whole class of availability risk.
Recovery time and recovery point objectives are defined for each critical service, so a disruption is bounded by an agreed target rather than open-ended. The tamper-evident ledger makes the recovery point provable.
Commitments are reviewed, reported, and enforced through defined process.
Availability, incidents, and maintenance are reported to the owner on a regular cadence with the underlying evidence. The sovereign sees the operational truth, not a curated summary.
Changes to the production platform pass through a governed process — impact analysis, approval, and rollback plan — proportionate to their risk. The owner has visibility into what is changing under their name.
Service reviews and a defined escalation path give the owner a standing forum to raise issues and hold commitments to account, rather than discovering problems only when they become incidents.
Long-lived infrastructure is planned as a program of refresh and capacity, not a one-time build.
New capacity is integration-tested and proven under load before it carries production. A node enters service having demonstrated its power, thermal, and settlement behavior, not on the assumption that it will work.
GPU, compute, and network generations are refreshed on a planned horizon so the platform does not age into obsolescence. Capacity planning anticipates growth in settlement volume and AI workload ahead of the demand.
Retired media and hardware are sanitized or destroyed under verified procedure before leaving the owner's custody. A decommissioned disk is a residency and secrecy risk until it is provably wiped.
Keys and certificates are rotated on defined schedules and on demand, and the post-quantum design allows migration to future standards without re-architecting the ledger. The cryptographic lifecycle is managed as deliberately as the hardware.
Long-term operation is designed so the sovereign is never captured by the operator.
Because the owner holds the keys and weights and the data resides in-nation, the sovereign retains the ability to change operators without surrendering their currency, models, or history.
Custody of keys, weights, and audit records persists across hardware refreshes and personnel changes. The chain of ownership is a designed invariant of the platform's lifecycle, not a property of any one vendor relationship.
Runbooks, architecture, and operational knowledge are documented so the owning nation can build and retain its own operational capability over time rather than remaining dependent on outside expertise.