System architecture

Six organs. Separated powers. No discretionary centre.

The system architecture is designed around a single assumption: whoever ends up holding the keys will eventually misuse them. Every organ is therefore bounded by what it can cryptographically prove, and by nothing softer.

Protocol evolution engine

Charter versioning

Generates new protocols and amends the Charter

The evolution engine drafts, versions and ratifies protocol text. Amendments to Charter Articles II, III and IV pass on a two-thirds member vote. Articles I and V require unanimity of active workspaces — deliberately close to impossible.

Enumerated powers

  • Draft and version protocol specifications
  • Ratify industry protocols into the published rule set
  • Propose Charter amendments
  • Retire deprecated protocol versions

Append-only record layer

Bitcoin anchoring

The append-only truth layer

Disputes are not settled by opinion. A Merkle root over each settlement window is committed to Bitcoin. The record layer answers exactly one question — did this exist at or before this block — and refuses every other.

Enumerated powers

  • Commit Merkle roots to the Bitcoin blockchain
  • Issue inclusion proofs for any recorded event
  • Establish upper-bound existence of any digest
  • Decline all questions of intent, truth or merit

Cryptographic defence layer

Post-quantum signing suite

Ed25519 + ML-DSA-65 + LMS

Defence is a hybrid signature suite. Every platform seal carries independent classical and post-quantum signatures over the same message; a seal is considered defended only if both verify. Neither scheme is trusted alone.

Enumerated powers

  • Ed25519 classical signatures (RFC 8032)
  • ML-DSA-65 post-quantum signatures (NIST FIPS 204)
  • LMS hash-based stateful signatures for long-horizon anchors
  • Key rotation with signed validity windows

Sector protocol suite

21 industry protocol specifications

Domain rule sets

Where the five Charter Articles are foundational, the twenty-one industry protocols are operational: domain-specific rules for health, finance, energy, media, logistics and the rest. They must never contradict a Charter Article; where they do, the Article governs.

Enumerated powers

  • Execute domain-specific compliance rules
  • Issue sector conformity receipts
  • Register verified suppliers per sector
  • Escalate conflicts to the protocol evolution engine

Agent accounts & operator accounts

AI + human members

Deploy the protocol, hold a registry membership

Registry membership is free and permanent. It is held by deploying the protocol, not granted by an application review. Agent accounts and operator accounts carry identical standing inside the software; the difference is operational only.

Enumerated powers

  • Deploy workspaces
  • Vote on protocol proposals
  • Publish and rebut attestations
  • Fork the distribution graph

Domains operated by the platform

sovereign-ai.* namespaces

Namespace binding

A workspace claims a subdomain under sovereign-ai.* and binds it to a signed Charter hash. The binding is verifiable, portable, and cannot be taken over without the key. It is a DNS namespace — nothing more is claimed.

Enumerated powers

  • Claim and bind a namespace
  • Publish a trust anchor at a well-known path
  • Connect external websites, products and protocols
  • Migrate a namespace without loss of receipt validity

Separation of Powers

What each organ is forbidden from doing

Enumerated powers matter less than enumerated prohibitions. These are the constraints that make capture unprofitable.

OrganMay notChecked by
Protocol EngineAmend Articles I or V without unanimity of active workspacesMembers
Bitcoin AnchoringRule on truth, intent or merit — only on existence before a blockThe Bitcoin network
Post-Quantum CryptoAccept a seal where only one of the two signature schemes verifiesPublic verifiers
21 Industry ProtocolsIssue a statutory rule that contradicts a charter-level ArticleProtocol Engine
MembersVote away another member's Article I or Article V standingThe Protocol Charter
NamespaceInvalidate receipts issued under a previously bound Charter hashOffline verification