Sovereign
00 / sovereign sign-off protocol

The accountability layer for autonomous AI decisions.

Sovereign creates cryptographically sealed, independently verifiable records that bind a named, authorized human to every consequential AI decision.

01 / why we exist

Across every sector, courts and regulators are asking the same question: Who decided?

When an AI-influenced decision is challenged, the institution cannot show who owned it. Courts are now assigning liability for that gap.

finance · eu
A score is a decision.

The EU's top court ruled an automated credit score is itself a decision under gdpr art. 22.

schufa · cjeu c-634/21 · 2023

public sector · nl
26,000 families, falsely accused.

A self-learning fraud model flagged families by nationality and income. The cabinet resigned.

toeslagenaffaire · 2021

platform work · eu
€825 million for automated deactivations.

Drivers' accounts were blocked with no human in the decision. Regulators ruled these automated individual decisions under gdpr art. 22.

uber · dutch dpa with cnil · 2026

health · usa
Appeals won 90% of the time.

A model alleged to carry a 90% error rate was used to deny extended care for the elderly.

nH predict · unitedhealth · 2023–2026

health · usa
1.2 seconds per claim.

Doctors rejected +300,000 claims in two months, in bulk, without individual examination.

pxdx · cigna · 2023

employment · usa
Liability reached everyone.

No named human owned the rejections, so courts let liability reach the vendor and +10,000 employers.

mobley v. workday · 2023–2026

Every case was missing the same record: which authorized human owned the decision, verifiable later, by anyone. That record is what Sovereign produces.

02 / the gap

A log records the decision. Sovereign proves who stood behind it.

Most AI systems already keep logs. It can be changed, it sits inside the application, and an outside reviewer has no independent way to establish what happened. Sovereign creates a separate record, signed by the named human who approved the decision, that can be verified without relying on the system itself.

audit log
A claim the institution made about itself.

Records that the system wrote something down. A human_reviewed: true field can be written by anyone with database access.

sovereign
A signature no one can take back.

Proves a specific, named, authorized human signed — and that neither the institution nor the signer can later deny it.

dora art. 5uk smcrfinmabafingdpr art. 22fca consumer duty
03 / sovereign sign-off

One decision. One human sign-off. Independently verifiable.

The approver reviews AI recommendation and evidence, records their rationale, and signs with a passkey on their own device. Sovereign then seals the decision and records its proof in a transparency log. Anyone can later verify what was signed and detect any change to the record, without trusting the originating application, dashboard, or audit log.

approver dashboard
sovereign/queue audit··
sovereign sign-off
Decisions awaiting your review
My reviewsUpcomingWaiting on othersClosed
adverse_action.credit_denial · case 2216-084
needs your sign-off
model recommends: deny · policy 2026.05.12 · evidence sha256:b8d1…42c7
View the recommendation & evidence ›
Your rationale (required) 98 / 600
Income verification failed under policy 4.2. The model's evidence is consistent; I uphold the denial.
Your rationale is signed and recorded in the public transparency log — don't include personal or health information (PII/PHI). Keep it about the decision, not the data.
By signing, you confirm that you personally reviewed this evidence and made this decision.
audit verification
sovereign/audit queue··
source: transparency log
Audit verification
Enter a ledger UUID to verify its cryptographic entry in the transparency log.
ledger uuid
01J9R2X9F0ENVZ7
raw log entry (json)
Results will display here...
verify this record yourself — offline, no server trust. the cli verifier (verify-ssp.py · trust-public.pem) re-checks everything; the trust key is supplied separately, so a bundle can never self-certify.
04 / how it works

Why the proof holds.

Five cryptographic steps turn a decision into evidence anyone can check without trusting Sovereign. Each is a public standard with public verification tooling.

01
canonicalize

The record serializes to one deterministic byte sequence. One byte changes and the digest changes.

rfc 8785 · sha-256

02
sign

The approver signs on their own device; a customer-held kms key wraps that signature. Sovereign never holds either key.

webauthn · ed25519

03
chain

Each record carries the digest of the one before it. Rewrite one and every record after it stops verifying.

per-tenant hash chain

04
anchor

Independent authorities attest to when the record entered custody. Three anchors; any one suffices.

rfc 3161 · sigstore rekor

05
verify

The exported proof verifies offline with public tooling. No Sovereign service, dashboard, or model required.

portable · independent

05 / non-repudiation

Two signatures. One the institution cannot forge, one the person cannot deny.

The approver signs on their own device; a customer-held kms key then wraps that signature so it cannot be detached from the claim or its anchors. Sovereign is never in the trust loop.

human signature — webauthn

The private key lives on the approver's device. The institution never holds it, and neither do we.

wraps →
trust signature — customer kms

A customer-held key binds the human act to the claim and its anchors.

A logged reviewer field can be written by anyone with database access. A webauthn signature can be produced by exactly one device, held by exactly one person — the difference a court cares about.

06 / custody

Runs in your cloud. You hold the keys.

Deploy from the marketplace into your own account: customer kms, customer storage, your domain as the webauthn relying party. Sovereign code never sees private key material.

aws
Marketplace.

Deploy into your own account, wired to customer storage.

azure
Customer cloud.

Evidence, keys and relying-party domain stay under your institution.

self-hosted
Own boundary.

Run the protocol where your controls already live.

kms
fips 140-3 level 3.

The customer-held key wraps the user signature.

07 / ssp 1.0

An open protocol, not a black box.

The Sovereign Sign-Off Protocol is published under cc-by with an mit reference implementation. Records are deterministic and verifiable with public tooling. The format outlives any single vendor, including us.

cc-bythe spec is inspectable and citable
mitverify records with public tooling
determ.the same payload produces the same canonical bytes across implementations
08 / fit

For decisions where a human owns the call.

The pattern is the same everywhere: a model recommends, a person decides, and someone will later ask who. Built first for EU, Swiss and UK institutions running adverse-action workflows.

finance
Credit denials, aml holds.

A named officer signs the adverse action over bounded evidence.

health
Coverage denials.

A named reviewer owns the denial, not the model that scored the claim.

public sector
Benefit determinations.

Who decided the flag, the debt, the closure — under what authority.

employment
Screening rejections.

A named human accountable for the call an algorithm recommended.

not for
No discrete human moment.

Real-time agentic control, fully automated flows.

09 / start

Who decided. Now anyone can prove it.

Put a name on the decision and a proof behind it, verifiable the day it is signed and the decade after.

sealed receipt
envelope01J9R2X9F0ENVZ7
claimsha256:e7c9a4…b1
signerofficer-7741 · senior credit officer
authoritycredit-adverse-action 2026.05.12
anchorrekor index 84510293