Sovereign
Sovereign creates cryptographically sealed, independently verifiable records that bind a named, authorized human to every consequential AI decision.
When an AI-influenced decision is challenged, the institution cannot show who owned it. Courts are now assigning liability for that gap.
Every case was missing the same record: which authorized human owned the decision, verifiable later, by anyone. That record is what Sovereign produces.
Most AI systems already keep logs. It can be changed, it sits inside the application, and an outside reviewer has no independent way to establish what happened. Sovereign creates a separate record, signed by the named human who approved the decision, that can be verified without relying on the system itself.
The approver reviews AI recommendation and evidence, records their rationale, and signs with a passkey on their own device. Sovereign then seals the decision and records its proof in a transparency log. Anyone can later verify what was signed and detect any change to the record, without trusting the originating application, dashboard, or audit log.
Five cryptographic steps turn a decision into evidence anyone can check without trusting Sovereign. Each is a public standard with public verification tooling.
The approver signs on their own device; a customer-held kms key then wraps that signature so it cannot be detached from the claim or its anchors. Sovereign is never in the trust loop.
The private key lives on the approver's device. The institution never holds it, and neither do we.
A customer-held key binds the human act to the claim and its anchors.
A logged reviewer field can be written by anyone with database access. A webauthn signature can be produced by exactly one device, held by exactly one person — the difference a court cares about.
Deploy from the marketplace into your own account: customer kms, customer storage, your domain as the webauthn relying party. Sovereign code never sees private key material.
The Sovereign Sign-Off Protocol is published under cc-by with an mit reference implementation. Records are deterministic and verifiable with public tooling. The format outlives any single vendor, including us.
The pattern is the same everywhere: a model recommends, a person decides, and someone will later ask who. Built first for EU, Swiss and UK institutions running adverse-action workflows.
Put a name on the decision and a proof behind it, verifiable the day it is signed and the decade after.