PRI11
Sovereign by design
The architecture is location- and trust-agnostic: a proof verifies identically in a datacentre, a browser, a device at the point of inspection, or offline — trust travels in the artifact, never in where it is processed or who operates the infrastructure — and where data resides or is processed is the holder’s explicit, auditable choice, enforced at the access layer.
Rationale
Sovereignty means the holder — not the infrastructure — decides where data lives and where it is acted on, and that decision is a declared, auditable choice enforced at the access layer rather than a cryptographic guarantee. Because the guarantees travel in the artifact and never depend on trusting a particular place, platform or operator, you are free to deploy where regulation, cost or latency dictate without weakening what you can prove, and free of lock-in to any single environment. This principle and Principle 12 divide the ground between them: here, trust does not depend on where processing happens; there, the evidence itself travels with the data.
Implications
- You can run the same capability in a datacentre, a browser, an inspector’s handheld device or fully offline and get identical results, so deployment choices follow your business needs rather than being constrained by where the technology happens to work.
- Where data resides and is processed is configuration you set and can evidence to a regulator or customer — a deliberate, auditable choice, not an implicit consequence of which vendor or region you happened to use.
- No part of the system asks you to trust a particular operator, region or platform for correctness, and an action that cannot be verified is refused rather than allowed — so relocating or changing providers never quietly erodes the guarantees.