Content-addressing + chain integrity
Used for atom hashing, RefreshAnchor chains, Merkle witnesses, certificate digests. Parallelizable + SIMD-accelerated; no successful collision attacks in published cryptanalysis.
Sovereign Clearinghouse's compliance posture is structural, not promotional. Below is the factual state, what's certified, what's in flight, what we don't yet claim, and how an examiner verifies any of it independently of us. No marketing veneer.
Each row links to the underlying evidence + the owning party's name + the expected milestone date.
| Framework | Status | Owner | Next milestone |
|---|---|---|---|
| SOC 2 Type II | In flight | Vanta-managed audit | R3.1 kickoff → first report ~6 months |
| FIPS 140-3 / CMVP | Lab-engaged | NVLAP lab (atsec / Acumen / Lightship target) | R3.5 ACVP testing → CMVP submission queued |
| MiCA CASP sandbox | Application drafted | Compliance + Legal | R3.6 ESMA-affiliated NCA submission |
| FINTRAC MSB registration | Pending | Compliance + Legal | R3.6 application filing |
| GDPR Article 28 DPA | Draft ready | Outside counsel | R1.5 red-line + customer-counsel review |
| Bug bounty program | Private channel live | Security Lead | R3.4 HackerOne public program launch |
| External crypto review | Pending | Trail of Bits target | R3.2 engagement + report |
| External penetration test | Pending | NCC Group target | R3.3 engagement + report |
| Cyber liability + Tech E&O | Broker outreach | Ashley + Legal | R3.9 binding coverage |
| EAR / Wassenaar export-control | Draft analysis | Outside counsel | R3.10 counsel red-line + BIS notification |
We don't market certifications we don't hold. The Auditor Compliance Brief §10 lists every honest gap in detail.
The substrate's cryptographic chain. Every primitive is publicly auditable.
Used for atom hashing, RefreshAnchor chains, Merkle witnesses, certificate digests. Parallelizable + SIMD-accelerated; no successful collision attacks in published cryptanalysis.
NIST FIPS 204 (formerly Dilithium-87). Resistant to Shor's algorithm. Used for every atom signature, capability token, ScreenProof, and TopologicalErasureCertificate.
NIST FIPS 203 (formerly Kyber-1024). Used for cross-tenant query sessions + observer access channels.
Every signed atom carries an algorithm-epoch header. Rotations to future post-quantum primitives are first-class operations; historical atoms remain verifiable under their epoch.
NIST FIPS 197. Encryption at rest (EFS, S3, KMS) + in transit (TLS 1.2+). Customer's KMS keys for Enterprise-tier deployments.
Customers + their auditors verify any erasure certificate, sanctions screen, or chain segment cryptographically without trusting us. Source at github.com/DIGITAL-FABRIC-AI/trustdb.
Implementation sourced from PQClean (public-domain reference) + AWS-LC (BSD-licensed) + OpenSSL (Apache 2.0). Full export-control analysis (TSU §740.17(b)(1) license exception) published.
Per DPA §8(2)(d). Updated with 30-day advance notice on changes.
| Sub-processor | Purpose | Region | Data category |
|---|---|---|---|
| Amazon Web Services (AWS) | Hosting, compute, EFS, S3, Backup, ACM, SES, Route 53 | ca-central-1, us-east-1, eu-west-1, ap-southeast-1 (customer choice) | All substrate data + operational metadata |
| Cloudflare | CDN / Pages / DDoS protection (if used for marketing) | Global edge | Public site assets only |
| Neon (Postgres) | Operational metadata (tenants, users, EULA, usage meters) | Customer-region match | Operational metadata (no compliance atoms) |
| Stripe | Billing + payment processing | US (Stripe HQ) | Billing details only (no transfer data) |
| Atlassian Statuspage | Status page (R1.7) | US | Operational uptime data only |
| PagerDuty | Incident response routing (Enterprise tier) | US/EU per customer choice | Incident metadata (no compliance data) |
| HackerOne (planned R3.4) | Bug bounty platform | US | Vulnerability reports + reporter contact |
| Plausible / Fathom | Privacy-respecting analytics (no cookies; no IP storage) | EU | Aggregate page-view counts only |
Customer security teams + procurement teams can self-serve these documents.
11-section brief covering substrate primitives, cryptographic primitives, operational controls, regulator replay procedures, sample evidence bundle, cooperation procedure, honest gaps.
30-minute evaluator brief: 30-sec pitch, 6 capabilities, deployment models, regulatory posture, pricing, integration footprint, honest gaps.
Day-1 + Day-2 procedures for deploying to customer's AWS account. 15-item verification checklist + common gotchas.
9-part operational manual for the CCO/MLRO running the substrate day-to-day.
4 severity levels, 8 incident-class playbooks, breach-notification matrix per jurisdiction, Article 5(2) evidence preservation.
Scope, reward tiers $50-$25K, safe-harbor language, disclosure timeline, contact channels.
All 14 customer-facing documents are at the docs site. EULA, DPA, AUP, Pricing drafts available for procurement on request.
These are the boundaries of our current posture. We update this list as gaps close.
excise_crossing returns the entanglement map for entangled crossings; polynomial-time path is roadmap.