The same authority in every environment.
Verity Command runs where the mission requires: inside a sovereign enclave, on an isolated network, in a sovereign cloud, or at the operational edge. The authority model, the evidence record and the customer's control of the roots of trust are identical in each.
Principles
- Customer-held roots of trustIdentity, signing and encryption roots are generated and held inside the customer domain through QECNet Trust Fabric.
- No vendor in the decision pathNo component depends on a vendor-operated service to authorize, distribute or record.
- No standing vendor accessSupport access is customer-approved, time-bound and evidenced.
- One authority domain per instanceOne set of roots and one evidence namespace; instances interact by federation, never by shared internals.
- Signed lifecycleReleases, configuration and policy delivered and approved through Verity Forge.
- Fail closed everywhereThe same refusal behavior in a data center, an air gap and a disconnected edge node.
Patterns
The complete platform on customer premises and customer hardware, inside the customer's security boundary. Suited to ministries, national commands and operators of critical infrastructure that keep mission data on their own estate.
No external connectivity. Updates, connectors and policy arrive as signed packages that are verified for signature and provenance and authorized before import. Model endpoints run inside the boundary.
National or regional cloud infrastructure selected by the customer, operated under customer-held keys, with the same authority domain boundaries as an on-premises enclave.
Verity Edge on virtual machines, servers, and ARM or x86 hardware beside the operational system, enforcing signed leases through degraded and disconnected periods and synchronizing through Tunnel Sovereign.
Separate authority domains for each organization or nation, exchanging releases through recorded decisions and acceptances. No shared master key; caveats travel with the material and withdrawal is honored.
Disconnected operation
One principle covers every disconnected case: authority must be verifiable where the authority issuer is not present. Edge nodes carry signed, time-bounded leases; they cannot grant new authority, extend their own leases or change policy; and on reconnection they apply authority state first and re-authorize queued work item by item.
Trusted time is part of the trusted computing base. Data collection continues through a loss of trusted time with its uncertainty recorded; authority decisions do not, once uncertainty exceeds the configured bound.
Deployment responsibilities
Sovereignty moves responsibility to the customer, and the architecture says so. The customer operates root key ceremonies and custody, the security of its infrastructure and facilities, and the availability planning that a fail-closed decision path requires. The boundaries between platform and customer responsibilities are set out in the Public Threat Model.