AUTHORITY BEFORE ACTION SOVEREIGN MISSION INTELLIGENCE AND AUTHORIZED ACTION DENY by default EVIDENCE before effect
Tunnel Sovereign symbolVERITY COMMAND
Public Technical Note

Public Threat Model and Security Boundaries

What the architecture protects, detects and cannot guarantee.

Document
VC-PUB-002
Version
1.1
Published
16 September 2026
Edition
Public
PDF
Download (326 KB)
PDF SHA-256
2505ed91e06c9154aa0a830d11619be2496a65e1470c6340e1c1b49758143d59
PUBLIC EDITION

1Governing principle

Verity Command does not make intelligence inherently true. It makes the basis, authority and consequences of acting on intelligence inspectable and enforceable.

Every statement in this note follows from that sentence. A platform cannot verify reality; it can record what was asserted, by whom, on what basis, under whose authority and with what effect. Where this note describes a control, it describes a constraint on action and a record of decision — not a guarantee about the world.

2Method and scope

The analysis follows the thirteen trust boundaries defined in the Trust, Authority and Evidence Architecture (VC-PUB-001): a spoofing, tampering, repudiation, disclosure, denial and elevation review at each boundary; attack trees for the highest-value objectives; and abuse cases for misuse by authorized actors. It describes the architecture's controls. It does not report an independent assessment, audit or penetration test, and none is claimed.

Out of scope by declaration. The security of customer infrastructure, the physical security of customer facilities, and the conduct of people after an instruction leaves the enforcement boundary. A threat model that quietly omits its boundaries is misleading, so they are named here.

3Assets and adversaries

Four assets shape most of the architecture — authority state, cryptographic roots, the evidence record and communications payloads — because an adversary holding any one of them can act as, or authorize, anything else.

AssetWhy an adversary wants it
Authority state — grants, leases, policyAbility to act as, or authorize, anything
Cryptographic roots and keysTotal compromise of an authority domain
Evidence recordErase or fabricate the record of what happened
Communications payloads and metadataOrders and intelligence in transit; tempo and relationships
Mission content and source detailsIntelligence value; exposure of methods and people
Coalition-released materialDiplomatic damage; loss of partner trust
Model routing and AI outputsManipulation of analysis and decisions
Software supply chainPersistent, wide compromise
Availability of the decision pathDeny decision-making at a critical moment

Adversaries range from state-sponsored actors with supply-chain reach to the careless authorized user. Three hold legitimate credentials and receive particular attention: the malicious insider, the malicious administrator and the hostile federation partner. A design that only resists outsiders is not a design for this domain.

4Residual risks

These are the risks an evaluator should weigh most carefully. They are stated first and in full, not left to footnotes.

Residual riskStatement
Sensor spoofingA spoofed signal received by a genuine sensor is a genuine observation of a false signal. Contradiction detection and source reliability tracking raise the chance of noticing; they do not guarantee it.
Authenticated but materially false dataSource authentication establishes who supplied data, not whether it is true. A false report from a genuine source remains a correctly attributed false report.
Insider with valid keysAuthority is scoped by mission, direction, duration and label ceiling, and use is recorded. An insider acting within a valid grant is acting legitimately; the architecture bounds reach, it does not read intent.
Compromised customer roots of trustThe customer holds the roots, so a compromise of them compromises that authority domain. The vendor cannot recover it, because the vendor holds no key that can authorize, decrypt or sign inside it.
Compromised endpointsA captured, unlocked device with content displayed is not protected by cryptography. Lease duration, minimal local data and truthful duress signaling reduce scope. The Distribution Endpoint, if compromised, exposes the packages it is distributing at that time.
Data and model poisoningValidation, reliability tracking, contradiction surfacing and statement typing raise the cost of poisoning. Patient, sophisticated poisoning is not claimed to be detectable. Model responses are untrusted input: recorded, attributable, and possibly wrong.
Model and dependency supply chainSigned builds, a bill of materials, provenance attestation, recorded model versions and restricted model routes reduce exposure. A permitted route to a compromised model, or a compromised upstream dependency, remains a risk.
Quorum collusionQuorum across people and organizations raises the cost of a fraudulent authorization. Coercion or collusion of an entire quorum is possible and is not claimed to be solved.
Traffic analysisSeparating key material per mission does not defeat traffic analysis. No claim of anonymity or unlinkable mission activity is made.
Metadata observationConnection metadata, timing and volume remain observable to network infrastructure, including the relay. Content is protected; the existence and pattern of communication is not hidden.
Loss of trusted timeAuthority decisions fail closed when time uncertainty exceeds the bound. That is a denial-of-service surface by construction: degrading time degrades the ability to authorize. The trade is deliberate.
Stale revocation stateRevocation reaches an enforcement point when it receives the signed state. A disconnected point acts on what it last received, bounded by lease expiry; the residual window is shown to the commander at revocation.
Prolonged isolationAn isolated Verity Edge node enforces its lease and then fails closed. Isolation ends in loss of capability, which is itself an operational risk to plan for.
Human error under valid authorityQuorum, digest-bound approval and a reconstructable view of what was known reduce and expose error. A well-formed, correctly evidenced authorization can still be the wrong decision.
Physical actions outside the enforcement boundaryThe platform governs decisions, authorizations and distribution. It does not govern what a person or system does in the physical world after receiving an instruction.

5Prevented or constrained

Threats the architecture stops, or bounds so tightly that success yields little.

ThreatConstraintWhat remains
Elevation through delegationDelegated permissions never exceed the delegator's at decision time; an AI agent is bounded by grant, delegator and missionA delegator with excessive authority passes on a share of too much
Approval launderingApprovals and authorizations bind to an exact content digest; any edit invalidates themLow while digest binding holds
Replay of a consumed authorizationSingle-use consumption, nonces and expiryLow
Mission substitutionThe mission comes from the authorizing grant, never from the callerLow
Central interceptionOnly endpoints and the Distribution Endpoint hold payload keys; the relay carries ciphertextDistribution Endpoint exposure (section 4)
Data reaching an unauthorized modelClassification-aware routing; no permitted route means refusal, not reroutingA permitted route to a compromised model
Prompt injectionContent is data, never instruction; tools run from a registry, in a sandbox without default egressDegraded answer quality
Caveat stripping on releaseRelease decision and acceptance required; caveats bound; withdrawal honoredPartner misuse after acceptance
Unrecorded actionEvidence admitted before effect; no record, no actionActions taken outside the platform
Authority surviving revocation indefinitelyLeases and validity windows cannot be extended locallyA bounded residual window offline

6Detected or evidenced

Threats that cannot be prevented but can be made visible, with a record an investigator can rely on.

ThreatHow it is surfaced
Evidence tamperingHash chain and signed checkpoints, optionally exchanged with a partner; continuous verification raises a critical incident and freezes writes on any break
Over-release to a partnerRelease decisions and projections are recorded: what, to whom, under whose decision
Vendor accessNo standing access; support access is customer-approved, time-bound and evidenced
Misuse by an authorized userPurpose recording, mission-scoped grants and a reconstructable decision context
Contradictory or repeated sourcesContradictions preserved and shown; lineage exposes repetition presented as corroboration

7What Verity Command does not protect against

  • A compromised customer root of trust. Sovereignty means the customer holds the roots and carries that risk.
  • A captured, unlocked endpoint with content on screen. Cryptography does not help at that point.
  • A coerced or colluding quorum. Quorum raises cost; it does not make fraudulent authorization impossible.
  • Traffic analysis and metadata observation. The pattern of communication remains observable.
  • A lying source. Authentication establishes origin, not truth.
  • Patient data poisoning. Raised cost is not detection.
  • Incorrect AI output. Governance constrains what AI may do, not whether it is right.
  • A lawful decision that is simply wrong. The record makes it reconstructable, not preventable.
  • Physical consequences beyond the enforcement boundary.
  • Denial of availability. Failing closed means that degrading identity, policy, evidence or time degrades the ability to act. That is the chosen trade.

8Properties not claimed

Not claimedWhy
Revocation reaches every endpoint at onceFalse for disconnected endpoints; the lease is the bound
The relay learns nothingMetadata, timing and volume are observable
Mission activity is unlinkableKey separation does not defeat traffic analysis
The system cannot be misconfigured into insecurityDefaults, tests and quorum reduce the risk, not eliminate it
AI cannot produce a wrong answerEvaluation bounds quality; it does not guarantee correctness
A validated cryptographic moduleNone is claimed
Any certification, accreditation or approval for classified informationNone is claimed
Hardware-backed, non-exportable keys on every platformPlatform support varies; assurance is stated per platform and algorithm
Guaranteed secure deletion of mediaMedia remanence is outside software control
Independent assessment or cryptographic reviewNone is claimed

9Related documents and revisions

VersionDateChange
1.02026-09-16First public edition.
1.12026-09-16Residual risks consolidated into one section; aligned to the canonical platform architecture; related documents linked.

Document VC-PUB-002 · Version 1.1 · Published 16 September 2026 · PUBLIC EDITION
© 2026 Sovereign Inc. All rights reserved.