SH Sovereign Hub SECURITY-OFFICER · DPO

jurisdictional tenants · treaties · cross-border flow · sovereign audit chain
◂ Mission Control
NOT THE OPERATOR HOME. Daily-driver portfolio steward → Mission Control · Per-company operator home → Company Cockpit. SH is the data-sovereignty plane — sovereign-tenant key custody, cross-border data-flow gating, air-gap export, and federation attestations. The crypto-critical panels (TN, KE, AG, FD) below are locked unless the active persona is security_officer. Switch persona from the omni-bar to operate them.

TN Sovereign tenants ·

jurisdiction · residency · sovereign key · treaty count
code legal name residency regions sovereign key allowed classes treaties updated
loading…

TR Treaty graph

per-tenant outgoing flow agreements · allowed data classes · consent / key-share requirements
source → counterparty allowed classes requires consent requires key share reference
— select a tenant above —

XB Cross-border flow evaluator ·

submit a flow intent · receive allow / review / deny decision

AC Sovereign audit chain

per-tenant Merkle log · phase 196 · click verify to re-walk
jurisdiction entries head SHA oldest newest chain valid
loading…

AX Audit entries explorer

drill into individual Merkle entries · jurisdiction + optional time range
seq at kind actor subject sha prev → curr
— pick a jurisdiction and click load —

FH Cross-border flow history

recorded evaluations per source jurisdiction · phase 194
at route classes decision reason sha
— pick a jurisdiction and click load —

AG Air-gap manifests ·

content-addressable signed bundles for disconnected sovereign export
Why it matters. GDPR Art. 46 (transfer safeguards), KSA PDPL Art. 29 (cross-border restrictions), UAE PDPL Art. 22 (controlled transfers). Each manifest is a Merkle-rooted, ed25519-signed bundle that lets a regulator verify the exact dataset that crossed the boundary — without network access to the source tenant.
jurisdiction manifest id (sha) purpose entries signed issued at
— no air-gap manifests issued —

KE Key escrow · Shamir K-of-N ·

master secrets split into N shares · K threshold for recovery · vault holds metadata only
Why it matters. ISO 27001 A.10.1 (key management lifecycle), NIST SP 800-57 §5.2 (split-knowledge custody), SOC2 CC6.1 (cryptographic key controls). The vault never reconstructs the master secret — recovery requires K independent share-holders to physically combine their shares, which is the SoD primitive regulators look for.
jurisdiction label k / n secret fp recoveries last recovery created
— no escrow records —

FD Federations ·

multi-tenant pacts · signed attestation exchange · hash-chained per-federation ledger
Why it matters. EU DGA (Data Governance Act) Art. 10 (data altruism organisations), GCC sovereign data sharing frameworks. A federation is a hash-chained ledger of signed attestations between sovereign tenants — every flow that crosses tenant boundaries leaves a non-repudiable receipt that any party can verify offline.
id name members max class updated
— no federations registered —
at federation issuer → target kind subject sha
— no attestations yet —