NOT THE OPERATOR HOME.
Daily-driver portfolio steward → Mission Control ·
Per-company operator home → Company Cockpit.
SH is the data-sovereignty plane — sovereign-tenant key custody, cross-border data-flow gating, air-gap export, and federation attestations. The crypto-critical panels (TN, KE, AG, FD) below are locked unless the active persona is security_officer. Switch persona from the omni-bar to operate them.
SU Guided setup · DPO first-run
no sovereign tenants registered yet — three moves to a working data-sovereignty surface
Register a residency region. Pick a jurisdiction code (EU · US · AE · SA · IL) and assign it residency regions + an allowed-class ceiling. POST /sovereign/tenants.
Sign one treaty. The treaty graph (TR) lets every outgoing flow check itself against an explicit per-counterparty contract (allowed classes, consent flag, key-share flag, reference doc).
Test a flow. Use the Cross-border Flow Evaluator (XB) — pre-filled with the example below — and confirm the engine returns the right allow / review / deny verdict for your treaty.
TN Sovereign tenants ·
jurisdiction · residency · sovereign key · treaty count
drill into individual Merkle entries · jurisdiction + optional time range
seq
at
kind
actor
subject
sha
prev → curr
— pick a jurisdiction and click load —
FH Cross-border flow history
recorded evaluations per source jurisdiction · phase 194
at
route
classes
decision
reason
sha
— pick a jurisdiction and click load —
AG Air-gap manifests ·
content-addressable signed bundles for disconnected sovereign export
Why it matters. GDPR Art. 46 (transfer safeguards), KSA PDPL Art. 29 (cross-border restrictions), UAE PDPL Art. 22 (controlled transfers). Each manifest is a Merkle-rooted, ed25519-signed bundle that lets a regulator verify the exact dataset that crossed the boundary — without network access to the source tenant.
jurisdiction
manifest id (sha)
purpose
entries
signed
issued at
— no air-gap manifests issued —
KE Key escrow · Shamir K-of-N ·
master secrets split into N shares · K threshold for recovery · vault holds metadata only
Why it matters. ISO 27001 A.10.1 (key management lifecycle), NIST SP 800-57 §5.2 (split-knowledge custody), SOC2 CC6.1 (cryptographic key controls). The vault never reconstructs the master secret — recovery requires K independent share-holders to physically combine their shares, which is the SoD primitive regulators look for.
jurisdiction
label
k / n
secret fp
recoveries
last recovery
created
— no escrow records —
FD Federations ·
multi-tenant pacts · signed attestation exchange · hash-chained per-federation ledger
Why it matters. EU DGA (Data Governance Act) Art. 10 (data altruism organisations), GCC sovereign data sharing frameworks. A federation is a hash-chained ledger of signed attestations between sovereign tenants — every flow that crosses tenant boundaries leaves a non-repudiable receipt that any party can verify offline.