Data sovereignty is the ability to say, with evidence, that the knowledge your organisation runs on belongs to your organisation: that you know where it is, who can read it, which of it a machine wrote, and that you can prove all of that to a regulator, a counterparty or a court without asking anyone's permission. It is not a storage location and it is not a checkbox in a procurement form. It is a property of the whole estate, and either you have it or you are renting your own understanding of your business back from somebody else.
Two forces have made this the defining infrastructure question of the decade. The first is that language models absorb institutional knowledge and return it as prose that cannot be cited, corrected or audited. The second is that the cryptography protecting almost every record in existence has a known expiry date, and adversaries are already collecting encrypted material to open later. Both are running now. Neither waits for a budget cycle.
KXCO delivers data sovereignty through two systems that are built for it. Round Table delivers the knowledge layer: a typed, sourced, dated model of your business that compounds with every deal and outlives every model vendor. Sentinel delivers the cryptographic layer: it finds the breakable cryptography across your code, your dependencies and your live endpoints, hands you the fix, and ships every release with a post-quantum signature anyone can verify. This article sets out what each one delivers, and what an organisation holds at the end of a quarter that it did not hold at the start.
01What data sovereignty actually means
The phrase gets used loosely, so it is worth being exact. Data sovereignty is the condition in which an organisation retains authority over its own information: its location, its access, its provenance, its portability and its proof. Five properties, and all five have to hold at once. Any one of them missing and the others become claims rather than facts.
Location is the one most people mean when they say the words, and it is the least interesting of the five. Knowing which jurisdiction a database sits in matters for data residency law, and residency is a genuine obligation under the European Union's General Data Protection Regulation, the United Kingdom's data protection regime, and the growing set of national rules that require citizen records to remain inside national borders. But residency alone is weak. A file can sit in the right country and still be unreadable, uncitable and unattributable.
Access is the second: knowing precisely who can read each item, being able to prove that the control was applied rather than intended, and being able to show after the fact who actually read it and when. An access policy that exists in a document and not in the system is a statement of hope.
Provenance is the third and the one that has changed most in the last two years. For every fact your organisation holds, you should be able to answer four questions: where did this come from, when was it true, who accepted it, and did a machine write it. Before generative systems, the fourth question rarely came up. It now comes up in every serious diligence process, every audit and every regulatory conversation, and an organisation that cannot answer it is not in control of its own record.
Portability is the fourth: the ability to take your knowledge somewhere else. Not to export a database dump that only the original system can interpret, but to move the meaning, the structure and the evidence intact. Knowledge that only one vendor's software can read is knowledge that vendor part-owns, whatever the contract says.
Proof is the fifth and it binds the other four. Every claim above should be demonstrable to a third party who does not trust you, using tools they already have. A sovereignty claim that requires the claimant's cooperation to verify is a marketing position, not a control.
Hold those five together and you have a working definition that survives contact with a regulator: you know where it is, who can reach it, where it came from, that you can take it with you, and you can prove every part of that to somebody who has no reason to believe you.
02Two clocks, both already running
Data sovereignty moved from an architectural preference to an urgent obligation because of two independent timers. They have nothing to do with each other technically. They arrived at the same moment, which is why this decade is different.
The absorption clock
Every prompt an organisation sends to a hosted language model carries its proprietary context: pricing logic, client history, internal reasoning about a transaction, the operating procedure that took fifteen years to develop. That context is processed by a model the organisation did not train and cannot inspect, and what comes back is a single answer that is not retained as a durable asset.
Repeated at scale, this is an organisation renting its own thinking back to itself one token at a time. The pattern that its best people carry, the thing that actually distinguishes it from its competitors, never becomes something the organisation owns. It is absorbed rather than structured. You cannot cite a weight. You cannot correct one fact inside a model. You cannot take a customer back out of one. Ask the same question after a version change and the answer can move, with nothing to point at and no way to tell whether you or the model was wrong.
This clock runs faster the more successful an AI programme is. The organisations furthest along are the ones losing the most, because volume is the mechanism.
The cryptographic clock
The second timer is arithmetic. The public-key cryptography that protects essentially every transmitted and stored record, RSA and elliptic curve, is breakable by a sufficiently capable quantum computer using an algorithm published in 1994. The machine does not exist yet in the required form. The consequence, however, does not wait for it.
Encrypted traffic captured today can be stored today and decrypted the day the capability arrives. Security practitioners call this harvest now, decrypt later, and it converts a future capability into a present exposure for anything with a long confidentiality life: patient records, legal privilege, sovereign communications, transaction files, board material, identity credentials, anything with a multi-decade retention obligation.
Regulators have already priced this in. The United States National Institute of Standards and Technology ratified the replacement algorithms in 2024 as FIPS 203, FIPS 204 and FIPS 205. The National Security Agency's Commercial National Security Algorithm Suite 2.0 sets 2030 for national security systems. National Security Memorandum 10 sets 2035 for United States federal migration. Those are not aspirations. They are procurement gates, and they will arrive in supplier questionnaires long before they arrive in law.
The two clocks compound. An organisation that solves the knowledge problem and leaves the cryptography breakable has built a durable asset it cannot protect. An organisation that migrates its cryptography and leaves its knowledge inside a vendor's weights has protected a wrapper around something it does not own. Sovereignty requires both, which is precisely why KXCO builds both.
03The law is arriving ahead of the technology
Data sovereignty began as an architectural argument. It is becoming a legal one, and the direction of travel across every major jurisdiction is the same: obligations are moving from where data is stored towards what an organisation can prove about it.
Residency was the first wave
The European Union's General Data Protection Regulation established the pattern that most of the world has since followed: personal data carries obligations that travel with it across borders, and transfers outside the regime require a lawful basis. India, Brazil, China, Saudi Arabia, Indonesia, Vietnam, Nigeria and dozens of others have since enacted localisation or transfer rules of their own, with sector-specific requirements layered on top for finance, health and public records.
For a multinational this produces a practical problem that has nothing to do with storage cost. The same customer record can be subject to four different regimes depending on which entity holds it, which processor touched it and which purpose it was collected for. Answering a regulator's question about one record can require reconstructing its entire history across systems that were never designed to be read together.
Provenance is the second wave
The newer obligations are about origin rather than location. The European Union's Artificial Intelligence Act requires providers and deployers of certain systems to maintain technical documentation, keep logs, and be able to describe how outputs were produced. Financial regulators across the United Kingdom, the European Union, Singapore and Hong Kong have issued guidance on model risk and algorithmic accountability that asks, in various wordings, the same underlying question: for a given decision, can you show what informed it.
That question is trivial if the record was built with origin tracked on every fact, and close to unanswerable if it was not. An organisation that has been running generative tools across its operations for two years without provenance has accumulated an obligation it cannot discharge, and the volume grows daily.
Cryptographic assurance is the third wave
The third wave is already visible in procurement before it appears in statute. The United States has set federal migration deadlines through National Security Memorandum 10, the National Security Agency has set 2030 for national security systems under CNSA 2.0, and European and United Kingdom guidance points the same way. What that produces immediately, ahead of any enforcement date, is a supplier questionnaire asking what cryptography a vendor ships and when it will be replaced.
These three waves compound in a specific and expensive way. Residency asks where the data is. Provenance asks where the fact came from. Cryptographic assurance asks whether the record can be trusted at all. An organisation can satisfy the first and fail the second and third completely, which is exactly the position a great many organisations are currently in without having noticed.
The useful way to think about it is that the three waves converge on one requirement. An organisation must be able to produce, on demand, an account of a fact that includes where it lives, where it came from, who accepted it, what produced it, and cryptographic evidence that the account has not been altered. Every one of those is a property of the record rather than of a policy, which means it has to be built in rather than documented afterwards.
04What data sovereignty delivers
It is easy to describe sovereignty as a set of controls. It is more useful to describe what an organisation gets, because that is what the investment is measured against.
An asset that compounds. Knowledge captured as structure accumulates. The second transaction is easier than the first because the first is still there, typed and searchable and connected to everything else. The fifth is easier again. This is the compounding curve that a chat transcript never produces, because a transcript ends when the session does.
An answer to the audit question. When a supervisor, an auditor, a board or a counterparty asks where a number came from, the answer is a source, a date and a named person, produced in seconds rather than assembled over a fortnight from email. The cost of being asked drops to nearly nothing, which changes how often you can afford to be asked.
Leverage over your suppliers. An organisation whose knowledge lives as its own structure can change model vendors on a commercial decision rather than a migration project. The vendor knows it. That is worth more at renewal than any clause.
Speed with a defensible record. The reason institutions move slowly is rarely that the work is hard. It is that nobody can prove the work was done properly, so everything is checked twice. When proof is automatic, the second check stops being necessary.
A defence that survives the transition. Records signed with post-quantum cryptography today remain verifiable after the transition, without re-signing, re-issuing or explaining. The organisation crosses the line once and does not think about it again.
Institutional memory that survives its people. The senior person who knows why the 2019 structure was written that way retires. If their knowledge went into the model as typed structure, it is still there. If it went into their inbox, it left with them.
Those six outcomes are the return. Everything below is how KXCO delivers them.
05Round Table delivers the knowledge layer
Round Table is the KXCO ontology engine: the system that turns what your organisation knows into a typed, sourced, dated model that machines and people can both work in. It is the answer to the absorption clock, and it is the part of the estate that appreciates.
Start with what it hands you. At the end of a quarter running Round Table, an organisation holds a model of its own domain in which every entity is typed, every relationship is directional and named, every value carries the source it came from and the date it was true, and every acceptance carries the name of the person who made it. That model is queryable, exportable and independent of any model vendor. It is the asset.
Structure rather than prose
The difference between Round Table and a document store with search over it is that Round Table holds meaning rather than text. A company is an object of a type that has properties. A person works for it through a named, directional relationship. A holding has a size, an instrument and a date. Because the structure is explicit, a question like "which of our positions depend on a counterparty that also appears in three other exposures" is answerable by traversal rather than by reading.
This is what makes an ontology different from a vector store. A vector store retrieves passages that resemble your question. An ontology answers the question, and shows you the path it took.
The model proposes and a person decides
Round Table uses language models where they are strongest, which is reading a document and suggesting typed structure, and constrains them where they are weakest, which is deciding what is true. Every proposal a model makes enters a queue in a provisional state. A named person with the appropriate role accepts, corrects or rejects it, and that acceptance is itself a recorded, attributable act.
The result is a record in which the machine's contribution is enormous and completely traceable. You get the throughput of automated extraction and the defensibility of human acceptance, and the two are never confused with each other because the system holds them as different facts.
Separation of duties, enforced structurally
The operator who runs an extraction is not the person who accepts its output. That is a rule in the code rather than a line in a policy document, which is the difference between a control and an intention. Financial institutions recognise the pattern immediately, because it is the same principle that governs trade capture and settlement, and it is the reason the resulting record stands up in front of a supervisor.
06Industry knowledge, delivered as an owned asset
An ontology starts empty, and an empty ontology is a project rather than a product. Round Table ships with starting models for the domains institutions actually operate in, so the first day of work begins with a vocabulary rather than with a blank page.
A category is industry knowledge in structured form: the vocabulary of a domain, what its sources are called, and how they map to each other. It names no firm, no person and no figure. It is the frame, and your entities go inside it. Categories currently shipped include the following.
| Category | What it gives you on day one |
|---|---|
| Corporate oversight | The vocabulary of governance, risk and control: obligations, owners, evidence, review cycles and the reference standards they map to. |
| Trading equities | Instruments, issuers, holdings, exposures and the relationships that connect a position to the entities behind it. |
| Portfolio | Vehicles, commitments, capital movements and ownership chains, structured so a look-through question is a traversal. |
| AI sector | Who builds the compute, who builds the models, who builds the chips, and how they depend on each other, as a map rather than a reading list. |
| Biotech research | The vocabulary of programmes, assets, trials, endpoints and the evidence that supports each claim. |
| Object tokenization | Real assets, their legal wrappers, their rights and the record that ties a token to the thing it represents. |
| Customer behaviour | Accounts, journeys, signals and the relationships that make a pattern legible across products. |
| Behavioural | The vocabulary for describing how parties actually act, so behaviour becomes evidence rather than anecdote. |
| Process | Steps, owners, controls and handoffs, so an operating procedure becomes a model instead of a diagram. |
The commercial significance is straightforward. Buying an ontology platform with no starting model means paying a consultancy to invent your vocabulary before any value appears. Categories collapse that phase. Your team's first day is spent on your own entities, in a frame that already knows what an obligation, a holding or an endpoint is.
Categories are also the mechanism by which industry knowledge becomes an owned asset rather than a personal one. The sector expertise that currently lives with three senior people becomes the frame everybody works inside, and it stays when they do not.
07The record you can hand to anyone
Provenance is the property that turns a useful internal system into a defensible institutional one, and it is where Round Table is deliberately uncompromising.
Every fact carries its origin. The record distinguishes a value a person entered, a value a model proposed and a person accepted, a value that arrived from an external connector, and a value that came from the settlement layer. Those are four different kinds of knowledge and they are held as four different facts, because collapsing them makes the question "how much of this did a machine write" unanswerable.
The record names which model. As of the current release, provenance records the specific model that produced a proposal. Before it, the record knew that a machine had written something and nothing finer than that. This matters the moment an organisation runs more than one, and it matters enormously the moment an organisation runs its own. A record that says a machine wrote something is useful. A record that says which machine, on which date, accepted by which person, is evidence.
Sources and dates travel with the value. Every claim carries the source it came from, the date it is asserted true as of, and a tier describing what kind of source that is: a filed document, an audited statement, a board approval, a management assertion, an interview, a report. A number from an audited statement and a number somebody remembered in a meeting are both recorded, and they are never recorded as the same kind of thing.
Disagreements are kept, not resolved silently. When a second source says something different, both are held together with their sources and dates. A contradiction between two cited sources is a finding about the world, and a system that quietly overwrites one with the other has destroyed the most valuable thing in the record.
Acceptance is signed. Material changes are signed with post-quantum cryptography and recorded, which means the record is tamper-evident and independently checkable. This is where Round Table and the cryptographic layer meet, and it is why the two systems belong in the same estate.
Put together, this delivers something specific: an organisation can hand its record to a supervisor, an auditor, an acquirer or an opposing counsel and let them check it themselves. That is a fundamentally different negotiating position from one in which every claim requires your cooperation to verify.
08Rent the intelligence. Own the knowledge.
This is the sentence that captures the whole architecture, and it is worth taking literally.
Every model an organisation uses is rented: somebody else's weights, on somebody else's hardware, on somebody else's release schedule. That is a perfectly reasonable arrangement for the reasoning. It is a poor one for the thing being reasoned over. Round Table draws the line exactly there. The model is a component. The knowledge is the asset. The component is replaceable and the asset is yours.
In practice this delivers three things.
Model choice becomes a commercial decision. Round Table reaches a model through a single, deliberate point in the system, which means the whole engine moves to a different provider, a different model, or an open-weight model running on your own hardware, through configuration rather than a rewrite. Frontier model this quarter, open weights next quarter, a model fine-tuned on your own accepted history after that. The ontology's rules do not change, because they were never expressed in terms of a vendor.
Your context stops leaving. When the inference runs on infrastructure your organisation controls, the proprietary structure inside a prompt stays where your policies apply. A prompt is not a throwaway string. It routinely contains the same pricing logic, client context and operating procedure that the whole exercise exists to protect, and sovereignty covers what is sent as well as what is returned.
The upgrade path costs nothing. When a better model appears, and one always does, pointing at it is a change of address. The knowledge does not migrate, because it never lived in the model. As the ontology page puts it: you should never have to migrate the truth.
There is a discipline underneath this, and KXCO applies it before any deployment. Five things have to be true before a model is put to work: a typed structure exists for the domain, every model output is provisional until a named person accepts it, origin is tracked on every fact, the permission model is enforced structurally, and the institutional knowledge is captured as structure rather than left in a context window. Where those five hold, a model deployment produces a compounding asset. That standard is what makes the difference between a system an institution can run on and a demonstration.
09Why an ontology, and not the things it gets compared to
Every organisation considering this already owns systems that hold data, and the reasonable first question is what an ontology adds. The answer is specific in each case, and it is always about what the system can be asked.
| What you already have | What it answers well | What the ontology adds |
|---|---|---|
| Data warehouse | Aggregate questions over rows you already model: totals, trends, cohorts. | Meaning between the rows. A warehouse knows a column called counterparty_id. An ontology knows that this counterparty guarantees that obligation, which is held by that vehicle, in which you have this exposure, and can traverse it. |
| Vector store | Finding passages that resemble a question. | An answer rather than a resemblance. A vector store returns text that looks relevant; an ontology returns the fact, the source, the date, who accepted it, and the path it took to get there. |
| Document management | Custody, versioning and retrieval of files. | The contents as structure. A document system knows it holds a contract. An ontology knows the parties, the term, the triggers and the obligations inside it, and connects them to every other agreement that shares a party. |
| CRM | What somebody chose to write down about a relationship. | What actually happened. Relationships built from recorded activity rather than from manual logging, which is the difference between a history that is thin and stale and one that is complete because nobody had to maintain it. |
| Model fine-tuning | Producing outputs in your organisation's idiom. | An asset you can inspect. A fine-tune absorbs knowledge into weights that cannot be cited, corrected fact by fact, or carried to another model. An ontology holds the same knowledge in a form you can query, correct, prove and take with you. |
The test that separates them
There is a single question that distinguishes an ontology from everything above, and it is worth putting to any system an organisation is relying on: pick a number that matters, and ask what it rests on.
A warehouse returns the number. A vector store returns a passage containing something like the number. A document system returns the file it might be in. A fine-tuned model returns a confident sentence and no way to check it. An ontology returns the value, the source it came from, the date it was true as of, the tier of that source, the person who accepted it, whether a machine proposed it and which machine, and every other claim in the record that disagrees with it.
The last of those is the one people underestimate. A system that silently resolves contradictions between sources has destroyed the finding. Two cited sources that disagree is not a data quality problem to be cleaned up. It is information about the world, and in diligence it is frequently the most valuable information present.
These are not alternatives to each other
None of this argues for replacing systems that work. A warehouse remains the right place for aggregate analytics. A document system remains the right custodian of files. The ontology is the layer that gives those systems meaning between them, and it is the layer that a model has to reason over if its output is going to be usable in an institution rather than merely impressive in a demonstration.
That is the reason the ontology is the part of the estate worth owning outright. Every other layer is replaceable infrastructure with competitive suppliers. The model of your own business is the one thing nobody else can sell you, and the one thing that is worth more every year you keep it.
10Sentinel delivers the cryptographic layer
Sentinel is the KXCO quantum-resistant cloud: it finds the breakable cryptography across your software, hands you the exact fix, and ships every release with a post-quantum signature anyone can verify. It is the answer to the second clock, and it is the part of the estate that has a deadline attached.
Start again with what it hands you. At the end of a Sentinel engagement an organisation holds three things it did not hold before: a complete inventory of where breakable cryptography lives across its code, its dependencies and its live endpoints; a remediation path for each finding, with the fix rather than a severity score; and a signed, independently verifiable proof for every deployment that went out. That third item is the one that turns a security programme into evidence.
Why an inventory is the hard part
Every serious organisation intends to migrate its cryptography. Almost none of them can say where it is. RSA and elliptic curve are not concentrated in one place; they are distributed across application code written over twenty years, transitive dependencies nobody chose directly, container images, certificates, hardware modules and endpoints that were configured before the current team arrived.
Migration cannot be scheduled until the inventory exists, and the inventory is not something a team can produce by asking around. That is the bottleneck Sentinel removes first, because everything downstream of it is planning.
Two components, one outcome
Sentinel delivers through two named components. Bastion finds the exposure and gives you the fix. PQC Host ships your software with the proof attached. Together they cover the two halves of a migration: knowing what to change, and being able to demonstrate that you changed it.
11Bastion delivers the map and the fix
Bastion scans code, dependencies and live endpoints for quantum-vulnerable cryptography, and hands back the exact remediation. Point it at a repository or a URL.
What it delivers is a map, not a report. The distinction matters commercially. Existing scanning platforms produce a document with a severity score, and that document then requires an engineering team to work out what to actually do, which is where these programmes stall. Bastion names the file, the dependency and the endpoint, and gives the fix that makes it post-quantum. The output is work you can assign on Monday.
It covers the transitive surface. The cryptography that will fail an assessment is rarely the cryptography a team chose. It is four levels down a dependency tree in a library that was pulled in for something unrelated. A scan that reads only first-party code produces a clean result and a false sense of security.
It produces a cryptographic bill of materials. Bastion exports a CBOM in CycloneDX 1.6 format, the industry standard for describing exactly which cryptographic assets a piece of software contains. This is the artefact that supplier questionnaires are beginning to ask for, and the organisations that can produce one on request will win procurement decisions against organisations that need six weeks to assemble one.
Every scan result carries a signature. A Bastion report is signed with ML-DSA-65, the NIST post-quantum signature standard, which means the result cannot be quietly altered after the fact, by anyone. A security report that can be edited is a conversation. A signed one is a record.
It keeps watching. The estate does not stay fixed, because dependencies update and endpoints get reconfigured. Daily rescans and drift alerts mean the inventory stays true rather than becoming a snapshot of the day the project ended.
12PQC Host delivers the proof with every release
Finding the exposure is half the work. Demonstrating that you fixed it, continuously, to somebody who does not take your word for it, is the half that decides audits and procurement.
PQC Host is hosting with the proof built into the pipeline. Connect a repository. Every deployment is scanned before it builds. Quantum-vulnerable dependencies can block the deploy rather than merely annotate it. The moment the build completes, the platform signs a deployment manifest containing the commit hash, the timestamp, the scan result and the live URL, with an ML-DSA-65 post-quantum signature.
The proof stands on its own. This is the property worth dwelling on. Verification depends on the signature and on a platform public key that is published openly. No account is required, no connection to KXCO is required, and no trust in KXCO is required. The check is mathematical, which means a result cannot be quietly rewritten and a counterparty can satisfy themselves without involving you at all.
Consider what that changes in practice. A regulator asks whether the version of the system that processed a set of transactions in March was the version you told them it was. Instead of an internal change log and an assurance, you provide a signed manifest they verify themselves with open tooling. The conversation ends in minutes rather than becoming a workstream.
The pipeline is the control. A migration that depends on engineers remembering to check something will regress, because every migration eventually does. When the gate is in the deploy path, the estate cannot silently drift backwards. The organisation crosses the line once and stays across it.
The full path, end to end: connect the repository, scan the cryptography, score the risk, apply the post-quantum fix, attest the deployment with ML-DSA-65, then monitor with daily rescans and drift alerts. Six steps, and the artefact at the end of them is a proof rather than a promise.
13The standards, and the dates attached to them
Sovereignty claims are worth what the standards behind them are worth, so it is worth being precise about which ones apply and when they bite.
| Standard | What it covers | Why it matters |
|---|---|---|
| NIST FIPS 203 | ML-KEM, post-quantum key encapsulation | The ratified replacement for the key exchange protecting data in transit. |
| NIST FIPS 204 | ML-DSA, post-quantum digital signatures | The signature standard behind KXCO identities, attestations and settlement. ML-DSA-65 is the parameter set in use. |
| NIST FIPS 205 | SLH-DSA, hash-based signatures | A conservative alternative resting on different mathematics, available where an organisation wants a second foundation. |
| CNSA 2.0 | NSA suite for national security systems | Sets 2030 for national security systems, and drives supplier requirements well ahead of that date. |
| NSM-10 | US federal migration memorandum | Sets 2035 for federal migration, which shapes procurement across every vendor selling into that market. |
| CycloneDX 1.6 | Cryptographic bill of materials | The format in which an organisation demonstrates what cryptography its software actually contains. |
KXCO builds on the NIST standards directly. Identities, signatures and settlement use ML-DSA-65, and every action is recorded so it can be verified independently with open tooling.
The dates deserve reading carefully. Nineteen thirty and twenty thirty-five sound distant until you count backwards through the work: an inventory, a remediation programme across a dependency tree nobody has fully mapped, a certificate estate, hardware modules, third-party integrations whose vendors have their own timelines, and a testing cycle for each. Institutions that have run a large cryptographic migration before recognise the shape immediately, because the last one took most of a decade.
There is also a commercial timer that runs ahead of the regulatory one. Supplier questionnaires asking for post-quantum readiness are already circulating. The organisation that answers with a signed CBOM wins the procurement against the organisation that answers with an intention.
14Two systems, one sovereign estate
Round Table and Sentinel deliver different halves of the same property, and they are designed to meet.
Round Table produces the knowledge: typed, sourced, dated, attributed. Sentinel produces the proof: signed, timestamped, independently verifiable. Where they meet, an acceptance in the ontology becomes an attested act rather than a database row. The fact that a named person accepted a model's proposal on a particular date, over a particular source, is recorded and signed with the same post-quantum cryptography that protects the deployment that produced it.
That combination delivers something neither system produces alone: a knowledge asset that is defensible under adversarial examination. Not merely well organised, but provable. The distinction becomes obvious in the moments that matter, which are the moments when somebody has an incentive to doubt you.
Underneath both sits Armature L1, the post-quantum settlement network and public record, which is where attestations anchor so that a claim about what happened at a particular time can be checked against a record nobody controls unilaterally.
And around both sits the practical layer: Meridian, where the deals actually run, with rooms whose every access, signature and document movement becomes typed structure in the ontology when the transaction closes. This is what makes the compounding real rather than theoretical. The knowledge is not gathered in a separate exercise after the fact. It accumulates as a by-product of the work, and it survives the room.
An organisation that runs all of it holds a single sovereign estate: the transactions, the knowledge they generated, the evidence for every fact, and the cryptographic proof that the whole record is what it says it is. That is the deliverable. Everything else is implementation detail.
15Sovereignty when the actor is a machine
The sovereignty question changes shape the moment software starts acting rather than answering. An agent that reads a document raises a confidentiality question. An agent that spends, signs or commits raises an authority question, and authority is a harder problem than access.
KXCO treats an autonomous system as a first-class participant held to the same cryptographic standard as a person, which is the only arrangement that keeps the record coherent once machines are acting inside it.
An agent holds a real identity
Every agent carries a verifiable identity anchored on the open record, derived from an ML-DSA-65 key. That means an agent can prove which agent it is and who it belongs to, to a counterparty that has never encountered it before, without a shared account system. The alternative, which is the current industry default, is an API key that proves only that somebody knows a secret.
Authority is granted in explicit limits
An agent is authorised to act within bounds that are set rather than assumed: what it can spend, what it can sign, what it can access, and nothing beyond that. Where authority is delegated onward, the delegated authority can only ever be narrower than the authority it came from. That property matters more than it sounds. It is what stops a chain of agents from accumulating permissions nobody granted, which is the failure mode that makes autonomous systems unusable in a regulated setting.
Every action carries the agent's own signature
An agent's outputs and decisions carry its own quantum-safe signature, provably from that agent and unaltered. Because everything is signed and recorded, an agent's actions can be traced and audited afterwards by the organisation that deployed it or by any counterparty it dealt with. Accountability stops being a policy commitment and becomes a property of the record.
A proposal becomes an action only by a named decision
This is the rule that makes the rest of it safe to operate. Where a wrong or unaccountable action is a real liability rather than a defect to patch later, a proposal is not permitted to become an action until it has been checked, previewed and approved by name. The agent prepares the change and shows what it would do. A person with the authority to accept it does so, and the acceptance is what is recorded and signed.
An organisation running agents this way gets the throughput of automation and keeps the thing that matters: at every material step, a named human decision exists in the record, and the machine's contribution is visible rather than merged into it.
Why this is a sovereignty question and not only a safety one
It is tempting to file agent governance under safety and move on. It belongs under sovereignty for a straightforward reason. An organisation whose agents act through an external provider's identity, under permissions that provider defines, producing outputs that provider logs, does not have authority over its own operations. It has an operating dependency dressed as a productivity gain.
When the identity is yours, the authority model is yours, the signatures verify against a key published on an open record, and the resulting facts land in an ontology you own, autonomy becomes something the organisation extends rather than something it outsources. That is the difference between deploying agents and being deployed by them.
16What the first quarter delivers
Sovereignty programmes fail when they are scoped as transformations. They succeed when they are scoped as a sequence of things an organisation holds at the end of each phase. Here is what a first quarter produces.
Weeks one to two: the map
Bastion runs across the repositories, the dependency tree and the live endpoints. At the end of it the organisation holds a complete inventory of breakable cryptography, a CBOM in a format procurement recognises, and a remediation list ordered by exposure. This is the artefact most organisations have never had, and it converts the migration from an unbounded worry into a finite list of tasks.
Weeks three to six: the starting model
A category is selected and the ontology is stood up against one real dataset. Not a synthetic fixture, and not a pilot with representative data: one genuine, unmodified body of the organisation's own material. Round Table's agents propose typed structure, named people accept or correct it, and the queue moves.
The measurable output is a model of a real part of the business with a provenance record behind every fact in it. The measurable behaviour change is that people begin asking the model questions they used to ask each other.
Weeks seven to ten: the pipeline
PQC Host takes the first services. Deployments begin carrying signed manifests. The remediation list from week two starts closing, and each closure is attested rather than asserted. The organisation can, for the first time, answer the question "prove that the version running in production is the version you approved" without assembling anything.
Weeks eleven to thirteen: the compounding starts
The second dataset goes into the same model and takes a fraction of the time, because the vocabulary already exists and the entities are already there. This is the point at which the curve becomes visible to whoever authorised the budget, and it is the point at which the programme stops needing to be defended internally.
At the end of the quarter the organisation holds: a cryptographic inventory and a live CBOM, a working ontology over real data with full provenance, signed deployment attestations for the services that moved, and a team that has done it once and can now do it repeatedly. All of it belongs to the organisation, and all of it is portable.
17Where to begin
The two clocks run at different speeds for different organisations, and the right first move follows from which one is closer.
If a supplier questionnaire, an audit or a regulatory timetable is the pressure, begin with Bastion. The inventory is the gate on everything else and it is the fastest artefact to produce. Point it at your repositories and your live endpoints and you will know within days what the actual scope of the migration is, which is almost never what the estimate assumed.
If an AI programme is already running and the knowledge is disappearing into it, begin with Round Table. Choose the domain where institutional memory is most concentrated in the fewest people, because that is where the compounding is worth most and where the loss is most expensive. Pick a category, load one real dataset, and put the queue in front of the people who actually know the answers.
If a transaction is in front of you, begin with Meridian. Run it in a room, and the knowledge it generates arrives as structure rather than as a folder nobody opens again. The deal pays for the infrastructure and the infrastructure outlives the deal.
Whichever entry point applies, the principle is the same and it is the thing worth carrying away from this article. Take the business as seriously as the US Government takes its wars. The knowledge an organisation runs on and the cryptography protecting it are not IT line items. They are the two things that determine whether the organisation still owns itself in ten years, and both of them are on a clock that started without asking.
KXCO delivers both. Round Table for the knowledge. Sentinel for the proof. Meridian for the work that generates them, and Armature L1 for the record underneath. One estate, sovereign, and yours.
KXCO Sovereign AI sets out what a customer-hosted deployment delivers, what to have ready, and what it costs. KXCO Sentinel covers the cryptographic layer, and the KXCO ontology is the public model of how the whole thing works.
18Frequently asked questions
What is data sovereignty?
Data sovereignty is the condition in which an organisation retains authority over its own information across five properties at once: where it is located, who can access it, where each fact came from, whether it can be moved elsewhere intact, and whether all of that can be proven to a third party who does not trust the organisation making the claim. Location alone, which is what the phrase is often reduced to, is the weakest of the five.
How is data sovereignty different from data residency?
Data residency concerns which jurisdiction data physically sits in, and it is a genuine legal obligation under regimes such as the European Union's General Data Protection Regulation. Data sovereignty is broader: it also covers provenance, portability and proof. A record can satisfy residency requirements completely and still be unciteable, unattributable and locked inside one vendor's format, in which case the organisation holds the file but not the authority over it.
What is Round Table?
Round Table is the KXCO ontology engine. It turns what an organisation knows into a typed, sourced, dated model that both people and machines can work in. Language models propose typed structure, named people accept or correct it, and every fact carries its origin, its source, its date and the identity of the person who accepted it. It ships with starting models for domains including corporate oversight, trading equities, portfolio, AI sector, biotech research, object tokenization, customer behaviour, behavioural analysis and process.
What is Sentinel?
Sentinel is the KXCO quantum-resistant cloud. It has two components. Bastion scans code, dependencies and live endpoints for quantum-vulnerable cryptography such as RSA and elliptic curve, and returns the exact fix along with a cryptographic bill of materials in CycloneDX 1.6 format. PQC Host provides hosting in which every deployment is scanned before it builds and signed on completion with an ML-DSA-65 post-quantum signature that anyone can verify independently.
Why does post-quantum cryptography matter before quantum computers arrive?
Because encrypted material captured today can be stored and decrypted once the capability exists. This is known as harvest now, decrypt later, and it converts a future capability into a present exposure for any record with a long confidentiality life, including patient data, legal privilege, transaction files and identity credentials. Regulatory dates already reflect this: CNSA 2.0 sets 2030 for national security systems and NSM-10 sets 2035 for United States federal migration.
Which post-quantum standards does KXCO build on?
The NIST standards ratified in 2024: FIPS 203 for ML-KEM key encapsulation, FIPS 204 for ML-DSA digital signatures, and FIPS 205 for SLH-DSA hash-based signatures. KXCO identities, signatures and settlement use ML-DSA-65, and every action is recorded so it can be verified independently using open-source tools.
Can an organisation run its own model with Round Table?
Yes. Round Table reaches a model through a single deliberate point in the system, so the engine moves to a different provider, a different model, or an open-weight model running on the organisation's own hardware through configuration. The ontology's rules are expressed in terms of structure rather than in terms of a vendor, so they are unchanged by the move.
How does provenance record what a model contributed?
Each fact carries an origin describing the class of actor that produced it, distinguishing a person, a model, an external connector and the settlement layer. Alongside it the record names the specific model that produced a proposal. The person who accepted the fact is recorded separately, because the operator and the origin are two different facts and conflating them makes the question of how much a machine wrote unanswerable.
What is a cryptographic bill of materials, and why is it being asked for?
A CBOM is a structured inventory of the cryptographic assets a piece of software contains, expressed in CycloneDX 1.6. It is becoming a standard item in supplier questionnaires because an organisation cannot assess a vendor's quantum readiness without knowing what cryptography that vendor actually ships. Producing one on request is increasingly a procurement advantage.
How is a KXCO attestation verified?
Verification uses the ML-DSA-65 signature and the platform public key, which is published openly. No account, no connection to KXCO and no trust in KXCO is involved. The check is mathematical, which is what allows a counterparty, an auditor or a regulator to satisfy themselves independently.
What is harvest now, decrypt later?
Harvest now, decrypt later is the practice of capturing encrypted material today and storing it until a quantum computer capable of breaking the encryption becomes available. It converts a future capability into a present exposure, because the interception has already happened by the time the capability arrives. It is the reason post-quantum migration deadlines are set well before any such machine is expected, and the reason records with long confidentiality lives, including patient data, legal privilege, transaction files and identity credentials, are the priority for migration.
What is knowledge sovereignty, and how does it differ from data sovereignty?
Knowledge sovereignty is the part of data sovereignty concerned with meaning rather than storage: whether an organisation owns the structured understanding of its own business, or whether that understanding has been absorbed into a model it does not control. Data sovereignty asks whether you hold your data. Knowledge sovereignty asks whether you hold what your data means. An organisation can retain every file and still lose knowledge sovereignty by routing its reasoning through a vendor's model, because the pattern that results is held in weights that cannot be cited, corrected fact by fact, or carried elsewhere.
How long does a post-quantum migration take?
The determining factor is not the cryptography, it is the inventory. Organisations that have completed a large cryptographic migration before generally describe multi-year programmes, and the phase that consumes the time is discovering where the affected cryptography actually lives across application code, transitive dependencies, certificates, hardware modules and third-party integrations. That is why the inventory is the first artefact worth producing: it converts an unbounded programme into a finite and schedulable list, and everything after it is planning.
Where should an organisation start?
If a supplier questionnaire, audit or regulatory timetable is the pressure, start with Bastion, because the cryptographic inventory gates everything else and is the fastest artefact to produce. If an AI programme is already absorbing institutional knowledge, start with Round Table in the domain where that knowledge is concentrated in the fewest people. If a transaction is in front of you, start with Meridian and let the deal generate the structure.