Engineered for Institutional Margins.
Adopted for Human Sovereignty.
Every capability across the Salient Innovation Set delivers an immediate, symmetrical return: radical margin recovery for the enterprise tenant, paired with frictionless dignity and absolute cryptographic safety for the citizen.
How the Tenant Expands Margins
Transforming operating models from defensive cost centres into agile, shared revenue engines through multi-tenant pooling and mathematical compliance.
-
CapEx Pooling & No Single-Tenant Hardware
POI Appliances run white-label on co-funded premises. Reach 50 commercial catchments without funding 50 proprietary branch builds.
-
Zero Interchange & Flat-Fee Clearing
Instant Account-to-Account rails (SEPA Instant / PayShap) bypass 1.5–3.5% card scheme tolls with predictable, flat sub-cent clearing fees.
-
Compliance by Construction
Agreement DAGs enforce statutory mandates at wire speed; non-compliant states cannot execute, eliminating retrospective audit penalties.
-
Accelerated Partner Onboarding
Pre-verified BIAN and ArchiMate capability components compress multi-firm integration cycles from quarters to days.
Why the Customer Loves Using It
Delivering sovereign dignity and verifiable security where users never surrender control over their identity, consent, or funds.
-
Nothing Stored to Steal
Credentials remain in the user's oneWallet. A breach of a merchant's server reveals zero identity records, protecting citizens completely.
-
One Pattern, Everywhere
The same intuitive tap-and-confirm interaction works seamlessly at a high-street kiosk, transit hub, EV charger, or smartphone.
-
Delegated Authority, Never Escalated
Autonomous AI agents carry single-use, bounded warrants; an agent checking information cannot escalate its authority to transfer money.
-
Payments That Do Not Fail
When a payment network degrades, the transaction reroutes with authentication preserved – zero declines, zero repeated entries.
Notary Runtime Manifest
Hardware-Anchored Legal-Cryptographic Witness
The Notary: The Epistemic Anchor of Non-Repudiation, Bitemporal Proof & Substantiated Integrity
I. The Paradigm Shift of the Constitutional Notary
In traditional enterprise architectures, auditing, identity validation, and security logging are passive, decoupled, and retrospective software-layer concerns. Conventional IT Asset Management (ITAM), Configuration Management Databases (CMDBs), and Security Information and Event Management (SIEM) systems act as passive "graveyards of static data". They capture what an administrator believes or hopes is running, creating a dangerous "compliance shadow" where operational drift, unauthorised configuration mutations, and active vulnerabilities go completely undetected.
The platform redefines this framework by introducing the Constitutional Notary (operating within the platform’s System of Record (SoR)) as an active, highly privileged platform capability and legal-cryptographic anchor. Rather than functioning as a soft, application-layer logging utility, the Constitutional Notary enforces Substantiated Integrity as a hardware-rooted physical invariant.
The Authoritative Trinity
Under the platform’s Separation of Powers, the control plane is structured as The Authoritative Trinity, which independently and mathematically proves:
By strictly separating legal state, cryptographic routing, execution boundaries, and the forensic recording of evidence, this architecture establishes a "Silicon Judiciary" at the physical edge of the network. This guarantees that the executive branch – the System of Orchestration (SoO) – operates as a Structurally Hobbled Executive, completely incapable of executing operational scripts, modifying data structures, or actuating physical edge peripherals (like secure cash vaults or locker latches) without the explicit, notarised warrant of the Silicon Judiciary.
II. The Augmented Taxonomy of Notary Capabilities
To convert analogue trust into digital sovereignty, the Constitutional Notary is organised around four active, non-bypassable functional pillars:
Identity Attestation
- Continuous KYC and KYB
- Sovereign NHI Minting & Keys
QTSP/QEAA
- eIDAS 2.0 VC Issuance (DToD)
- Zero-Knowledge Attribute Proof
TSA Notarisation
- Valid-Time Verification
- Policy Version Locking (PH)
LAHE & WAS Sealing
- Cryptographic State Packaging
- TEE/HSM-Signed Journal Entries
1. Identity Attestation & The Phygital Root of Trust
Before any human or machine entity is permitted to propose an intent or execute a transaction, the Notary establishes a verifiable, hardware-rooted identity boundary. This is executed through **Continuous KYC/KYB & Onboarding** (utilising forensic-grade biometrics scanned at physical POI Appliances) and **Non-Human Identity (NHI) Minting** (provisioning TEE enclaves and autonomous software actors with unique cryptographic identities bound to specific roles to enforce least privilege).
2. QTSP and QEAA Functional Equivalency
The Notary is architected to operate at the standard of a Qualified Trust Service Provider (QTSP) and a Qualified Electronic Attestation of Attributes (QEAA) authority under eIDAS 2.0. This includes **Verifiable Credential (VC) Issuance** via the **Digital Twin of the Document (DToD)**, which ingests wet-ink physical instruments via multi-spectral sensors at POIs to issue cryptographically secure digital counterparts, and **Attribute Attestation** to enable privacy-preserving Zero-Knowledge Proofs (ZKPs) across multi-tenant boundaries.
3. Time-Stamping Authority (TSA) Notarisation
The TSA acts as the temporal locking mechanism that establishes the irreversible physics of the platform's ledger. It generates **Valid-Time Cryptographic Proof** of when a specific real-world event occurred, and enforces **Policy Version Locking** by sealing the exact active Policy Hash (PH) and Axiom MESH Version Hash active at the precise millisecond of execution. This prevents retroactive regulatory, litigation, or contract drift.
4. Lawful Act Hyperedge (LAHE) Sealing
The final mechanism that transforms a transient software transaction into an immutable, legally binding event. It bundles the payload (including ephemeral On-Behalf-Of / OBO Tokens), measured Hardware Bill of Materials (HBOM), Verifiable Adjudication Commitment (VAC), and TSA timestamp into an indivisible **Provenance Envelope**, applying a qualified digital seal via FIPS 140-3 Level 3 Central Cryptographic Key Management System (CKMS) HSMs. Any post-execution alteration immediately breaks the seal.
III. Advanced Architectural Primitives & Operational Execution
To bridge the gap between absolute regulatory auditability and high-frequency, wire-speed transactions, the Notary implements three advanced architectural primitives:
1. The Asynchronous Observer Model
Completes transactions instantly at wire-speed the moment the hardware-isolated DRAGON ASIC adjudication engine issues its Lawful Warrant (PERMIT) and executes the local operation inside a TEE. Completed execution telemetry is immediately bundled, stamped with a Sequential Hyperedge Nonce, and pushed out-of-band to the Notary, which asynchronously commits the final LAHE to the bitemporal ledger.
2. The Minimum Viable Evidence Bundle (MVEB)
To protect user privacy, the MVEB encapsulates only the explicit verdict (PERMIT/VETO), the active Policy Hash (PH) version, the Dominant Rule ID, Zero-Knowledge Proofs (ZKPs) verifying eligibility without transmitting raw PII, the executing node's physical configuration (HBOM), and the Wipe Attestation Signature (WAS) verifying post-execution memory sanitisation.
3. Bitemporal Semantics & "Auditability-as-Recomputation"
By tracking mutations across Valid-Time (\(T_V\)) and Transaction-Time (\(T_X\)), the Notary eliminates log-tampering vectors. Under audit, regulators inject the sealed MVEB into a read-only Recomputation Sandbox running a deterministic clock environment. Replaying the path against the archived Policy Hash mathematically validates compliance without exposing sensitive data.
Bitemporal Graph Matrix & Replay Sandbox
Visualising the coordinate matrix showing Valid-Time (\(T_V\)) versus Transaction-Time (\(T_X\)) state lattice recomputation under version-locked Policy Hashes.
Target Asset: /images/diagrams/bitemporal-replay-matrix.svg
IV. Guardianship of the Three-Lifecycle PAP Canvas
The Constitutional Notary provides continuous verification and cryptographic record-keeping across the platform's core Product, Agreement, and Party (PAP) lifecycles:
Product (PDLC)
Audits xBOM files via oneCERT to emit a Notarised Provenance Hash.
Agreement (ALM)
Locks Actuator Runbooks to governing contracts and active Policy Hashes.
Party (PLM / cATO)
Monitors live nodes via cATO heartbeats, triggering halts on security drift.
1. Product Lifecycle Management (PDLC) & Provenance Hash
SBOM, HBOM, MBOM, and DBOM assets are audited automatically by the oneCERT subsystem. If compliant, oneCERT issues a certificate which the Notary intercepts and packages with Transaction-Time (\(T_X\)) to write a permanent, tamper-evident **Notarised Provenance Hash** to the ledger. This enforces a strict "No xBOM, No Deploy" policy.
2. Agreement Lifecycle Management (ALM) & Executable Contracts
Converts natural language agreements into mathematically verified, machine-executable Agreement DAGs. Every sensitive operational act executed by an Actuator DAG is witnessed and signed by the QTSP Notary, guaranteeing that system outputs are mathematically bound to verified policies and legal contracts.
3. Party Lifecycle Management (PLM) & cATO Lease Verification
Tracks active identities (DToP and NHIs) using the Registrar's Continuous Authority to Operate (cATO) leases. The Notary validates these leases via high-frequency cryptographic heartbeats; security drift or policy failure triggers immediate lease revocation and a kernel-level **Atomic Halt** to block resource access.
V. Decommissioning, Revocation & Lifecycle Decoupling
Managing the end-of-lifecycle phase requires robust boundaries. The Notary orchestrates a secure, fail-closed decommissioning sequence to prevent data persistence, security drift, or policy evasion.
1. The Separation of Powers in Decommissioning
Decommissioning is partitioned across three branches to prevent administrative bypass: the **Registry Branch (Registrar)** formally updates the Party KG to revoke active attestations; the **Executive Plane (System of Orchestration)** triggers Actuator DAG runbooks to run physical wipes; and the **Witness Branch (The Notary)** independently intercepts execution telemetry to verify the hardware wipe and write cryptographic proof to the ledger.
2. The Wipe Attestation Signature (WAS)
Enclave session termination triggers the DRAGON ASIC's hypervisor to execute a hardware-level interrupt loop, zeroing CPU registers, cache lines, and encrypted memory pages. The local TPM verifies the zeroed registers and signs a **Wipe Attestation Signature (WAS)**, which the Notary packages into an MVEB and commits to the ledger.
3. Catastrophic Fault Witnessing: The "Last Gasp" Protocol
Upon complete power failure or chassis breach, super-capacitors supply temporary power, triggering a mandatory, kernel-level "Last Gasp" routine. This zeroes all registers and cryptographic keys, generating a final WAS which the Notary logs out-of-band to prove zero data leakage.
4. Access Severance vs. Obligation Persistence (The Data Orphan Solution)
The Notary decouples legal authority from legal obligation. A revocation event instantly collapses active permissions (\(P\)-nodes) and OBO Tokens, preventing key access. However, legal obligations to retain (\(O\)-nodes) are preserved as permanent, isolated constraints within the federated data mesh. Once the retention window expires, the system executes a final purge and TEE wipe, verified by a Notary-witnessed WAS.
POI Hardware Enclave & Edge Attestation Stack
Visualising the hardware cross-section of a POI Appliance showing DRAGON ASIC registers, TEE Silicon Apartments, secure bus interfaces, and XFS4IoT forensic peripherals.
Target Asset: /images/diagrams/poi-hardware-enclave-stack.svgVI. The NHI-Anchored Lifecycle & Agentic Governance
Trust for machine entities and autonomous agents is established through a strict four-step cryptographic chain of custody:
1. Provisioning
Registrar issues a purpose-bound cryptographic identity (DID/X.509) bound to Tenant, Purpose, and keys.
2. Artifact Generation & Signing
NHI executes training or reasoning task, generates artifact (MBOM), and signs it with its key.
3. Notarisation
Signed artifact is submitted to Notary; Notary verifies signature and anchors the hash in the ledger.
4. Distribution & Verification
Edge node loads model, performing full-stack verification of the signature chain and policy match before execution.
Every action or contract negotiation executed by the AI under this delegated authority is dynamically adjudicated and sealed as an independent VAC. This guarantees that the human principal is provided with a completely transparent, unalterable, and machine-readable record showing exactly how, when, and why their authority was exercised, establishing an unbreakable chain of custody for autonomous commerce.
VII. Phygital Edge Expansion: The Silicon Judiciary in Action
The platform provides a transformative perspective on how boutique institutions, such as Tier 3 and 4 law firms, can leverage POI Appliances (CivicHUBs, LockerShop appliances, and Switcher+ nodes) to transition from remote advisors into High-Assurance Service Anchors. Smaller firms can provide a "Silicon Judiciary" at the edge of the network, ensuring transaction validity:
Ubiquitous Identity Proofing
POI appliances equipped with 3D UHD Depth Mapping, UV/IR multi-spectral scanners, and liveness checks match physical individuals to credentials, allowing boutique firms acting as QTSPs to issue remote Lawful Warrants.
Secure Document Fulfilment
Smart lockers allow physical credentials, deeds, or wills to be loaded by staff and retrieved by authenticated clients. Locker latch activation commits a Lawful Act Hyperedge (LAHE) at the exact millisecond.
"Monetised Act" Royalties
Firms pre-certify Agreement DAG stanzas or Skill Envelopes containing legal rules. When clients invoke these stanzas at POIs, the firm earns micro-royalties, scaling legal logic into passive infrastructure products.
VIII. Standards Integration: BIAN Executable Semantics
Co-formalised with the Banking Industry Architecture Network (BIAN) Service Landscape v13.0/v14.0, the platform converts passive Service Domains (SDs) into active, hardware-anchored execution blocks:
Separation of Powers Branch Tags
Idempotent Atomic Stanzas
Verifications, card issuances, and payments are defined as idempotent stanzas compiled inside declarative Actuator DAG Runbooks to guarantee predictable execution behaviour.
Insurable AI Assets
Autonomous AI actions are mathematically bounded by hardware-enforced Agreement DAGs, rendering non-compliant states physically impossible and allowing AI liabilities to be strictly capped and insured.
IX. The Technical Specification At A Glance
| Component Spec | Architecture Runtime Value |
|---|---|
| Architectural Layer | System of Record (SoR) / Layer 01 |
| Observation Mode | Asynchronous Out-of-Band Observer (Decoupled synchronous path) |
| Target Adjudication Latency | Sub-45 Microseconds (DRAGON DCPU hardware register execution)* |
| Cryptographic Standards | FIPS 140-3 Level 3 Central Cryptographic Key Management, Ed25519, PQC |
| Temporal Tracking | Dual-Axis Bitemporal Graph substrate (\(T_V \parallel T_X\)) |
| Regulatory Frameworks | eIDAS 2.0 (QES/QEAA), UK DIATF, DORA, NIS2, EU AI Act, Gartner CSMA |
* Note: Expressed performance latencies are target metrics of the near-term target state architecture (Q4 2026 / 2027 roadmap).