ChapterI00 · Sovereignty

Your data. Your model. Your keys.

Nebbos is designed so no vendor — not even Nebbos — sits between operator intent and enterprise state. When you leave, everything moves with you.

01Three axes of sovereignty

Three commitments, one architecture.

Sovereignty on Nebbos is not a policy statement. It is a set of substrate guarantees, each enforced by the layer that ships it. Data sovereignty: row-level client isolation at Layer 01 · Data. No application-layer bug can leak your data to another client — the isolation is enforced at the substrate, not by the application code that sits on top of it. Every request carries an identity checked before the query runs. Model sovereignty: every human decision your team makes trains YOUR Pearl — not Nebbos’s next base model. The tuned Pearl and its memory are your property, exportable in full when you offboard. Portability is a contractual guarantee, not a marketing line. Operational sovereignty: no vendor sits between operator intent and enterprise state. The classifier that decides which tier a request runs at executes on YOUR host, before egress. The MCP binary that mediates every tool call lives on YOUR Cradle. The audit trail is written to storage YOUR keys unlock.

02Five treatment tiers for your data

You decide how much your model gets to see.

  1. 01
    Sealed

    Journal-grade artifacts stay on your Cradle. Decryptable only by you, only when you are physically present with the device. Nebbos never sees ciphertext or plaintext.

  2. 02
    Portable

    Cross-device personal state — same operator, multiple laptops. Server-stored, but wrapped with a key only your Cradle carries. Our operators see ciphertext only.

  3. 03
    Redacted-to-cloud

    Full-fidelity model performance without leaking PII. Personal identifiers are stripped on your host before egress; the response is re-materialized locally when it comes back.

  4. 04
    Attested-cloud

    Full-fidelity model running inside a hardware-attested enclave. Every response comes with a cryptographic receipt binding the output to the enclave that produced it.

  5. 05
    Air-gapped

    Local open-weights inference. Zero egress. For classified-sensitivity work where even attested-cloud is too much.

03The classifier

The tier decision runs on your host. Not on our servers.

Before any query leaves your operator’s laptop, the classifier reads the query text, the client policy, and the operator’s current authority level. It decides which of the five tiers this specific request runs at, redacts any PII that would otherwise egress, and hands the tier decision to the MCP binary that services the call. The classifier is a binary carried on your Cradle. Its policy is YAML — you set the defaults, your admin overrides, your operator can force-downgrade a request to a stricter tier, your regulator can inspect the policy under NDA. The classifier does not run on Nebbos-hosted infrastructure. It cannot be swapped by a Nebbos-side deploy. Its behavior on any request is a fact about what your Cradle carries — not a policy Nebbos administers.

04Recovery custodians

You elect who has break-glass keys.

Vendor break-glass exists. The client chooses whether to use it. Path A — vendor-mediated recovery (default). If a user loses their Cradle and needs a fresh device, a Nebbos-side recovery flow re-issues one, with an audit event that lands in the client’s own audit trail. Fast, standard, works for most enterprises. Path B — user-quorum recovery (opt-in). The client elects three-to-five recovery custodians from within its own organization. Cradle reissue requires a Shamir 3-of-5 quorum of the custodian Cradles. Nebbos-side cannot unlock a lost device. The client carries the operational cost; the client carries the sovereignty guarantee. Every enterprise decides which posture it operates under. The two paths are not a technical accident — they are a designed choice about who holds the last mile of trust.

05Portability

When you leave, everything moves with you.

Portability on Nebbos is contractual, not marketing. On offboarding: your tuned Pearl model — the weights, the preference pairs, the routing policy — exports as a portable format compatible with any inference substrate that speaks the same model spec. Your memory — the accumulated context that made the Pearl valuable — exports as a structured, importable graph. Query-compatible with the underlying substrate. Your audit trail — every action, every approval, every decision — exports as an append-only hash-chained record, verifiable on any auditor’s tooling. Your MCP capability policy — the YAML that decided which tier which request ran at — exports as a versioned file. Your CRM data, your task history, your document graph, your identity roster — all export in the shape you can re-import into any successor substrate. Portability tests run continuously against the substrate; the export path is exercised as part of the pipeline, not as an offboarding-day surprise.

06One physical Cradle per user

Sovereignty enforced by the object on your desk.

Every operator authorized above L1 carries one Nebbos-issued Cradle, tied to their identity, sealed at manufacture. When they are at their desk, the Cradle is in the port. When they leave, the Cradle comes with them. Elevated capability follows the physical device, not the network location. This is what makes model, data, and operational sovereignty mechanically enforceable. The tier a request runs at is not a claim we make about our own trustworthiness. It is a fact about what hardware is on your operator’s desk.

07Which architecture layers make sovereignty real

Which architecture layers make sovereignty real.

  1. 01
    Layer 01 · Data

    Row-level client isolation. Structural, not policy. No application bug can leak across clients.

  2. 02
    Layer 02 · Identity

    Every request carries an identity. Hardware-attested at L2 (biometric + Cradle) and L3 (biometric + Cradle + enclave).

  3. 03
    Layer 05 · API + MCP

    The classifier runs at this boundary, on the operator’s host, before egress.

  4. 04
    Layer 07 · Memory

    Portability tests run continuously. Export path exercised on every deploy.

  5. 05
    Layer 15 · Attestation

    Hash-chained audit trail. Portable in machine-readable form. Your inspector-general reads the same records ours do.

08Related

Deeper reading.

  • Trust — the meta-posture and accountability pillars
  • Security — technical controls in depth
  • Compliance — status per framework
  • Legal — MSA, DPA, Responsible Disclosure

Sovereignty is a substrate, not a policy.

Every enterprise says its data is its own. Nebbos ships the architecture that makes it so.

Sovereignty · Your data. Your model. Your keys. — Nebbos