Architecture and security
Use these documents to evaluate how Sovereign works and where its trust boundaries sit. This page is an index: the architecture reference describes the implemented system, architecture rules are normative for contributors, and RFCs record proposals and decisions.
- Architecture overview
- Security model
- Architecture rules
- Sovereign requirements and design record
- RFC index
The runtime is self-hostable and plugin-first, but a conventional instance is not trustless. Users trust the instance operator, and plugins access the host only through supported contracts and declared capabilities.