Skip to content

Architecture and security

Use these documents to evaluate how Sovereign works and where its trust boundaries sit. This page is an index: the architecture reference describes the implemented system, architecture rules are normative for contributors, and RFCs record proposals and decisions.

The runtime is self-hostable and plugin-first, but a conventional instance is not trustless. Users trust the instance operator, and plugins access the host only through supported contracts and declared capabilities.

Open source under AGPL-3.0. Each Sovereign instance is independently operated.