Developer Docs
Sovereign Vault — Developer Guide
Run private runtime, Guardian, and Auditor stacks with enterprise SLAs and telemetry.
Sovereign Vault (Enterprise) — Developer Quickstart
Sovereign Vault delivers a dedicated runtime, Guardian, and Auditor stack with private data residency, SLAs, and enterprise controls.
Use this if you are…
- An enterprise that needs isolated provenance infrastructure with contractual SLAs.
- Regulated industries (defense, healthcare, finance) requiring dedicated Guardian/Auditor clusters and auditability.
What you get
- Private tenant for artifacts, datasets, contracts, and runtime telemetry.
- Enterprise project + release modeling tied to CI/CD or artifact pipelines.
- Guardian and Auditor orchestration with jurisdiction-specific policies.
- Unlimited artifacts/datasets with concierge support.
Core APIs
| Capability | Endpoint |
|---|---|
| Create project | POST /api/v1/enterprise/projects |
| List / update projects | GET/PATCH /api/v1/enterprise/projects/:id |
| Create releases | POST /api/v1/enterprise/projects/:project_id/releases |
| Export provenance bundle | GET /api/v1/enterprise/projects/:id/provenance/export |
| Trigger Guardian/Auditor actions | POST /api/v1/guardian/enforce, GET /api/v1/ai/audit/export |
SDK quickstart
import { createSovProvClient } from '@sovprovenance/sdk-js'
const client = createSovProvClient({
baseUrl: process.env.SOVEREIGN_API_URL!,
apiKey: process.env.SOVEREIGN_VAULT_KEY!,
})
// 1. Model an enterprise project
const project = await client.request('POST', '/enterprise/projects', {
name: 'Helios Autonomy Stack',
owner_team: 'autonomy-core',
status: 'active',
data_residency: 'eu-central',
notes: 'Air-gapped build pipeline; Guardian mirror in Berlin.',
})
// 2. Record a governed release tied to artifacts + Accord metadata
const release = await client.request(
'POST',
`/enterprise/projects/${project.id}/releases`,
{
version: 'v2.4.0',
build_id: 'build-9821',
artifacts: [
{ id: 'artifact-atlas-model', integrityScore: 0.97, accordPolicy: 'accord-atlas' },
],
origin_classifications: { internal: 23, third_party: 4, open_source: 12 },
}
)
// 3. Trigger Guardian enforcement when needed
await client.request('POST', '/guardian/enforce', {
identityId: 'guardian-helios',
passportId: release.artifacts[0].id,
violation: 'off_policy_export',
requestedAction: 'quarantine',
})
// 4. Export a provenance bundle for legal + compliance
const bundle = await client.request(
'GET',
`/enterprise/projects/${project.id}/provenance/export`
)
console.log('Bundle exported at', bundle.docket.exported)
Implementation notes
- Use Vault projects to align with product lines or programs; releases map to regulated drops or deployments.
- Enterprise API keys should be mapped to
sovereign_vault_enterpriseso entitlements unlock unlimited artifacts, Guardian + Auditor toggles, and higher request ceilings. - Pair exports with your existing GRC tooling by storing the JSON bundle plus attachments; the export payload contains hashed references for external verification.
- For air-gapped or hybrid deployments, use the same APIs pointed at your private runtime ingress—only metadata needed for public verification leaves the vault.