Developer Docs

Sovereign Vault — Developer Guide

Run private runtime, Guardian, and Auditor stacks with enterprise SLAs and telemetry.

Sovereign Vault (Enterprise) — Developer Quickstart

Sovereign Vault delivers a dedicated runtime, Guardian, and Auditor stack with private data residency, SLAs, and enterprise controls.

Use this if you are…

  • An enterprise that needs isolated provenance infrastructure with contractual SLAs.
  • Regulated industries (defense, healthcare, finance) requiring dedicated Guardian/Auditor clusters and auditability.

What you get

  • Private tenant for artifacts, datasets, contracts, and runtime telemetry.
  • Enterprise project + release modeling tied to CI/CD or artifact pipelines.
  • Guardian and Auditor orchestration with jurisdiction-specific policies.
  • Unlimited artifacts/datasets with concierge support.

Core APIs

CapabilityEndpoint
Create projectPOST /api/v1/enterprise/projects
List / update projectsGET/PATCH /api/v1/enterprise/projects/:id
Create releasesPOST /api/v1/enterprise/projects/:project_id/releases
Export provenance bundleGET /api/v1/enterprise/projects/:id/provenance/export
Trigger Guardian/Auditor actionsPOST /api/v1/guardian/enforce, GET /api/v1/ai/audit/export

SDK quickstart

import { createSovProvClient } from '@sovprovenance/sdk-js'

const client = createSovProvClient({
  baseUrl: process.env.SOVEREIGN_API_URL!,
  apiKey: process.env.SOVEREIGN_VAULT_KEY!,
})

// 1. Model an enterprise project
const project = await client.request('POST', '/enterprise/projects', {
  name: 'Helios Autonomy Stack',
  owner_team: 'autonomy-core',
  status: 'active',
  data_residency: 'eu-central',
  notes: 'Air-gapped build pipeline; Guardian mirror in Berlin.',
})

// 2. Record a governed release tied to artifacts + Accord metadata
const release = await client.request(
  'POST',
  `/enterprise/projects/${project.id}/releases`,
  {
    version: 'v2.4.0',
    build_id: 'build-9821',
    artifacts: [
      { id: 'artifact-atlas-model', integrityScore: 0.97, accordPolicy: 'accord-atlas' },
    ],
    origin_classifications: { internal: 23, third_party: 4, open_source: 12 },
  }
)

// 3. Trigger Guardian enforcement when needed
await client.request('POST', '/guardian/enforce', {
  identityId: 'guardian-helios',
  passportId: release.artifacts[0].id,
  violation: 'off_policy_export',
  requestedAction: 'quarantine',
})

// 4. Export a provenance bundle for legal + compliance
const bundle = await client.request(
  'GET',
  `/enterprise/projects/${project.id}/provenance/export`
)

console.log('Bundle exported at', bundle.docket.exported)

Implementation notes

  • Use Vault projects to align with product lines or programs; releases map to regulated drops or deployments.
  • Enterprise API keys should be mapped to sovereign_vault_enterprise so entitlements unlock unlimited artifacts, Guardian + Auditor toggles, and higher request ceilings.
  • Pair exports with your existing GRC tooling by storing the JSON bundle plus attachments; the export payload contains hashed references for external verification.
  • For air-gapped or hybrid deployments, use the same APIs pointed at your private runtime ingress—only metadata needed for public verification leaves the vault.