Sovereign
The owner is the root of authority. Nobody else, ever. Their root signing key is created on their device and never enters your infrastructure.
The category
Sovereign Delegated Access and Revocation Chain
A protocol that separates holding data from the authority to use it. Not better security around the copy. A different relationship to the copy: the holder borrows authority, and the owner can end the loan.
Sovereignty Theft
Every upload quietly transfers authority away from the individual. Permanently. SDARC is the architecture that makes that transfer unnecessary: live authority, delegated by the owner, usable for as long as needed, and revocable at any time.
Withdraw consent, and stored data rotates to fresh keys. Old ciphertext cannot be reopened. SDARC does not unsay what was already disclosed. It stops the raw record from becoming a reusable file in the first place.
What SDARC is not
It is the binding of delegated access to continuous, revocable cryptographic authority, with the individual as the root.
The chain
Zero Trust corrected implicit trust. SDARC corrects Sovereignty Theft. Enforced by cryptography, not by policy, trust, or a promise to delete.
The owner is the root of authority. Nobody else, ever. Their root signing key is created on their device and never enters your infrastructure.
Access is granted, not transferred. You receive permission to act under live, owner-signed authority: purpose-bound, cryptographically enforced, and revocable at any time.
Authority can be withdrawn at will. Immediately. Provably. Data rotates to fresh keys; rewind or restore fails closed against dead grants.
Enforced mathematically. Authority the owner has withdrawn cannot be exercised or restored. Recipients hold bounded artifacts, never usable keys.
For the person
They approve, or they do not. Control does not end at approval. Every grant can be revoked by the person whenever they choose: all access at once, a single type of data, or an entire area. Complete. Immediate. Asking no one's permission.
Start in your workspace
Install the SDKs, create an intent, and prove delegated access in sandbox. Owner keys remain on the owner's device. Your server stores ciphertext and receives only authorised results.
Build with ZeroGrant.
ZeroGrant builds SDARC. Delegated by consent. Bounded by purpose. Revocable by design. Provable by cryptography. Sovereign for life.