SOVEREIGN
Sovereign Architecture · Local Provenance System · v1.0

PROVE
YOU MADE IT.

Cryptographic identity, file lineage, and verifiable authorship proof — entirely on your machine. No cloud. No accounts. No expiry.

All Systems Local · No Cloud · No External Services
● ALL SYSTEMS LOCAL· provenance log: dual-chain append-only ✓· $ init provenance-engine· SHA3-256 dual fingerprint engine loaded ✓· sqlite connected ✓· ed25519 creator key loaded ✓· file watchers engaged ✓· vault-wide chain verified ✓· verification pipeline ready ✓· ● ALL SYSTEMS LOCAL· provenance log: dual-chain append-only ✓· $ init provenance-engine· SHA3-256 dual fingerprint engine loaded ✓· sqlite connected ✓· ed25519 creator key loaded ✓· file watchers engaged ✓· vault-wide chain verified ✓· verification pipeline ready ✓
Who It's For

If you make it,
Sovereign protects it.

You should not need a law degree to prove you made something. Drop your files in a folder. Sovereign handles the rest.

🎵

Musicians & Songwriters

Protect demos, stems, lyrics, and masters before they leave your hard drive. Every version timestamped. Prove the song was yours before the split sheet existed.

🎨

Visual Artists

Your work gets scraped and fed into AI models. Sovereign embeds a watermark that survives resizing, recompression, and metadata stripping, and keeps a provenance trail from first sketch to final piece.

📷

Photographers

Metadata gets stripped the moment your image hits social media. The frequency watermark lives inside the pixels — it survives resizing, recompression, and format conversion.

✍️

Writers & Creators

Manuscripts, blog drafts, scripts, research. Every save is fingerprinted. If someone publishes your work before you do, the provenance log proves you had it first.

⚖️

IP Lawyers

The proof bundle is built for you. SHA3-256 fingerprint, hash-chained timeline, self-verifying script. Hand it to opposing counsel. They run one command and see the evidence.

🎬

Filmmakers & Producers

Protect pre-release cuts, raw footage, storyboards, and scripts. Full archive mode preserves every version so you can prove the creative timeline from concept to delivery.

How It Works

Seven stages.
Zero cloud.

Every file passes through a deterministic seven-stage pipeline, entirely on your machine — from intake to a signed, exportable proof bundle.

01 — INTAKE

Intake Creator Artifact

Creator adds a digital asset — image, audio, video, document, or other file — via the vault watcher or manual import.

02 — DUAL IDENTITY

Dual Identity Fingerprinting

SHA3-256 fingerprint of the original as saved, then fingerprinted again after sealing. Dual identity is recorded.

03 — SEALING

Authorship Sealing

Frequency-domain watermark and embedded authorship labels applied via atomic copy–mutate–swap, so the original is never modified in place.

04 — LOGGING

Provenance Logging

Provenance event created and timestamped; the per-artifact chain and the vault-global chain are both updated.

05 — SIGNING

Creator Signing

Event signed with the creator's local Ed25519 key. The signature binds identity, time, and content together.

06 — DECLARATION

Declaration & Evidence

Creator optionally records a process declaration — process, tools, collaboration, licensing, other — with supporting evidence hash-committed, not stored.

07 — EXPORT

Package & Export

Portable, self-verifying proof bundle created with all evidence — signed, dual-chained, and independently checkable.

Architecture

The Local-First
Protection Architecture

Sovereign: The Local-First Architecture for Creator IP Protection infographic showing the 7-stage protection pipeline, layered evidence model, creator process declarations, dual hash-chain provenance, offline time evidence, C2PA/AIP-7 alignment, and the portable proof bundle

Seven-Stage Protection Pipeline · Layered Evidence Model · Dual Hash-Chain Provenance · Creator Process Declarations · C2PA and AIP-7 Alignment · Alterna Axiom Labs 2026

See It In Action

What creators
actually see.

A live vault, a creator declaration in progress, and the immutable report a proof bundle produces — every screen local, every field verifiable.

Sovereign dashboard showing a watched vault, a protected audio file with its SHA3-256 fingerprint, embedded authorship label, intact provenance chain, and recent provenance events

The vault dashboard — fingerprint, authorship label, provenance chain, and creator declarations for every protected file.

Record a Declaration dialog in Sovereign, letting a creator select a category and creative process tags, write a statement in their own words, and attach hash-committed supporting evidence

Recording a creator process declaration — your words, your process, hash-committed evidence.

Sovereign immutable provenance report showing file identity, dual SHA3-256 fingerprints, provenance chain hash, vault chain head, creator public key, and a provenance timeline

The immutable provenance report — dual fingerprints, chain hash, vault chain head, and creator public key, ready to hand to anyone.

Evidence Model

Seven layers of proof.
Any one is enough.

Redundant, cumulative authorship evidence. Each layer independently supports a claim; together they bind identity, order, authorship, and intent.

01

Embedded Authorship Label

Metadata written directly inside the file — ID3 tags for audio, document properties for PDFs and Office files. Strippable by standard tools; the fingerprint is the durable evidence.

Metadata
02

Frequency-Domain Watermark

Authorship evidence in DCT coefficients — survives metadata stripping, resizing, recompression, social uploads.

Frequency
03

Dual Cryptographic Fingerprint

Quantum-resilient SHA3-256 identity of both the pre-watermark original and the sealed artifact. Tamper-proof, independently verifiable.

SHA3-256
04

Dual-Chain Provenance Log

Per-artifact and vault-global hash chains, bound to wall-clock, monotonic, session, and filesystem time. Backdating leaves detectable contradictions.

Hash-Chained
05

Creator Signature

Ed25519 signature from a locally generated keypair — authenticated provenance, not just tamper-evident history.

Ed25519
06

Creator Process Declarations

Signed, hash-chained statements in the creator's own words about how a work was made, with optional hash-committed supporting evidence.

Declared
07

Portable Signed Proof Bundle

Self-contained, externally anchorable verification package for independent third-party confirmation. No app required.

Portable
Proof Bundle · Format v1.3.0

One bundle.
Complete proof.

Everything needed to independently verify authorship, order, and attribution. No access to the original system required.

artifact_file

Your original file, included for verification.

#

fingerprint.txt

Dual SHA3-256 identity — pre-watermark original and sealed artifact.

{}

provenance_export.json

Full dual-chain provenance record, vault chain head, creator public key, and creator declarations.

chain_hash.txt

Tamper-evidence hash of the entire provenance log.

signature.txt

Ed25519 signature over the chain hash, from the creator's local key.

provenance_report.pdf

Human-readable report, including verbatim declaration pages, for legal or dispute use.

verify.py + verify.bat

Self-verification script. Python 3, zero dependencies. Verifies both chains, the signature, and supports a reveal mode for sealed declaration evidence.

Comparison

What the alternatives
actually offer.

Most IP protection tools require cloud accounts, subscriptions, or blockchain wallets.

FeatureSovereignScoreDetectDigimarcEmail / Cloud
Works offline✓ Yes✗ Cloud required✗ No✗ No
No account required✓ Yes✗ Account required✗ No✗ No
PriceFreeSubscriptionSubscription
Proof survives if company shuts down✓ Self-contained✗ Certificates die✗ No✗ No
Self-verifying proofverify.py — zero depsRequires platform✗ No✗ No
Frequency watermark✓ Survives stripping✗ No✓ Yes✗ No
Quantum-resilient hashSHA3-256Standard hash✗ No✗ No
Hash-chained timelineDual-chain (per-artifact + vault-wide)Blockchain only✗ No✗ No
Creator-signed proof✓ Local Ed25519 keyPlatform account✗ No✗ No
Creator process declarations✓ Signed, hash-committed✗ No✗ No✗ No
Runs from USB✓ Air-gapped✗ No✗ No✗ No
Data stays on your machine✓ AlwaysCloud + blockchainCloudThird-party servers
Specifications

Built for any machine.

0Cloud Dependencies
0GPU Required
Tauri v2Rust + React
SQLiteLocal Single-File DB
Price

Free.
No limits. No accounts.

Sovereign is free software. Protect one lyric sheet or your entire catalog — there are no file limits, no subscription, and nothing ever leaves your machine.

Sovereign

Free Download

Free
NO LIMITS · NO ACCOUNT · NO EXPIRY
  • Unlimited vaults and files
  • Dual SHA3-256 fingerprinting
  • Format-matched watermarking
  • Local Ed25519 creator signing
  • Creator process declarations
  • Portable, self-verifying proof bundles
Download for Windows
436 MB · hosted free on the Internet Archive

Windows 10/11 (64-bit). Sovereign is independent software, so Windows may show a “protected your PC” notice on first launch — click More info, then Run anyway.

FAQ

Common questions.

How does Sovereign protect my creative work?

Sovereign fingerprints every file with SHA3-256 — once before watermarking, once after — embeds a frequency-domain watermark that survives resizing, recompression, and metadata stripping, logs every event in two interleaved hash chains, signs the record with a local Ed25519 key, and exports a proof bundle anyone can verify by running one Python script.

Does it need an internet connection?

No. Everything runs on your machine, including creator signing. Sovereign works air-gapped from a USB stick on any Windows machine. No cloud, no account, no login. An optional anchor card lets you publish your vault's chain head externally by your own choice — Sovereign itself never makes that connection.

What is a proof bundle?

A ZIP file containing your original file, its dual SHA3-256 fingerprints, the full dual-chain provenance record, an Ed25519 signature, a human-readable PDF report, a tamper-evidence hash, and a self-verification script. Hand it to a lawyer or opposing counsel — they run one command and see the evidence.

What is a creator process declaration?

An optional, signed statement in your own words about how a work was made — process, tools, collaboration, licensing, or anything else. Sovereign records that the statement was made, when, and by which key. It never judges whether the statement is true.

What file types does it support?

Images (JPG, PNG, TIFF, WebP), audio (WAV, MP3, FLAC, M4A), video (MP4, MOV), documents (PDF, DOCX, TXT, MD), and more. Each format gets appropriate watermarking — frequency-domain for images, ID3 for audio, container metadata for video, sidecar files for everything else.

What does it cost?

Nothing. Sovereign is free software with no file limits, no subscription, and no account. Your proof never expires, and nothing you make ever leaves your machine.

What makes SHA3-256 better than SHA-256?

SHA3-256 uses the Keccak sponge construction, which is structurally different from SHA-256 and provides stronger resistance against future quantum computing attacks. Your proof needs to hold up years from now — SHA3-256 ensures it will.

Public Record

Documentation
and Prior Art

The Sovereign architecture is fully documented through defensive publications on public record.

Defensive Publication · v4.3 · Zenodo

Sovereign Architecture

Full defensive publication establishing prior art for the complete Sovereign architecture. Dual SHA3-256 fingerprinting, dual hash-chain provenance, clock-anomaly detection, local Ed25519 creator signing, external anchoring, creator process declarations, frequency-domain watermarking, C2PA and AIP-7 alignment.

DOI 10.5281/zenodo.19056811 →
Defensive Concept Note · Addendum · Zenodo

Sovereign DAW

Prior art documentation for a provenance-aware digital audio workstation where music creation actions automatically generate cryptographic authorship events. Song projects as protected creative containers.

Zenodo DOI →