Regulatory posture
Compliance is not a feature. It is the architecture.
Regulated firms in wealth management, law, healthcare, and family-office practice are buying AI infrastructure under a thickening regulatory canopy. This page documents which laws, rules, and federal directives we have read and evaluated — and how the Sovereignware™ operating system, deployed on the Trinary Bound™ custody architecture, is structurally aligned with each.
And where most vendors ask you to take their word, we hand you the arithmetic: every record is sealed with a SHA-256 hash computed over its content and the hash of the record before it. Verification is a calculation, not a promise — recompute the chain and a single altered byte breaks every hash after it. No account, no network, no trust in us required.
Last reviewed: 5 June 2026 · Sovereignware™ Architecture Decision Log
Strategic market function, and the DMH technical execution
Three properties · What each one is, and how it is actually implemented
Workflow Preservation
Nothing to migrate
Your firm keeps working the way it works. Sovereignware™ connects to
Google Workspace through a signed one-way bridge: Node 0 holds
no Google credential and never reads your mailbox — the Workspace side
reports what happened, and Node 0 verifies the signature before storing anything.
No new mail client, no migration, no retraining.
Local Sanitization
The original never moves
The Trinary Bound™ architecture seals the original file in the
Layer −1 vault behind a physical key touch. Only a machine-readable
twin — carrying the original's SHA-256 fingerprint — is ever indexed or
read by a model.
That fingerprint is both the proof the document is unaltered and the address used to
retrieve it, so lookup and verification are the same operation.
Zero-Cloud by Default
Out of the training set
Firm material is processed on the firm's own hardware and is
never sent to a model vendor, so it cannot enter public training
weights.
Where a firm explicitly opts into a cloud lane, PII is stripped before egress and the
request fails closed if the stripper cannot run.
If you have ninety seconds
For managing partners, principals, and owners · The detail is below
1. What are you exposed to?
Every time someone in your firm pastes a client document into a general-purpose AI assistant,
confidential material leaves the firm and enters a service provider you have not contracted,
assessed, or documented. It is fast, it is genuinely useful, and it is happening in your firm right
now whether or not you have a policy against it. The exposure is not the tool — it is that you
cannot say where the material went or prove what happened to it.
2. What changes?
The work happens on hardware you own, in your building. The models run locally, the records never
leave, and there is no third-party AI vendor in the relationship to oversee, contract with, or
explain to a regulator. Your people get the assistant they were going to use anyway — inside the
boundary instead of outside it.
3. What do you have to take on faith?
Nothing about the records. Each one is sealed with a SHA-256 hash computed over its content and the
hash of the record before it, so verifying them is arithmetic your own people — or your auditor, or
opposing counsel's expert — can run without us. Change one byte of any earlier record and every hash
after it stops matching.
The one thing we will not tell you: that this makes your firm compliant.
Compliance is a programme — written, staffed, trained, and overseen — and no software supplies that.
What this supplies is the evidence underneath it, and the ability to prove that evidence is intact
without anyone taking our word for it. Any vendor promising you more than that is selling something
that will not survive an examination.
Executive Order 14409 — Promoting Advanced AI Innovation and Security
Federal · Signed 5 June 2026 · Executive Office of the President
Executive Order 14409 establishes a federal posture toward frontier artificial intelligence systems, addressing pre-deployment evaluation, supply-chain considerations, and security review obligations for advanced AI developers. The order's principal compliance burden falls on frontier model developers — companies training large foundation models above defined compute thresholds.
Sovereignware™ does not train foundation models. We deploy already-released open-weight models (Llama, Mistral, and similar) onto customer-owned hardware. We are a deployment integrator and operating-system vendor, not a model lab. Our operating posture is informed by, but not principally scoped under, EO 14409.
Architectural alignment: Sovereign on-premises deployment, no cross-border data flow, no third-party model-as-a-service inference, and full chain-of-custody auditability — these are the structural properties EO 14409 seeks to ensure at the frontier developer layer. We have read the order, evaluated applicability to our deployment model, and continue to track implementation guidance.
Primary source: Federal Register: Promoting Advanced Artificial Intelligence Innovation and Security
SEC Regulation S-P — Privacy & Safeguarding of Customer Information
Federal · 17 CFR Part 248 · 2024 amendments effective for smaller entities 3 June 2026
Regulation S-P governs how broker-dealers, registered investment advisers, investment companies, and transfer agents handle nonpublic customer information. The 2024 amendments expanded the rule to require written incident response programs, 30-day customer notification for unauthorized access, and verifiable oversight over third-party service providers handling customer data — including a 72-hour breach notification window from vendor to firm.
For covered firms, the operational hazard under the expanded rule is the moment customer data leaves the firm's control through a third-party SaaS or cloud-hosted AI service, creating an audit gap the firm cannot prove closed to an SEC examiner.
Architectural alignment: Sovereignware™ runs entirely on hardware physically resident in the customer's office. Customer information is processed locally, never transmitted to third-party inference providers, and never co-mingled with vendor-side data. Where a customer elects the hybrid configuration, all PII and nonpublic personal information is stripped at the Sovereign Layer before any cloud relay — producing a documented chain of custody the firm can present at examination.
Primary source: SEC: Regulation S-P — Privacy of Consumer Financial Information and Safeguarding Customer Information
Florida HB 473 — Cybersecurity Incident Liability Act
State (Florida) · 2024 Session · Effective 1 July 2024
Florida HB 473 (Giallombardo & Steele) provides covered entities and third-party agents a statutory liability shield in connection with cybersecurity incidents — provided they document and implement a cybersecurity framework substantially aligned with recognized standards (NIST CSF, ISO 27001, and similar). The act specifies that certain failures are not evidence of negligence per se and that the defendant in qualifying actions has a specified burden of proof.
Firms that cannot document a substantive, framework-aligned cybersecurity posture inherit full liability exposure under traditional Florida negligence standards in the event of a breach.
Architectural alignment: Customers deploying Sovereignware™ on Trinary Bound™ topology receive deployment documentation explicitly mapped to NIST Cybersecurity Framework controls — including hardware-level network isolation, on-device encryption, signed boot, and physical-key revocation. This documentation is designed to support the customer's invocation of the HB 473 safe harbor when needed.
Primary source: Florida Senate: HB 473 — Cybersecurity Incident Liability
HIPAA — Health Insurance Portability and Accountability Act
Federal · 45 CFR Parts 160, 162, 164
HIPAA governs the handling of Protected Health Information (PHI) by covered entities and their business associates. The Security Rule mandates administrative, physical, and technical safeguards over electronic PHI. For medical practices, the use of public cloud AI services for patient-record summarization, transcription, or charting creates a Business Associate relationship with the AI vendor — often without an executed Business Associate Agreement (BAA), and frequently in violation of the Security Rule's transmission and access control standards.
Architectural alignment: Sovereignware™ deployments process PHI entirely on customer-owned hardware in the practice's physical premises. No BAA with a third-party AI vendor is implicated because no PHI is transmitted to a third party. The deployment model is structurally consistent with HIPAA Security Rule §164.312 access control and §164.310 physical safeguard requirements.
Primary source: U.S. Department of Health & Human Services — HIPAA
Gramm-Leach-Bliley Act — Safeguards Rule
Federal · 16 CFR Part 314 · FTC Safeguards Rule (2023 amendments)
The GLBA Safeguards Rule, as amended by the FTC in 2023, requires financial institutions to maintain a written information security program with explicit access controls, encryption of customer information in transit and at rest, multi-factor authentication for systems containing customer information, and written oversight of service providers handling customer information.
Architectural alignment: The Sovereignware™ deployment model collapses the service-provider oversight problem by eliminating the third-party service provider entirely. Customer financial information is processed on customer hardware, by software the customer has licensed, with encryption keys held physically on-site. The Safeguards Rule's "oversight of third parties" obligation is materially reduced because there is no third party to oversee.
Primary source: Federal Trade Commission — Gramm-Leach-Bliley Act
Where this sits: compliance automation, hyperscale cloud, and sovereign evidence
Comparison · Different jobs, not competing claims
Buyers evaluating us usually already run a compliance-automation platform such as Vanta, and keep
their records in a hyperscale cloud such as Google. The useful question is not which is best — it is
which problem each one actually solves. They are largely complementary, and we say so.
|
Compliance automation (e.g. Vanta, Drata) |
Hyperscale cloud (e.g. Google, Microsoft) |
Sovereignware™ on Trinary Bound™ |
| What it is built to prove |
That a control was configured and continuously observed. |
That the provider's infrastructure meets its certifications. |
That this specific record existed in this exact state at this time, and has not changed since. |
| Where the evidence lives |
In the platform's cloud. |
In the provider's infrastructure. |
On drives the customer owns, in their building. |
| How a third party verifies it |
Auditor is granted read access to the platform. |
Provider's own audit reports (SOC 2, ISO, HIPAA BAA). |
Recompute the SHA-256 chain from the files. No account, no network, no trust in us. |
| If the vendor disappears |
Evidence access depends on the subscription. |
Data export depends on the provider. |
The records and the means to verify them are already on the customer's hardware. |
| Who can be compelled to produce the records |
The platform, for data it holds. |
The provider — and legal process is often accompanied by a non-disclosure obligation, so the customer may not learn of it. |
The customer. A demand has to name them and reach them. |
| Policy, personnel & vendor-risk management |
Yes — this is its core strength. Policy templates, training attestations, onboarding and offboarding, subprocessor tracking, auditor workflows. |
Partial, via admin and identity tooling. |
No. We do not do this at all. If you need a compliance program managed, you need a platform of that kind. |
| Independent certification |
Platform typically holds its own certifications and drives customers toward theirs. |
Extensive — SOC 2, ISO 27001, HIPAA BAA and more. |
None. We have not been audited, accredited, or certified by anyone. |
| Scale, uptime & redundancy |
Managed SaaS. |
Global, mature, and far beyond what a single appliance offers. |
One appliance per client, plus whatever backup regime the customer runs. This is a real trade-off. |
Vanta and Drata are trademarks of their respective owners; Google and Microsoft likewise. Descriptions
reflect the general shape of each category and are offered for orientation — verify current capabilities
with each vendor directly.
The honest summary: a compliance-automation platform proves your program
exists. A hyperscale cloud gives you scale and its own certifications. We produce
portable evidence about your records that survives without us. Most regulated firms should
expect to use more than one of the three — and any vendor claiming to replace all of the others is
overselling.
Architecture Decision Log
Internal · Maintained by HecTec.ai engineering
We maintain a dated, internal Architecture Decision Log documenting every structural decision in the Sovereignware™ and Trinary Bound™ stack relevant to security, privacy, and regulatory posture. Each entry records: the decision, the date adopted, the threats it mitigates, the alternatives considered, and the consequences accepted.
Customers procuring Sovereignware™ under enterprise terms receive the Decision Log relevant to their deployment configuration as part of standard onboarding documentation. The log is the artifact a customer presents to their own auditor or regulator when asked: "How does this system actually work, and why was it built that way?"
Why this matters: Most AI vendor security disclosures are marketing artifacts. A Decision Log is an engineering artifact. We chose the engineering posture because regulated buyers can tell the difference.
Important — what this page is, and what it is not.
This page documents Sovereignware™'s architectural alignment with the regulations listed above. It is a posture statement, not a certification claim. We have not been audited, accredited, or certified by any government agency, standards body, or third-party assessor referenced on this page. Our customers' regulatory obligations are their own, and the appropriateness of Sovereignware™ for any specific compliance use case must be evaluated by the customer's own counsel and compliance officers.
Nothing on this page constitutes legal, regulatory, or compliance advice. Primary sources are linked above and should be consulted directly.