For investors
The binding constraint on the most valuable remaining data is governance, not capability.
The easily-reachable training corpus is largely spent. What remains genuinely valuable is private, continuously generated behavioural, sensor and access data from humans and agents — withheld not because models would not benefit, but because using it currently means surrendering custody of it.
The thesis
Custody is the market, and nobody has solved it at the data plane.
Behavioural traces, sensor observations, access histories and decisions made by humans and agents describe how the world and its operators actually behave over time. That is the substrate the next generation of models needs, and its owners will not export it.
Continuous, private histories are becoming more valuable as models move from static documents toward understanding people, environments and workflows — and that raises the stakes on being able to prove what a model was trained on.
Decoupling, not another warehouse
sovm moves compute to the data. There is no export step, because the stored objects are already encrypted Parquet that authorized nodes feed straight into standard loaders.
Untrusted capacity becomes usable
Because holding the bytes conveys no ability to read them, replication can run on rented storage, a cloud bucket in an account you do not administer, or a message bus — cryptographic assurance instead of contractual.
Audit becomes cheap
Object identity is the hash of its ciphertext and every object carries a producer signature, so dataset provenance and reproducibility are properties of the format rather than of a compliance process.
Standards, not novel cryptography
MLS (RFC 9420) and COSE (RFC 9052). The primitives are already reviewed; the contribution is the architecture around them.
What is de-risked, and what is not
Specification maturity is the honest headline.
The architecture is written down in normative detail across two layers, with the threat model, the limits and the open decisions stated rather than glossed. What does not exist yet is a released implementation of either layer.
Diligence should read the status page before the pitch: SOP/1 is a frozen architecture baseline with ten open decision gates, and SSP/1 is a new specification whose conformance corpus does not exist yet.
Note — No shipped product
Note — Not a privacy claim about models
Note — Single trust authority by design