Thesis / Why now
The binding constraint on the most valuable remaining data is governance, not capability.
The easily-reachable training corpus is largely spent. What remains genuinely valuable is private, continuously generated behavioural, sensor and access data from humans and agents — withheld not because models would not benefit, but because using it currently means surrendering custody of it.
Why increasingly valuable private datasets need a different custody model
Custody is the market, and nobody has solved it at the data plane.
Behavioural traces, sensor observations, access histories and decisions made by humans and agents describe how the world and its operators actually behave over time. That is the substrate the next generation of models needs, and its owners will not export it.
Continuous, private histories are becoming more valuable as models move from static documents toward understanding people, environments and workflows — and that raises the stakes on being able to prove what a model was trained on.
The data is not inaccessible because of capability gaps. It is withheld because accessing it has always required surrendering custody of it. That is the problem sovm addresses at the data-plane level.
Compute goes to the data, not the data to the compute
sovm moves authorized compute to where the data already is. There is no export step, because authorized nodes recover ordinary Parquet that feeds standard loaders directly.
Untrusted capacity becomes usable
Because holding the bytes conveys no ability to read them, replication can run on rented storage, a cloud bucket in an account you do not administer, or a message bus — cryptographic assurance instead of contractual.
Verifiable provenance by construction
Object identity is the hash of its ciphertext and every object carries a producer signature, so dataset provenance and reproducibility are properties of the format rather than of a compliance process.
The timing argument
Training corpus exhaustion is driving demand for private data access.
Static public corpora — the books, the code repositories, the web — are largely spent as a differentiator. The frontier of model capability now depends on access to continuously generated private data: what people actually do, not what they have written about doing.
This is not a future prediction. The competition for private data access is happening now, and the existing mechanisms — data licensing, synthetic generation, federated learning with trusted aggregators — each require either surrendering custody or accepting meaningful capability limits.
The architectural bet is that the decade ahead requires a different primitive: one where compute moves to data rather than data moving to compute, and where custody is provable rather than contractual.
Standards, not novel cryptography
MLS (RFC 9420) and COSE (RFC 9052). The primitives are already reviewed; the contribution is the architecture around them, not a new cryptographic scheme.
The architectural bet
Centralization-only architectures — warehouse, data lake, federated with a trusted aggregator — each require either surrendering custody or accepting a trusted third party. sovm's bet is that the next decade of private data access needs a model where neither is required.
Decoupling placement from access
The organization that generates the data decides who can read it; where it is stored is a separate, independent decision. This is the property that centralization-only architectures cannot provide.
What is de-risked, and what is not
Specification maturity is the honest headline.
The architecture is written down in normative detail across two layers, with the threat model, the limits and the open decisions stated rather than glossed. What does not exist yet is a released implementation of either layer.
Diligence should read the status page before anything else: SOP/1 is a frozen architecture baseline with ten open decision gates, and SSP/1 is a new specification whose conformance corpus does not exist yet.
Note — No shipped product
Note — Not a privacy claim about models
Note — Single trust authority by design