ENTITY Documentation
Architecture Guide

Account recovery is not sovereign authority recovery

A provider can reset a password, restore a database or re-enable an account. That does not necessarily restore the same cryptographic authority, rights state, provenance lineage and portable identity. ENTITY treats those as a separate sovereignty problem.

The provider-capture problem

If identity exists only inside one vendor account, the vendor can become the practical root of authority. Infrastructure custody can then be confused with ownership or control. ENTITY's design instead treats hosting, aliases and providers as infrastructure around an authority root, not as the authority root itself.

What must survive recovery?

A sovereign recovery process should preserve or verifiably reconstruct the state that gives the system its identity and authority: the ENTITY identifier, signing capability, delegated authority, rights/evidence relationships, protocol lineage where applicable, and enough portable state to verify continuity after restoration.

Three different operations

OperationWhat it means
Backup restoreRecover stored state after loss or corruption.
Sovereign exportProduce portable state that is not dependent on one provider remaining online.
Authority recoveryRe-establish controlled signing/authority while preserving continuity and revocation rules.

Why exact restore matters

For a protocol whose claims depend on canonical state, recovery must be testable. ENTITY v3.4.2's published qualification records protected-state recovery PASS, exact restore true, and restored sovereign signing true. Those are BTG-controlled release qualifications, not independent external assurance.

Portable does not mean uncontrolled

Exportability should not weaken authorization. A copied database or exported state file does not automatically grant a new actor authority. Protected mutation still depends on the relevant ENTITY authorization and key material.

What remains post-release

The release explicitly leaves additional qualification open, including hardware-backed key custody, physical multi-host qualification, certified-device pilots, a 30-day wall-clock run, independent security audit and independent assessor receipt.

How to evaluate the design

Try a destructive recovery, inspect whether the same governed state and signing authority are restored, and check whether the recovery process accidentally elevates infrastructure possession into authority. A reproducible failure is useful evidence.

Take the external verification challenge →