SOVP Sovereign Validation Protocol
The Sovereign Validation Protocol is a deterministic, machine-readable verification protocol for technical infrastructure evidence. It has been submitted as an IETF Draft and is patent-protected.
SOVP assesses 80+ parameters across 6 clusters and produces a cryptographically signed, DNS-anchored evidence record — the Sovereign Vault. The result is CERTIFIED, FAILED, or — if the scan could not sufficiently reach the domain — INCOMPLETE (see CERTIFIED / FAILED / INCOMPLETE).
Relevant for: EU AI Act Art. 50 (transparency obligations), DORA Art. 28 (third-party risk), NIS2 (cybersecurity requirements).
Technical details on SOVP →
CES Compliance Evidence Score
The Compliance Evidence Score is the numeric overall value of an SOVP scan on a scale from 0 to 100. It results from the weighted aggregation of all 6 cluster scores.
A system is considered CERTIFIED when two conditions are met simultaneously:
- CES overall value ≥ 75
- Cluster F score ≥ 40 (cybersecurity minimum requirement)
If either condition is not met, the result is FAILED — regardless of the overall score. This gate logic assumes the scan was able to sufficiently reach the domain; if it was not, the result is INCOMPLETE regardless of the CES (see CERTIFIED / FAILED / INCOMPLETE).
Cluster F AI Governance Hard Gate
Cluster F is one of the 6 SOVP verification clusters and assesses machine-readable AI governance declarations of the checked infrastructure. It is the only cluster with its own minimum score (≥ 40) that is mandatory for CERTIFIED.
Checked parameters include: ai-disclosure.json, AI Policy URL, deepfake disclaimer, AI training opt-out, AI contact point, and well-known endpoints, which CERTavia uses as machine-readable evidence of AI governance for Art. 50.
Background: EU AI Act Art. 13 and Art. 50 require transparency and labeling obligations for AI systems — the machine-readable labeling of AI-generated content (Art. 50 para. 2) applies only to providers of generative AI systems, not to operators of third-party AI tools — they do not prescribe a specific technical evidence format. Cluster F translates these obligations into deterministically verifiable parameters and provides machine-readable evidence for them.
CERTIFIED / FAILED / INCOMPLETE
The result of an SOVP or CERTavia scan has three possible values, with no further intermediate states.
CERTIFIED means: the checked infrastructure meets all minimum requirements of the protocol. The evidence can be used as an attachment for audits under EU AI Act Art. 50, DORA and NIS2.
FAILED means: the scan was completed in full, but at least one threshold was not met (CES < 75 or Cluster F score < 40). The detailed report shows which clusters are affected and which measures lead to improvement.
INCOMPLETE means: the scan could not sufficiently reach the domain during the check — usually due to a firewall or bot-protection block — and therefore does not deliver a reliable result. This is not a statement about the domain's compliance, but about its reachability at the time of the scan. No CES score is deliberately reported; a re-scan is recommended. Introduced on 2026-08-01 — scans before this date only knew CERTIFIED/FAILED and were not retroactively reclassified.
Important: CERTIFIED is not an officially recognized certificate, but a technical infrastructure evidence record. More information under Not a Certificate — what's the difference?
Sovereign Vault
The Sovereign Vault is the persistent, cryptographically secured evidence store for an SOVP scan result. Every purchase of a Full Scan produces a unique vault entry with a stable URL.
Properties: DNS-anchored (the hash is stored in the DNS of the checked system), cryptographically signed (subsequent tampering is detectable), directly shareable with auditors or clients.
Vault availability: Basic scans have 90 days of vault access (local archiving required afterward), Pro scans are permanently retrievable via token — recommended for audit dossiers and long-term compliance evidence.
Customer Portal
With Annual Starter, Annual Subscription and Enterprise, access to the customer portal is automatically activated upon contract signing. There is no need to create a separate account: on the portal login page, the purchase email address is sufficient — a login link is delivered by email (no password required).
Basic, Pro and Bulk purchases are one-time purchases without automatic portal access — the report is delivered directly by email via the scan access code (token link, see Support), which is used exclusively to trigger a single scan. Customer portal access is available for these packages on request via Support.
In the portal, you manage your scanned domains, retrieve previous reports and see the respective Sovereign Vault status.
CAD Conformity Assessment Dossier
The Conformity Assessment Dossier is the technical audit dossier that operators of high-risk AI systems must maintain under EU AI Act Art. 43. It documents how the system meets the requirements of Art. 8–15.
A CERTavia Full Scan Pro delivers the infrastructure evidence for the CAD-relevant part of Art. 50 (transparency and machine-readable labeling). The Sovereign Vault serves as a permanent, verifiable attachment to the dossier.
CAD mapping: which clusters correspond to which articles →
Annex III EU AI Act
Annex III of the EU AI Act lists the categories of high-risk AI systems by sector and use case. Systems that fall under Annex III are subject to the stricter requirements of Art. 8–15, including robustness requirements, transparency obligations and cybersecurity measures.
Affected sectors include, among others: critical infrastructure, education, employment, essential services (credit, insurance), law enforcement, biometrics and border control.
You can check whether your system falls under Annex III with the free quick test: Go to the Annex III quick test →
Art. 50 EU AI Act Transparency obligations by paragraph
Article 50 bundles four separate transparency obligations. Depending on the paragraph, they apply either to providers (whoever develops an AI system or offers it under their own brand, including white-label) or to deployers (whoever uses a third-party AI system) — never automatically both at once:
- Para. 1 — Chatbot disclosure (provider): Users must be able to recognize that they are interacting with an AI system, unless this is obvious from the context.
- Para. 2 — Machine-readable marking of synthetic content (provider): Outputs from systems that generate image, audio, video or text content must be machine-readably marked as AI-generated.
- Para. 3 — Emotion recognition and biometric categorization (deployer): Affected individuals must be informed of the use of such systems. Does not concern deepfakes.
- Para. 4 — Deepfakes and AI-generated text on matters of public interest (deployer): Both cases fall under the same paragraph. The disclosure obligation does not apply to text under human editorial responsibility.
Most common error: deepfakes are incorrectly attributed to para. 3 (which is emotion recognition/biometric categorization) instead of para. 4, or para. 4 is described as "provider and deployer" instead of correctly as a deployer-only obligation. This mapping is the canonical source for certavia.org and the sovp-validator mailer templates — corrections should be made here, not at individual points of use.
QUAIDAL
QUAIDAL stands for Quality criteria for AI Data Lifecycle — a quality framework from the BSI (German Federal Office for Information Security) for AI training data.
In the context of the EU AI Act, QUAIDAL is relevant for operators who must document the quality of their training data as part of the conformity assessment. CERTavia takes QUAIDAL-relevant parameters into account in the SOVP check.
High-Risk AI System
Under the EU AI Act, an AI system is considered high-risk if it is either listed in Annex III or embedded as a safety component in a product that falls under existing EU product safety legislation (e.g. medical devices, vehicles).
Operators of high-risk AI systems are subject to a conformity assessment obligation. Art. 50 requires general transparency and labeling obligations for AI systems — CERTavia delivers the machine-readable, cryptographically signed infrastructure evidence for this as documentation for the Conformity Assessment Dossier.
Technical Evidence vs. Official Certification
CERTavia does not issue an officially recognized certificate. The result of an SOVP scan is technical infrastructure evidence — comparable to a penetration test report or a security audit, but fully automated, deterministic and machine-readable.
Official certifications (e.g. by notified bodies under Art. 43 EU AI Act) build on such technical evidence. CERTavia delivers the infrastructure part of this evidence package — cryptographically secured, directly usable as an attachment to the CAD.
The difference to a pentest: a pentest actively and manually tests attack surfaces. SOVP deterministically and passively checks the infrastructure configuration against a defined set of requirements — reproducible, automatable, auditable.
Vendor Scan
A Vendor Scan is an SOVP-based infrastructure evidence record for external service providers and third parties. It is initiated by the commissioning company, not by the service provider itself.
Relevant for: DORA Art. 28 (risk assessment of ICT third-party providers), NIS2 supply-chain obligations, EU AI Act requirements for providers of embedded systems.
Note on consent: a technical infrastructure check of a publicly accessible domain does not require the domain owner's consent, since only publicly visible configuration parameters are evaluated. Legal responsibility lies with the party commissioning the scan.
Request a Vendor Scan →
Full Scan Basic vs. Pro
Both tiers run the same complete SOVP scan (80+ parameters, 6 clusters, cryptographically signed PDF result).
The difference lies exclusively in the vault duration:
- Basic: Sovereign Vault available for 90 days (local archiving required afterward) — suitable for short-term evidence and one-time audits.
- Pro: Sovereign Vault permanently retrievable via token — recommended for audit dossiers (CAD), long-term compliance evidence and archiving obligations.
Compare tiers and pricing →