The technical evidence EU AI Act Art. 50 requires — in 90 seconds.
SOVP is the protocol behind CERTavia. For compliance teams and decision-makers, that means: a cryptographically signed, DNS-anchored infrastructure evidence record that can be used directly as an attachment to the conformity assessment dossier (CAD). No room for interpretation — the result is CERTIFIED or FAILED.
SOVP in the glossary →The web doesn't need better crawlers. It needs a foundation on which agents know where they stand. We're building that foundation as a protocol.
SOVP – Sovereign Validation Protocol
SOVP stands for Sovereign Validation Protocol — the deterministic infrastructure validation framework behind CERTavia. No AI scoring, no probabilistic statements. The result is binary truth: SOVP-CERTIFIED or SOVP-FAILED.
The mathematical core
SOVP checks AI infrastructure against 180+ deterministic parameters, grouped into 20 thematic clusters. Each cluster evaluates a specific infrastructure aspect: from DNS configuration through TLS integrity to machine-readable AI governance disclosure.
The result is binary: all parameters met → CERTIFIED. One parameter missed → FAILED. The procedure recognizes only clear boundaries: no scoring, no gray areas, no partial credit, no risk trade-offs.
Aflow = Ψcore · (C / Ev)
Aflow = Audit Flow Score | Ψcore = Core Compliance Matrix | C = Cluster completion | Ev = Evidence completeness
What SOVP checks
DNS & cryptographic base integrity
DNSSEC, CAA records, TLS certificate chain, HTTP security headers (HSTS, CSP, DMARC), SPF, and DKIM.
Privacy & consent
Crawler directives in robots.txt, consistency of opt-in/opt-out declarations for AI crawlers, WAF response consistency.
Machine-readable identity
Structured data per Schema.org, AI discovery layer (ai.txt, ai.json, llms.txt), agent-card.json.
AI Governance Hard Gate
AI policy URL, deepfake disclaimer, AI training opt-out status, contact point for AI inquiries: externally verifiable governance signals.
What SOVP is not
Cryptography and DNS anchor
Every SOVP certificate is signed with Ed25519, one of the most secure and efficient signature schemes. The public key is anchored in the operator's DNS, so any third party can independently verify the certificate's authenticity.
Why SOVP doesn't need ISO status: The EU AI Act does not mandate a specific tool or format for infrastructure evidence. Art. 50 requires that the machine-readable transparency, labeling, and provenance of an AI system be demonstrable. CERTavia delivers this evidence as a cryptographically signed, DNS-anchored document with a full parameter breakdown — independently verifiable, without involving CERTavia. That's the criterion that matters.
IETF Internet Draft
draft-litzki-sovp, submitted as an Individual Submission to the IETF Datatracker. Not an official IETF working-group standard — but publicly viewable, fully documented, and traceable for any auditor.
USPTO provisional patent
Application number #64/005,737. Provisional patent application with the United States Patent and Trademark Office.
CERTavia analyzes technical infrastructure signals. The result is a machine-readable finding, not a legal opinion and not a certification within the meaning of the EU AI Act conformity assessment under Article 43. For legally binding compliance assessments, consult an accredited conformity assessment body.
Questions about SOVP and infrastructure evidence
Is this an official certification?
No. CERTavia does not issue a government-recognized certificate. SOVP delivers technical infrastructure evidence — deterministic, cryptographically signed. Official conformity assessments under EU AI Act Art. 43 build on evidence like this. More in the glossary →
What's the difference from a pentest or ISO 27001?
Pentest: active, manual vulnerability search by experts. SOVP passively and deterministically checks the infrastructure configuration against a defined requirements catalog — in 90 seconds, reproducible, auditable. ISO 27001: comprehensive management system. SOVP delivers the technical infrastructure evidence for EU AI Act Art. 50 — complementary, not competing.
Who recognizes this evidence?
The EU AI Act does not mandate a specific evidence format — it requires that the Art. 50 requirements for transparency, machine-readable labeling, and provenance be demonstrably met. The SOVP evidence record is a cryptographically signed, DNS-anchored document with a full parameter breakdown. Internal compliance teams, external auditors, and notified bodies can independently verify authenticity, timing, and content — without involving CERTavia. The document is designed as an attachment to the conformity assessment dossier under Art. 11.
Does the auditor need to know SOVP?
No. The SOVP evidence record is a structured, machine-readable document that documents a defined infrastructure state at a cryptographically confirmed point in time. An auditor doesn't need to know SOVP — no more than they need to know the internal software a company used to document its ISO 27001 scope. They check whether the required infrastructure parameters were demonstrably met. CERTavia delivers exactly that documentation.
SOVP validation for your infrastructure
In 90–120 seconds you'll see whether your infrastructure meets the SOVP requirements.