What SOVP means for your audit

The technical evidence EU AI Act Art. 50 requires — in 90 seconds.

SOVP is the protocol behind CERTavia. For compliance teams and decision-makers, that means: a cryptographically signed, DNS-anchored infrastructure evidence record that can be used directly as an attachment to the conformity assessment dossier (CAD). No room for interpretation — the result is CERTIFIED or FAILED.

SOVP in the glossary →
The web doesn't need better crawlers. It needs a foundation on which agents know where they stand. We're building that foundation as a protocol.
Thorsten Litzki, Founder & CEO, Litzki Systems LLC
Technological foundation

SOVP – Sovereign Validation Protocol

SOVP stands for Sovereign Validation Protocol — the deterministic infrastructure validation framework behind CERTavia. No AI scoring, no probabilistic statements. The result is binary truth: SOVP-CERTIFIED or SOVP-FAILED.

180+ parameters 20 clusters Ed25519-signed IETF draft USPTO patent
How it works

The mathematical core

SOVP checks AI infrastructure against 180+ deterministic parameters, grouped into 20 thematic clusters. Each cluster evaluates a specific infrastructure aspect: from DNS configuration through TLS integrity to machine-readable AI governance disclosure.

The result is binary: all parameters met → CERTIFIED. One parameter missed → FAILED. The procedure recognizes only clear boundaries: no scoring, no gray areas, no partial credit, no risk trade-offs.

Aflow = Ψcore · (C / Ev)

Aflow = Audit Flow Score  |  Ψcore = Core Compliance Matrix  |  C = Cluster completion  |  Ev = Evidence completeness

What SOVP checks

DNS & cryptographic base integrity

DNSSEC, CAA records, TLS certificate chain, HTTP security headers (HSTS, CSP, DMARC), SPF, and DKIM.

Privacy & consent

Crawler directives in robots.txt, consistency of opt-in/opt-out declarations for AI crawlers, WAF response consistency.

Machine-readable identity

Structured data per Schema.org, AI discovery layer (ai.txt, ai.json, llms.txt), agent-card.json.

AI Governance Hard Gate

AI policy URL, deepfake disclaimer, AI training opt-out status, contact point for AI inquiries: externally verifiable governance signals.

Scope

What SOVP is not

Not AI SOVP operates entirely rule-based and deterministically, without using AI models for evaluation. Fully traceable.
Not scoring No points, no percentages, no risk ratings. Binary result: SOVP-CERTIFIED or SOVP-FAILED.
Not an audit substitute SOVP prepares for the formal conformity assessment by notified bodies.
Not a black box Every parameter is documented. Every check is traceable. The IETF draft is public.
Technical anchoring

Cryptography and DNS anchor

Every SOVP certificate is signed with Ed25519, one of the most secure and efficient signature schemes. The public key is anchored in the operator's DNS, so any third party can independently verify the certificate's authenticity.

Why SOVP doesn't need ISO status: The EU AI Act does not mandate a specific tool or format for infrastructure evidence. Art. 50 requires that the machine-readable transparency, labeling, and provenance of an AI system be demonstrable. CERTavia delivers this evidence as a cryptographically signed, DNS-anchored document with a full parameter breakdown — independently verifiable, without involving CERTavia. That's the criterion that matters.

Transparency

IETF Internet Draft

draft-litzki-sovp, submitted as an Individual Submission to the IETF Datatracker. Not an official IETF working-group standard — but publicly viewable, fully documented, and traceable for any auditor.

Protection

USPTO provisional patent

Application number #64/005,737. Provisional patent application with the United States Patent and Trademark Office.

CERTavia analyzes technical infrastructure signals. The result is a machine-readable finding, not a legal opinion and not a certification within the meaning of the EU AI Act conformity assessment under Article 43. For legally binding compliance assessments, consult an accredited conformity assessment body.

Frequently asked questions

Questions about SOVP and infrastructure evidence

Is this an official certification?

No. CERTavia does not issue a government-recognized certificate. SOVP delivers technical infrastructure evidence — deterministic, cryptographically signed. Official conformity assessments under EU AI Act Art. 43 build on evidence like this. More in the glossary →

What's the difference from a pentest or ISO 27001?

Pentest: active, manual vulnerability search by experts. SOVP passively and deterministically checks the infrastructure configuration against a defined requirements catalog — in 90 seconds, reproducible, auditable. ISO 27001: comprehensive management system. SOVP delivers the technical infrastructure evidence for EU AI Act Art. 50 — complementary, not competing.

Who recognizes this evidence?

The EU AI Act does not mandate a specific evidence format — it requires that the Art. 50 requirements for transparency, machine-readable labeling, and provenance be demonstrably met. The SOVP evidence record is a cryptographically signed, DNS-anchored document with a full parameter breakdown. Internal compliance teams, external auditors, and notified bodies can independently verify authenticity, timing, and content — without involving CERTavia. The document is designed as an attachment to the conformity assessment dossier under Art. 11.

Does the auditor need to know SOVP?

No. The SOVP evidence record is a structured, machine-readable document that documents a defined infrastructure state at a cryptographically confirmed point in time. An auditor doesn't need to know SOVP — no more than they need to know the internal software a company used to document its ISO 27001 scope. They check whether the required infrastructure parameters were demonstrably met. CERTavia delivers exactly that documentation.

Next step

SOVP validation for your infrastructure

In 90–120 seconds you'll see whether your infrastructure meets the SOVP requirements.

Scan your domain now – free Request enterprise