Technology

The Sovereign Validation Protocol: The technical foundation of CERTavia.

CERTavia is built on the Sovereign Validation Protocol (SOVP), a deterministic infrastructure validation framework with a binary result. SOVP is formally submitted as an IETF Internet Draft, filed as a USPTO provisional patent application, and available as an open-source reference implementation on GitHub. This page explains the protocol, its architecture, and the credibility foundation on which CERTavia stands as a product.

View IETF draft sovp-python on GitHub
The web doesn't need better crawlers. It needs a foundation on which agents know where they stand. We're building that foundation as a protocol.
Thorsten Litzki, Founder & CEO, Litzki Systems LLC
The principle

Deterministic. Binary. Rule-based.

SOVP solves a precisely defined task: checking a domain's technical infrastructure for its integrity and trustworthiness as a data source for AI systems. The result is binary: SOVP-CERTIFIED or SOVP-FAILED.

The protocol contains exclusively rule-based, deterministic parameters. The validation procedure itself operates entirely rule-based, without probabilistic scoring or an AI component. The same infrastructure state produces the same result on every check. This reproducibility is the foundation for the certificate's auditability.

The protocol operates at Layer 0: the infrastructure layer that precedes content, authorship, and every other signal. At this level, AI systems and agentic pipelines decide which domains are treated as trustworthy data sources.

The architecture

80+ parameters in 6 clusters A–F

CERTavia checks 80+ parameters, organized into 6 clusters A–F. The clusters address the essential areas of infrastructure integrity.

DNS and cryptographic base integrity

DNSSEC configuration, CAA records, TLS certificate chain, certificate transparency, HTTP security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options), SPF, DKIM, and DMARC. The base layer on which all further validation steps build. Gaps at this level are the first thing visible in an audit.

Privacy & consent

Crawler directives in robots.txt, consistency of opt-in and opt-out declarations for all relevant AI crawlers (GPTBot, ClaudeBot, Google-Extended, CCBot, Anthropic-ai, and others), WAF response consistency, consent declaration integrity. Checks whether the declared configuration matches the actual infrastructure response. A discrepancy between declaration and infrastructure reality is a FAILED parameter.

Machine-readable identity and authorship

Structured data per Schema.org, canonical entity declaration, AI discovery layer (ai.txt, ai.json, llms.txt, llms-full.txt), machine-readable authorship signals, agent-card.json, WebMCP configuration, API catalog per RFC 9727: Link Relation Types for Web APIs, JWKS endpoint, RFC 8615: Well-Known Uniform Resource Identifiers, and HTTP Message Signatures directory. The layer on which a domain declares its identity to AI systems and agentic pipelines in a machine-readable way.

AI Governance Hard Gate

AI policy URL, privacy AI section, robots.txt AI directives, deepfake disclaimer, AI training opt-out status, contact point for AI inquiries. The governance layer at which the regulatory requirements from Art. 50 of the EU AI Act become technically verifiable and machine-readable.

The signature scheme

Ed25519, DNS-anchored, independently verifiable

Every SOVP certificate carries a cryptographic signature using the Ed25519 scheme. Ed25519 is an elliptic-curve signature scheme known for high security combined with a compact key size, specified by the IETF in RFC 8032: Edwards-Curve Digital Signature Algorithm. For DNSSEC applications, RFC 8080: Edwards-Curve Digital Signature Algorithm for DNSSEC additionally applies.

The signature is DNS-anchored. The signing key is stored in the validated domain's DNS. Any external reviewer can independently verify the signature without needing access to CERTavia's or Litzki Systems LLC's internal systems.

The Sovereign Vault stores the certificate with a configurable TTL. In the Basic package, vault availability is 90 days (local archiving required afterward). In the Pro package, the vault entry is permanently retrievable via token. The Sovereign Vault link can be forwarded to external auditors, notified bodies, and authorities, and is retrievable as a machine-readable verification URL.

The IETF draft

draft-litzki-sovp: Formal protocol specification at the IETF

The Sovereign Validation Protocol is formally submitted as an IETF Internet Draft under the identifier draft-litzki-sovp – IETF Datatracker. The draft contains the complete technical specification of the protocol: parameter definitions, cluster architecture, signature scheme, DNS anchoring, and the binary result framework.

IETF Internet Draft status means the protocol is subject to the formal IETF review process and is publicly viewable in the IETF Datatracker. This status is an established procedure for the open specification of internet protocols and lays the groundwork for later standardization by an IETF working group.

CERTavia actively uses the IETF draft as a credibility signal toward enterprise customers, auditors, and notified bodies. The draft is fully available to IT leaders and CTOs for technical evaluation ahead of a purchase decision.

The patent

USPTO Provisional Patent Application #64/005,737

The Sovereign Validation Protocol is protected by a provisional patent application with the USPTO – United States Patent and Trademark Office under number 64/005,737. The application documents the priority of the invention and secures the protective scope for the protocol during the standardization process.

The inventor and applicant is Thorsten Litzki. The application is filed under Litzki Systems LLC, St. Petersburg, Florida, USA.

Thorsten Litzki describes the protocol's origin story, from a weighted SEO audit catalog to an active IETF draft, here: Why I stopped optimizing websites and started specifying a protocol →

Back to CERTavia Technology

The open-source reference implementation

sovp-python: Apache 2.0 on GitHub

The Python reference implementation of the Sovereign Validation Protocol is publicly available on GitHub under the Apache 2.0 license. The repository contains the complete implementation of the validation parameters, the cluster architecture, and the signature scheme.

Publishing under Apache 2.0 lets IT teams and security researchers independently evaluate the protocol, integrate it into their own systems, and contribute to its further development. The open-source availability of the reference implementation is a deliberate part of the credibility strategy: anyone who wants to review the protocol finds all the foundations publicly accessible.

SOVP and the competition

What sets SOVP apart from other approaches

The market for AI compliance tools is growing. SOVP occupies its own category because it answers a different question than most available approaches.

Probabilistic scoring systems measure a domain's visibility in AI systems. They indicate how often a domain appears in LLM outputs and how stable that visibility is. That's a backward-looking measurement of a state.

SOVP measures the infrastructure prerequisites that produce that state. That's a forward-looking check of the conditions under which a domain is ingested as a trustworthy source. The result is binary, deterministic, and independent of the probabilistic fluctuations of individual LLM outputs.

Another structural difference: SOVP is a formally specified protocol with a public reference implementation, IETF registration, and cryptographic signature infrastructure. This combination creates a verification foundation that proprietary scoring systems structurally lack.

IPR and competitive integrity

Active protection of the protocol

Litzki Systems LLC actively pursues protection of the intellectual property rights to the Sovereign Validation Protocol. An IPR disclosure with the IETF (Disclosure ID 7291 and 7294) documents the ownership rights to the protocol in the context of the IETF standardization process.

If there are signs of misuse of the protocol name or of imitation products using the SOVP framework without a license, Litzki Systems LLC pursues the legally available steps.

Benchmark data

496 validated domains. The market situation in numbers.

The CERTavia engine has validated 496 domains from Fortune 500 companies, DACH market leaders, and the enterprise segment based on the SOVP framework. The results show the current infrastructure state of the market.

54.5
Median readiness score
Half of all checked enterprise domains fall below this value on the SOVP readiness scale.
71.0
Q3 threshold
Only 25 percent of all checked domains reach or exceed this value.
0 / 150
Fortune 500 and DACH domains
In a sample, not a single domain delivered a complete machine-readable sovereignty declaration at the Layer 0 level.

This data is reproducible. Each of the 496 checked domains can be re-checked with the same deterministic procedure. The result is the same.

Frequently asked questions

Questions about SOVP technology

Is there API documentation?

Yes. The SOVP engine is reachable via a REST API and supports MCP (Model Context Protocol) for integration into AI agents and automated compliance workflows. API documentation and access credentials are included in the Enterprise package. Request API access →

What happens if my infrastructure changes?

A SOVP scan is a snapshot. We recommend a new scan whenever your infrastructure changes (new TLS configurations, DNS changes, certificate renewals). The result is deterministic — the same infrastructure always produces the same result. The result can change accordingly with any change.

What's the difference from a pentest?

A pentest actively and manually searches for attack surfaces. SOVP passively and deterministically checks the infrastructure configuration against a defined requirements catalog — in 90 seconds, reproducible, automatable. The two are not mutually exclusive.

Experience the protocol in practice

Experience the protocol in practice

The free quick scan delivers your domain's SOVP result in 90 to 120 seconds. The result shows the current Layer 0 status based on all 80+ validation parameters.

CERTavia analyzes technical infrastructure signals. The result is a machine-readable finding, not a legal opinion and not a certification within the meaning of the EU AI Act conformity assessment under Article 43. For legally binding compliance assessments, consult an accredited conformity assessment body.