Governance

How JIL Sovereign Is Governed

A controlled governance model designed for institutional stability and regulatory compliance.

Overview

Controlled Governance Model

JIL operates under a controlled governance model. Unlike open networks where anyone can participate, JIL requires its independent signing nodes to meet jurisdictional, technical, and operational requirements before joining the network. This approach prioritizes institutional stability and regulatory compliance over open participation.

Governance Domains

Four domains of protocol governance.

Signing Node Admission

Jurisdiction requirements and regulatory standing verified before any signing node joins the network.

  • 7-gate startup sequence: handshake, config bundle, digest verification, key generation, auth token, service deployment, health confirmation
  • Jurisdiction verification and regulatory standing
  • Minimum hardware and network requirements
  • Cryptographic key generation and digest verification

Protocol Upgrades

Three-stage deployment pipeline with digest verification and rollback at every stage.

  • Development to staging to production promotion pipeline
  • Build verification at every stage
  • The fleet control plane coordinates rollouts
  • Rollback capability at each stage

Policy Rule Updates

Compliance rule management across regulatory jurisdictions with zero-downtime deployment.

  • Compliance rule management for 10 regulatory jurisdictions
  • Asset-class policy configuration
  • Audit logging for all policy changes
  • Zero-downtime policy deployment

Emergency Procedures

Automated health monitoring and failover with anti-loop protection and golden snapshot recovery.

  • SentinelAI automated health monitoring and failover
  • Fleet cycling with anti-loop protection - max 3 cycles per 2 hours
  • Auto-recovery when fleet health drops below 30% for 5 consecutive cycles
  • Golden snapshot backup and restore
signing-key set

Network Structure

The JIL signing-key set is designed for geographic distribution, regulatory alignment, and operational independence. Each signing node is independently operated with no shared infrastructure.

20
Target Active Nodes
20
Standby Capacity
hybrid signature
Signing Quorum
13
Legal Jurisdictions
Independence

How Signing Node Independence Is Maintained

JIL signing nodes are distributed across independent infrastructure providers in separate legal jurisdictions. No two signing nodes share the same hosting provider, network segment, or legal entity. A permissioned JIL-operated quorum is as-designed. Independent 14-of-20 multi-party confirmation and a live six-node-offline claim are not current fact.

  • Separate Infrastructure - Each signing node runs on an independent server with dedicated compute, storage, and network
  • Jurisdictional Diversity - Signing nodes operate under different legal frameworks, preventing any single government from controlling the network
  • Independent Key Management - Each signing node generates and holds its own cryptographic keys through a secure boot sequence
  • Quorum-Based Signing - Settlement requires independent cryptographic signing from permissioned JIL-operated signing nodes. Independent 14-of-20 live multi-party confirmation is not current fact.
Transparency

Governance Transparency

All governance actions - signing-node admissions, protocol upgrades, policy changes, and emergency interventions - are logged immutably in the tamper-evident evidence ledger. External validation of settlement proofs, compliance attestations, and network health is available at /proof.

Protocol Governance

Learn More About JIL Governance

Controlled governance designed for institutional stability. Explore the infrastructure, contact the team, or review validation evidence.