Layer 01Sovereign Land
The corridor itself: Tiers I–IV, one continuous federal custody boundary on both borders.
Tier I–IV corridor
Layer 02Sovereign Hardware
No camera, radio, tower, gate controller, or sensor joins the corridor network without hardware provenance and dual attestation. Unattested devices are refused rather than trusted.
Sovereign CircuitDual Attestation Protocolkristenslab/sovereign-circuitSealed Enclave UnitStrongRoomSE/sealed-enclave-unit
Layer 03Sovereign Networks
Every outbound transfer receives an explicit ALLOW, INSPECT, or BLOCK decision; every inbound connection is screened in a sandbox against typed tokens by class. Doctrine: track-back, never hack-back.
Layer 04Sovereign AI
A deterministic Guardian router with model admission, provenance registry, jurisdiction and classification routing, air-gapped import, egress gating, quarantine, audit chain, and recovery. Observed evidence and asserted configuration are never displayed as the same thing. No black-box model gets a vote on a border decision.
Layer 05Sovereign Infrastructure Protection
Corridor power, water, comms, and sensor infrastructure defended by deception layers that detect and document intrusion, with the same non-retaliatory evidence boundary.
Guardian SphereVigilantGuardkristenslab/vigilantguard
Layer 06Sovereign Evidence
Append-only Merkle commitments, k-of-N guardian thresholds on adversarially independent infrastructure, registered witnesses counter-signing signed tree heads so equivocation becomes visible, dual-control sealing, and hash-sealed evidence packs. Every custody event becomes tamper-evident.
ProofCoreStrongRoomLockChainkristenslab/proofcore
Layer 07Sovereign Elections
The same custody doctrine, already running for mail-ballot chain of custody, where paper stays authoritative and the software produces tamper-evident procedural records without revealing how anyone voted. Proof of doctrine.
BB2G Election CommandBallot Trail / MBLTSProvable Custody
Layer 08Sovereign People
Personnel integrity designed for coercion rather than pretending it away: dual control, rotation, independent witness attestation, and the Duress Door with a statutory protected-witness pathway.
Layer 09
Protected tier
Sovereign Children
A child's safety data belongs to the child's family, not to a platform or a database. The child carries a
receive-only ranging module with a wristband alert; fixed mains-powered anchors confirm the
enforceable distance. The child's side never transmits, because a transmitting child device
announces the child's position. Rotating identifiers prevent observations from becoming a reusable movement
history — protection without a national child-tracking database.
Layer 10
Protected tier
Sovereign Families
A national family-support network that moves resources to families while children remain at
home. Applied here it is the tier that makes the Duress Door usable — an officer who reports coercion
needs their family relocated, supported, and safe before the interdiction, not after.
Layer 11Sovereign Build
Corridor software developed local-first, with four visibly distinct operating modes — Local Device, U.S. Sovereign Cloud, External Cloud, Sandbox — local model execution, encrypted local storage, metadata-only activity logging, and explicit outbound disclosure. Border systems should not be built in an environment where the build itself leaks.
Secure Build LabStrongRoomSE/secure-build-lab
Layer 12Sovereign Record
The public accountability surface. Null findings stay published beside confirming findings; conflicting figures stay labeled rather than harmonized into a cleaner unsupported answer. A program of this magnitude earns public consent only if its own record is auditable — including the parts that did not work.
FOIA ConsolePublic Record LedgerFollow the Data