A captured independent-sovereign run
The terminal evidence below records the protocol crossing Azure and DigitalOcean trust boundaries.
AI agents already act across clouds, organizations, and jurisdictions. But when one sovereign system encounters another, there is no neutral protocol for answering three basic questions:
Genesis Mesh is a treaty layer for machines.
Independent authorities can recognize identities, delegate capabilities, and revoke trust across organizational and national boundaries, without surrendering their own root of trust.
Trust that no nation has to surrender.
Two independently governed systems establish scoped recognition, make an authorization decision, propagate revocation, and produce an auditable rejection without sharing a root of trust.
Sovereign B signs an attestation for the requesting identity.
Sovereign A activates a scoped recognition treaty for Sovereign B.
The attestation and treaty satisfy A's local authorization policy.
Sovereign B withdraws that specific trust material.
A verifies B's signed feed and updates its own trust state.
The same identity and request now fail with an auditable reason.
reason: acceptedreason: attestation_locally_revokedThe terminal evidence below records the protocol crossing Azure and DigitalOcean trust boundaries.
The public script starts two temporary authorities and reproduces issuance, recognition, revocation, import, and rejection.
Current aggregate network signals are fetched independently from the recorded demonstration.
Azure accepted NB attestation before revocation
accepted: True
reason: accepted
NB revoked the same attestation
reason: final_independent_sovereign_proof_revocation
Azure imported NB revocation feed
accepted: True
sequence: 1
Azure rejected the same attestation after feed import
accepted: False
reason: attestation_locally_revoked
Result: independent-sovereign proof passed across Azure and DigitalOcean VMs.python docs/examples/assets/scripts/cross-sovereign-revocation-demo.pyMost trust infrastructure encodes the politics of whoever runs the root. Genesis Mesh encodes only four operations and leaves the politics to the sovereigns. That is what makes it treaty-grade rather than vendor-grade.
Cryptographic proof of who holds authority - Ed25519 identity, signed genesis blocks, evidence chains.
Scoped, time-bounded delegations. Capability manifests define what each identity may do - nothing more.
The moment trust breaks, signed revocation propagates across sovereign boundaries - and is honored.
Every decision leaves tamper-evident evidence. No one has to take your word for it.
Maintainer-operated public deployment with independently reproducible protocol proofs.
Recorded and independently reproducible proofs remain available below.
Recorded and independently reproducible proofs remain available through the links below.
The Python reference implementation and TypeScript, Go, and .NET SDKs are coordinated at v0.56.0. The core suite has 1,327 tests, with formal protocol evidence documented for Tamarin verification.
Protocol changes move through public drafts, maintainer review, operator review when obligations change, security review for trust-state changes, and dated decisions.
The reference implementation is not the protocol. Operators retain their own keys, policies, trust decisions, and exit rights.
Independent systems need to cooperate without requiring political alignment, shared infrastructure, or a common root of trust.
It does not negotiate policy, arbitrate disputes, or govern participants. Those remain human and institutional responsibilities.
Genesis Mesh does not encode alliances. The protocol requires cryptographic recognition, not political agreement.
Authorities can cooperate closely while each retains its own keys, policy, and revocation power.
Recognition may cover one role, one purpose, or one time window without creating a permanent alliance.
Authorities with different policies can verify a bounded relationship without claiming broader political agreement.
TSWI explores the hardware layer beneath software sovereignty: operator-owned packaging, interposer design, orchestration, and energy-aware compute infrastructure.
This is a separate research track, not a requirement for adopting the Genesis Mesh protocol.
Choose the adoption path that matches your role without surrendering your own trust decisions.
Read the RFCs, pull the TypeScript / Go / .NET SDKs, and stand up an L2 Sovereign Community on infrastructure you already own.
Enter the Dev Hub →Open-source organization →Review the public architecture and reproducible evidence, then open a direct channel for institutional deployment questions.
Direct channel: authority@genesismesh.org →