SoundChain
SoundChainSovereign Infrastructure
Severance Manifest September 2026

Fourteen vendors,
severed and
replaced.

A complete social, media and AI platform, rebuilt to run on hardware its operator owns. No hyperscaler. No managed identity. No hosted inference. No app store. Every dependency was removed one at a time, in production, and the date recorded.

What follows is that record, mapped onto the procurement framework Europe now scores sovereignty against — because for the right acquirer this is not a product story. It is an instrument for passing a test they are already being given.

14vendors severed
and replaced
$20monthly third-party
cloud floor
240mscold boot, full
platform, offline
12AI agents on
owned silicon
§01  Why now

Sovereignty stopped being a principle
and became a purchase order.

For a decade, "digital sovereignty" was a position papers argued about. In 2026 it became a line item with a budget, a scoring rubric, and buyers who are disqualified without it.

$80Bworldwide sovereign
cloud spend, 2026
83%European spend growth,
year over year
€180Msingle EU tender,
awarded April 2026
€11Bone retailer's bet on
one sovereign cloud

The enforcement arrived with the money. In May 2026 the Dutch government prohibited a €100M acquisition of a domestic cloud provider by a US acquirer — the first time its investment screening body has ever blocked a deal — because the target operated national digital identity infrastructure and foreign ownership would have exposed it to extraterritorial law.

The message to every European provider was unambiguous: dependency is now a disqualifying defect, and it cannot be acquired away from a foreign parent. It has to be engineered out.

Engineering it out is slow, unglamorous, and almost never finished in time for a tender. SoundChain has already done it fourteen times, under live traffic, with dates. That record is the asset. The consumer application is the proof it works.

§02  How the scoring actually works

The floors are pass/fail.
That is the whole game.

The EU Cloud Sovereignty Framework assesses eight objectives. Each carries a minimum assurance level used as a rejection threshold — applied before any weighted ranking. A bid scoring 70 % that misses one floor loses to a bid scoring 55 % that clears them all.

This is the detail that reorders everything. Sovereignty gaps do not cost a bidder points. They remove the bidder. And closing one means replacing a named dependency with something the operator controls — then proving it, with evidence, to a contracting authority.

No certification is claimed anywhere in this document, and none exists to claim. SEAL ratings are assessed per provider, per procurement, by the contracting authority; there is no accreditation body. What follows is a contribution analysis, not a credential.

§03  Mapped to the framework

What acquiring this does to your score.

The eight objectives below are the framework's own, in its own weightings, ordered by weight. Against each: what SoundChain contributes — and, marked in amber, what it does not.

SOV-5 Supply Chain Sovereignty weight 20% · highest

Assesses: origin and transparency of hardware and software design, build, packaging and distribution.

  • A documented severance record. Fourteen third-party dependencies identified, replaced and dated — precisely the artifact this objective demands, and the one most bidders cannot produce at any price.
  • Self-built distribution. Signed binaries published as content-addressed identifiers and peer-to-peer magnet links, byte-verified across three independent public gateways. No store, no intermediary, no gatekeeper in the chain.
  • Own forge and build path. Source hosting, compilation and deployment all run on operator-controlled infrastructure.
  • Hardware origin is not European. Compute and accelerators are commodity parts of US design. The software chain is sovereign; the silicon is not, and is not claimed to be.
SOV-1 Strategic Sovereignty weight 15%

Assesses: where decisive authority, ownership and financing sit, and how stable that is.

  • Clean, unencumbered title. Sole ownership. No investors, no board, no co-founder, no contractor claims, no licensing encumbrance. Chain of title is a one-line answer — which, in a market where the last comparable deal died on ownership grounds, is not a small thing.
  • Transferable in full. Because ownership is undivided, an outright assignment moves decisive authority into the acquirer's jurisdiction on closing. No consent chain, no minority holdout.
  • Not EU-owned today. This objective is satisfied by the transaction itself rather than by the asset — which is exactly why a European acquirer extracts more value here than a non-European one.
SOV-4 Operational Sovereignty weight 15%

Assesses: whether EU actors can independently run, support and develop the service with no non-EU involvement.

  • Zero-downtime deployment on owned iron. Blue/green cutover with health-gated traffic swap, currently carrying four production applications.
  • Operates disconnected. Demonstrated serving full interface, API and authentication with both the compute host and the public front door unreachable — the scenario every continuity plan describes and almost none has tested.
  • Currently one operator. Independent operation is achievable and documented, but not yet staffed by a second party. This is exactly what a bounded transition period exists to resolve, and it is scoped as such rather than deferred.
SOV-6 Technology Sovereignty weight 15%

Assesses: openness of the stack — standards, open licensing, auditability, and freedom from vendor lock-in.

  • No proprietary runtime anywhere in the path. Every replacement is an open, self-hostable component under operator control.
  • Lock-in removed by construction, not by assertion. The platform demonstrably runs with its vendors removed — that is how each replacement was validated in the first place.
  • Auditable by design. A 217-entry engineering corpus records every incorrect assumption made during the build, the check that would have caught it, and the standing rule that replaced it. Few codebases of any size can hand a buyer their own failure history.
  • Reversible cutovers. Retired paths are ghosted rather than deleted, so a migration can be rolled back under load instead of being a one-way door.
SOV-3 Data & AI Sovereignty weight 10%

Assesses: cryptographic control over data, processing location, and independence of AI capabilities.

  • Inference never leaves the building. Twelve specialist agents run on locally owned accelerators. No prompt, document or user record is transmitted to a model provider — the constraint no hosted API satisfies at any price, for any customer, under any contract.
  • Own search substrate. Research queries route through a self-hosted metasearch node, so even an agent's lookups disclose nothing to a third party.
  • Own identity and key material. Passkey and code-based authentication replaced a hosted identity vendor. No custodial third party holds user credentials.
  • One managed database remains off-box. Disclosed in full at §05. It is the single largest open engineering item and it is named here rather than discovered later.
SOV-2 Legal & Jurisdictional weight 10%

Assesses: exposure to foreign laws with extraterritorial reach, and whether non-EU authorities can compel access.

  • Almost no third party left to compel. With hosting, mail, identity, storage, search and inference all self-operated, the list of external processors an authority could serve is close to empty. Sovereignty here is a consequence of architecture, not of contract language.
  • Data resides where the hardware resides. Processing location is a physical fact about an owned machine rather than a regional promise in a service agreement.
  • Resolved on transfer. As with SOV-1, extraterritorial exposure is a function of who owns the asset. An EU assignment removes it.
SOV-7 Security & Compliance weight 10%

Assesses: EU-controlled security operations, formal certifications, and GDPR / NIS2 / DORA alignment with audit rights.

  • Security operations are in-house. No outsourced monitoring, no third-party agent holding privileged access to production.
  • No formal certifications held. ISO 27001, NIS2 and DORA attestation work has not been undertaken. This is the objective with the furthest to travel, and an acquirer with an existing management system will close it faster than this asset could alone.
SOV-8 Environmental Sustainability weight 5% · lowest

Assesses: energy efficiency, renewable sourcing, circular practice and reporting transparency.

  • Genuine circularity. Production inference runs on prior-generation workstation accelerators deliberately kept in service — reuse rather than procurement, which is what the objective actually rewards.
  • A very small footprint. The entire production estate is one workstation, against a third-party cloud floor of roughly $20 per month.
  • No formal reporting. Efficiency and sourcing are not yet measured or published to any standard.

Read as a set: the objectives SoundChain strengthens most are SOV-5 at 20 % and SOV-6 at 15 % — the two heaviest after strategic ownership — while the objectives it cannot satisfy alone, SOV-1 and SOV-2, are satisfied by an EU acquirer merely completing the purchase.

§04  Evidence

It runs where a modern platform should not.

Each claim below has a corresponding artifact — a build, a test run, or a device it was demonstrated on. None are projections and none are roadmap.

The whole platform fits in a laptop bundle
180 MB containing 312 compiled API routes. Cold boot to a serving application in roughly 240 ms.
It survives total infrastructure loss
Demonstrated with both the compute host and the public front door unreachable: full interface, API and login brought up locally, with zero database credentials in the bundle.
It runs on hardware a decade out of support
A 2013 laptop on a 2012 operating system held a live two-way session with a current smartphone. Also demonstrated on a games console.
Peers find each other with no coordinator
Discovery over a distributed hash table that has had no owner since 2005 — no company to serve process on, no registry to seize. Candidates stay untrusted until a nonce round-trip. Suites pass 6/6 and 16/16.
State converges with no authority
A signed conflict-free replicated ledger. Legacy records enter as attestation, never as forged authorship.
Distribution needs no gatekeeper
Signed desktop binaries published as content-addressed identifiers and magnet links, byte-verified across three independent public gateways.
§05  What is rented, and what is thin

The parts that are not sovereign yet.

Diligence surfaces these in week one. They are listed here, first and unprompted, because a severance claim is only worth what its exceptions are worth.

Rented
Managed databaseThe one significant off-box dependency and the largest remaining engineering item. Data sovereignty is the open work, and it is open.
Rented
Public front doorA single small cloud instance still terminates public traffic and relays mail. The door is still someone else's and is never described otherwise.
Rented
Registrar DNSNames remain delegated to a commercial registrar.
Rented
Third-party media deliveryParts of the sports surface depend on external content delivery outside the operator's control and revocable at the provider's discretion. A degraded fallback is already shipped and tested against that event.
Thin
Consumer tractionApproximately 781 registered profiles. This is not a user-growth story and is not presented as one.
Thin
RevenueNo meaningful recurring revenue. Token and fee rails are built and live; they are not monetised at scale.
Thin
CertificationsNo ISO 27001, NIS2 or DORA attestation work undertaken. SOV-7 is the objective with the furthest to travel.
Thin
Single operator, single siteOne engineer holds the architecture; production runs on one machine in one location. No high-availability tier and no disaster-recovery site. An acquirer is buying an architecture and its author, not an operations organisation.

Read both lists together, because they are one argument. The severance is real, dated and reproducible; the business around it is small and the operations are one deep. That combination is what makes this an engineering acquisition rather than a platform acquisition — and it is scoped, structured and priced accordingly.

§06  The estate

One box, fully owned.

Deliberately unglamorous, and that is the argument. This is a workstation, not a datacentre contract — which means the economics reproduce anywhere hardware can be bought, in any jurisdiction, at a cost a procurement officer will not query.

Compute

A single dual-socket workstation running a current Linux distribution.

Inference

Two owned accelerators, 24 GB combined, carrying twelve agents. Three further cards owned and not yet installed.

Third-party floor

≈ $20/month total external cloud spend, itemised and audited.

Live applications

Four in production on the owned stack: social and music, sports statistics, issuance, and a local-model assistant.

The sports surface is the sharpest demonstration of the operating model. When a rights-holder restricted third-party playback of its clips, the platform detected the restriction programmatically, re-ranked to permitted sources, and routed the remainder to the rights-holder's own property — designed, shipped and verified inside a single working day. That is the cadence the whole estate runs at.

§07  Scale

The cost curve flattens
instead of compounding.

The usual objection to sovereign infrastructure is that it cannot grow. The opposite is true here, and the reason is architectural rather than a matter of buying a bigger machine.

Horizontal by design

Capacity comes from nodes, not from a larger central box. Each node carries its own local model and its own replica, so every participant that joins brings the compute it consumes. This is the opposite of the hyperscaler curve, where every new user is a new invoice.

Headroom already bought

The current estate runs on two accelerators of a five-card inventory — three further cards are owned and uninstalled. The platform is dual-socket with unpopulated memory and expansion capacity. Near-term growth costs installation time, not procurement.

Proven on the low end

The floor was tested harder than the ceiling: the platform runs on a 2013 laptop and a games console. Software that survives those constraints does not become the bottleneck when given current hardware.

Marginal cost

Growth is met with capital expenditure you own and depreciate, not per-seat fees that scale with success. The current estate carries four production applications on a $20/month external floor.

Stated precisely, because a buyer will verify it: the estate today is one workstation and is sized as one. What is proven is the scaling model — horizontal distribution across owned nodes — and the fact that the expansion hardware for the next step is already purchased and on the shelf. What has not yet been demonstrated is that model under production load at national scale. That is a funded engineering exercise, not an unknown.

§08  See it running

Open any of these. Right now.

Claims in an acquisition document are worth what they can be checked against. Every link below is live production on the owned stack, served from the same machine serving this page. Nothing here is a screenshot, a staging mirror, or a demo environment.

Product surfaces

The severance, running

Each of these replaced a named commercial vendor. They are not descriptions of the replacement — they are the replacement, serving traffic.

Not listed: internal operator surfaces, staging environments and the agent control plane. They exist and can be shown in a technical session under NDA — they are simply not appropriate to publish. Two further severed components, the self-hosted search node and the media pipeline, bind to localhost by design and are demonstrated live rather than linked.

§09  Three ways in

What is actually on the table.

Acquire outright

Full assignment of an unencumbered title: codebase, mesh protocol work, distribution channel and failure corpus — plus a bounded, fixed-term transition so your engineers operate it without the author.

Sovereign cloud · Defense

Licence the stack

Take the deployer, identity layer, object store, mail server, search node and local-inference tooling as a sovereign reference architecture for your own estate.

Integrators · Telecom

Fund a pilot

A scoped deployment on your hardware, in your jurisdiction, proving the claim against your own compliance requirements before any transaction is discussed.

Public sector · Regulated finance

The fastest evaluation is not a meeting. Take the published signed binary, verify its hash against the public identifier, disconnect the network, and watch the platform boot and serve. That takes under five minutes, it cannot be faked, and it is the entire pitch.