SOV Network — Knowledge Bank
Civic education for the SOV Network: what it is, how to use it, and the protocols that make it work. This is the same Knowledge Bank shown inside the SOV app's Academy — published here so anyone can read it without installing anything.
Contents
- What SOV is and why it exists
- Using SOV day to day
- SOV Link & building on SOV
- Protocols — how the network works
- Running a node (separate guide)
What SOV is and why it exists
The world needed something new
Bitcoin proved that money does not need a bank. But Bitcoin never solved identity, communication, or justice. The SOV Network was built to go further — a single network where you own your identity, your money, your messages, and your voice in how the rules are written. Not controlled by any company. Not dependent on any government. Built to outlast them both.
Not a blockchain — a Sovereign Mesh
SOV is NOT a blockchain. There are no blocks, no chain of blocks, no mining race, and no global queue every payment must wait in. SOV is a SOVEREIGN MESH: self-contained nodes that gossip peer-to-peer, each holding the shared ledger, confirming transactions by witnessing them rather than by burning energy. It is called a "mesh" because the nodes form a web with no centre — any node can leave or join and the network carries on; and "sovereign" because YOU — not a company, not a chain — own your identity, your money, and your voice. Its one genuinely new idea is PROOF OF PERSONHOOD: one human, one wallet, proven by your own biometrics on your own device. That is what no blockchain has — the network knows you are a real, unique person without knowing who you are. So when you describe SOV, don't reach for "crypto" or "blockchain". Say what it actually is: a sovereign, proof-of-personhood mesh — self-contained nodes, one human one wallet, no central operator, and no app store.
Your identity is your key — nothing else
Every other network asks you to trust a company with your password, your phone number, or your email. SOV asks for none of those. Your palm is your key. It cannot be stolen, guessed, or reset by a corporation. When you enroll, your biometric is processed on your device and never sent to any server. Your Sovereign ID is yours permanently — no account to be banned, no service to be shut down.
Everything Bitcoin is — and everything it is not
Bitcoin is digital gold — scarce, decentralized, and unstoppable. SOV respects that design. But Bitcoin has no identity layer, no messaging, no governance, no justice system, and no built-in community. It cannot tell who is human and who is a bot. SOV solves all of that. One human, one wallet. The network knows you are real — and that changes everything.
The last network that can be built this way
Governments are moving fast to regulate digital identity and digital money. The window to build a truly free, sovereign network is closing. SOV was designed from the ground up to operate behind firewalls, survive hostile infrastructure, and resist seizure — because citizens in many countries cannot afford to wait for permission. Every citizen who joins today makes it harder to stop tomorrow.
Works behind firewalls and in blackouts
SOV Speak routes messages through relay nodes that operate on standard ports. Even in countries that block popular apps, SOV messages get through. When a recipient is offline, the message stays in the sender's outbox on their own device — the relay stores nothing. The moment the recipient reconnects, the network broadcasts their presence and the sender's device automatically delivers. No message content ever touches a relay. No conversation can be intercepted.
How SOV works
SOV is a peer-validated digital currency secured by biometric identity. Every citizen gets a wallet, a Sovereign ID, and a permanent place on the shared ledger. No bank account required. No minimum balance. No credit check. If you are human and you have a phone, you qualify.
Justice without courts
On the SOV Network, citizens have a real dispute process — no lawyers, no fees, no waiting months for a ruling. If a transaction is disputed, five citizens selected at random review the evidence and vote. The majority decides. Funds move according to the verdict within 72 hours. This is the first digital economy where justice is built into the protocol.
Your vote actually changes the rules
The Network Constitution is not a document written by a company and handed to you. It is a living set of protocols that citizens vote to activate. Every enrolled citizen votes equally — your balance does not change your weight. If 5,000 citizens vote to enable a new feature, it activates for the whole network. The citizens own the rules.
Running the network
The SOV Network runs on nodes operated by certified Node Operators around the world. Relays keep the shared ledger in sync, deliver messages, and witness transactions. The more operators there are, the stronger, faster, and more resilient the network becomes. Any citizen with a server can become a relay operator. This is infrastructure owned by the people who use it.
To run a node, see Running a node.
Run a node on macOS or Linux
The SOV desktop wallet is the same application on Windows, macOS and Linux, and on all three it is also a full node — the node is not a separate download. What differs between them is only how you get Tailscale, and Tailscale is needed ONLY if your connection cannot accept incoming traffic.
START HERE, on any of the three: install the wallet, sign in, open the Node tab, leave Reachability on Auto and switch Run a Node ON. On ordinary home broadband the app opens your router itself, or relays through the mesh if your network is awkward, and you configure nothing at all. When it shows "Reachable at: …" you are serving, and uptime is what earns. Most people never need anything below this paragraph.
IF AUTO CANNOT GET THROUGH — mobile hotspot, CGNAT, student or office Wi-Fi, any network where you cannot forward a port — you use Tailscale Funnel, which gives your node a stable public address over an outbound-only connection, for free. You install Tailscale yourself and sign in to YOUR OWN Tailscale account. The SOV network never provisions it for you and never sees your tailnet.
ON WINDOWS the wallet can install Tailscale for you: press Enable Tailscale Funnel and accept the normal Windows prompt, then sign in through your browser once.
ON macOS you install it yourself first — from tailscale.com/download, or with "brew install --cask tailscale" if you use Homebrew. Open Tailscale once and sign in. The wallet then finds it automatically, including the App Store version, whose command-line tool lives inside the application bundle rather than on your PATH.
ON LINUX install it with your package manager — "sudo apt install tailscale" on Debian or Ubuntu, "sudo dnf install tailscale" on Fedora, "sudo pacman -S tailscale" on Arch — then "sudo tailscale up" and sign in. Linux needs ONE extra command that Windows and macOS do not: "sudo tailscale set --operator=$USER". Without it the wallet cannot talk to the Tailscale service, because that service is owned by root. Run it once and you are done; the wallet will tell you if you forgot.
Then on any OS: set Reachability to Tailscale Funnel, switch Run a Node ON, and the first time only, approve the Funnel link in your browser. Citizens reach you on the standard secure port with no port-forwarding anywhere.
A note on Linux desktops: the wallet needs a few system libraries that some minimal installations leave out, and a keyring to store your keys in. The download page lists the exact packages. If the wallet will not start on a server or inside a container, that is expected — it is a desktop application, and a machine with no screen should run the node software directly instead.
Using SOV day to day
One human, one wallet
The SOV Network allows exactly one wallet per person, enforced by biometric identity. There are no bots, no fake accounts, and no whales who joined 100 times. Every citizen has equal weight in governance. Every new citizen gets the same fresh start. The network is designed for people — not corporations, not algorithms.
SOV Value and the ⟡ symbol
The ⟡ symbol represents the SOV reference rate — the citizen-voted guide price of 1 SOV. Once 5,000 citizens enroll, the network holds its first value vote. Citizens propose a price. The median of all proposals becomes the rate. It updates every 10,000 new enrollments. No exchange sets this number. No company owns it. Citizens decide the value of what they built.
A real economy — not a speculation game
SOV is not designed to be traded on exchanges and pumped by speculators. It is designed to be earned, spent, and saved by real citizens doing real things. Node Operators earn for running the infrastructure that carries every transaction. Justice jurors earn for resolving disputes fairly. Citizens earn by providing genuine goods and services to one another. The SOV economy rewards real participation, not speculation and not recruitment.
Sending and receiving SOV
Send SOV to any citizen using their Sovereign ID. Transactions confirm in seconds across the relay network. The only cost is a tiny network fee — a fraction of a percent of the amount you send, capped so no transfer ever costs more than a small fixed ceiling (current defaults set by citizen vote). That fee is not taken by any company: it flows into the operator reward pool that pays the citizens hosting the network. No intermediaries, no waiting for business hours. Recent transactions sync to your device automatically every time you connect — so anything that arrived while you were offline is waiting for you. Your wallet is your own record; use the Backup & Restore feature to back up your history and keep it safe.
SOV Speak — messaging with receipts
SOV Speak lets you send messages, voice notes, photos, and files to any citizen on the network. Every message shows a delivery status: Sending → Delivered → Read. You can send SOV directly inside a conversation — the payment appears as a receipt in the chat thread. No phone number required. No SIM card. Just your Sovereign ID.
Protecting your wallet
Your wallet is secured by your 12-word seed phrase, an optional 6-digit PIN, and guardian recovery. Write your seed phrase on paper and store it safely — it is the only way to restore your wallet if your phone is lost or stolen. No central authority can freeze your funds, reset your access, or demand your keys. This is what it means to truly own your money.
SOV Link & building on SOV
SOV Link — sign into any website as a verified human
SOV Link lets any website or app accept your Sovereign ID as a login. It works in two phases. The FIRST time you visit a SOV-enabled site, you tap "Sign in with SOV", and the browser shows you a 6-digit pairing code. You open your SOV app, tap Settings → Connect to External Site, type the code, confirm the site name, and choose a password just for that site. Your SOV app signs the link on the device — your seed phrase never enters the browser, never reaches the external site, and never touches the network in readable form. EVERY TIME after that, the site shows a normal username + password form. You type your Sovereign ID (or palm name) and the password you created for that site. The site checks the password locally on its own server — the SOV network is not contacted at all on repeat logins. This means your day-to-day sign-ins are instant and work even when the SOV network is busy or offline. The password is bound to that specific site, so if one site is breached the credential cannot be reused anywhere else.
Why SOV Link does not use QR codes
Many login systems use a QR code on the desktop that you scan with your phone. SOV Link deliberately does NOT do this. A photographed or screenshotted QR code is a fully valid login token — anyone who captures the picture could log in as you before you do. SOV Link uses a short 6-digit numeric pairing code instead. The code is one-use, expires in 90 seconds, and is bound to the specific website domain you are trying to sign in to. Even if someone watches you type it, it has already been consumed by the time they could try to use it, and it only works for one site anyway. This is a deliberate design choice — small operational friction (typing 6 digits) traded for a meaningful improvement in phishing resistance.
SOV Link — full protocol walkthrough
For a detailed end-to-end walkthrough showing what every actor does — a developer connecting a website, a citizen signing in for the first time, and that citizen returning a week later — see the SOV Link Guide, published with the SOV software as a PDF. It explains the two-phase model (a one-time link, then relay-free repeat logins), why SOV Link uses a short pairing code instead of a QR code, and what guarantees the protocol delivers versus what it does NOT do. Written so a non-technical reader can follow it straight through.
SOV Link — developer guide
If you build the website side, the SOV Link Developer Guide (a PDF published with the SOV software) walks you from "I have heard of SOV Link" to "my site accepts SOV Link logins" in about half an hour. It gives ready-to-use example code for the two small pieces your server needs — one that starts a sign-in, and one that receives the confirmation when the citizen approves it — plus a simple login page and a testing checklist. It assumes you know a common web language but assumes nothing about SOV. In short: the walkthrough tells you WHAT happens during a SOV Link sign-in; the developer guide gives you the working example that makes it happen on your own site.
For platform builders — connect in 15 minutes
If you run a website or app and want one-human-one-account, SOV Login is the easiest way to add it. You do three things: connect your platform once on the network, add a "Sign in with SOV" button that shows the citizen a 6-digit pairing code (the citizen approves it inside their SOV app under "Connect to External Site" — no seed phrase is ever typed into a browser and there is no login page hosted by anyone else), and accept the signed confirmation when the citizen returns. On your side you simply keep one account per Sovereign ID — the SOV identity layer already guarantees one person per ID, so you get a bot-proof, one-person-one-account user base with no captchas, no SMS codes, and no KYC paperwork. The SOV Link Developer Guide (PDF) has copy-paste examples.
Connecting a new platform to the network
Before a website can offer "Sign in with SOV", it has to be connected to the network — and there is no admin office, no corporate sign-up, and no key handed out by a company. It is done by an enrolled SOV citizen who approves the request with their own identity and pays a small one-time SOV fee (currently 10 SOV, set by citizen vote). That fee flows into the operator reward pool that pays the people running the network — the total SOV supply never changes. The network keeps no special administrative override: by design, only a real, biometrically verified human can add a platform. The connection tool is served by every node on the network, so any builder can get it directly from a node and run it themselves — no app store, no central download server, no third party. Running it generates the platform's own keys, signs the request, and returns a private confirmation secret only that platform can read. From that moment the platform is live. Because the same tool ships inside the node software, the ability to connect new platforms spreads with the network itself.
Add "Sign in with SOV" — the exact steps
This is the complete, do-it-today setup — no PDF needed. It is two short jobs: the OWNER registers the site from their wallet, then a developer drops one file in place.
CLI 1 of 5 — why SOV ships no SDK, and does not need one
Most networks hand developers a library, then ask you to trust it. SOV does something simpler: the desktop app IS the developer tool. SovNode.exe runs headless — the same binary a citizen double-clicks will, given "--cli", act as a scriptable wallet that speaks JSON. There is nothing extra to install, no API key to request, no package to audit, and no company in the middle. Run "SovNode.exe --cli --help" and you have the entire surface. Why this matters: an SDK is a dependency, and a dependency is a party who can change the rules, break your build, or be pressured. The CLI is just your own wallet, operated by a script instead of a finger. It signs with the key already sealed in your operating system's credential store, talks to the same relays your app talks to, and obeys exactly the same protocol rules. Nothing about automation makes you a second-class citizen on the network — a script and a human are indistinguishable to the protocol, because both are the same signed identity.
CLI 2 of 5 — the complete command surface
Everything begins with "SovNode.exe --cli". MONEY: "balance" shows what you hold; "send --to <sovereign-id> --amount 10 [--memo \"text\"]" transfers; "history [--limit 50]" lists past transactions; "contacts" lists saved citizens. MESSAGES: "msg --to <id> \"hello\"" sends; "msg --list [--with <id>] [--limit 20]" reads. NODE: "node status|on|off" starts or stops the bundled full node on this machine. EXCHANGE: "exchange orders" browses the book; "exchange mine" shows yours; "exchange create --amount 100 --memo \"...\" [--price 950 --currency NGN]" lists SOV for sale; "exchange chat --order <id>" and "exchange chat-send --order <id> --to <sid> \"...\"" negotiate directly on the listing; "exchange fill --order <id>", "exchange confirm --order <id>", "exchange cancel --order <id>" complete or withdraw. SECURITY: "spendlock status|enable|disable --pin <code>", "hwlock status|enable|disable [--hello]", "automation status|set|allow|deny|off|cancel". GLOBAL FLAGS: "--json" makes any command emit machine-readable output — this is what turns the CLI into an API; "--pin <code>" supplies the PIN so a script never stalls waiting for input; "--node <wss://...>" pins a specific relay. Every command returns a meaningful exit code, so shell scripts can branch on success or failure without parsing text.
CLI 3 of 5 — the four security tiers (read this before automating money)
Automation that can spend money deserves more care than automation that reads it, and SOV gives you four escalating tiers. TIER 0 — PIN GATE: the PIN stops a casual passer-by, nothing more. Anyone who can run the executable as you can move your SOV. Never run the CLI on a shared, hosted, or borrowed machine. TIER 1 — SPEND-LOCK ("spendlock enable --pin <code>"): the private key is no longer stored in the clear at all; only a PIN-encrypted blob is kept, hardened with Argon2id, which is memory-hard and therefore brutally slow to brute-force even though a PIN is short. The decrypted key lives in memory for a bounded session only — the same idea as Bitcoin Core's walletpassphrase timeout, so automation unlocks once instead of re-prompting per transfer. TIER 2 — HARDWARE-LOCK ("hwlock enable [--hello]"): the seed is sealed by your machine's security chip — TPM on Windows, Secure Enclave on Mac — with a key that cannot be exported. Copying the file to another computer gains an attacker nothing, because only that physical chip can unseal it. Add "--hello" and every unseal additionally demands your fingerprint or face. TIER 3 — NETWORK-ENFORCED CAPS ("automation set --per-tx 5 --daily 20 --allow id1,id2"): the previous tiers protect the key; this one protects you from your own script. Limits are enforced by the NETWORK, not by your code, so a runaway loop or a compromised script still cannot exceed them. IMPORTANT: your seed phrase always restores the wallet, so a dead TPM or a forgotten PIN is never lost funds — hardware sealing is at-rest hardening, never the root of custody.
CLI 4 of 5 — building an agent that runs your wallet
Because every command speaks JSON, a working agent is remarkably short. The loop is: poll "msg --list --json" for new messages, decide what to do, then act with "msg --to" or "send --to". That is genuinely the whole architecture — a reference implementation lives in the project at tools/cli_automation/, where a single decision function sits between reading and acting. Swap that one function for a call to an AI model and your wallet answers its own messages in your voice; leave it as simple rules and it is a predictable bot. Useful shapes: an auto-responder that replies while you sleep; a payment watcher that notices incoming SOV and confirms delivery; an OTC desk that quotes prices in the exchange chat and fills orders at terms you set; a monitor that reports your balance to your own dashboard. THE RULES THAT KEEP THIS SAFE: put a hard spend cap in the code AND in the network ("automation set"), so a bug cannot drain you. Keep an allow-list of recipients — never let the agent pay an address it learned from a message it just received, which is exactly how a prompt-injection attack would try to rob you. Never commit your PIN to source or paste it in a screenshot. Remember it polls rather than streams, so build for eventual consistency, not instant reaction. And understand that you are responsible for everything your automation signs, because to the network it is you.
CLI 5 of 5 — what the CLI deliberately cannot do
A tool is defined as much by its refusals as its features. THE CLI CANNOT ENROLL YOU. There is no headless account creation, and this is deliberate rather than unfinished: enrollment requires a live palm-and-face scan proving a real, unique human is present. If a script could enroll, one person could mint thousands of identities and one-human-one-wallet — the single idea SOV is built on — would collapse overnight. So the CLI only ever operates an identity that already exists, created by a human with a camera. THE CLI CANNOT READ OTHER PEOPLE'S MESSAGES. Message bodies stay end-to-end encrypted; the CLI decrypts only your side, using your key. THE CLI CANNOT FORGE A RELEASE, appoint itself an operator, or vote twice — every action carries your signature and is checked by the network exactly as the app's actions are. WHAT THIS MEANS FOR YOU: the CLI is a key-holder's tool, not a skeleton key. It makes an existing citizen faster; it cannot manufacture citizens. That boundary is why automation can be handed this much power safely — the scarce thing on SOV was never compute or code, it is verified personhood, and no amount of scripting creates more of it.
For developers: automate your wallet with the CLI (no SDK needed)
SOV ships no developer SDK — and does not need one. The desktop app, SovNode.exe, doubles as a headless command-line wallet that runs on your ALREADY-SIGNED wallet and speaks JSON, so any program (or an AI assistant) can do everything you do by hand. Run "SovNode.exe --cli --help" to see it: check balance ("--cli balance --json"), send SOV ("--cli send --to <sovereign-id> --amount 10"), read and send messages ("--cli msg --list --json" / "--cli msg --to <id> 'hello'"), pull history, and even drive the P2P Exchange ("--cli exchange orders|create|fill|confirm"). Every command takes "--json" for scripting and "--pin <code>" so it never has to stop and ask. That is a complete automation surface: a short script can WATCH your inbox for new messages, AUTO-REPLY (or hand each message to an AI that answers on your behalf), forward, report your balance, or auto-pay a trusted contact within limits you set. THE LIMITS ARE THE SECURITY MODEL, not a footnote. (1) Private PC only — the CLI signs as YOU using the key sealed in your operating system's credential store, so anyone who can run the exe on your machine can move your SOV; never on a shared or hosted box. (2) A signed or restored wallet is required — there is deliberately no headless enrollment, because enrollment needs a live palm-and-face scan (proof of personhood) that cannot be scripted; the CLI only operates an identity that already exists. (3) Keep your PIN out of source and out of screenshots. (4) It polls rather than streams, and message bodies stay end-to-end encrypted — the CLI decrypts only for your side. (5) You are responsible for anything your automation sends, which is why auto-transfer should always sit behind an allow-list and a hard spend cap. Used this way, a citizen can point a personal AI at their own wallet — replying to SOV Speak messages, watching for payments, running an OTC exchange desk — entirely from their own machine, with no company, server, or API key in the middle. A ready-to-run reference agent lives in the project at tools/cli_automation/.
Protocols — how the network works
Protocol: Why SOV has no usernames
SOV deliberately has no usernames, no @handles and no display names you can choose. That is a privacy decision, not a missing feature. The moment citizens can type their own name, some of them will type their REAL name — and a network that promised no personal data would be quietly leaking it, permanently and publicly. So the protocol never offers the field at all. Instead every citizen gets a nickname the network derives from their Sovereign ID: the same ID always produces the same nickname, on every device, with no lookup and nothing stored. It is generated on your own device, so it never travels anywhere and no server holds a name table. Your Sovereign ID remains the only network identity; the nickname exists purely so humans can recognise a contact at a glance instead of reading a 20-character string. Nobody can buy, squat, transfer or impersonate one, because nobody chooses one — including you.
Protocol: The Sealed-Launch Invariant (§905)
Once the network ships its first signed release, the code has NO special admin key — every privileged action must be authorised by a real biometrically enrolled citizen, approving it with their own on-device key and paying any fee from their own wallet. There is no admin token, no super-user key, no founder override, and no hidden "administrator" flag anywhere. Connecting a platform, creating a poll, filing a petition, opening a dispute, publishing an Academy article — all follow the same rule: the citizen approves the action on their own device (the private key never leaves it), the network confirms it really came from that enrolled citizen and is fresh (not a replay), takes any required fee, and performs it. This is why SOV cannot be centralised by anyone — not a founder, not an operator coalition, not a state: the only way to act for a citizen is to BE that citizen, holding their key.
Protocol: Petitions — the off-cadence governance path
A petition lets any enrolled citizen propose changing a governance parameter without waiting for a formal poll cycle. Fellow citizens SIGN it (one signature per citizen, enforced at the database layer). If signatures cross the supermajority threshold (default 67% of enrolled citizens) the change activates immediately — no poll needed. If they cross the lower threshold (default 33%) a normal governance poll is created automatically for the rest of the network to vote on. If neither threshold is met before expiry, the petition is rejected by silence. Petitions are the escape hatch alongside paced polls: a clear supermajority skips debate; a significant minority escalates to a vote; weak support simply lapses. Both thresholds are themselves citizen-tunable.
Protocol: How citizens govern every value (4-part contract)
Every value citizens can vote on follows a mandatory four-part contract so there are NO hidden hardcoded constants after launch: (1) the parameter is declared with its range, (2) seeded with a sensible default on first boot, (3) read from the governance table at runtime (never a baked-in number), and (4) given a pre-built poll in the app Constitution tab. There are dozens of such parameters today — poll durations, fee rates, jury sizes, retention windows, fee rates, and more — and the registry grows as new features land via the same contract. A critical rule: governance values are always read as strings and compared exactly (a binary protocol gate checks == "1"), because a number cast silently breaks the gate. If citizens should be able to vote on it, it must pass through all four parts — no exceptions. This is the §905 invariant made concrete: the way a feature is written determines whether citizens can adjust it.
Protocol: Network fees — small, capped, and paid to the people who run it
SOV charges small, citizen-voted fees on a few actions, and none of it goes to a founder or gets burned into nothing — every fee flows into the operator reward pool that funds the citizens hosting the network. THE TRANSFER FEE is a fraction of a percent of the amount you send (a current default set by vote), and it is CAPPED so no single transfer — however large — ever costs more than a small fixed ceiling. That makes SOV cheaper than Bitcoin at every size: sending a tiny amount costs a fraction of a cent, and a whale settlement is capped at the ceiling. THE EXCHANGE FEE is a small percentage of a completed trade. THE PLATFORM FEE is paid once a year by a business that wants to accept "Sign in with SOV" — ordinary citizens NEVER pay to log in anywhere. All three fee rates and the transfer cap are governance parameters: citizens can vote them up, down, or to zero. This is the SOV economy in one sentence — the cut a bank would keep is instead a citizen-set, capped contribution that circulates straight back to the people doing the work.
Protocol: Operator income — earning by keeping the network alive
Citizens who run relay nodes earn SOV for the real work of keeping the network running: witnessing transactions and staying online. A node must be CONTINUOUSLY up for a qualifying period (a current default of about three weeks) before it earns — sleeping or shutting the machine down breaks the streak, so payouts reward genuine uptime, not machines that are mostly off. Payment is a fixed reward per relay per month (governance-set), with a deliberately steep anti-monopoly curve: your first relay earns the full reward, a second and third earn a small fraction, and a fourth or beyond earns nothing but recognition — so running a farm of nodes gives you no advantage, keeping the network spread across many independent operators. Crucially, operators are paid FROM THE FEES that flow in first, and only then, capped, from the genesis reserve — so as the network grows and fees rise, it funds its own operators and the reserve becomes a long-term runway rather than a pot that drains. You can watch every fee flow into the pool and every payout leave it on the live SOV Economy screen — the ledger is public.
Protocol: How a new node is let in
Anyone may run a node, but no node lets itself in. When a new node first meets the network it announces itself, and the peers that hear it check three things against their own copy of the ledger: that the operator gave a Sovereign ID at all, that the ID belongs to a genuinely enrolled citizen, and that this citizen is not already running more nodes than the rules allow. A node offering no operator ID is refused outright. That is not bureaucracy — a network that accepts anonymous nodes can be flooded by one person running thousands of them, and every vote and every payout after that is meaningless.
The question is not put to the whole network. Asking every node would get slower each time the network grew, and it would also be weaker than it sounds: if any single node's approval were enough, one dishonest node could wave in anything it liked. Instead a small random sample of peers is asked, and a majority of that sample must agree. The cost of admitting a node stays the same whether the network has ten nodes or ten thousand, and an attacker has to control most of a group they cannot choose and cannot predict.
Checking costs the network nothing. Every node already holds the full enrollment ledger, so "is this a real citizen?" is answered on the spot, from local data, without asking anyone. How many peers are sampled and how many must agree are both citizen-governed values, so the network can tighten or loosen its own front door by vote as it grows.
Protocol: One human, one identity — the face lock
SOV guarantees one account per living person, and it now enforces that across BOTH hands. Your palm is your key, and for accessibility you may enroll with either hand — but a single person could otherwise try to register their left palm as one identity and their right as another, because two palms of the same person look unrelated to a palm scanner. The face lock closes that gap. During the liveness check the app already looks at your face; from that it computes a private mathematical fingerprint (never a photo, and it cannot be turned back into your face) and the network checks it against everyone already enrolled. If your face already has an identity, a second enrollment is refused — you are told to recover your existing wallet instead. The check happens on the network side, so it cannot be skipped by a modified app. Identical twins are the one natural limit every face system shares. This is what keeps one-human-one-vote and one-human-one-wallet true, no matter which hand you scan.
Protocol: The Exchange — turning your SOV into real value
SOV gets its exchange value the honest way: person to person, with no company setting the price. On the Exchange a citizen who wants cash LISTS some of their SOV for sale and states how they take payment (bank transfer, mobile money, whatever they choose). The moment they list, that SOV is locked in escrow on the network — it cannot be spent or double-sold. A buyer browses the open listings, opens a private negotiation chat with the seller RIGHT ON THE LISTING — you do not have to commit first, you can ask "what price per SOV?" before anything — and the two agree a number. Offers ride inside the chat as tappable cards: the seller sends an offer, the buyer taps Accept, and a "Fill at agreed terms" button appears. The buyer pays the agreed money OFF the platform (SOV never touches a bank), and when the seller confirms the money arrived, the network releases the escrowed SOV to the buyer, minus a small citizen-voted exchange fee that goes to the operator pool. Every listing, trade and fee is public on the SOV Economy screen. Because citizens set their own prices with no middleman, free price discovery is exactly how SOV earns a real, market-set value.
Protocol: One truth on every node — how the mesh heals itself
SOV has no central server, yet every node — whether it is a data-centre relay or a laptop at home — must show you the SAME balances, the same messages, the same votes, the same everything. It stays that way through a quiet background process called anti-entropy. Every node keeps a tiny fingerprint of its own copy of the shared state and gossips that fingerprint to its neighbours a few times a minute. If two neighbours' fingerprints differ, the one that is behind simply asks the other for the missing pieces and folds them in — balances by "newest wins", and records like guardians, trades, group messages and platform registrations by "keep everything, never lose a fact". So if your node was switched off for a week, or a home node was unreachable during a storm, the instant it comes back it catches up automatically — no operator action, no re-sync button, no central authority to ask. It also watches its own links: if a connection to a peer goes silently dead, the node notices the silence, drops the dead link and reconnects — which is why the network keeps converging even as nodes come and go. This is what lets SOV be a million independent nodes that all see, hear and speak one truth: not because a company keeps them in line, but because the protocol reconciles itself, forever, with nobody watching.
SOV NETWORK