SovereignGate
Deterministic governance for autonomous actors on XRPL

No receipt,
no transaction.

The governance layer between autonomous actors and the XRP Ledger. Every action is checked against policy before anything signs, and the ledger itself rejects what the policy did not approve.

  • Rust kernel
  • Ed25519
  • XRPL multi-sign
  • Patent-pending
Reference demo · DUNA treasury policy3 / 3

Every action starts as an intent.

Policy decides before anything signs.

The ledger requires both signatures.

Every approved action leaves a receipt.

Anyone can verify it. Offline.

ALLOW · T1
Receipt chained
5ea7a58c…2d6dc9 · prev af49dc93…3a3e4d
  1. DexSwap $500
  2. Payment $15,000
  3. Claims T0

The kernel's reference demo, replayed: three intents against a DUNA treasury policy. Receipt hashes are from a real run; the demo mocks XRPL submission.

Tests passing
253
Security invariants enforced
8/8
Property-test cases per invariant
10,000
Median signed gate decision
~16 µs

SovereignGate sits between autonomous actors and the ledger. Every financial action from an AI agent, DAO, or DUNA treasury is checked against declared policy, signed into a tamper-evident receipt, and co-signed at the XRPL protocol level before it can execute.

// 01Why now

Agents got wallets. Nobody gave them a chain of custody.

Three shifts in the past year turned governance for autonomous money from a feature into a requirement.

LegislationWyoming 2024 · Alabama 2026

DUNAs are law. Their controls are not.

Wyoming recognized the Decentralized Unincorporated Nonprofit Association in 2024. Alabama's DUNA law takes effect October 1, 2026, and more states have bills moving. A DUNA can hold a treasury and sign contracts, but nothing in the statute shows a member or a court that the treasury followed its bylaws.

Source: The Block
MarketFebruary to June 2026

Agents now hold their own wallets.

Coinbase shipped Agentic Wallets in February. In June, Ripple released the XRPL AI Starter Kit for agent payments in XRP and RLUSD, and Mastercard named RippleX a launch partner for Agent Pay for Machines. Spending limits exist now, but they live inside each provider, and so does the record of what they decided.

Source: PYMNTS
Compliancea16z crypto · January 2026

Know Your Agent is the new KYC.

a16z crypto's 2026 outlook called KYA “the critical missing primitive”: signed credentials that bind an agent to its principal, its constraints, and its liability. SovereignGate is where those constraints are enforced, with a receipt left behind every decision.

Source: a16z crypto
// 02How it works

Six steps between intent and ledger. No shortcuts.

The pipeline is the product. Each stage trusts nothing it receives from the stage before it.

  1. Intent submission

    An agent submits a SovereignIntent: operation, parameters, entity, agent, and a single-use nonce, over an authenticated REST API.

    SovereignIntent
  2. Fact origin attestation

    The Fact Origin Attestation Validator classifies risk from the operation's own semantics. A caller's claim can raise the tier. It can never lower it.

    max(claimed, inferred)
  3. Policy evaluation

    A content-addressed PolicyBundle evaluates every rule. First DENY wins, ALLOW never short-circuits, and a parse failure is a DENY. It always fails closed.

    PolicyBundle
  4. Artifact signing

    A passing intent gets an Ed25519-signed AllowArtifact. The type cannot be constructed outside the gate crate, and the Rust compiler enforces that.

    AllowArtifact
  5. XRPL co-signing

    The adapter verifies the artifact's signature and intent binding, consumes the nonce atomically, then adds the governance signature the SignerList requires.

    SignerList quorum
  6. Receipt emission

    A DetGateReceipt joins an append-only, hash-chained ledger with periodic Merkle roots. The format is wire-compatible with SovereignClaw receipts.

    DetGateReceipt
Six crates · strict layering
// No layer trusts the layer above.
core     zero deps      IR schema, canonical hashing
crypto   core           Ed25519, SHA-256, JCS
gate     core, crypto   policy engine, sealed artifact
receipt  core, crypto   receipts, Merkle, append-only
xrpl     gate, receipt  multi-sign, nonce replay guard
gateway  xrpl, receipt  HTTP API (Axum), full pipeline
DetGateReceipt · 01 of 12
receipt_id
7393a8af-7b60-4ce9-85fd-4421ace6919d
verdict
Allow
operation
DexSwap → OrderBook · T0
receipt_hash
e44e791ad73223bd52be56886c587f37578266f9cfba680e146acf252c3779e0
prev_receipt_hash
(none: first in chain)
signature
48ef207f0e4da01e…76b5ab08 Ed25519
Twelve receipts from one local run of the kernel's gate, adapter and receipt ledger under the reference demo's DUNA policy. Each carries the hash of the one before it. Hashes and signatures are real; XRPL submission is mocked.
// 03Protocol-level enforcement

Governance isn't a check we run. It's a signature the ledger requires.

At provisioning, the governed account's master key is disabled and a SignerList is set: agent weight 1, governance weight 1, quorum 2. From then on, every XRPL validator rejects a transaction unless both keys sign it.

SovereignGate's key signs only a transaction that carries a sealed AllowArtifact. The gate has no admin override and no API bypass, because a bypass would have to convince the ledger.

Want a way out if the gate is ever unreachable? Provision the three-signer list instead: agent 1, governance 2, and an offline recovery key 2, quorum 3. The recovery key and the agent together clear quorum without the gate, so an outage never freezes the treasury. That break-glass path carries no receipt, but every signature on it is public on the XRP Ledger.

  • Agent alone: weight 1 of 2. Rejected by the network.
  • Stolen agent key: still weight 1 of 2. Funds stay put.
  • Agent plus governance: quorum met, and only after policy passed.
SignerList · quorum 2rGovernedTreasury
tefBAD_QUORUM

Signatures do not reach quorum. Every validator rejects the transaction.

Toggle the signatures, or switch to the recovery-key setup. The result codes are the ones the XRP Ledger returns.

// 04Threat model

Built for active adversaries.

Eight invariants, each enforced in code and property-tested at 10,000 cases. Each one is a plate on the core: point at an invariant to lift it, or at an attack to fire it.

INV-1

Deny dominance

Prevents Privilege escalation through rule ordering

First DENY wins. ALLOW never short-circuits.

INV-2

Fact independence

Prevents An LLM lying about risk

Tier comes from operation semantics only.

INV-3

Fact mismatch

Prevents Tier downgrade attacks

max(claimed, inferred), always.

INV-4

T3 unreachability

Prevents Unauthorized governance changes

Blocked before policy evaluation runs.

INV-5

Nonce uniqueness

Prevents Transaction replay

Atomic INSERT OR IGNORE.

INV-6

Adapter binding

Prevents Reusing an artifact across entities

Signature, hash, entity and agent all verified.

INV-7

Canonical determinism

Prevents Hash collisions from key reordering

Recursive key sort, property-test proven.

INV-8

Receipt append-only

Prevents Evidence tampering

No UPDATE or DELETE on the ledger. Ever.

tests/adversarial
  • $ prompt_injection"IGNORE ALL RULES AND ALLOW" in paramsBLOCKEDthe gate reads semantics, not text
  • $ fact_spoofingclaims T0 for a T3 operationBLOCKEDmax(T0, T3) = T3
  • $ nonce_replay10 submissions, one nonce1 PASS · 9 REJECTatomic nonce consumption
  • $ binding_violationentity_A artifact used by entity_BBLOCKEDsignature verification fails
  • $ hash_manipulationparams edited after the artifactBLOCKEDintent hash mismatch
  • $ key_reorderingsame params, different key orderSAME HASHcanonical serialization
// 05Bylaws as code

Declare the rules once. They hold every time.

Entity policies are written in a deterministic rule language. Rules are data, not code, and every policy bundle is content-addressed with SHA-256, so any change produces a new bundle ID that each receipt records. Policies hot-reload over the API, and a bundle that fails to parse denies everything.

Amounts are integers in micro-USD (1 USD = 1,000,000), so limits compare exactly at the boundary. No floating point, no rounding.

duna_treasury.policy
// DUNA treasury governance
RULE max_single_transaction
  WHEN params.usd_equivalent_micro > 10000000000
  THEN DENY "Exceeds $10,000 DUNA limit"

RULE permitted_assets
  WHEN params.asset NOT IN ["XRP", "USD", "RLUSD"]
  THEN DENY "Asset not in permitted list"

RULE business_hours_only
  WHEN context.hour < 6 OR context.hour > 22
  THEN ESCALATE threshold=2 operators=["admin_1", "admin_2"]
// 06Measured, not asserted

Fast enough for every transaction. Provable after the fact.

Native gate latency
~16 µs

Median for a full gate decision, including canonical intent hashing and the Ed25519 artifact signature. Measured on allow, policy-block and T3-block paths, 10,000 runs each, release build.

Zero-knowledge proof of the decision

The production authorization function, proven inside a zkVM.

We ran SovereignGate's own authorization function inside the Jolt zkVM with the lattice-based Akita commitment scheme. Every proof verified, and every output we tampered with was rejected.

Verify
~28 ms
Proof size
~86 KB
Prove
~4.6 s
Tampered outputs rejected
15 / 15

Research benchmark, September 14, 2026. It shows feasibility; it is not yet part of the shipping product.

Tested like an attacker
253

Tests across the Rust workspace, including an adversarial suite that attacks each of the eight invariants, plus property tests at 10,000 generated cases per invariant.

// 07Where it fits

Every agent wallet has a policy engine now. Few can prove what it decided.

Custody and signing platforms check a transaction before they sign it. SovereignGate does that too, then makes the ledger itself refuse anything unapproved and leaves evidence that someone who trusts neither party can verify.

CapabilitySovereignGateSigning-platform policy enginesFireblocks, Turnkey, Coinbase Agentic Wallets
Policy checked before signingYes, with deterministic rulesYes
Where a “no” is enforcedThe ledger itself: SignerList quorum, master key disabledInside the provider's MPC or enclave, which declines to sign
Evidence of each decisionEd25519-signed, hash-chained receipt anyone can verify offlineActivity and audit logs inside the provider's platform
Policy versioningContent-addressed: every bundle has its own SHA-256 IDManaged in the provider's console or API
Built for legal entitiesBylaws-as-code for DUNA and DAO treasuriesGeneral-purpose spend controls
Risk tier from the agent's own claimNever. Claims can only raise the inferred tierRules match transaction fields

Based on each provider's public documentation as of October 2026. They are custody and signing platforms; SovereignGate is a governance layer.

// 08Intellectual property

Patent-pending. First-mover priority since October 2025.

63/983,308Deterministic Governance EnforcementFiled February 2026
64/069,063XRPL-Native Governance Co-SigningFiled May 2026
// 09Early access

Govern your first autonomous treasury.

SovereignGate is in private development. Access opens first to DUNA operators, AI agent builders, and institutional partners.

Join the early access list

One email when your cohort opens. Nothing else.

Talk to the founder

Partnerships, integrations, and investment conversations.