Data Sovereignty, Authority, and Capability
Policy brief
Core proposition
Data sovereignty is credible when legitimate authority and practical capability align.
A community may have a valid claim over records concerning its people, language, lands, services, or institutions but lack the infrastructure or leverage to exercise it. An operator may control servers, keys, and software without a legitimate mandate to decide how the data is used. Neither condition is sufficient.
The World Economic Forum's 2026 briefing paper Data Sovereignty in Practice offers a useful diagnostic: sovereignty is not a binary status and cannot be reduced to where data is stored. It depends on enforceable rights, technical control, accountable governance, institutional capability, and a realistic ability to audit, recover, and exit.
Mainstay supports those capabilities. It does not confer sovereignty, jurisdiction, or legitimacy by installation.
Beyond data localization
Keeping data within a community or country can serve privacy, continuity, cultural, legal, or security objectives. Location alone does not answer:
- who controls encryption keys and administrator access;
- who can update or discontinue the software;
- what happens when data is transferred or processed;
- whether data can be used for analytics or model training;
- who can inspect audit logs and investigate misuse;
- whether identities, records, and services can move to another provider; or
- what correction, appeal, and redress are available.
Data must be considered at rest, in motion, and in use. Local storage can still depend on remote compute, vendor-controlled mobile platforms, opaque subcontractors, or update channels the local operator cannot govern.
Sovereignty is therefore a capacity exercised across the stack, not a label attached to one server or jurisdiction.
Authority and capability
The paper distinguishes four conditions:
| Authority | Capability | Meaning |
|---|---|---|
| High | High | Legitimate decisions can be carried into practice |
| High | Low | Rights exist but may be difficult to exercise or enforce |
| Low | High | Technical control exists without a legitimate mandate |
| Low | Low | Little practical sovereignty is present |
This distinction is central to Mainstay. The software can preserve signatures, records, policies, keys, Mint Notes, routes, and evidence. It cannot decide who rightfully speaks for a community, whether an issuer's promise is legitimate, or whether another institution must recognize a record.
The responsible community or institution supplies authority. Mainstay helps make the corresponding capability local, portable, inspectable, and recoverable.
Sovereignty is layered
Different actors hold different interests:
- individuals assert privacy, dignity, consent, access, and redress;
- communities assert cultural integrity, collective benefit, and stewardship;
- institutions need continuity, compliance, and operational control;
- governments exercise jurisdiction and public responsibilities;
- regional partners pool capacity and bargaining power; and
- technology platforms exercise practical power through infrastructure, access conditions, models, APIs, and standards.
Community governance does not erase individual rights. State jurisdiction does not automatically create operational capability. Platform capability does not create public authority. Good governance identifies the relevant claims and fits decisions to the data, purpose, community, and law involved.
Mainstay's neutral architecture supports this separation. It does not prescribe one governing body or collapse every role into a platform administrator.
Trusted interdependence
Sovereignty does not require complete technological self-sufficiency. Smaller communities and institutions benefit from shared infrastructure, outside expertise, hosted services, and cross-border cooperation.
The practical question is whether authority and capability survive the relationship. A trusted partnership preserves:
- transparent responsibilities and dependencies;
- control of consequential keys and policies;
- auditable access and processing;
- agreed limits on use and onward transfer;
- fair allocation of benefit and risk;
- continuity when one participant is unavailable; and
- a workable, proportionate route to exit.
Mainstay calls this cooperative independence: a dependable local home from which communities can work with wider systems on clearer terms.
What Mainstay contributes
Mainstay coordinates components with distinct responsibilities:
- Acorn provides portable keys, authority, records, and wallet custody;
- Grove stores encrypted, content-addressed artifacts;
- Spurline preserves and transports signed events;
- Stroma provides narrow signing, encryption, and event protocols;
- OpenETR separates exact Digital Artifacts, signed evidence, Consequential State, and recognition;
- Clear supports bounded, issuer-defined exchange without becoming sovereign currency or compelling acceptance; and
- Mainstay coordinates installation, routes, health, recovery, and local user experience without becoming the underlying government, archive, mint, or source of authority.
These boundaries support sovereignty because no application needs to become the permanent owner of every identity, record, route, and decision.
The right to exit must be practical
Portability is meaningful only when it has been tested. An operator should be able to:
- export data in usable and documented formats;
- retain stable identities while routes and hosts change;
- rotate encryption and signing keys under a governed procedure;
- restore the same records, obligations, and service identities;
- replace storage, relays, applications, and providers without rebuilding the entire system; and
- verify that an outgoing provider no longer retains unauthorized control.
Open protocols and source code help, but they transfer responsibility to the adopter. A community that cannot patch, monitor, recover, or integrate an open stack may have theoretical freedom and little practical capability.
Avoiding sovereignty-washing
Mainstay should apply the paper's warning about sovereignty in name only to its own product language.
Claims such as local-first, private, portable, community-governed, and resilient require evidence. Operators and participants should be able to ask:
- Who has legitimate authority, and how can that authority be reviewed or revoked?
- Who controls keys, privileged access, updates, logs, backups, and routes?
- Which external providers and subcontractors can access or affect the system?
- Can access, processing, issuance, recognition, and transfer events be independently verified?
- What happens to exported, derived, or model-training data?
- Can a provider or component be replaced without unreasonable assistance or loss?
- What remedies exist when a person or community disputes a decision?
- Has continuity been tested under outages, compromised keys, and hostile or mistaken administrative changes?
A dashboard reporting healthy containers does not answer these questions. Technical health, current authority, policy validity, and governance fitness are different states.
Proportionate sovereignty
Full localization carries costs. Separate infrastructure needs skilled staff, security maintenance, sufficient capacity, incident response, and sustainable funding. Shared infrastructure can provide quality, scale, and resilience that a small deployment cannot reproduce.
The aim is not maximum control for its own sake. A community should place and govern each capability according to the consequence of failure, applicable rights, cultural importance, continuity need, and available operational capacity.
Some keys, policies, records, or approval functions may require a strong local boundary. Other services may be safely hosted or shared when contracts, architecture, audit, and exit preserve meaningful choice.
Policy implications
A community or institution evaluating Mainstay should:
- document the legitimate authority behind each consequential role;
- map the full control set, including keys, infrastructure, updates, logs, providers, and recovery material;
- identify individual, collective, institutional, and external legal claims;
- govern data at rest, in motion, and in use;
- require purpose, provenance, onward-transfer, and benefit rules where data is shared;
- test export, recovery, key rotation, and component replacement;
- maintain accessible complaint, correction, appeal, and redress procedures;
- invest in operator skill, maintenance, security, and succession;
- stress-test geopolitical disruption, vendor outage, compromised authority, and administrative change; and
- describe sovereignty no more broadly than the evidence supports.
Conclusion
Data Sovereignty in Practice supports Mainstay's local-first direction while rejecting its easiest possible marketing claim. Mainstay is not sovereignty in a box.
It is a set of coordinated capabilities that can help a legitimate community or institution exercise greater agency over records, identity, exchange, storage, communications, and continuity. Its value lies in keeping authority visible, important state portable, dependencies governable, and collaboration reversible.
Sovereignty emerges from the combination of mandate, capability, evidence, accountability, and choice. Mainstay can support that combination, but every deployment must prove it in practice.
The detailed analysis note examines the paper's framework, operating models, sovereignty-washing test, and specific implications for Mainstay.