Here is what we can show about how the identity core works, and why each property matters — without exposing the parts that would help someone attack it. The mechanism is the physics of the chip; the outcome is proof you can hand to anyone.
Identity is never issued or stored — it is derived from the silicon the moment it's needed, then carried into a signed record and re-proven for the life of the machine.
The physical machine is bound to its operator, facility, and jurisdiction — establishing authorization by the owner's own policy.
Authenticity is established from a physical property of the silicon — expressed only at the moment it's needed, never at rest.
Keys, models, and data are released only after the machine proves it is the approved one — model provenance, bound and unmodified.
The run produces a portable record — node, model, policy, result — cryptographically signed and anchored in the hardware identity.
The same machine is re-proven tomorrow, next quarter, and across every job — a continuous chain of accountability.Lifecycle-long, not a one-time check
Most digital identity is data — copyable, extractable, replayable. UBIQS roots identity in something that exists because of how the chip was made, not written in afterward. There is no master key in memory or flash. Nothing is stored to steal.
No per-device secret is held by whoever is checking, and no enrollment record has to exist anywhere in advance. A device can prove it's real the moment it's built, without either side trusting a stored value.
Conventional identity depends on a certificate authority that generates a key and vouches for it. UBIQS has no issuing event and no assignment step — authenticity is established by verifying the device's own physical identity, with no third party to trust or compromise.
Firmware exploits, credential theft, and supply-chain compromise live in the software and firmware layer, because that's where identity has always lived. UBIQS moves the root of trust off that plane — a compromised OS, app, or firmware has nothing stored there to take.
An invasive attempt to probe the identity-deriving structure disturbs the very property being read — it corrupts what it's trying to steal. There's no clean extraction path, only a failed one. That's what makes the identity unclonable: not hardened against copying, but structurally unavailable to copy.
Because authenticity comes from the physics of the specific device, a cloned credential, a swapped node, or a counterfeit part can't pass as the enrolled machine. Genuineness is proven, not assumed — the basis for anti-substitution and counterfeit detection.
On a persistent, silicon-rooted identity, UBIQS builds the layer sovereign AI actually needs.
The node's identity bound to operator, facility, and jurisdiction, so authorization is provable, not asserted.
The identity of the model that actually ran — which model, which version, unmodified — bound into the record.
Keys, models, and data released only after the physical machine proves it is the approved one.
A portable record connecting node, runtime, model, and policy to the result — any later alteration detectable.
Enrollment, re-verification, and controlled retirement — identity that's durable, not a one-time check.
A trust root and receipt format not owned solely by a single hardware vendor or cloud operator.
A trusted execution environment answers "is this workload isolated and measured?" UBIQS answers "which enrolled physical machine is accountable for it, under whose authority, and can that be proven again tomorrow?" UBIQS consumes and binds a TEE's evidence into its own persistent node identity and signed receipt — rather than leaving it as a point-in-time platform assertion.
Others protect the workload. UBIQS proves the machine — and holds the evidence.
The specific physical mechanism behind identity derivation isn't published here — for the same reason a lock manufacturer doesn't publish the exact tolerances of its pins. The properties on this page are what matter for evaluating the system; the implementation details are exactly what would help someone attack it.
What's on this page is what we stand behind publicly — property-level claims. Deeper technical review, including the underlying mechanisms and validation data, is available under NDA for design partners and investors.
Design partners and investors can request access to the full architecture and validation data under NDA.