<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Proof, not promises]]></title><description><![CDATA[Proof, not promises]]></description><link>https://proofnotpromises.hashnode.dev</link><image><url>https://cdn.hashnode.com/res/hashnode/image/upload/v1593680282896/kNC7E8IR4.png</url><title>Proof, not promises</title><link>https://proofnotpromises.hashnode.dev</link></image><generator>RSS for Node</generator><lastBuildDate>Sat, 19 Sep 2026 02:08:45 GMT</lastBuildDate><atom:link href="https://proofnotpromises.hashnode.dev/rss.xml" rel="self" type="application/rss+xml"/><language><![CDATA[en]]></language><ttl>60</ttl><item><title><![CDATA[Residency Is Not Sovereignty]]></title><description><![CDATA[Residency answers only one question
Where is the server?
That matters, but it is not sovereignty. A workload can sit inside a national boundary while the control plane, keys, operators, legal exposure]]></description><link>https://proofnotpromises.hashnode.dev/residency-is-not-sovereignty</link><guid isPermaLink="true">https://proofnotpromises.hashnode.dev/residency-is-not-sovereignty</guid><dc:creator><![CDATA[indiainfranotes]]></dc:creator><pubDate>Wed, 16 Sep 2026 18:35:17 GMT</pubDate><content:encoded><![CDATA[<h2>Residency answers only one question</h2>
<p>Where is the server?</p>
<p>That matters, but it is not sovereignty. A workload can sit inside a national boundary while the control plane, keys, operators, legal exposure, and failure policy live elsewhere. The map may look local while the decision rights remain remote.</p>
<p>Sovereignty is a chain of control:</p>
<ul>
<li>who can inspect or move the data</li>
<li>who can rotate or revoke the keys</li>
<li>who can change the service policy</li>
<li>who can compel access</li>
<li>who can keep the system running when a foreign dependency disappears</li>
</ul>
<p>Residency is a location property. Sovereignty is a control property.</p>
<p>This distinction is easy to lose in procurement. A region label becomes a proxy for autonomy. A local facility becomes a proxy for jurisdictional independence. Neither is enough. If the administrative account, encryption root, software update path, or support escalation can be exercised outside the intended jurisdiction, the system still has an external control surface.</p>
<p>The practical test is not "where is the data today?" It is "who can change the outcome tomorrow?"</p>
<p>That suggests a better architecture review. Trace every authority, not just every packet: identity, keys, orchestration, audit, upgrades, backups, and shutdown. Then test the system with one dependency unavailable. A sovereign design should degrade predictably and preserve evidence.</p>
<p>A useful companion white paper is <a href="https://proof-not-promises.indiainfranotes.workers.dev/">Proof, not promises</a>. Its core idea is simple: make claims about infrastructure verifiable through evidence, not branding.</p>
<p>Residency is a boundary on placement. Sovereignty is the ability to decide, prove, and continue. Treating them as synonyms is how control gets outsourced by accident.</p>
]]></content:encoded></item><item><title><![CDATA[Proof, not promises]]></title><description><![CDATA[The short version
The Platform serves. The Ledger records.
This white paper sketches sovereign, verifiable digital infrastructure for India: a platform for applications, plus a permissioned consortium]]></description><link>https://proofnotpromises.hashnode.dev/proof-not-promises</link><guid isPermaLink="true">https://proofnotpromises.hashnode.dev/proof-not-promises</guid><dc:creator><![CDATA[indiainfranotes]]></dc:creator><pubDate>Wed, 16 Sep 2026 16:31:31 GMT</pubDate><content:encoded><![CDATA[<h2>The short version</h2>
<p><strong>The Platform serves. The Ledger records.</strong></p>
<p>This white paper sketches sovereign, verifiable digital infrastructure for India: a platform for applications, plus a permissioned consortium ledger that creates independent evidence about what happened.</p>
<p>No token. No speculative coin. Services are billed in rupees. The ledger uses authorised accounts and resource limits instead of a native currency.</p>
<h2>Two layers</h2>
<p><strong>The Platform serves:</strong> Run code in any language or container, with databases, storage, delivery, DNS, functions, identity, security, and GPU compute. Usage is metered in published units, with billing that can be checked.</p>
<p><strong>The Ledger records:</strong> Verified consortium members run it under a governance charter. It stores compact evidence—not application data—including anchors, deployment manifests, usage receipts, access grants, and governance outcomes.</p>
<p>A verifier can hash a record, follow its Merkle proof, fetch the finalised anchor, check sequence links, and validate signer keys. If it checks out, the record existed in that exact form. The platform operator has no magic override.</p>
<h2>Finality, privacy, and the honest bit</h2>
<p>Validators use Byzantine fault-tolerant finality. More than two-thirds must be honest for safety; when the network gets messy, the system prefers pausing safely over pretending a disputed record is final. Governance changes are explicit and human-decided.</p>
<p>Personal data stays off-ledger, so correction and erasure remain possible. Hybrid signatures pair Ed25519 with ML-DSA-65.</p>
<p>This is a design, not a victory lap. It needs diverse operators, real audits, and governance that works under pressure. Verifiability is not a vibe; it is a chain of checks.</p>
<p><strong><a href="https://proof-not-promises.indiainfranotes.workers.dev/">Read the full preview: Proof, not promises</a></strong></p>
]]></content:encoded></item></channel></rss>