{"generated":"2026-09-03T16:08:59.097450+00:00","components":[{"component":"FPGA","name":"FPGA-over-PCIe accelerator","visibility":"PRIVATE","driver":"fpga_pcie","function":"Hardware-accelerated EVA inference and cryptographic offload.","controls":["self-test","bind/unbind"],"production":"real PCIe device; emulated in this deployment"},{"component":"HSM","name":"Hardware Security Module (PKCS#11)","visibility":"PRIVATE","driver":"hsm_pkcs11","function":"Dual-custody signing of the audit Merkle root — the private key never leaves the HSM.","controls":["self-test","sign root"],"production":"real PKCS#11 HSM; emulated in this deployment"},{"component":"TPM","name":"Trusted Platform Module","visibility":"PRIVATE","driver":"tpm","function":"Measured boot and platform attestation for tamper-evidence.","controls":["attest","self-test"],"production":"real TPM; emulated in this deployment"},{"component":"NIC","name":"Sovereignty-inspection NIC","visibility":"PRIVATE","driver":"nic_inspect","function":"Inspects BGP / traceroute / DNSSEC to verify data-path sovereignty — feeds the SVS.","controls":["self-test","path scan"],"production":"real NIC; emulated in this deployment"},{"component":"Cassandra-WORM","name":"Cassandra WORM nodes","visibility":"INTERNAL","driver":"cassandra","function":"Write-once, Merkle-linked audit storage — the immutable evidence chain.","controls":["health","verify chain"],"production":"clustered WORM nodes in production"}],"self_test":"hw-bringup/selftest/udoc_selftest.py","note":"Sovereignty hardware is emulated in this deployment; real PCIe / PKCS#11 / TPM in production."}