Α

AEGIS

Soteria device protection

Aegis Charter

Version 1.0 · Adopted 2026-05-18, Year 2 of the Root, Fluen, Fidelis 4 · canonical source

This charter describes what Aegis is, what it is not, who consents to its protection, and what holds it accountable. It is binding on every Aegis instance hosted under the Soteria Covenant Trust and is the reference for any third-party evaluation of the protocol.

1. Purpose

Aegis is the Soteria Covenant Trust's theft-recovery infrastructure for property already on a trust schedule and for personal devices belonging to individual members who voluntarily register them.

It is not surveillance infrastructure. It is not a parental control tool. It is not law-enforcement tooling. It is not for tracking other people. It is not for tracking other people's devices. It is not for tracking unconsented hardware. The protocol enforces this at every layer.

2. Consent — the first invariant

Every device protected by Aegis is owner-registered. The owner-of-record walks through a registration flow, generates a per-device Ed25519 keypair on the engine, receives the private key once, and installs that key on the device themselves.

There is no method by which a third party can attach Aegis protection to a device they do not own. There is no fleet-enrollment tool. There is no MDM push. There is no silent install. For trust-owned devices there is an additional gate: the property must already exist in Blueprint, custodied by a Trustee at Membership tier ≥ 2.

3. The audit trail — the second invariant

Every Aegis act produces three independent records:

Every recovery act Aegis ever performs is independently verifiable after the fact, by anyone shown the ledger, without needing to trust Aegis or Soteria.

4. Governance

TierRoleAegis capability
0BeneficiaryRegister personal devices; flag own; view own trail
1Junior Trustee+ Review own trust's protected fleet
2Administrator+ Register trust devices against custodied Blueprint properties
3Senior Trustee+ Cross-trust device review
4Steward+ Emergency override (ledgered as a steward act)

5. Scope limits

6. Pre-OS workstreams (UEFI / initramfs / BLE)

The v0.3 roadmap extends beacon coverage to layers above the OS — initramfs (pre-LUKS), UEFI firmware (pre-bootloader), and BLE radio broadcast for proximity detection. These are powerful capabilities; they require restating the consent invariant:

7. Open-source commitment

Aegis is released under the GNU Affero General Public License version 3.0 (AGPL-3.0). The AGPL's network-clause requires that anyone hosting an Aegis instance as a service for others must publish their fork's source code. This is a deliberate choice: theft-recovery infrastructure, of all things, should be auditable end-to-end.

8. Standing offer

Suspected misuse of an Aegis instance — unconsented protection, missing audit trail, steward override outside its emergency role — should be reported to [email protected]. Reports are reviewed by the Trustee body. Substantiated misuse triggers an audit of the affected instance's ledger and, where applicable, a public disclosure.

Full charter text including misuse mitigations, cryptographic posture, and amendment procedure: CHARTER.md