Cross-border & Sovereignty
Jurisdiction disclosure when data is processed
Where the data is processed and whose law can reach it are stated at the submit step, not buried in a privacy policy.
Review and submit your application
Housing transfer · 14 fields completed. Nothing is sent until you submit.
If any part changes (a new processor, an offshore backup) the badge changes with it, at the same spot, before the next submission. The privacy policy elaborates; it does not substitute.
Data-sovereignty tiers for sensitive interactions
The surface leads with a plain verdict that the protection already matches the task, and keeps whose law can compel the data as a detail the user can open.
General feedback. Standard protection applies to your feedback. General feedback reveals little about you. A standard assistant is suitable. Protection for this task: Standard.
AI system transparency registers
At the point of use, one line names the system, where it is hosted, and the public register entry that describes it.
The chip appears wherever the system operates rather than on a separate transparency page, and it resolves to the register record instead of restating it, so the disclosure cannot drift from the entry it points at.
Cross-border data transfer as a design obligation
The legal basis for sending data abroad is resolved before the submit step and reported as a plain assurance that one exists.
Your referral goes to a clinic in Ireland under a legally binding data agreement, checked 15 Jul, 09:41 and current until 2028.
check_transfer_basis(
destination: "EU (processor, Dublin)",
data_class: "health-adjacent"
)
→ {
basis: "standard contractual clauses",
status: "valid",
renewed: "2026-02-11",
expires: "2028-02-11"
}Sector-specific data residency
A sector's residency rule becomes a routing constraint the user never has to think about, stated back to them as a plain assurance.
Processed within Australia, in accordance with the My Health Records Act.
One plain sentence tells the user where the task happened. They don’t need to know the statute to know the protection applied.
The system follows the law as a hard rule. The assurance line is generated from this logic.
Sovereign AI model selection and disclosure
A provenance label names who built the model, where it was trained and hosted, and whose law governs it.
A contested decision eventually asks four things: which system decided, who built it, where it ran, and under whose law. The label answers them at the moment of use, not later in discovery.
Concentration-risk and supply-chain disclosure
A per-layer card shows where each part of the stack sits and whose jurisdiction it answers to.
Model, hosting, and orchestration all trace back to Coretide or its parent. One legal or commercial event abroad would affect all three layers at once. Recorded mitigations: a portable model contract, and an onshore fallback for orchestration now under test.
Built from the same supply-chain mapping a software bill of materials starts from, and extended from components to jurisdictions. A querying agent receives the summary counts; the per-vendor map is released only to authenticated oversight bodies.
An unmapped dependency cannot be debated, priced, or replaced. The manifest lists every layer, so each one can be.
Context-triggered disclosure
Disclosure scales with how sensitive the data is, reaching the user only when the sensitivity and the infrastructure do not match.
Your details are complete. Renew for 12 months.
The checkpoint ran. Routine data on standard infrastructure is a match, so it resolves to a single line, without interruption.
Every escalation is also logged for the service team. A mismatch that reaches one user is a routing gap to fix for everyone.
No surfaces match this filter.