Skip to content
Concept of record Not a commitment Rev. 0.2 — 29 Aug 2026

Nobody should have to destroy a working computer.

Companies retire hardware that is still excellent. Sovereign Circuit takes it in, sanitizes it to a published standard, proves the wipe, matches it to a real workload, and places it running the full sovereign stack — on a subscription, not a purchase.

The customer never buys a box. They subscribe to a protected system that is always present, always inside the security envelope, swapped same-or-better on failure, and upgraded on schedule. Every valuation in the loop is settled by two independent, sealed assessments — so neither side can be taken advantage of.
4 sides
Supply, rebuild, placement, return — a closed loop
2 seals
Independent valuations, locked before either is revealed
4 lives
Business down to child, every step documented
0 exposed
No unit ever sits on an open network
Sovereign Software Core Supply refresh cycles Rebuild wipe · verify Placement business → family Return regrade
Where the model comes from

The equipment-placement business, applied to secure computing.

The reference model is a proven one: the vendor owns the machine, places it on site, keeps it supplied, and when it fails it is swapped same-or-better immediately rather than repaired in place while the customer waits. Coffee machines, printers and copiers ran this way inside hospitals for decades. The customer's outcome was never "I own this." It was "a working machine is always here."

They owned all the equipment. They put it in the hospitals, they brought the toner and the paper, and if it ever broke down it got swapped out immediately with the same or better.

That is the whole business, translated one column at a time. What changes is what the consumable is: not toner and paper, but policy, protection, evidence, and updates.

  • Coffee machines & copiers Hardened workstations & gateways
  • Toner, ink, paper Policy, protection, updates, evidence
  • Placed inside hospitals Placed inside homes, churches, schools, firms
  • Breaks down → swap same or better Fails → imaged replacement, sealed return
  • Vendor owns the asset Vendor owns the fleet and the posture
  • Service call Evidence event on a sealed chain

The market it sits in

IT hardware subscription and Device-as-a-Service is sized around USD 17.67 billion in 2026, heading to USD 48.15 billion by 2031 (Mordor Intelligence).

The supply it draws on

IT Asset Disposition was valued around USD 21.98 billion in 2025 (SNS Insider), with the enterprise segment at USD 7.74 billion (Fortune Business Insights).

Why nobody owns this

Refurbishers cannot add sovereign infrastructure. Software companies cannot ship certified sanitized hardware. Neither runs dual-attested valuation. Doing all three, with evidence, is the position.

The four sides

A closed loop, and every crossing produces a record.

Nothing enters or leaves the loop undocumented. That is what lets the program publish real diversion figures instead of marketing claims — and what lets a customer's auditor trace any unit end to end.

SIDE 01 / SUPPLY

Companies that are upgrading

Businesses hand over retiring fleets and get back something more useful than a disposal invoice.

  • A sanitization certificate per device — serial, method, operator, timestamp, hash-chained
  • One chain-of-custody report for their own auditor or insurer
  • Trade-in credit, cash buyback, or a documented charitable-placement receipt
  • Optional named sponsorship of where the fleet lands — a school lab, a church, a family cohort
SIDE 02 / REBUILD

Sanitize, verify, harden, image

The part that has to be genuinely rigorous, because the whole brand rests on evidence rather than assertion.

  • Sanitized to NIST SP 800-88 Rev. 2, published September 2025, cited by revision on every certificate
  • Pursue R2v3 certification — third-party audited across data security, environment and worker safety, and required to comply with SP 800-88 (ITAD Intelligence)
  • Firmware provenance: UEFI reflash, ME/PSP posture, TPM clear and re-provision — failures go to recovery, not to a customer
  • Spec-matched to the workload and documented, never upsold to the most expensive unit on the shelf
  • Imaged with Sentinel, Control Tower policy, Secure Build Lab, sovereign network client
  • Ships with a build manifest: components, firmware versions, image hash, policy set
SIDE 03 / PLACEMENT

Who receives, and on what terms

Tiers mirror the existing Sentinel structure so pricing stays coherent across the portfolio. Published prices are a floor and are not undercut.

  • Family — hardened workstations, sovereign network client, safety policy
  • Extended family — adds a small on-prem gateway node and shared vault
  • Small business, nonprofit, church — fleet units, gateway, egress policy, evidence vault
  • Business — managed fleet, Control Tower console, air-gapped tier, drills and runbooks
  • Government / agency — sealed enclave configs, jurisdictional policy, documented custody
  • Lab / education — cohort bundles, curriculum tie-in, sponsor attribution
SIDE 04 / RETURN

The circular close

Failed, aged-out and upgraded units come back in. The loop is what makes the economics work and the environmental claim true.

  • Remaining useful life → re-graded and re-placed one tier down
  • Fails firmware or physical inspection → certified material recovery
  • Returned media sanitized and certified again on intake
  • Predictable return volume is what makes the guaranteed upgrade path financeable
The centerpiece

Dual attestation — two sealed valuations, neither able to see the other.

Every secondary-hardware market runs on information asymmetry: whoever knows more about the machine wins. This deletes the advantage in both directions. The program cannot lowball a seller, and a seller cannot conceal a fault, because both numbers were locked before either was visible.

Valuation event — commit, then reveal

Tolerance band ±10% Auto-settle at midpoint
Party A

The holder's claim

  • Declared specification and age
  • Self-assessed condition grade
  • Accessories included
  • Known faults disclosed
  • Expected value
commit_A = SHA-256( valuation ‖ nonce_A )
Party B

The intake observation

  • Verified specification
  • Benchmark and battery result
  • Physical inspection grade
  • Firmware provenance status
  • Market comparable
commit_B = SHA-256( valuation ‖ nonce_B )

Grade independently

The holder submits their own claim. Intake performs its own inspection. Neither sees the other's work.

Commit before reveal

Each valuation is hashed with a nonce and the hash published first. Nobody can revise a number after seeing the other side's.

Reveal together

Both open simultaneously. Hashes are checked against the revealed values, so a changed number is detectable.

Inside tolerance, auto-settle

Within the published band, the transaction settles at the midpoint. No negotiation, no haggling, no sales pressure.

Outside tolerance, escalate

A published market-comparable index plus documented review. The reason for the gap is recorded — disputes become data.

Seal the record

Both valuations, both identities, the settlement math and the evidence go into a hash-chained record either party can produce years later.

Why it matters most at upgrade time

When a customer trades up at refresh, the residual credit on the returned unit is set the same way. They are not accepting whatever the vendor says their old machine is worth.

That is precisely where phone carriers lose customer trust. Doing it with sealed dual attestation turns the single most resented moment in the subscription-hardware model into the most defensible one. It is also the doctrine applied to money: the holder's claim is an assertion, the inspection is an observation, and the record shows both rather than collapsing them into one price.

The trust cascade

One fleet, four useful lives — and the reason for every step down is written.

A machine that is no longer a fit for a business is not a worse machine. It is a machine whose best use has changed. Every move down the ladder carries a documented reason, and the reason is a fit change — not a defect.

Tier A
Business fleets & agencies
In vendor firmware support, meets the current business security baseline.
Tier B
Small business, nonprofit, church
Aging out of the business baseline but fully capable for the workload.
Tier C
Family adult workstations
No longer meets a business security baseline — often for a reason unrelated to how well it works.
Tier D
Children, homework, coding labs
Lower spec, still genuinely solid for its workload. Graded and verified, never dumped.
Recovery
Certified material recovery
Fails firmware verification or physical inspection. Never placed with a customer.

A concrete example of a fit change that is not a defect: Microsoft requires TPM 2.0 for Windows 11 and has held that line as an indispensable standard rather than relaxing it (PCWorld), and TPM 1.2 is explicitly no longer sufficient (CRN). A perfectly good machine can fail a business baseline for a reason that has nothing to do with whether it works well for a ten-year-old learning to type.

The line that does not move

Hardware is matched to the workload. Protection is not. A child's machine ships with the same Sentinel protections, the same egress policy, the same evidence vault and the same gateway boundary as a business fleet unit.

Normally the cheapest customer gets the weakest protection. Here the cheapest customer gets a machine that is older and protection that is not. If anything a child's device carries more policy, not less — safety and content controls, the anchored-zone logic from Safe Perimeter, and the tightest egress rules in the program.

Sentinel modules
Identical at every tier
Egress policy
Tightest rules at Tier D
Evidence vault
Every unit, every tier
Gateway boundary
Enrolled before first use
Always inside the envelope

No unit in this program is ever a bare machine on an open network.

The security envelope is not installed at the end — it wraps the hardware at every stage of its life. This is defensible only because the program controls the entire path rather than selling a box and hoping.

01
Intake
Isolated bench network with no route to the internet or the business network. A client's unknown drive is treated as untrusted evidence, not as a device to plug in.
02
Sanitize & rebuild
Air-gapped bench for firmware work. Images arrive by controlled import, matching the airlock pattern rather than a download.
03
Storage
Powered down and offline. Nothing sits idle on a live network waiting to be shipped.
04
Transit
Sealed and policy-locked, with no network-capable state until enrolled at destination. Tamper-evident seal recorded in the build manifest.
05
Deployment
Enrolled behind the on-site gateway before first use. Never a direct-to-internet first boot.
06
In service
Continuous policy enforcement, egress control and evidence logging under the track-back, never hack-back boundary.
07
Return
Sealed on pickup, sanitized on intake, certificate issued, chain closed. The unit re-enters the loop or goes to recovery.
Service layer

Swap on failure, upgrade on schedule, support that is scoped and priced.

Swap on failure

A failure means a same-or-better unit is on site inside a committed window, already imaged and policy-loaded, with the failed unit sealed and returned. The customer never diagnoses, never waits on parts, never loses their configuration.

The failure is also an evidence event. If a unit failed because of tampering rather than wear, that distinction is visible in the record — and it is a Sentinel incident, not a warranty claim.

Scheduled upgrade path

Every subscription includes a defined refresh at 24 or 36 months depending on tier, moving the customer to a newer graded unit with no additional capital cost. The residual on the returned unit is set by dual attestation.

This is the mechanic that turns a one-time refurb sale into recurring revenue — and it guarantees intake a predictable return volume, which is what makes the supply side work at all.

Technical assistance

A paid layer separate from the swap promise: setup, migration, hardening review, family onboarding, policy tuning and incident support. Priced per seat or per household, with a higher tier for businesses that want a named engineer.

Membership & household extension

A business subscriber can extend seats to employees' households at a member rate. That is how the fleet reaches homes beyond the office, and it is a real benefit an employer can advertise.

The extension

Wrap the air gap around the IoT, and treat the IoT as infrastructure.

IoT is where the soft underbelly is. Cameras, badge readers, HVAC controllers, printers, medical peripherals, thermostats and sensors rarely get patched, often cannot run an agent, and sit on the same flat network as everything that matters. The program's structural advantage is that it is already placing a gateway on site.

Devices are assumed untrustworthy

IoT is a protected tier, not a set of endpoints. The devices are treated as unpatchable and compromised-capable. Protection happens at the boundary around them, never on them.

The gateway becomes the perimeter

Every IoT segment sits behind the on-prem gateway. Nothing reaches the internet or the business network except by explicit policy — the same ALLOW / INSPECT / BLOCK model, pointed inward at the device population.

One-way for anything critical

Where a segment must be genuinely isolated — life-safety, control systems, ballot or evidence hardware — the crossing is a controlled one-way path with import and export gates, not a firewall rule.

Inventory and behavioral baseline

Enroll every device, record what normal traffic looks like, alert on deviation. For devices that cannot be patched, knowing exactly what they should ever be doing is the only real control.

Evidence, not just blocking

Every boundary decision is loggable and exportable into the evidence vault, so an IoT incident produces an investigator-ready package rather than a vague alert history.

A live training range

Refurbished units plus a real IoT segment behind a real gateway is a curriculum. A student can watch a badge reader try to phone home, then watch policy stop it. This is the Cyber Labs and Digital Resilience Lab angle made concrete.

Worth scoping separately. The IoT gateway may be the stronger standalone product, sellable into sites that never take a single refurbished workstation.
Participation credits

Pay participants in program value, not cash.

Because the program owns both the supply side and the placement side, discounts can be denominated in program value — far cheaper than cash, and every credit pulls the loop tighter. Stacking rules and caps still need setting so discounts cannot erode the price floor.

Participation credits, how they are earned, and why each pays for itself
Credit Earned by Why it pays for itself
Supply credit Handing over a retiring fleet Turns a disposal cost into subscription value and secures inventory
Verified-condition bonus Self-assessments landing inside tolerance Buys honest grading; cuts inspection and dispute cost
Cascade credit Letting a unit continue down the tiers Feeds family and education tiers at almost no acquisition cost
Sponsorship credit Funding a named school lab, church or cohort Buys a real, publishable story for the sponsor
Household extension A business extending seats to employees' homes Distribution into households at near-zero acquisition cost
Return-on-time credit Returning swapped or refreshed units promptly Keeps reverse logistics predictable and cheap
Multi-year commitment Longer subscription terms Improves financing terms on the fleet
Referral Bringing in another supply company or site The cheapest acquisition channel available
The environmental case

Measured from our own records, not claimed.

Because every unit is tracked through the cascade, the program can report actual service-life extension per device rather than an industry average — consistent with the portfolio's refusal to present assertions as evidence. The reason it matters is that the numbers are stark.

62 Mt
e-waste generated in 2022

Up 82% from 2010 and on track to reach 82 million tonnes by 2030.

Global E-waste Monitor 2024
22.3%
properly collected and recycled

Leaving USD 62 billion in recoverable resources unaccounted for, at an average of 7.8 kg per person per year.

ITU
40–80%
of lifetime emissions are manufacturing

Driven by component fabrication in coal-dependent regions. For a typical laptop about 84% of the footprint sits in Scope 3, with semiconductor and board fabrication alone around 38%.

Aalto University · Climatecost
6.23 bn kg
CO₂e avoided by two extra years

Calculated for the notebooks certified in 2019 if used six years instead of four. Extending a corporate refresh cycle by even one year measurably cuts a workplace footprint.

TCO Certified · Computerworld
The framing

The greenest computer is the one that already exists.

Destroying a working machine wastes carbon that was already spent — most of a device's footprint was emitted before it was ever switched on. Every cascade step is carbon already paid for, being used instead of thrown away. Extending life is the single highest-leverage action available, and it happens to also be the cheapest way to put a protected system in someone's hands.

Honest about the hard parts

What will actually decide whether this is real.

None of these are trivial, and overclaiming on any of them would undermine the whole brand. They belong on the board next to the upside.

Capital

Owning the fleet puts it on the balance sheet

Swap inventory must exist before the first failure. This is an asset-heavy business and likely needs equipment financing or a leasing partner rather than being funded from subscription cash flow.

Logistics

Committed swap windows mean regional footprint

Depots or a partner with existing coverage. Reverse logistics is the single most underestimated cost in this entire model.

Technical

Firmware trust is genuinely hard

Wiping the disk is the easy half. Establishing supply-chain provenance on used enterprise hardware is the hardest part of the intake line, and the honest position may be "verified to this documented level, not beyond."

Certification

Cost and timeline before first revenue

R2v3 is cited in the USD 15K–40K range, with e-Stewards stricter and pricier (Investment Recovery Association), plus ISO 9001, 14001 and 45001 or RIOS. Budget time as well as money.

Regulatory

Obligor rules, state by state — and data custody

Service-contract regulation varies by state, leasing rules may apply, and accepting a client's drive means accepting custody of their data until it is destroyed.

Economics

Family-tier support can eat the margin

Support has to be scoped and priced, and the self-install swap path has to actually work without a truck roll.

Actuarial

Swap promises need real failure data

Used enterprise hardware has real failure curves. Windows should not be published until they are grounded in the program's own intake history.

Next moves

Nothing here requires building hardware yet.

In rough order. The first four are specification and documentation work that can be done and demonstrated before a single unit is acquired.

01

Write the doctrine page

One page defining what the program will and will not claim, in the same style as the existing platform doctrines. Prevents scope drift and marketing overreach later.

Spec · no hardware
02

Draft the evidence artifact formats

Sanitization certificate and build manifest. These are the product's core artifacts and they reuse the existing hash-chained audit pattern.

Spec · no hardware
03

Specify the dual-attestation protocol

Commit format, nonce handling, reveal trigger, tolerance band, midpoint math, escalation path and the sealed record schema. Prototypeable with zero hardware — and probably the most compelling thing to show a partner first.

Spec · demoable
04

Define the cascade grading rubric

Testable criteria for each tier move — firmware support status, TPM version, RAM, storage class, battery health — so a demotion reason is objective rather than a judgment call.

Spec · no hardware
05

Model the unit economics on one slice

Twenty-five business-class laptops through one family tier and one small-business tier over 36 months, including one swap event per unit and a single refresh.

Financial model
06

Find one supply partner and one recipient

One company with a refresh cycle, one church or school. A ten-unit pilot with real certificates proves more than a full written spec.

Pilot
07

Legal review on the protection structure

Before any pricing page mentions replacement, coverage or insurance. This gates all customer-facing language.

Blocking · counsel
08

Scope the IoT gateway separately

It may be the stronger standalone product and could sell into sites that never take a refurbished workstation.

Product scoping
Related work

Where this plugs into the existing portfolio.

SENTINEL Sovereign Cyber Platform

The software that ships on every unit; the existing tier structure this stays consistent with.

Sovereign Control Tower

Node admission, egress policy, audit chain, and the airlock and perimeter patterns behind the IoT boundary.

Secure Build Lab

The local and offline development boundary for developer-tier units.

Digital Resilience Lab

The training and curriculum home for the Cyber Labs angle and the live IoT range.

Safe Perimeter

Anchored-zone and proximity logic that shares the on-site gateway with the network boundary.

BB2G Sovereign AI Cluster

Sealed-enclave and offline-update patterns for the highest tiers.

Sovereign network layer

Currently in build. This program is its hardware distribution channel.