Sovereign Mode

Keep every scan, feed and cryptographic key within your borders. Air‑gap ready — see Offline Kit.

Status. Full Sovereign bundle ships with v1.0 (Q4 2026). The essentials—Offline Kit & anonymous 33/333 scan quotas—are available from the first alpha (v0.1 late 2025).

Why organisations demand sovereignty

Offline scanning & fair‑use quota

Stella Ops works out‑of‑the‑box on an isolated network: 33 scans per UTC day anonymously or 333 scans per day with a free e‑mailed JWT. Throttling never blocks builds; it slows down scans and shows a gentle reminder once you cross 90 % of daily scan quota.

Sovereign TLS providers (v1.0)

Support for regional TLS stacks is exposed via an ITlsProvider interface. Stella Ops does not ship or advertise any country‑specific providers by default; availability depends on customer‑supplied modules and local law.

ProviderStatusAlgorithms
OpenSSL (default)ImplementedRSA, ECDSA, Ed25519
SM2Planned v1.0Chinese SM2
OthersPost v1.0As per law jurisdiction

Implementation via ITlsProvider interface in the .NET 10 LTS core; Angular 20 UI auto‑detects available providers.

Unified global + regional CVE database

The FeedMerge service consolidates multiple public and regional feeds into one signed SQLite snapshot that ships in every Offline Update Kit.

FeedRegionRefresh
NVD JSON 2.0GlobalDaily
OSV + GHSAGlobal6 h
CNVDChinaDaily
JVNJapanDaily
OthersAs per configurationDaily

Offline Kit workflow

1 · Build

CI merges feeds, signs bundle and SBOM.

2 · Transfer

Single curl -LO or USB to the air‑gap.

3 · Import

CLI verifies Cosign, swaps DB live in < 3 s.

Grab the Offline Kit   Follow Sovereign roadmap