Runtime sovereignty score — fraction of installed packages with no CLOUD Act exposure.
Overall: PARTIAL · Automated coverage: 50%
| Article | Title | Status | Coverage | Detail |
|---|---|---|---|---|
| Art. 9 | Risk management | PARTIAL | auto | Policy evaluator configured; every decision records the policy result. |
| Art. 10 | Data governance | ACTION_REQUIRED | manual | Data governance is not automatable by a middleware kernel. |
| Art. 11 | Technical documentation | ACTION_REQUIRED | manual | Annex IV technical documentation is a human deliverable. |
| Art. 12 | Automatic record keeping | COMPLIANT | auto | Every wrapped call produces a DecisionTrace automatically, stored append-only. |
| Art. 13 | Transparency & information to deployers | COMPLIANT | auto | Traces record agent, model, policy name/version, and result per decision. |
| Art. 14 | Human oversight | COMPLIANT | auto | Kill switch implemented; every override recorded as linked trace entry. |
| Art. 15 | Accuracy, robustness, cybersecurity | ACTION_REQUIRED | manual | Model evaluation and adversarial testing are outside the trace layer. |
| Art. 17 | Quality management system | COMPLIANT | auto | Continuous, append-only trace record satisfies the traceability requirement. |
Overall score: 100%
| Dimension | Detail | |
|---|---|---|
| ✅ | jurisdiction | 0 critical-path violations |
| ✅ | kill_switch | kill switch API present |
| ✅ | storage | backend: sqlite |
| ✅ | bsi | targeting 2026-12-31 |
Sovereign: 59 · US-owned: 1 · Unknown: 46
| Package | Version | Parent | Jurisdiction | CLOUD Act | Critical path |
|---|---|---|---|---|---|
| shellingham | 1.5.4 | Unknown | Unknown | no | no |
| requests | 2.33.1 | Python Software Foundation | Neutral | no | no |
| more-itertools | 10.8.0 | Unknown | Unknown | no | no |
| pexpect | 4.9.0 | Unknown | Unknown | no | no |
| platformdirs | 4.9.4 | Unknown | Unknown | no | no |
| rfc3986 | 2.0.0 | Unknown | Unknown | no | no |
| jaraco.classes | 3.4.0 | Unknown | Unknown | no | no |
| click | 8.3.1 | Pallets | Neutral | no | no |
| ptyprocess | 0.7.0 | Unknown | Unknown | no | no |
| certifi | 2026.2.25 | Unknown | Unknown | no | no |
| iniconfig | 2.3.0 | Unknown | Unknown | no | no |
| jaraco.context | 6.1.2 | Unknown | Unknown | no | no |
| virtualenv | 21.2.0 | Unknown | Unknown | no | no |
| pytest-cov | 7.1.0 | pytest-cov | Neutral | no | no |
| uv | 0.11.3 | Unknown | Unknown | no | no |
| tomlkit | 0.14.0 | Unknown | Unknown | no | no |
| hyperlink | 21.0.0 | Unknown | Unknown | no | no |
| idna | 3.11 | Unknown | Unknown | no | no |
| distlib | 0.4.0 | Unknown | Unknown | no | no |
| build | 1.4.2 | Unknown | Unknown | no | no |
| rich | 14.3.3 | Unknown | Unknown | no | no |
| userpath | 1.9.2 | Unknown | Unknown | no | no |
| librt | 0.8.1 | Unknown | Unknown | no | no |
| tomli_w | 1.2.0 | Unknown | Unknown | no | no |
| httpcore | 1.0.9 | Unknown | Unknown | no | no |
| filelock | 3.25.2 | Unknown | Unknown | no | no |
| nh3 | 0.3.4 | Unknown | Unknown | no | no |
| markdown-it-py | 4.0.0 | Unknown | Unknown | no | no |
| sentinel-kernel | 0.1.0 | sentinel-kernel | EU | no | yes |
| docutils | 0.22.4 | Unknown | Unknown | no | no |
| hatchling | 1.29.0 | Ofek Lev | Neutral | no | no |
| twine | 6.2.0 | Unknown | Unknown | no | no |
| h11 | 0.16.0 | Unknown | Unknown | no | no |
| coverage | 7.13.5 | Coverage.py | Neutral | no | no |
| Pygments | 2.20.0 | Unknown | Unknown | no | no |
| mdurl | 0.1.2 | Unknown | Unknown | no | no |
| pathspec | 1.0.4 | Unknown | Unknown | no | no |
| pytest-asyncio | 1.3.0 | pytest-dev | Neutral | no | no |
| id | 1.6.1 | Unknown | Unknown | no | no |
| urllib3 | 2.6.3 | urllib3 | Neutral | no | no |
| readme_renderer | 44.0 | Unknown | Unknown | no | no |
| typing_extensions | 4.15.0 | Unknown | Unknown | no | no |
| jaraco.functools | 4.4.0 | Unknown | Unknown | no | no |
| trove-classifiers | 2026.1.14.14 | Unknown | Unknown | no | no |
| hatch | 1.16.5 | Ofek Lev | Neutral | no | no |
| charset-normalizer | 3.4.7 | Unknown | Unknown | no | no |
| ruff | 0.15.8 | Astral | US | no | no |
| mypy | 1.20.0 | Python Software Foundation | Neutral | no | no |
| pluggy | 1.6.0 | Unknown | Unknown | no | no |
| python-discovery | 1.2.1 | Unknown | Unknown | no | no |
| File | Component | Vendor | Jurisdiction | CLOUD Act |
|---|---|---|---|---|
| .github/workflows/ci.yml | github_actions | GitHub (Microsoft) | US | yes |
| .github/workflows/pages.yml | github_actions | GitHub (Microsoft) | US | yes |
| .github/workflows/release.yml | github_actions | GitHub (Microsoft) | US | yes |
| pyproject.toml | pypi | Python Package Index | US | no |
| File | Component | Vendor | Jurisdiction | CLOUD Act |
|---|---|---|---|---|
| No infrastructure findings | ||||