> For the complete documentation index, see [llms.txt](https://docs.optivalux.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.optivalux.com/trust/ownership-and-control.md).

# Ownership & Control

**Software can improve; what you own stays yours.**

Optivalux is designed around **owner sovereignty**: once a product is owned under a conformant protocol version, only its owner can start a change of ownership, and no brand, Optivalux role or later software can take it away. The scope and assumptions are set out [below](#where-this-applies-and-its-assumptions).

## Owner sovereignty

After a product has been claimed:

* **Ownership changes only by owner-authorized transfer**, which also requires the recipient's acceptance and fresh evidence from the product. See [Ownership & Transfer](/product/ownership-and-transfer.md).
* **No administrative reassignment exists.** There is no function by which a brand (including its security role), Optivalux or protocol governance (including its temporary safety role) can move an owned certificate to a different owner.
* **Only the owner can report the product lost or stolen, and only the owner can clear that report.**

## No burn, no seizure

* There is **no way to burn** (delete) a certificate.
* There is **no seizure**: no role can take a certificate from its owner.
* **Voiding** permanently ends a certificate's good standing, but preserves its owner and its history. It requires the brand's security role and a prior suspension of at least a minimum notice period.

Restrictive actions (suspension, voiding, temporary protocol safety restrictions) can limit what can be done with a certificate. **None of them changes ownership.**

## Later software cannot silently move owned certificates

Protocol software will evolve. Optivalux is designed so that evolution cannot be used to take control of existing certificates:

* **Each certificate stays with the protocol software version it was issued under.** Approving a new version gives that version **no authority** over existing certificates.
* New versions become eligible only after approval by protocol governance, a published build fingerprint and a **14-day** maturation period, and only for brands that consent to them.
* An owner's certificate moves to a new version only if **the owner chooses** to move it, with the owner's authorization and fresh evidence from the product.
* If a version the certificate uses is frozen or found unsafe, the owner can move the certificate to a fixed, protected state (see [Protection Mode](/product/recovery-and-protection.md#protection-mode)). A freeze never moves certificates by itself.

The result: **later protocol software cannot silently reassign an already-owned certificate.**

## Where this applies, and its assumptions

These guarantees apply to certificates **after they are owned**. Precisely:

* **Before first ownership,** the brand's security role together with protocol governance controls unclaimed stock. They are part of the issuer trust model for products that have not yet been claimed.
* **If an owner chooses to move** their certificate to another software version, that version then governs it. Owners can only move to approved versions that the brand has consented to, but the choice of version is theirs.
* **If the issuing brand chose a non-conforming software version** before the product was claimed, the certificate stays under that version. Applications are expected to show which version a certificate uses and to refuse non-conforming versions.
* **Owner sovereignty assumes the owner controls their own account.** It assumes neither Optivalux nor the brand controls the owner's signing credentials.

## Why this matters

Physical products last for years. The organisations and software around them change. Owner sovereignty means a product's ownership record does not depend on any one company, including Optivalux, continuing to behave well.

For how owners keep access when authenticators or services fail, see [Recovery & Continuity](/trust/recovery-and-continuity.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.optivalux.com/trust/ownership-and-control.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
