What is real,
and what is not.
Every claim on this site carries a status tag. This is the page those tags resolve to. Most of it is not finished, and it says so, line by line.
Twenty-one claims. Three we can prove today.
Every tagged claim on this site appears below, in the state it is actually in, with a note on how we checked it. If a claim ever appears on a page and not here, that is a bug, and a check in our build stops it shipping.
last checked · checked against the platform source, not against a slide
| Tag | What it means |
|---|---|
| LIVE | We checked it today and can show you where to look. |
| IN BUILD | Designed and being written. The phase number says which stage it sits in. |
| PLANNED | Agreed, not started. No date is promised, ever. |
We hold no names, birthdays, photos or addresses
LIVEThere is no pile of personal data here to steal, leak, sell, or be ordered to hand over.
How we checked
This website makes no outside requests and sets no cookies
LIVENo fonts from elsewhere, no analytics, no tag manager, no tracking pixel, no cookie banner, because there is nothing to consent to.
How we checked
European rules require phone-based identity people control
LIVEThe design this site describes is the design those rules are written around.
How we checked
A machine refuses to start on settings it cannot check
IN BUILD · P0A misconfigured machine does not run badly. It does not run at all, and it names the setting that stopped it.
How we checked
A machine that cannot sign stops taking work
IN BUILD · P0Before any machine is given traffic, it proves it can still sign. If it cannot, it is taken out of rotation, not restarted in a loop.
How we checked
Your keys are made on your phone and never leave it
IN BUILD · P1The design is settled: keys are born inside the phone's secure chip and cannot be exported. The code that does it is not written here yet.
How we checked
An organisation you trust can hand a document to your phone
IN BUILD · P1Signed by them, bound to your phone, useless as a copy on anyone else's device.
How we checked
Whoever asks is checked against a public list first
IN BUILD · P1Your phone looks up who is asking before you are shown anything to approve.
How we checked
One sheet for every ask, with a row per fact
IN BUILD · P1The same sheet whoever is asking, with what they keep declared on it, every time.
How we checked
Your own branded issuer, on your own domain, in an hour
IN BUILD · P1And you can fire us by deleting one DNS record, keeping the identity you built.
How we checked
You can check exactly what is running
IN BUILD · P0The image, its parts list, and a signature you can verify — published, not described.
How we checked
A receipt of every share, held only by you
PLANNEDYour phone records what you shared and with whom. We never get a copy.
How we checked
Lose your phone, not your identity
PLANNEDGetting back in means being given your documents again, never a secret phrase.
How we checked
A public status page with real numbers
PLANNEDUptime and response times per location, published whether they flatter us or not.
How we checked
Disaster drills, published with their dates and timings
PLANNEDWe rehearse failures on purpose and publish how the rehearsal went.
How we checked
Checking a proof is free, forever
PLANNEDThe side that checks should never be charged per check.
How we checked
A hello-world you can run in ten minutes
PLANNEDA sandbox, a test phone, and a working example — no sales call.
How we checked
The early list
PLANNEDA way to be told when there is something to try.
How we checked
Forty-five languages
PLANNEDIncluding right-to-left layouts, in the language's own name.
How we checked
Messages nobody can read — including us
PLANNEDPrivate conversation between people who have proved who they are to each other.
How we checked
Filtering happens in your browser with no script at all. The buttons above are ordinary form controls, and they work with a keyboard.
Status
PLANNEDThere is no live feed yet, so there are no numbers here.
Nothing to report — and that is the report.
A status page with invented numbers is worse than no status page. When the feed is real, this section will show, per location:
- whether checks are being answered right now
- how long a check takes, at the slow end, not the average
- the last time the list of cancelled proofs was refreshed
- every incident, with what we got wrong
no feed connected ·
How your keys work
IN BUILD · P1In plain words, with the parts that are not built yet marked as such.
Where the key lives. Your phone makes its own key inside the locked chip that already guards your fingerprint. It is made there, used there, and cannot be copied out. We never see it, so we can never lose it, hand it over, or be forced to.
What we sign with. Our own signing keys will live in a managed key service, and a machine that cannot reach it is taken out of service rather than allowed to guess. That check is written and tested, but the machine deployed today is a placeholder, so its register row says IN BUILD, not LIVE.
What a break-in would get. Two tables: a count of things done, and a note of which settings each machine booted with. No names. No birth dates. No keys. That row is LIVE and shows how we checked it.
What is not built. The phone side. Everything in the first paragraph above is the design, not a running system, which is why this whole section is tagged IN BUILD rather than LIVE.
The last row is the honest one. Counts exist because someone has to be billed for them.
The drill ledger
PLANNEDWe intend to break our own system on a schedule, and publish how it went.
No drills recorded yet.
This ledger is empty because we have not run one. It is published empty on purpose: a trust page that only appears once the news is good is not a trust page.
When a drill runs, its row will carry the date, what we deliberately broke, how long recovery took, and what we found out that we did not like.
| Date | What we broke | Back in | What we learned |
|---|---|---|---|
| — no entries — | |||
Build provenance
IN BUILD · P0You should be able to check what is running, not take our word for it.
Nothing published yet.
There is a container recipe and a record of which settings each machine started with. Neither is published for you to inspect, so this section shows nothing rather than something reassuring.
When it is published, each entry will carry:
- the exact fingerprint of the image that is running
- the full parts list of what went into it
- a signature tying that image to the build that produced it
- the settings each machine booted with, which is already recorded internally
How this page could be wrong.
The failure modes we know about, written down before someone finds them.
-
A claim could appear on a page and not here.
A check in our build fails when a page and this register disagree. It reads every tagged claim on every page, compares it to the row below, and refuses the build on a mismatch, a claim pointing at a row that does not exist, or a counter above that has drifted. It is written and it runs; making it block a merge automatically is the step still outstanding, so today someone still has to run it. If you find a mismatch, the page is wrong and this register wins.
-
A LIVE row could go stale.
Every LIVE row was checked against the source on the date it carries. A change tomorrow could make one false. Re-checking on every release is the intent; there is no automatic re-check today.
-
A tag could be too generous.
Where a claim was arguable, we put it in the lower state. That is why the home page says IN BUILD in places you might expect LIVE.