For the practical reader

RosaTrust, in plain terms.

A metaphor-free companion to the Trust Society pages. Those pages tell you why; this one tells you what it is, what it does, and what it never does — the way a privacy, security, or procurement reviewer needs to see it. If you assess vendors or systems for a living, start here.

What it is, in one sentence

RosaTrust is a sovereign identity and data system where the individual holds the root key, their data stays encrypted in their own vault, and any use of that data happens through a consent they grant and can revoke — verified cryptographically, with no central party able to read the data or stand in as the sole authority.

What it does

What it never does

The guarantees a reviewer cares about — each one structural, not a policy promise.

The operator cannot decrypt your data

The vault is sealed to the person's keys; we hold ciphertext and hashes, never plaintext. This is our master litmus — every design decision is measured against it.

No cross-system correlation

Identifiers are pairwise; the same person cannot be linked across services, by us or by a partner.

No single point of authority

No one party is the sole verifier of you — verify everywhere, issue nowhere. There is no gate a single actor can close to take your identity.

We never hold your funds

RosaTrust instructs movement between accounts held at a licensed institution; the money-transmitter role sits with that licensed operator, never with us. Custody of money stays with the person or a chartered bank — never the protocol.

Consent grants access, not a copy

A "no" ends use immediately, because nothing ever left the person's custody in the first place.


How the data actually flows

Structured as a privacy / security / technology impact assessment — it doubles as a vendor-assessment starter pack.

Question an assessor asksRosaTrust's answer
What personal data do you collect / store?The person's data lives in their vault, encrypted under keys only they derive. As the operator we store ciphertext + content hashes — no plaintext, no readable profile.
Who can read it?Only the person (and whoever they grant a scoped, revocable consent to — and even then only as a verdict / aggregate, not the records).
How is consent captured and withdrawn?A cryptographically signed, scoped, time-boxed grant the person's root issues; revocation is a signed act that makes every consumer fail closed.
Data retention / deletion?The person holds the data; "delete" is theirs to exercise. Consent expiry and revocation are enforced, not advisory.
Sub-processors / third parties?A partner operates only inside its own namespace, gated by the person's consent; it cannot reach another partner's data or the person's other shelves.
Cross-border / correlation risk?Pairwise identifiers prevent linkage; roots-only anchoring means no content crosses any boundary.
Integrity / tamper evidence?Records are hash-anchored to a public ledger through a custody-controlled quorum (no single signer); anyone can verify a record wasn't altered.
Security assurance?Three rounds of adversarial self-audit; cryptographic core held under attack; fail-closed throughout; a public conformance-vector suite anyone can run. Honest gap: not yet a live wire-level pentest.

Where the storytelling fits

The Trust Society pages use metaphor deliberately — to make the stakes memorable: why extraction is the problem, why sovereignty is the alternative. This page is the plain counterpart: the mechanism. Both are true. A reader who wants the practical substance should reach it in one click, without translating the metaphors first — which is exactly the improvement this page exists to make.

Grounded in the working system — deeper detail in the security posture card, the wallet + consent readiness record, and the Ten Commandments (the same principles, stated as testable guarantees). This page is the mechanism; those are the receipts.

RosaTrust in plain terms — the practical companion to the Trust Society.

The working stack is live today — Rosalind (sovereign health) · Abakus and its Foundation (sovereign banking) · RosaTrust (the trust engine underneath it all).

Owned by no one · anyone can verify it · no lock-in, ever.