RosaTrust — self-sovereign identity

An identity that is yours to keep.

Claim a real key in your browser, sign a record, and watch it verify across the live trust mesh beside you — then break it, revoke it, and see what would (and wouldn't) change it.

An account is a row in someone else's database. An identity is a key in your hands. This page lets you feel the difference.

Live and sovereign — your root key is minted in your browser and verified to the Master root; the bench below lets you feel exactly how it works first.

A hand holding a small worn brass key in front of a towering wall of identical timber ledger drawers receding into shadow, one drawer hanging open and empty, a green shoot growing from a crack at its base.
An account is a row in someone else's book. An identity is a key in your hand.

checking your browser's crypto…

1·Claimkey→ID
2·Issuesign
3·Verifyoffline
4·Tamperone byte
5·Revokeforever
— claim an identity: a keypair is created in this tab, and its unique fingerprint becomes a face only your key can reproduce —
The signed record
— nothing issued yet —
The signed bytes
awaiting a verify
Trust mesh illustrative
verify anchor revoke
verified 0anchored 0
mesh status loading…

One truth, many witnesses. Your record is signed once, in your hands — the mesh never holds it. Verify nodes answer a single question (does this proof check out?), and the ledgers at the base witness only a fingerprint of the record, never the record itself. Your actions on the bench fire real pulses; where this page can reach the live registry, the status line below is real.

What would change this ID — and why that matters

The difference between an identity and an account is who controls the verbs.

Your RosaTrust identity
A normal online account
Who can change it?Only your key. A new record exists only if your private key signs it — and that key never left your device.
Who can change it?They can, anytime. The company holds the record and can edit, reset, or repurpose it without asking you.
What does “delete” mean?You leave with everything. Export your keys, credentials and receipts; they verify forever, with or without us.
What does “delete” mean?They erase their copy. “Delete account” removes their record of you — proof it was theirs, not yours.
Whose copy is your life?Yours is the primary. Everyone else's is derived from it. Platforms, providers and partners become contributors to your record — not custodians of it.
Whose copy is your life?Theirs. A portal shows you their copy of your own life. Close the tab, and you hold nothing.
Revoked out from under you?No — revocation is yours. You revoke, it stays revoked everywhere, permanently. No silent reinstatement.
Revoked out from under you?Yes — and quietly. They can suspend, reinstate, or sell access; the terms are theirs to change.

What you just proved

Three properties, demonstrated — not asserted.

VERIFY EVERYWHERE

No one in the room

The verify ran against your public key alone. No server — if we vanished, your records still verify.

FAIL-CLOSED

One byte is enough

Change a single byte and the signature stops matching. A denial isn't a bug to route around — it's the product working.

REVOCATION IS REAL

Once revoked, always

A revoked record is refused even when its signature is perfect. Revocation strictly advances — it never quietly returns.

Why this is bigger than a login

The key you just claimed is the first move of five. Together they take your online life — the one being quietly monetized without you — and put it back in your hands.

Claim

All that is you, gathered under a key only you hold. The scattered traces of your life become claimable — and you become the authority the moment you show up.

Close

The doors of quiet extraction shut. Each service sees its own pairwise face of your identity, so no one can join your life together across platforms behind your back.

Consent

Every access passes your gate and leaves a signed receipt. Consent enforced by code, not policy — revoke once, and it stays revoked everywhere.

Collect

When your data has buyers, they deal with you. The extraction economy, inverted: they pay you, on your terms, with a receipt trail you can audit.

Carry

Your keys export. Take your identity — records, receipts, proofs — anywhere, and it verifies forever. "Delete your account" erased their copy; this one is yours to keep.

Your online life is being sold — for free.

The same woman at her kitchen table twice: first reading while beads of light travel out along copper pipes to distant towers, then with brass valves within reach at the table edge, one closed, the light travelling back to a dish beside her cup.
Before the switch — it all flows outAfter — a valve at your end
Nothing about the pipes changed. The valve did. The same connections that drain you, with a shut-off in your reach, are an income.

See what Google, Apple, and Meta have monetized about you. Then flip one switch to shut it off — and get paid when your consented data is sold.

~$6,500/ year — the average American's data, all of it

Most people have no idea. Your searches, your purchases, your health — packaged and sold every day, and none of it comes back to you. Link an account and we show you exactly what they hold and what it's worth. ~$6,563/yr, average American, incl. ad targeting + data-broker resale + AI training (Web3 Foundation, 2024). Figures are industry estimates, not a per-user appraisal.

Search & online behavior~$290/yr Google's own ad revenue per active US user; $50–300/yr to advertisers generally.
Financial & card purchasespremium Among the highest-value datasets — Mastercard & Amex sell cardholder transaction data at scale (US PIRG, CBS News).
Health & medical recordsup to ~$1,000 / record On the black market — ~10× a stolen credit-card number, because a medical record never expires (Trustwave / IBM).
1 · See

What they know, what it's worth

Link an account, import your data export, and get a scored map of every extraction surface — with an estimated annual value on each. The number is the wake-up.

2 · Shut it off

One switch, per firm

Revoke every link, request erasure, deactivate tracking, prove zero standing consent — customized for each firm. You see exactly which doors are confirmed shut and which need one more click.

3 · Get paid

Value flows back

Going forward, when your consented data is sold, the money comes to you — the majority, always — settled through your own wallet. The extraction economy, inverted.

Say-doWe never claim "deleted" for a step we only guided you to — every action reads confirmed, requested, or guided, honestly. A reclaim is certified complete only when every door is confirmed shut.
Try it — link the firms you use (illustrative, nothing leaves your browser)
Extracted from you, per year$0

Speaks every standard. Depends on none.

Sovereignty and interoperability aren't a trade-off: open standards are how your identity talks to the world, and independence is why it survives it. What conforms and what is ours is always labeled — never blurred.

W3C · Spec-correct did:keyDID CoreEvery principal is natively a did:key over its public key — byte-exact to the W3C test vectors, zero registry dependency. The did:rosatrust method spec is drafted for publication.
W3C · Data-model shapedVerifiable Credentials 2.0Credentials and receipts carry a VC 2.0 envelope any VC ecosystem can consume — with an honestly-labeled JCS-style proof suite, and the record's own chain of proof intact beneath it.
FIDO Alliance · ShippedWebAuthn / FIDO2Hardware passkeys — Secure Enclave, TPM, security keys — front our secured demos; content stays encrypted at rest beneath the passkey factor.
OpenID · PKCE enforcedOpenID Connect + PKCE"Sign in with RosaTrust" is an OIDC-patterned code flow — PKCE required, pairwise subjects, no client secrets to leak; one integration for every partner.
NIST · Post-quantum readyFIPS 204 (ML-DSA)The suite registry runs Ed25519 and ECDSA P-256 today and ML-DSA-65 — including hybrid classical+PQ signing — for the decade ahead.
IEEE 2874-2025 · Adapter shippedSpatial WebHSML-shaped projection of principals, domains and receipted activities — including sovereign AI agents with provable lineage. Formal conformance targets the published test suite; the kernel stays sovereign beneath.

Developer & technical resources

Everything needed to build against RosaTrust — and to check our standards claims against the running code.

Reference · publishingDeveloper ReferenceMethods, runnable examples, and the principles your integration relies on. Dependency: cryptography.
Spatial Web · IEEE 2874 · publishingHSML CrosswalkHow RosaTrust maps to the standard's vocabulary — Entity/Agent/Domain/Activity/Contract, the four dimensions, SWID.
JSON-LD · liveHSML Profile ContextThe resolvable @context every projected entity references — vocabulary map + the enforced principles.
Try itTrust Mesh · Banking MeshThe interactive demos — the same kernel, offline-verifiable, running in your browser.
VerifyVerify an attestationCheck any RosaTrust attestation against the registry root — offline, no account.
Open sourcePublic repositoryComing soon — the mechanism published openly; sovereign key material and topology never leave our side.

Runs client-side with WebCrypto ECDSA P-256 — the same suite our hardware intermediates use. No data leaves your browser.