Claim a real key in your browser, sign a record, and watch it verify across the live trust
mesh beside you — then break it, revoke it, and see what would (and wouldn't) change it.
An account is a row in someone else's database. An identity is a key in
your hands. This page lets you feel the difference.
Live and sovereign — your root key is minted in your browser and verified to the Master root; the bench below lets you feel exactly how it works first.
An account is a row in someone else's book. An identity is a key in your hand.
checking your browser's crypto…
1·Claimkey→ID
2·Issuesign
3·Verifyoffline
4·Tamperone byte
5·Revokeforever
— claim an identity: a keypair is created in this tab, and its unique fingerprint becomes a face only your key can reproduce —
The signed record
— nothing issued yet —
The signed bytes
awaiting a verify
Trust meshillustrative
verifyanchorrevoke
verified 0anchored 0
mesh status loading…
One truth, many witnesses. Your record is signed once,
in your hands — the mesh never holds it. Verify nodes answer a single question (does this proof
check out?), and the ledgers at the base witness only a fingerprint of the record, never the
record itself. Your actions on the bench fire real pulses; where this page can reach the live
registry, the status line below is real.
↳What would change this ID — and why that matters
The difference between an identity and an account is who controls the verbs.
Your RosaTrust identity
A normal online account
Who can change it?Only your key. A new record exists only if your private key signs it — and that key never left your device.
Who can change it?They can, anytime. The company holds the record and can edit, reset, or repurpose it without asking you.
What does “delete” mean?You leave with everything. Export your keys, credentials and receipts; they verify forever, with or without us.
What does “delete” mean?They erase their copy. “Delete account” removes their record of you — proof it was theirs, not yours.
Whose copy is your life?Yours is the primary. Everyone else's is derived from it. Platforms, providers and partners become contributors to your record — not custodians of it.
Whose copy is your life?Theirs. A portal shows you their copy of your own life. Close the tab, and you hold nothing.
Revoked out from under you?No — revocation is yours. You revoke, it stays revoked everywhere, permanently. No silent reinstatement.
Revoked out from under you?Yes — and quietly. They can suspend, reinstate, or sell access; the terms are theirs to change.
↳What you just proved
Three properties, demonstrated — not asserted.
VERIFY EVERYWHERE
No one in the room
The verify ran against your public key alone. No server — if we vanished, your records still verify.
FAIL-CLOSED
One byte is enough
Change a single byte and the signature stops matching. A denial isn't a bug to route around — it's the product working.
REVOCATION IS REAL
Once revoked, always
A revoked record is refused even when its signature is perfect. Revocation strictly advances — it never quietly returns.
↳Why this is bigger than a login
The key you just claimed is the first move of five. Together they take your online life
— the one being quietly monetized without you — and put it back in your hands.
Claim
All that is you, gathered under a key only you hold. The scattered traces of your
life become claimable — and you become the authority the moment you show up.
Close
The doors of quiet extraction shut. Each service sees its own pairwise face of your
identity, so no one can join your life together across platforms behind your back.
Consent
Every access passes your gate and leaves a signed receipt. Consent enforced by
code, not policy — revoke once, and it stays revoked everywhere.
Collect
When your data has buyers, they deal with you. The extraction economy,
inverted: they pay you, on your terms, with a receipt trail you can audit.
Carry
Your keys export. Take your identity — records, receipts, proofs — anywhere, and it
verifies forever. "Delete your account" erased their copy; this one is yours to keep.
↳Your online life is being sold — for free.
Before the switch — it all flows outAfter — a valve at your end
Nothing about the pipes changed. The valve did. The same connections that drain you, with a shut-off in your reach, are an income.
See what Google, Apple, and Meta have monetized about you. Then flip one switch to shut it
off — and get paid when your consented data is sold.
~$6,500/ year — the average American's data, all of it
Most people have no idea. Your searches, your purchases, your health — packaged and sold
every day, and none of it comes back to you. Link an account and we show you exactly what they
hold and what it's worth.
~$6,563/yr, average American, incl. ad targeting + data-broker resale + AI training (Web3 Foundation, 2024). Figures are industry estimates, not a per-user appraisal.
Search & online behavior~$290/yrGoogle's own ad revenue per active US user; $50–300/yr to advertisers generally.
Financial & card purchasespremiumAmong the highest-value datasets — Mastercard & Amex sell cardholder transaction data at scale (US PIRG, CBS News).
Health & medical recordsup to ~$1,000 / recordOn the black market — ~10× a stolen credit-card number, because a medical record never expires (Trustwave / IBM).
1 · See
What they know, what it's worth
Link an account, import your data export, and get a scored map of every extraction surface — with an
estimated annual value on each. The number is the wake-up.
2 · Shut it off
One switch, per firm
Revoke every link, request erasure, deactivate tracking, prove zero standing consent — customized for
each firm. You see exactly which doors are confirmed shut and which need one more click.
3 · Get paid
Value flows back
Going forward, when your consented data is sold, the money comes to you — the majority,
always — settled through your own wallet. The extraction economy, inverted.
Say-doWe never claim "deleted" for a step we only
guided you to — every action reads confirmed, requested, or guided, honestly.
A reclaim is certified complete only when every door is confirmed shut.
Try it — link the firms you use (illustrative, nothing leaves your browser)
Extracted from you, per year$0
↳Speaks every standard. Depends on none.
Sovereignty and interoperability aren't a trade-off: open standards are how your identity
talks to the world, and independence is why it survives it. What conforms and what is ours is always
labeled — never blurred.
W3C · Spec-correct did:keyDID CoreEvery principal is natively a did:key
over its public key — byte-exact to the W3C test vectors, zero registry dependency. The
did:rosatrust method spec is drafted for publication.
W3C · Data-model shapedVerifiable Credentials 2.0Credentials and receipts carry a
VC 2.0 envelope any VC ecosystem can consume — with an honestly-labeled JCS-style proof suite, and
the record's own chain of proof intact beneath it.
FIDO Alliance · ShippedWebAuthn / FIDO2Hardware passkeys — Secure Enclave,
TPM, security keys — front our secured demos; content stays encrypted at rest beneath the passkey
factor.
OpenID · PKCE enforcedOpenID Connect + PKCE"Sign in with RosaTrust" is an
OIDC-patterned code flow — PKCE required, pairwise subjects, no client secrets to leak; one
integration for every partner.
NIST · Post-quantum readyFIPS 204 (ML-DSA)The suite registry runs Ed25519 and
ECDSA P-256 today and ML-DSA-65 — including hybrid classical+PQ signing — for the decade
ahead.
IEEE 2874-2025 · Adapter shippedSpatial WebHSML-shaped projection of principals,
domains and receipted activities — including sovereign AI agents with provable lineage. Formal
conformance targets the published test suite; the kernel stays sovereign beneath.
↳Developer & technical resources
Everything needed to build against RosaTrust — and to check our standards claims
against the running code.
Reference · publishingDeveloper ReferenceMethods,
runnable examples, and the principles your integration relies on. Dependency: cryptography.
Spatial Web · IEEE 2874 · publishingHSML CrosswalkHow RosaTrust
maps to the standard's vocabulary — Entity/Agent/Domain/Activity/Contract, the four dimensions,
SWID.
JSON-LD · liveHSML Profile ContextThe resolvable
@context every projected entity references — vocabulary map + the enforced principles.
Try itTrust Mesh · Banking MeshThe
interactive demos — the same kernel, offline-verifiable, running in your browser.
VerifyVerify an attestationCheck any
RosaTrust attestation against the registry root — offline, no account.
Open sourcePublic repositoryComing soon — the mechanism published openly; sovereign
key material and topology never leave our side.
Runs client-side with WebCrypto ECDSA P-256 — the same suite our hardware intermediates
use. No data leaves your browser.