Identity · the foundations of trust

Every fact has an author.
Every author, a name that belongs to them.

Beneath every span of the bridge lies the same foundation: self-sovereign digital identity — SSI, Self-Sovereign Identity. The model, a W3C standard, in which companies, people and machines own their own identity and their own attestations, present them when needed, and anyone can verify them with cryptography. Three words hold it up: SSI, DID, VC.

The three words

The wallet, the name, the attestation.

Company digital identity rests on three elements: a wallet the holder controls, a name anyone can resolve, and attestations signed by whoever has standing to issue them. These are public W3C standards, not formats of our own.

SSI

Identity in your own wallet

Self-Sovereign Identity: like the documents you carry with you — you own them, you show them, to whoever you decide. Digital identity stops living on someone else's servers and returns into the hands of its holder: company, person or machine.

DID

The digital name

Decentralized Identifier (a W3C standard): the name you introduce yourself with in the web of data. It is registered to you and publicly resolvable by anyone — like an internet domain, like a VAT number: yours, and recognisable by everyone.

VC

The signed attestation

Verifiable Credential: a digital attestation that carries the signature of whoever issued it — like a driving licence or a chamber of commerce certificate. Whoever receives it verifies it with cryptography, independently, at every presentation.

The digital name, for real · DID Document (did:web format, W3C standard)
{
  "@context": "https://www.w3.org/ns/did/v1",
  "id": "did:web:azienda-esempio.it",
  "verificationMethod": [{
    "id": "did:web:azienda-esempio.it#key-1",
    "type": "Ed25519VerificationKey2020",
    "controller": "did:web:azienda-esempio.it",
    "publicKeyMultibase": "z6Mkf…"
  }],
  "authentication": ["#key-1"],
  "assertionMethod": ["#key-1"],
  "service": [{
    "id": "#verifica",
    "type": "CredentialVerificationService",
    "serviceEndpoint": "https://verifica.azienda-esempio.it"
  }]
}
The digital name of a company, publicly resolvable on its own domain: signing key and verification service declared, readable by any compliant system. An illustrative example in the standard's format.
The life cycle

It is born, it is attested, it is verified.

Step 1

Creation

The cryptographic key pair is generated and the DID is published in a form anyone can resolve: from this moment the digital name exists, and it is registered to its holder.

Step 2

Attestation

Issuers — authorities, lead firms, your own company — attach signed verifiable credentials to the DID: qualifications, certifications, roles.

Step 3

Verification

Anyone checks authenticity with cryptography, independently: the check is mathematical and repeats, identical, at every presentation.

The triangle of trust

Who issues, who carries, who verifies.

The whole model fits in a triangle: an issuer signs an attestation, a holder keeps it and presents it, a verifier checks it with standard tools. Every exchange redoes the check from scratch: trust is a procedure that repeats, with its own proof, every time.

Issuer

Who signs the attestation

The certification body, the lead firm, the authority — or your own company towards its operators: whoever has standing to declare, signs. And the signature stays attached to the attestation, wherever it goes.

Holder

Who keeps it and presents it

The attestation lives with its holder and travels only when they present it: in full, or showing only what is needed — the qualification, without the rest of the file.

Verifier

Who checks, on their own

Valid signature, recognised issuer, intact attestation: the check is mathematical and local. The verifier gets their proof directly from the attestation in front of them.

Verification

The check is mathematical, and anyone can run it.

Verification asks trust of no one: it runs with standard tools, on the document in front of you. Whoever checks does not have to query our platform or take a declaration on faith — the attestation, the digital name of whoever signed it and cryptography are enough.

The signature

Who signed it

You resolve the issuer's digital name — its DID, publicly resolvable on the domain that hosts it — and check the signature against the key it declares. The issuer can be a certification body, a lead firm, or the company itself towards its operators.

The hash

Whether it is intact

You recompute the document's cryptographic hash and compare it with the one the signature covers. If even a single bit changed after signing, the check fails: the outcome is binary, there is no room for interpretation.

The status

Whether it is still valid

Credentials carry their own validity status: you check that they have not expired and that the issuer has not revoked them. Provisioned according to the W3C standard on credential status.

The attestation, for real · Verifiable Credential (W3C standard)
{
  "@context": [
    "https://www.w3.org/ns/credentials/v2",
    "https://www.w3.org/ns/credentials/examples/v2"
  ],
  "type": ["VerifiableCredential", "ConformityCertificate"],
  "issuer": "did:web:ente-certificatore.example",
  "validFrom": "2025-01-01T00:00:00Z",
  "validUntil": "2030-01-01T00:00:00Z",
  "credentialSubject": {
    "id": "did:web:azienda-esempio.it",
    "batch": "LOTTO-ESEMPIO-0001",
    "conformsTo": "EN 00000:0000"
  },
  "credentialStatus": {
    "type": "BitstringStatusListEntry",
    "statusPurpose": "revocation",
    "statusListIndex": "94",
    "statusListCredential": "https://ente-certificatore.example/status/1"
  },
  "proof": {
    "type": "DataIntegrityProof",
    "cryptosuite": "eddsa-rdfc-2022",
    "verificationMethod": "did:web:ente-certificatore.example#key-1",
    "proofPurpose": "assertionMethod",
    "proofValue": "z3Fk9…"
  }
}
A certificate of conformity bound to a production batch: who issued it, what it refers to, how long it holds and where the status check is provisioned. An illustrative example, with fictional identifiers.
The check sits with whoever verifies

The attestation carries everything needed to check it: the signature, the hash, the name of whoever issued it. Whoever verifies runs the check where they are, with standard tools, without asking anything of the supplier or of us. The check is local and mathematical.

On the bridge

This is how identity holds the bridge up.

The facts

Every event carries a DID signature

Every recorded stage is signed with the digital identity of whoever performed it — the operator, the machine, the supplier. Responsibility is by name and the proof travels inside the fact.

The certifications

Attestations become VCs

System and product certifications circulate as verifiable credentials: each with its issuer, its signature, its expiry — checkable at every step of the supply chain.

The machines

Sensors sign too

Machines and sensors have their own DID and sign the data they produce: the origin is certain, non-repudiation is mathematical, and the digital twin rests on attested measurements — not on copies of copies.

The people

Privacy by construction

Only digital identifiers travel in the immutable ledger; personal data lives in the master-data records, with its own rights. GDPR erasure has its exact point, provided for by design.

The foundations of portability

It is this identity — yours, standard, verifiable anywhere — that makes your digital assets portable and the passport a fact. The foundations hold up everything else.

Where the signature meets the fact: the engine →
What follows: the assets stay yours →