Architecture
The Protocol.
Structure
Structure.
Design Principles
Built for sovereign, long-term deployment.
Implementations operate within sovereign infrastructure, independently of external network dependencies, cloud services, or third-party key management.
All security guarantees are grounded in hardware attestation. Software-only implementations are not conformant with any Foundation specification.
All cryptographic primitives are selected for long-term security against quantum-era adversaries.
Proof objects and ledger credentials are compatible with any public or permissioned ledger.
Different implementations produce compatible proof objects under consistent governance and verification rules.
Hardware-enforced zeroisation upon proof object generation is a protocol-level requirement. No implementation retains raw data after processing.
Interoperability
Designed for integration.
| Standard | Domain |
|---|---|
| HL7 FHIR | Health data exchange |
| GA4GH | Genomic data sharing |
| W3C DIDs / VCs | Decentralised Identifiers and Verifiable Credentials |
| X.509 (RFC 5280) | Public-key infrastructure |
| PKCS#11 / CMS (RFC 5652) | Cryptographic interoperability |
| ERC-5192 / EIP-4973 | Non-transferable on-chain credential standards — or equivalent |
| HIPAA | Health data privacy — United States |
| GDPR | Data protection — European Union |
| ISO 27001 / 27701 | Information security and privacy management |
| NIST SP 800-53 | Cryptographic and security controls |
| ISO/IEC 30107 | Biometric Presentation Attack Detection |