Skip to content

Prove someone.Reveal no one.

Your passport's chip proves far more than your age, and none of it reveals who you are. Agents already earn and settle alongside people. Only a proof tells the two apart.

See what it can prove
signing certificates
588signing certificates
issuing authorities
112issuing authorities
checks on every chip
4checks on every chip
documents we receive
0documents we receive

A digital ID that answers, rather than reveals.

Every identity check today works by handing something over: a photograph of the document, a date of birth, a scan filed in a database you will never see again. A passport can do more than that. It can answer the question, prove the answer is true, and never leave the device.

Select the question a counterparty is asking.

Are you over eighteen? Yes. Settled against a date of birth that is never transmitted.

Are you over eighteen?

On your phone

Type / code
Passport no.
Surname
Given names
Date of birthread here
Issuing state

In the chip

Issuer's signature
The chip's own key
asksproves

What they hold

Yes

Settled against a date of birth that is never transmitted.

In place of the eight opposite:

Whichever question is asked, eight things remain on the device and one answer crosses. Age is one of the five here, and one of many the document can settle.

Prove anything that is asked.

A counterparty is shown what it needs to know, and only that. Everything else remains on the device, so there is nothing for it to retain, sell, or lose.

They learn

That a real person is behind this

They never see

Your name, and every other page of the document

They learn

That you are over eighteen

They never see

Your date of birth

They learn

That you are entitled to work here

They never see

Your nationality, and the document that settles it

They learn

That the passport is genuine and yours

They never see

The document number

They learn

Which country issued it

They never see

The document itself, which never leaves your phone

The proof travels. The data does not.

A zero-knowledge proof lets the phone demonstrate that a statement is true without transmitting what makes it true. The verifier checks the mathematics and learns only the answer. There is no database of scans to leak, because there is no scan to send.

Custody remains with you.

The same identity holds a wallet. Face ID opens it, and no third party holds a key, including us. If the phone is lost, the passport and a recovery password restore the same address. Custody without a custodian.

A company can now be run entirely by software.

Agents already research, sell, deliver and settle. A firm whose work is done end to end by software still earns revenue and still creates economic value, at a speed and cost no human company can match.

That value should be taxed. It cannot be while nothing separates human activity from machine activity, because both reach a counterparty as the same string of characters. Tax was written on the assumption that a person sat at one end of the transaction.

The same proof that keeps a person private can carry a tax identity. A human identity and an AI identity, each provable, each distinguishable, neither disclosing who or what is behind it. Once the two can be told apart, different policies can apply to each.

Two senders, one counterparty

Today

A person
An agent
0x7a3f…9c21

One address, arriving twice. Nothing in it says which sender.

With a proof attached

A person
Human
0x7a3f…9c21

Policies written for people who earn and spend.

An agent
AI
0x51c8…3d0e

Policies written for machine labour, which can now be told apart.

Nothing here discloses a person or an operator. Only the addresses differs.

Told apart, without either being named.

Who is behind the activity

Human

A person, holding a passport a government signed.

AI

Software, and whoever deployed it.

What it can prove about itself

Human

A human tax identity, proved without disclosing the person.

AI

An AI tax identity, proved the same way.

What a counterparty sees today

Human

An address.

AI

An address.

Which policies can apply

Human

Policies written for people who earn and spend.

AI

Policies written for machine labour, which can now be told apart.

An agent can carry an identity of its own. It should not be able to carry yours, and at present nothing stops it.

None of it works unless the document is real.

A proof is only worth what stands behind it. There is a small chip in the front cover of your passport, and four checks run against it in order, each depending on the one before it.

  1. 1

    Read the printed page

    The camera reads the two machine-readable lines under the photograph. Check digits must agree before anything is accepted, so a misread cannot invent a document number.

    Nothing cryptographic yet.

    The two printed lines

    P<GBRSPECIMEN<<ANGELA<ZOE<<<<<<<<<<<<<<<<<<<

    9250764733GBR8501178F2201018<<<<<<<<<<<<<<02

    Five check digits, marked. All five have to agree.

  2. 2

    Open the chip

    Those printed lines are the key to the chip. Held against the phone, the passport opens an encrypted session over NFC and hands over the data groups it will share.

    The phone is connected to a genuine contactless document.

  3. 3

    Check the signature

    Every data group is hashed against the security object the issuing country signed, and that signature is chained back to a country signing certificate in the app's trust store.

    The data is intact and the United Kingdom signed it.

  4. 4

    Prove it is not a copy

    The app sends the chip a challenge it has never seen and asks it to sign. A cloned chip can replay data it copied. It cannot produce this signature.

    This is the original document, not a duplicate.

It will not show a badge it has not earned.

Every check reports its own result and the overall verdict is capped by the weakest one, so a camera scan can never rank above Unverified, however clean the read was. That ceiling is enforced by a test rather than by good intentions.

Coverage is published the same way. Where an authority still signs with an ageing algorithm, documents under it are capped at Partly verified, and stated as such.

588 marks: one for each signing certificate the app carries, from all 112 issuing authorities. Nothing here is rounded up.

  • Verified

    The chip is genuine and the issuing country signed it.

  • Partly verified

    The data is intact, but the signer could not be traced to a country.

  • Unverified

    Read from the printed page. Nothing has been proven cryptographically.

  • Not verified

    A check failed. Treat the document as suspect.

On the phone, today.

The passport is read once and kept encrypted on the device under a passcode that is never stored. After that the app answers on your behalf, without reopening the document to anyone.

The app's verification screen: a chip read marked VERIFIED, with a list of what was proven and one item that could not be read.

The document, checked

Every check reports separately, including the two files reserved for border control that the app is not permitted to read. It reports the unticked box rather than rounding up.

The app's age screen, proving the holder is over eighteen.

One claim, proved

Age was the first claim built, because it is the easiest to check against. The same proof carries any other fact the document can settle, and discloses none of them.

The app's wallet screen: unlocked with Face ID, showing a recoverable address written in passport machine-readable format.

An address you hold

Face ID opens it day to day. If the phone is lost, the same address returns from the passport and a recovery password together.

Early accessis a small number of phones.

iPhone only. Seats are released in batches as TestFlight builds are ready.

A name and an email address. Nothing else.

How those two are handled