TRUST · THE EVIDENCE LAYER
Every claim, its real state, and the thing that proves it.
Almost nobody in this industry publishes the rows that say no. Those are the ones worth reading first — so this section leads with them, links the endpoint that settles each one, and prints the date it was last checked beside it. If a row here is wrong, it is falsifiable in one fetch, and we would rather be told than be right by default.
This section is a register, not a brochure.
Everything else on this site makes an argument. This section carries the receipts for it. Ten pages, one discipline: a claim is written down, given a state that comes from a measurement rather than from a meeting, and pinned to an artefact you can open. Where the measurement has not been taken, the page says the measurement has not been taken.
The four words, and what each one costs you.
The register uses exactly four states, spelled here the way the data spells them. No rounding up, no fifth word for "nearly".
live- It works on the cell serving this page. The linked endpoint answers right now. Open it.
partial- Part of it works, and the row says which part. Usually: the machinery is implemented and tested, but one link in the chain is not yet witnessable end to end.
planned- Built elsewhere in ORBIS, not carried into this rebuild. It has run before. It does not run here.
not-yet- It does not work. Nothing on this site pretends otherwise. The row names the endpoint that fails and what that costs you today.
A compliance posture nobody can check is a leaflet.
Ten pages, and what each one is for.
- The register — every claim in one wall, filterable, with a link straight to any single row.
- Standards — one row per standard, including the ones we do not meet, each stating what the standard demands and what the cell actually answers.
- Regulations — the law, and specifically what it does not require of us. We are not going to borrow its authority.
- The clock — the legal deadlines, counted against your own device clock, each with its citation and the correction against the common misreading.
- How we compare — six axes against five other vendors. Three of the six are axes we lose, and they are printed first.
- What we withdrew — claims we published, re-checked, and took back. Most of them cost us something.
- Security — how to report a flaw, what happens next, and the certifications we do not hold.
- Architecture — what this system can see about you, and what it structurally cannot.
- The Declaration — the founding document, scored against what the running system actually proves.
Served by the cell that rendered this page.
Open any of them. Each was probed for this build; a link that did not answer is not printed at all, rather than printed and broken.
- /.well-known/did.json the trust anchor, resolvable from any machine
- /conformance/vectors the vectors this platform holds itself to
- /openapi.json the route census, generated from the live route table
- /status/1 the signed status list a verifier fetches
Probed 2026-08-30.
Before you go any further.
The register this site reads from is not the platform's own capability register — it is this site's copy of it, and it is being filled in from measurement rather than from memory. That means it is currently short, and the honest thing to do about a short register is to say how short.
- LIVE Publishes deterministic vectors a third party can recompute offline to check their implementation against ours conformance-vectors
- PLANNED A wallet a person installs from an app store. wallet-native You cannot hold a credential on a phone you own. Everything a person would do with a proof waits behind this.
The register holds 17 live · 2 partial · 2 planned · 5 not yet.
4 of the 6 capabilities this page depends on have no row in the register yet, so this page will not print a state for them. They are named rather than dropped, because a slice that silently shortens itself is the same defect as a claim with no receipt.
- did-web-anchor
- vc-issuance
- revocation
- generated-contract
The register route serves, but it carries no row for these yet. List what it does carry:
curl -s https://id.orbis.id/api/site/register | jq -r '.entries[].slug' This build reads 26 register rows · 17 live · 2 partial · 2 planned · 5 not yet.
Straight answers.
- Are you certified?
- No. ORBIS holds no verifiable-credential conformance certification, no ISO 27001, no SOC 2, and has commissioned no published third-party code audit. Every one of those is a separate process run by somebody else, and none has been completed. What we do hold is on the security page.
- Who checked these states?
- Each register row carries the method that established it and the date it was established, and both travel with the row wherever it is shown — including in the chip’s tooltip. A state with no method is not a state, and the build refuses it.
- What happens when a row is wrong?
- It gets withdrawn in public, with what it stood as, what re-checking found, and what we publish instead. Fourteen of those are on the record.
- Does a deadline on the clock page create a duty on you?
- Mostly not, and the page says which. eIDAS binds member states and the parties who must accept a wallet. It does not bind us. The regulations page draws that line explicitly.
Do not trust us. Check us.