For business
Verify more. Hold less. Be liable for almost none of it.
A credential your customer already holds can be checked properly, every time, by your own code. The data you never stored is data you can never lose, never have to defend, and never have to report.
Every promise on this page names an entry in the public capability register, and where an entry is not live the state is printed beside the claim rather than filed away somewhere else.
01
Accept a check that was already done properly
The same identity check is repeated from scratch at every bank, insurer, telecom and landlord, and each repetition creates another copy to defend.
A credential issued over open standards can be presented to you and checked on its own merits — issuer, integrity, expiry and status — with the holder disclosing only the fields your check actually needs.
What is real here
- Live Issue credentials over OID4VCI as SD-JWT VC — the same wire any standards-compliant wallet already speaks.
- Live A holder can prove a single claim — over 18, licensed, employed — without revealing the rest of the credential.
- Live Anyone can verify an ORBIS credential without registering, paying, or asking permission.
02
A credential cannot be photoshopped
A document photo is a picture of a claim. A credential is the claim itself, signed, with a published key you can resolve yourself.
A withdrawn credential stops verifying on the next check, and the issuer does not learn that you were the one checking.
What is real here
- Live A revoked credential stops verifying, without the issuer learning where or when it was checked.
- Live Anyone can verify an ORBIS credential without registering, paying, or asking permission.
- Live A zero-dependency library that checks ORBIS credentials in Node or a browser, and performs no network calls of its own.
03
Minimisation stops being a policy and becomes an architecture
The cheapest way to survive a breach is not to hold the data. When a holder proves a single fact rather than surrendering a document, the record that would have leaked was never assembled.
What is real here
- Live A holder can prove a single claim — over 18, licensed, employed — without revealing the rest of the credential.
04
Workforce and contractor authority that expires
Right-to-work, qualifications, professional licences and contractor scope can each be issued as a credential with an expiry, so access ends when the engagement does rather than when someone remembers.
If it ends early, it is withdrawn and the next check sees it.
What is real here
- Live Issue credentials over OID4VCI as SD-JWT VC — the same wire any standards-compliant wallet already speaks.
- Live A revoked credential stops verifying, without the issuer learning where or when it was checked.
- Live A holder can prove a single claim — over 18, licensed, employed — without revealing the rest of the credential.
05
Check it yourself, in your own process
A published library performs the whole validation chain in your own runtime, with no network call back to ORBIS, so an outage here is not an outage in your onboarding.
A public set of conformance vectors lets you prove your own verifier accepts what it should and refuses what it should not — including the failures, which is the half most test suites skip.
Credential events can be delivered to you as signed webhooks with retries and a dead-letter queue.
What is real here
- Live A zero-dependency library that checks ORBIS credentials in Node or a browser, and performs no network calls of its own.
- Live Sixteen public test vectors let anyone prove their verifier accepts what it should and refuses what it should not.
- Live Subscribe to credential events over HMAC-signed webhooks, with retries and a dead-letter queue.
- Live Anyone can verify an ORBIS credential without registering, paying, or asking permission.
06
Getting an integration to production
Two parts of the partner path are not finished, and the states printed with this section are the whole truth about them.
The first is the scored exercise an integration passes before go-live. The second is minting and rotating your own API keys inside limits an operator granted you — until that lands, every key is issued by an ORBIS operator, so plan for a human in that loop.
What is real here
- Partial A partner integration is exercised against a set of scored checks before it is allowed into production. Partial — built and wired; no end-to-end run yet.
- Partial A partner can mint, rotate and revoke their own API keys within limits an operator granted them. Partial — a partner can issue and revoke their own keys through the portal; an operator still attaches the grant first.
07
How the platform underneath is operated
Signing keys are moving to a hardware-backed vault, issuer by issuer, with the current count printed in the register rather than rounded up in prose.
Moving or rotating a signing key is composed by one operator and approved by another, and the whole ceremony is recorded. A sole-operator override exists for small teams; it requires a typed confirmation, writes its own audit event, and marks the record permanently.
Errors, unresponsiveness and degraded response times raise an alert. No service-level agreement is offered and no uptime figure is published — alerting is not an SLA and this site will not blur the two.
The deployment reports the exact commit it is running, so it can be compared against source.
What is real here
- Partial Issuer signing keys live in Azure Key Vault, and the platform signs by calling the vault rather than holding the key. Partial — two of fifteen issuers today.
- Live Moving or rotating a signing key is composed by one operator and approved by another, with the whole ceremony recorded.
- Live Server errors, an unresponsive service and degraded response times raise an alert.
- Partial The deployment reports the exact commit it is running so it can be compared against the source. Partial — commit reported; signed attestation unavailable.
08
Machines and agents
The idea: delegate bounded authority to a device or an autonomous agent, with a scope, an expiry, and a withdrawal anyone can verify.
There is no device layer in the platform today. The state is printed with this section; read it before it reaches a roadmap slide.
What is real here
- Planned Give a device its own credential so what it reports can be trusted and attributed. Planned — nothing is built today.
09
What this page does not claim
The content master proposed several commercial promises this register cannot support, so they are absent: consent as a signed, revocable, auditable object; supplier and product-passport assurance checked against a named trust registry; and a "Sign in with ORBIS" flow. There is one published SDK — the verifier — not a family of them.
No figure is given for drop-off, cost per verified customer, fraud losses, or onboarding time. The master proposed those numbers without a source or a date, which is the one thing that disqualifies a number from appearing at all.
No compliance certification is claimed anywhere on this site. Aligned with is not certified under, and the difference is not decorative.
Straight answers
Questions people actually ask.
Why would we accept a credential instead of collecting the document?
Because holding the document is the liability. The insight you wanted survives the check; the record you would have had to store, control, audit, insure and eventually disclose does not.
What is not production-grade yet?
The capability register answers this directly, with four states and the evidence behind each. It is the same register the engineers work from, updated when something changes state in either direction — not a roadmap written for buyers.
Do you hold a certification we can rely on for our own audit?
No certification is claimed on this site. What is offered instead is checkable: public conformance vectors, an installable verifier, and a deployment that reports the commit it is running.