For cities
You cannot secure what you cannot prove you own.
Unclear asset inventories, standing vendor access that outlives the contract, and vendor portals nobody can prove are complete. The proof layer that would fix it is described here honestly, including the large part of it that does not exist yet.
Every promise on this page names an entry in the public capability register, and where an entry is not live the state is printed beside the claim rather than filed away somewhere else.
01
Start with what is actually true today
Nothing about devices is built. There is no device enrolment, no device credential type and no device key custody in the platform, and this page opens with that rather than closing with it.
What is real is the layer underneath: issuing a credential over open standards, letting a holder disclose one field rather than a document, withdrawing a credential so the next check fails, and letting anyone verify without an account. Everything below is either built on that or is named as not built.
What is real here
- Planned Give a device its own credential so what it reports can be trusted and attributed. Planned — nothing is built today.
- Live Issue credentials over OID4VCI as SD-JWT VC — the same wire any standards-compliant wallet already speaks.
- Live A holder can prove a single claim — over 18, licensed, employed — without revealing the rest of the credential.
- Live A revoked credential stops verifying, without the issuer learning where or when it was checked.
- Live Anyone can verify an ORBIS credential without registering, paying, or asking permission.
02
A register of what the city owns
The idea: every city-owned device carrying a verifiable ownership credential, so compliance evidence becomes a query instead of a spreadsheet nobody can prove is complete.
Read the state printed with this section. It is the difference between a plan and a procurement.
What is real here
- Planned Give a device its own credential so what it reports can be trusted and attributed. Planned — nothing is built today.
03
Authority that ends when the contract does
Shared logins and standing vendor access outlive the contracts that justified them, and are named repeatedly in sector threat reporting as a structural failure rather than an accident.
The mechanism that replaces them is real for people and organisations: a credential with a scope and an expiry, disclosed field by field, withdrawn the moment the engagement ends. Binding that authority to a specific municipal asset is the part that depends on the device layer named above.
What is real here
- Live Issue credentials over OID4VCI as SD-JWT VC — the same wire any standards-compliant wallet already speaks.
- Live A holder can prove a single claim — over 18, licensed, employed — without revealing the rest of the credential.
- Live A revoked credential stops verifying, without the issuer learning where or when it was checked.
- Planned Give a device its own credential so what it reports can be trusted and attributed. Planned — nothing is built today.
04
Procurement you can walk away from
A vendor platform that holds the estate for the asset's life is a migration waiting to happen. Credentials issued over published standards are checkable by anyone, with the checking library and the conformance vectors both public, so a supplier change stops being a data migration.
The deployment also reports the exact commit it is running, so the service a city depends on can be compared against its published source.
What is real here
- Live Issue credentials over OID4VCI as SD-JWT VC — the same wire any standards-compliant wallet already speaks.
- Live Sixteen public test vectors let anyone prove their verifier accepts what it should and refuses what it should not.
- Live A zero-dependency library that checks ORBIS credentials in Node or a browser, and performs no network calls of its own.
- Live Anyone can verify an ORBIS credential without registering, paying, or asking permission.
- Partial The deployment reports the exact commit it is running so it can be compared against the source. Partial — commit reported; signed attestation unavailable.
05
One proof, reused across the counters
Residency, address and eligibility are proved again at housing, at benefits, at permits, at waste and at transport — each time producing another copy for the city to hold and defend.
A resident can instead prove the single fact each counter needs, and the counter can check it without holding anything afterwards.
What is real here
- Live A holder can prove a single claim — over 18, licensed, employed — without revealing the rest of the credential.
- Live Issue credentials over OID4VCI as SD-JWT VC — the same wire any standards-compliant wallet already speaks.
- Live Anyone can verify an ORBIS credential without registering, paying, or asking permission.
06
A city does not have to bet the estate
Phase one is a citizen-services flow — proving residency or eligibility at one counter — because that runs entirely on capabilities that exist today.
Phase two is contractor authority as scoped, expiring credentials, which is real for people and partial for assets.
Phase three is one asset class in a device register, which is not built. Sequencing it last is the honest order, not the cautious one.
What is real here
- Live A holder can prove a single claim — over 18, licensed, employed — without revealing the rest of the credential.
- Live Issue credentials over OID4VCI as SD-JWT VC — the same wire any standards-compliant wallet already speaks.
- Live A revoked credential stops verifying, without the issuer learning where or when it was checked.
- Planned Give a device its own credential so what it reports can be trusted and attributed. Planned — nothing is built today.
07
What this page does not claim
The content master proposed a citizen consent rail producing evidence-grade input to a digital twin, and a promise of alignment with the interoperability mechanisms European cities are standardising on. Neither has a register entry, so neither is claimed here.
Statements about cybersecurity, data and procurement obligations are a reading of the regulatory direction, not legal advice, and a city should take its own. No penalty figure, deadline or obligation count appears, because the master supplied none of them with a source and a date.
No pilot, reference city or partner is named. There is none to name, and implying one before it exists is the fastest way to lose a public-sector buyer permanently.
Straight answers
Questions people actually ask.
Is the device register something we could procure this year?
No. The register entry for device identity records that nothing is built — no device enrolment, no device credential type, no device key custody. It is published so the idea can be evaluated in public, not so it can be bought.
What could a city run today?
The citizen-facing half: proving a single fact at a counter, checked without an account, withdrawn when it stops being true. Each capability behind that carries its own register entry and evidence.
Is any of this legal advice about our obligations?
No. Regulatory statements on this site are a design position and are labelled as one. A city should confirm its own obligations with its own counsel.