Skip to content
Human rights. Public networks. Private proof. For people, AI agents and devices Wallet Alpha v1.0 · Working proof of concept

Prove what matters.
Keep your identity yours.

We’re building .zkdns: a public network for decentralised DNS and private proof. With .zkdid, your digital root stays under your control. Share the proof that matters, keep your personal information private, and carry your trust beyond any single app.

Explore the working Alpha
Prove only what is needed Keep personal data private No protocol token Sovereignty is the mission Public-good infrastructure
Start here

Identity without oversharing, explained simply.

Discover how a proof can answer a specific question—such as “over 18?”—without handing every service a copy of your identity document.

One useful fact No raw documents shared Privacy stays with you
ZKdude brain emblem
Meet ZKdude · Your guide to the mission

Big questions? Meet ZKdude.

New to zero knowledge? Curious about sovereignty? Ask ZKdude to explain the project in your language, at your pace.

Explain the ideaExplore the architectureQuestion the assumptions
Choose a question, then open ChatGPT.
The simple idea

Prove the fact, not your entire identity.

Today, one small question can mean handing over an entire identity document. Zero-knowledge proofs offer a different way: prove the relevant fact and keep the underlying evidence private. .zkdid® is being built to give that proof a root you control.

Think of it like this
“Show a green tick, not your passport.”

A service should learn whether its requirement is met. It should not automatically learn your full name, date of birth, document number and everything else about you.

The conventional approach

Upload your identity document

An age check can reveal far more personal information than the question requires.

Full name Exact date of birth Nationality Document number
A document full of personal information
The proposed .zkdid® approach

Approve one private proof

Your wallet uses an accepted credential to answer the specific request.

Requirement Age requirement met

Threshold proved · Source details private · Illustrative example

One relevant result disclosed
The problem today

We reveal far more than we need to.

Every copied document creates another database that must be trusted, secured and governed fairly.

  • The same passport or personal details are copied into many systems
  • A data breach can expose information that cannot simply be changed
  • One platform may control access, recovery and continuity
  • People are asked to trust organisations they cannot inspect
  • AI impersonation makes reliable proof increasingly important
Why a shared trust root matters

One open way to find and verify trust.

DNS helps you find a website. .zkdns™ is being developed to find and verify trust. A .zkdid® root provides continuity and control, so changing an app need not mean starting your digital life again.

Your keys stay with you Proof replaces oversharing Many services, one open root
With .zkdid®

Portable proof under your control.

.zkdid® aims to make trust reusable across services while keeping the person, not a platform, in control of the keys and evidence.

  • Prove a requirement without exposing the source document
  • Preserve continuity across compatible tools and services
  • Delegate defined authority to agents and devices
  • Use open rules and auditable public infrastructure
Your proof. Your keys. Your identity.
Holder-controlled roots Optional assurance AI-agent accountability Trusted devices Self-sovereign identity
Why decentralised DNS matters

Your root. Shared trust.
A network built for sovereignty.

.zkdns™ is the decentralised DNS and trust-resolution protocol. .zkdid® is its identity namespace. Together, our aim is a public network where no single company or government can own the directory of who gets to exist online. Your root comes first. Optional assurance adds a claim; it must never become permission to exist.

01
Your root

Start with continuity and control. A passport, wallet provider or blockchain must not own your root.

02
Decentralised resolution

.zkdns is being built to find and verify records without one company owning the directory.

03
Optional assurance

Add a specific claim when it is useful. Root control and assurance remain separate.

04
Private proof

Prove a defined requirement. The service applies its own access rules above the root.

Four roles, one trust system

A shared network. A root that stays yours.

Your root carries control. .zkdns resolves trust. Assurance supports a specific claim. Zero knowledge can keep the underlying evidence private. These are separate roles, working towards one open foundation.

Your rootCarries control dDNSResolves roots AssuranceAdds a claim Zero knowledgeProtects privacy
A service checks its own requirements
Valid proof · Requirement metService may grant access
×Invalid proof · Requirement unmetService may decline access
01

Control begins with the holder

Root creation, continuity and controller authority sit below optional assurance. External systems may support the protocol without becoming sovereign over it.

02

Trust should be independently verifiable

Compatible services should be able to find records and check their authority through .zkdns. Public-network operation is still being developed.

03

Assurance is a separate layer

The Alpha can add passport assurance through ZKPassport. That is an optional claim, not a tradeable token or the source of your right to a root.

04

Proof reveals only a defined fact

The network should carry what needs to be verified while the personal evidence stays under your control. Privacy belongs in the infrastructure.

Your rootcontrols + dDNSresolves + Assurancesupports + Zero knowledgeprotects = Verifiable trustshared, private and harder to capture
Why root control and proof of personhood stay separate
A passport proof ≠ global human uniqueness

The Alpha demonstrates a passport-assurance journey. It does not yet prevent every duplicate enrolment or establish one human, one root across providers. Those limits are part of the research.

Decentralised by ambition. Tested in a private lab.

.zkdns and .zkdid are protocol-native names under development, not delegated public Internet DNS top-level domains. The working Alpha is not yet a public production network.

See it step by step

Your root. Your proof.
See it come to life.

Meet the native iPhone Alpha. Create your root, add optional passport assurance, see the separate checks, and save an encrypted backup. Tap through the app journey below. These are illustrative screens; your identity stays out of this website.

Your root comes firstRoot control exists separately from passport assurance.
See each check clearlyRoot control, membership and assurance are separate results.
A real iPhone interfaceThe working Alpha pairs the app with your Mac.
Continuity you can carrySave and restore encrypted holder state in the Alpha.
Step 01 / 08

Your root comes before an identity check.

Create a root you control. In this Alpha, the iPhone guides you and the paired Mac holds the cryptographic keys. You can add passport assurance later; it is optional.

Tap or swipe the phone. Use the arrows to go at your own pace.

What’s proven?
Working Alpha v1.0

Built in the lab.
Building towards everyone.

Root creation, passport assurance, resolution and encrypted backup now form a working iPhone journey. The next work takes privacy and resilience deeper into the network.

Explore the Alpha: what’s demonstrated and what comes next
Demonstrated in the lab

The connected Alpha journey

  • Root creation through the iPhone interface
  • Live ZKPassport / NFC + strict FaceMatch
  • Root, membership and assurance checks
  • Encrypted holder export and restore
The current privacy boundary

Attributes stay out. Metadata remains.

The documented assurance flow shares no civil or passport attributes with the .zkdid adapter. Resolver nodes still process the opaque root and controller public material. Network metadata is not hidden.

Still to be established

What comes before public use

Cold recovery, global human uniqueness, duplicate-enrolment resistance and production security are not established. The current Mac bridge uses HTTP; the Alpha is for supervised private-lab use.

Architecture direction

A shared foundation.
A root nobody owns for you.

Root control, assurance and application permission do different jobs. A service may decide what you can do inside its app. It should not decide whether your underlying root may exist.

Services & policyWhat may this person, agent or device do here?
.zkdns™ · Resolution & proofFind the records. Check the authority. Verify the claim.
.zkdid® · Holder-controlled rootsYour continuity and control, below service-level permission.
Trust boundary explorer

See what .zkdid® keeps separate.

Tap a glowing node to explore its role. Keeping these boundaries separate helps stop one provider from becoming the owner of your whole digital life.

.zkdid® trust root active
Identity existence

The root should remain resolvable as infrastructure, not become a switch one institution can use to erase participation.

Scoped proof

Proofs should disclose only what a request needs. The Alpha keeps civil attributes out of its assurance result, while root and network-metadata privacy remain unfinished.

Policy above the root

Apps and institutions can set access rules higher up, while the trust anchor itself stays neutral and auditable.

Capture resistance

The mission is open-source public infrastructure with no protocol token and no founder, company or government holding a universal root override. The stewardship model still needs evidence and review.

A working Alpha. The next frontier.

The app is the beginning.
The network is the frontier.

The private-lab proof of concept is a milestone. The next direction is privacy beneath the app: how trust is resolved, how requests travel, and how continuity survives change.

01Alpha demonstratedReal iPhone flow, passport assurance, resolution and encrypted holder portability.
02Private resolutionResearch transport privacy and decentralised clients. Tor/onion services remain a candidate.
03Resilience & reviewCold recovery, duplicate-enrolment resistance and independent security review.
04Public-good infrastructureOpen implementations, independent operators and shared stewardship. A network built to belong to everybody.
Human rights need public infrastructure

Privacy is a human right.
Sovereignty should be infrastructure.

The freedom to participate online should outlast any app, device, company or government. That is why we are building .zkdns and .zkdid as open-source public infrastructure: no protocol token, no single owner of the root, and privacy designed into the fabric. Build it for people. Give it to the public.

01

Private holder

The holder controls the root. Tools and controllers should be replaceable.

02

.zkdid® root

Continuity and controller authority remain separate from service policy.

03

Scoped verifier

A service verifies the relevant proof and applies its own scoped rules.