ORBIS.ID · COMPANY
A trust company that can be checked.
Everything on this site carries its real state, and every state links the thing that proves it. This page holds the company to the same rule as the product — which means it prints the facts about us that are missing, in the place where they belong, with what each absence costs you while it lasts.
The one thing this page is about.
You are being asked to route something that matters — an identity, a licence, a proof of age — through infrastructure run by people you have never met. This page is the part of that question we can answer today, and the part we cannot.
What this company does, in one sentence.
An organization that already knows something about a person signs it once. The person carries that signed answer on their own phone. Anyone who needs to know can check it, without an account and without asking the organization that signed it. ORBIS.ID builds and runs the rail that makes those three things fit together, and publishes the state of every piece of it.
Three roles, never merged: someone vouches, someone holds, someone checks. Collapsing any two of them rebuilds a login provider — a company that sits in the middle of a person's life and watches. Everything this company refuses to build, it refuses for that reason.
The facts about us that are not published yet.
A trust company with no named entity is the largest single gap on this site, and it is a gap in the owner's court rather than in the code. Rather than leave the section out — which would read as an oversight — here is the shape of it, row by row.
- Legal entity
- not published yet
- You cannot name a counterparty in a contract, and you cannot look us up in any company register. A procurement process stops at this row.
- Jurisdiction of registration
- not published yet
- You cannot tell which courts, which regulator, or which data-protection authority we answer to before you send us anything.
- Registration number
- not published yet
- There is nothing for you to check the two rows above against. A name without a number is a claim; a number is a receipt.
- Named accountable person
- not published yet
- There is no human on this page you can hold to what it says. For a public-sector buyer that is a hard stop, and it is the second thing this page owes you.
- Postal address
- not published yet
- You cannot serve us, and you cannot write to us on paper. This row follows the entity in — an address for an unnamed company would not be worth printing.
These are five blanks, not five state words. A state word on this site is generated from the register and links the measurement behind it; the company's own registration is not a platform capability and has no register row, so it gets a blank that says so rather than a chip that would imply somebody had checked something. The rows fill in the day the entity is supplied, and the footer's legal line — which is missing for exactly the same reason — fills in with them.
We are not going to write something that sounds right in the meantime. A company whose entire argument is do not trust us, check us does not get to type its own registration number.
What we cannot do to you.
The interesting facts about an identity company are not its promises. They are the operations it is unable to perform. A person's key is generated inside their own device and never leaves it, so there is no request we can make of the system that returns it. Checking a proof needs no account and no key, so there is no authenticated seam on that path where we could build a record of where you verified — the privacy property and the price come from the same fact.
Custody is an operation we cannot perform, not a promise we make. That is a weaker sentence than the one a competitor would write, and it is the only one that survives a hostile reading.
Check us instead.
This page is words. Everything under it is a machine you can question directly. None of these need an account, a key or our permission.
curl -s https://id.orbis.id/.well-known/did.json | jq .
curl -s https://id.orbis.id/.well-known/security.txt
curl -s https://id.orbis.id/openapi.json | jq '.info'
curl -s https://id.orbis.id/conformance/vectors | jq 'length'
curl -s -o /dev/null -w '%{http_code}\n' https://id.orbis.id/readyz - /.well-known/did.json — the keys this platform signs with, published at its own name.
- /.well-known/security.txt — where to report a problem, served by the machine rather than promised by a page.
- /conformance/vectors — the test set. Point any implementation at it and prove us right or wrong without using our code.
Each of these answered a probe from this build. Links to destinations that did not answer are not rendered anywhere on this site.
Before you go any further.
The state of every capability this company runs is published, including the ones that say no — and the register is the only place a state word on this site is allowed to come from. This is the slice that bears on the company itself rather than on any one product.
The register holds 17 live · 2 partial · 2 planned · 5 not yet.
5 of the 5 capabilities this page depends on have no row in the register yet, so this page will not print a state for them. They are named rather than dropped, because a slice that silently shortens itself is the same defect as a claim with no receipt.
- build-attestation
- security-txt
- audit-chain
- permissionless
- did-web-anchor
The register route serves, but it carries no row for these yet. List what it does carry:
curl -s https://id.orbis.id/api/site/register | jq -r '.entries[].slug' Straight answers.
- Who owns ORBIS.ID?
- Not published yet — see the rows above. The ownership and the registered entity are the same missing fact, and this page will not guess at either.
- Can you read my credentials?
- No. The signing keys for an organization live in a key vault the platform calls but never exports, and a person’s own key is generated inside their device and never leaves it. There is no operation in the system that hands us a private key, which is a narrower and more honest claim than saying we would never look.
- Is any of this audited by someone other than you?
- No. No external audit, no certification, no attestation by a third party. What exists instead is that every claim on this site names the endpoint that produces it, so you can run the check yourself rather than trusting an auditor we chose and paid.
- What happens to what I hold if this company disappears?
- A credential you already hold keeps verifying, because checking it needs the signature, the issuer’s published key and the status list — not us. What stops is issuing new ones and publishing new revocations. That is the honest shape of the risk, and it is why the exit terms are published before the sale rather than after it.
- How do I report a security problem?
- security@orbis.id, published in the cell’s own security.txt rather than only on this page, so the route survives a redesign of this page.
Do not trust us. Check us.