ORBIS.ID
You are on Anyone PUBorbis.id

HOLD · WHAT THIS IS FOR A PERSON

The answer is smaller than the question.

You photographed your passport again this month. Someone needed to know one thing about you. They now hold your name, your face, your address and your date of birth, forever. They wanted a yes.

See the consent screenWhat is real today

One sentence, before anything else.

A wallet on your phone holds answers other people have already signed, and lets you send one answer at a time — so the person asking learns the thing they asked and nothing else.

Prove one thing without revealing five.

Over eighteen without your birthday. Resident without your street. Employed without your salary. Insured without your policy number. Qualified without the certificate that has your home address printed at the bottom of it.

Illustration · a credential, drawn

  • over_18 shared
  • full_name never sent
  • date_of_birth never sent
  • home_address never sent
  • document_number never sent

What the person asking received: 0 bytes of you.

They asked whether you are over eighteen. That is the whole answer they got.

Nobody accumulates you.

What happens today

You upload a photograph of your identity document to a company you will deal with once. They keep the file. It sits in a database you cannot see, is copied into a backup you will never be told about, and travels with the company when it is sold. When it leaks, the loss is yours and it is permanent — you cannot change your date of birth after a breach the way you change a password.

What happens with ORBIS

The database that never received your address cannot leak it, cannot sell it, cannot be subpoenaed for it and cannot lose it in an acquisition. Data minimisation stops being a policy somebody promises and becomes a property of the message.

The keys are yours, and we cannot take them.

The key that makes it work is created inside your phone's security chip and physically cannot be copied out. Not by a thief, not by the website, and not by us. We are not being generous. We built a system in which we do not have the ability.

Custody is an operation we cannot perform, not a promise we make.

You see exactly what you share.

One screen, five questions, in every language we ship: who is asking, what for, exactly what will be sent, what stays, and for how long. No pre-ticked boxes. No "manage preferences". You approve a specific request or you do not.

That screen has a page of its own, drawn field by field, with the words that appear on it. See the consent screen.

It can be taken back, and that is public.

A qualification that was revoked stops checking out — everywhere, at once, without anyone having to tell the places you showed it. And the list that says so is signed, so nobody can quietly un-revoke something either.

The list works by having the person checking fetch the whole thing and read its own bit, so whoever issued your proof never learns which one was being checked. The privacy comes from the shape of the answer, not from a promise.

Your account is small on purpose.

An ORBIS account is a key fingerprint. Not a row with your email in it. There is no password — you cannot lose a password you were never issued. Export is one call. Erasure is one call, and it happens on the spot: no ticket, no reviewer, no thirty days.

An account with no password · Export, erase, and the two endpoints

Now the honest part, before you go looking for it in an app store.

There is no ORBIS app you can install today. The wallet runs on the web and it works, but getting back in after losing your device is not built, and the app-store version is not built. We would rather you closed this page than believed otherwise.

One wallet, one device. If you lose the phone today, you lose what is on it. Do not plan around a recovery path that does not exist yet.

When the app ships, this page changes on the same day, and the register changes state with it.

These are the six pieces this page leans on. Every one of them carries its real state and the thing that proves it — including the pieces that say no.

  • PLANNED A wallet a person installs from an app store. wallet-native You cannot hold a credential on a phone you own. Everything a person would do with a proof waits behind this.

The register holds 17 live · 2 partial · 2 planned · 5 not yet.

5 of the 6 capabilities this page depends on have no row in the register yet, so this page will not print a state for them. They are named rather than dropped, because a slice that silently shortens itself is the same defect as a claim with no receipt.

  • wallet-web
  • account-recovery
  • holder-portal
  • selective-disclosure
  • revocation

The register route serves, but it carries no row for these yet. List what it does carry:

curl -s https://id.orbis.id/api/site/register | jq -r '.entries[].slug'

Straight answers.

What happens if I lose my phone?
Today, you lose what was on it. Recovery is designed and it is not built. The slug it will carry in the register is account-recovery, and there is no row for it yet, so this page prints no state for it rather than typing one. When it exists it will not be a secret phrase you can lose — but it does not exist yet.
Is this an offer to invest, or a promise of income?
No. Nothing here is an offer of securities or investment advice.
What does it cost me?
Nothing, and there is no plan under which a person pays to hold or show a proof.
Can ORBIS see what I prove, and to whom?
No, and not as a promise — checking a proof requires no account with us, so there is no record of who checked whom for anyone to request, subpoena or breach.
How do I know what is actually built?
The register. Every capability, its real state, and the endpoint that proves it. It lives at /trust/register, which is not in this build yet — until it is, the block above is the same data for the parts this page depends on.

Do not trust us. Check us.