Verifiable Trust Infrastructure

The open infrastructure for trust
in the age of AI.

VTI is a community-built stack that makes trust portable, verifiable, and agent-ready — between people, AI agents, and communities, with no central authority and no trust-me-bro.

Rust Apache-2.0 / MIT Post-quantum capable · experimental EUDI ARF-aligned
2,411 commits · last 90 days across 16 OpenVTC repositories
555 Trust Task specifications 38 namespaces · all currently draft
18,500+ credentials in production incl. the CardInfoLink production deployment
eIDAS 2.0 EUDI ARF-aligned ISO mdoc · SD-JWT VC · W3C VC 2.0
9,876 conformance checks automated, from 26 hand-written examples

Figures checked

The break

AI can fake a person. AI can act as you.
The internet has no answer to either.

Generative AI can fabricate a face, a voice, a résumé, a review, or an entire online history. And as agents start to act on our behalf, nothing today can verifiably answer whose interests they serve.

Both questions are really one: trust has become the scarcest resource on the internet — and every answer before VTI asked you to trust a platform, a government, or a company instead.

VTI breaks that assumption. A credential you hold. A proof you control. A check anyone can run — offline, cross-border, cross-community.


One coherent stack

Six interlocked threads. No central authority.

Nobody else ships all six as one coherent stack — people, agents, communities, cryptographic rails, human-in-the-loop governance, and regulatory compliance.

01

People & Orgs

Personhood and relationship credentials, wallets, and selective / zero-knowledge disclosure.

02

AI Agents

Scoped agent identity that acts on your behalf — with mandates it cannot exceed.

03

Communities

Verifiable Trust Communities write their own membership rules and own their trust graph.

04

Cryptographic Rails

did:webvh, DIDComm v2, the Trust Spanning Protocol, post-quantum and ZK cryptography.

05

Governance

Human-in-the-loop approval, least privilege, kill-switch, and tamper-evident audit.

06

Compliance

Architecturally aligned with eIDAS 2.0, Utah SEDI, and China’s 2026 agent rules.

Not built by one company.
Built by a movement.

The internet’s foundational protocols — TCP/IP, HTTP, TLS — became universal because no single company owned them. VTI is built on the same principle. Affinidi is a founding maintainer, not the owner.


Actively shipping

Not vaporware. Shipped code.

Every claim on this site is anchored to shipped code or a published spec.

16 public repositories
20 code contributors
9,876 conformance checks

Your next step

Build on it. Deploy it. Shape it.

  • 01
    Builder

    Build on VTI

    Start building

    Integrating trust into an app, agent framework, or community platform? Start with the open Trust Development Kit.

  • 02
    Strategist

    Trust at scale

    Read how it works

    Evaluating VTI for enterprise, government, or regulated industries? See how the architecture maps to regulation.

  • 03
    Community

    Shape what comes next

    Join OpenVTC

    A standards contributor, protocol designer, or builder organisation? Join the open community behind VTI.

Cookie Preferences

We use cookies to enhance your experience. You can manage your preferences below. For more information, read our Cookie Policy.

Strictly Necessary Always Active

These cookies are essential for core website functions such as security, session integrity, and cookie preference storage. They cannot be disabled.

  • _cf_bm: Distinguishes humans from bots (Cloudflare) · 30m
  • _cfuvid: Ensures secure browsing (Cloudflare) · Session
  • __hs_initial_opt_in: Prevents HubSpot's banner · 7 days
  • _gtm_debug: GTM debug mode (testing only) · Session
Analytics

These cookies help us understand how visitors interact with the site so we can improve content and performance. All data is aggregated and anonymous.

  • _ga, _gid, _gat: Google Analytics · Session – 2 years
  • __hstc, hubspotutk, __hssrc: HubSpot visitor tracking · 13 months
  • __hs_opt_out: HubSpot opt-out preference · 6 months
Marketing & Targeting

These cookies allow us and our partners to serve personalised ads and measure campaign performance.

  • _gcl_au, _gcl_dc: Google Ads conversion tracking · 90 days
  • IDE: Google Display Network personalisation · 1 year
  • _fbp: Meta / Facebook remarketing · 90 days
  • li_gc, _li_fat_id, bcookie: LinkedIn tracking · 1–24 months
  • guest_id, personalization_id: Twitter/X analytics · 2 years