Distributed Sovereign Identity Infrastructure for governments and enterprises

SovereignID.io enables portable, verifiable identity with Decentralized Identifiers (DID), Verifiable Credentials, Zero-Knowledge Proof via AnonCreds, DIDComm v2 secure messaging and cryptographic revocation. Credentials are issued once, held by the owner, and verified anywhere without exposing raw personal data.

SSI means Self-Sovereign Identity

In simple terms: instead of every company keeping copies of your documents, a trusted issuer gives you a digital credential. You keep it in your wallet and decide what to prove. A bank, government agency or company can verify the proof instantly without seeing everything about you.

Issuer signs Person controls Verifier checks Data stays private
DIDDecentralized identifiers
ZKPZero-knowledge proof
VCVerifiable credentials
LGPDPrivacy by design

Personal ID sovereignty turns identity checks into reusable proof

The holder controls the credential. Banks, agencies and enterprises receive a cryptographic answer, not a copy of documents. This changes identity from a repeated cost center into a reusable trust asset.

KYC cost reduction

60–80% less onboarding cost

Traditional KYC can cost R$80–150 per customer and take days. With a portable identity credential, a verified customer proves identity, risk level and income bracket in minutes, without resending documents to every institution.

10 min

Reusable onboarding

One verified credential can support Open Finance onboarding, credit pre-qualification, procurement access and public services.

Zero

Raw data exposure

Verifiers receive proof transcripts and predicates, not salary, CPF, address, full score or document images.

API ↓

Less integration burden

Credentials are verified offline against ledger material, reducing calls to fragile source APIs during peaks and audits.

Fraud ↓

Lower document fraud

Cryptographic signatures, revocation registries and non-replayable proofs replace PDFs, screenshots and manual certification checks.

LGPD

Minimization by design

The architecture proves eligibility while collecting the minimum necessary information, reducing breach surface and compliance exposure.

Identity without central custody

SovereignID.io operates below authentication portals and enterprise IAM systems as a cryptographic trust layer. It does not store personal data. Issuers publish schemas and public verification material on-ledger; holders keep credentials in their own wallets; verifiers receive only the proof they asked for.

Zero raw data

Predicates such as “income bracket is eligible” or “license is active” are proven mathematically, without revealing salary, address or full documents.

Portable trust

One credential can be reused across agencies, banks, councils and enterprises, replacing repetitive KYC, manual checks and fragile API dependencies.

Audit-ready

Every trust operation is independently verifiable through DID, schema, credential definition, revocation registry and immutable proof transcript.

SovereignID Protocol

A proprietary ledger architecture inspired by Hyperledger Indy, combining open DID/VC standards with commercial SLAs, sovereign deployment options and regulatory customization.

DID Core 1.0
AnonCreds
W3C VC 2.0
DIDComm v2
Ed25519 / BLS12-381
Pedersen commitments
Cryptographic accumulators
Multi-cloud / On-prem

What each protocol layer does in business terms

Sovereign identity is not a login screen. It is a chain of cryptographic primitives that lets a person prove facts about themselves while keeping control of the underlying credential.

DID Core 1.0

A decentralized identifier controlled by a cryptographic key, not by a central database row. It gives each person, issuer or verifier an addressable identity anchor.

AnonCreds

The credential format used to issue and verify privacy-preserving proofs, including selective disclosure and zero-knowledge predicates.

W3C VC 2.0

The global data model for signed digital credentials. It makes credentials interoperable across institutions, wallets and verification services.

DIDComm v2

Secure peer-to-peer messaging between wallets, issuers and verifiers. It replaces email/PDF exchange with encrypted identity workflows.

Ed25519 / BLS12-381

Cryptographic signature and proof primitives used to bind DIDs, issuers and ledger transactions to verifiable keys.

Pedersen commitments

The math that lets a wallet prove conditions such as “income is above X” without revealing the income value itself.

Cryptographic accumulators

Revocation mechanism that proves a credential is still valid without exposing which credential is being checked.

Multi-cloud / On-prem

Deployment model for governments and regulated enterprises that need sovereign control over nodes, keys, regions and operations.

Trust anchor registration

A steward endorses issuer DIDs on-ledger. Private keys remain in the issuer HSM or wallet infrastructure.

Schema and CredDef

Issuers publish schema vocabulary and ZKP public material, allowing verification without calling the issuer.

Credential issuance

Holder receives a signed credential through DIDComm and stores it locally. The issuer never controls the wallet.

ZKP presentation

Verifier requests attributes and predicates; holder returns a proof transcript with selective disclosure and replay protection.

Revocation

Accumulator-based revocation proves the credential is not revoked without correlating holder activity.

Audit transcript

The verification outcome is auditable without collecting the underlying personal data.

Built around high-friction identity workflows

Each vertical targets an expensive verification problem where cryptographic credentials reduce fraud, API load and personal-data exposure.

Government & public sector

Strategic beachhead
IdFuncional

Public servant credential

Passwordless access for HR and internal portals using DIDComm proof requests, including contractors and temporary credentials.

BenefícioJusto ZKP

Social eligibility

CRAS verifies “eligible / not eligible” without seeing salary, CPF or address. Eligibility predicates run on verifiable credentials.

LicitaçãoÁgil

Public procurement

Professional qualification verified in seconds, offline, without calling a professional council API during bid peaks.

eSocial Credential

Employment and income

Employment relationship, role, CBO, lotação and income bracket credentials for transfers, loans and public processes.

Financial services

Highest transaction value
Portable KYC

One onboarding, reusable proof

Identity verified once can be reused across Open Finance participants with ZKP over risk, PEP and KYC level.

RendaBR

Income proof without payslips

Credit pre-qualification through income-bracket predicates. No raw salary, no document copies.

Sovereign Score

Decentralized credit proof

Borrowers prove “score ≥ 700” without exposing the score or its components, preventing cross-lender tracking.

Agribusiness, health and education

Regulated identity chains
CARCredential

Rural compliance

CAR and EUDR compliance proof without exposing geolocation, supporting exporters, banks and ESG auditors.

CredSaúde

Emergency health proof

Minimal medical credentials available offline by QR, with selective disclosure for sensitive conditions.

DiplomaBR

Academic credentials

Diplomas and professional certifications verified in under five seconds without calling the issuing institution.

End-to-end SSI flows already deployed

The current public demo environment runs on a GCP VM with a real Hyperledger Indy ledger, ACA-Py agents, FastAPI backend and 11 Gov.br-style portals.

HubPortal Você.BR

Unified wallet and service hub for the sovereign identity PoCs.

API + LedgerDeveloper endpoints

Swagger API, health checks and ledger genesis/status endpoints.

PoC 1Functional credential

e-Folha, HR management and web wallet demonstration.

PoC 3Social eligibility ZKP

Citizen benefit proof and CRAS verifier with zero raw income data.

PoC 4eSocial / HR credentials

Employment, role, lotação and income-bracket credentials.

All demo links open in HTTPS. The public environment is intended for executive validation, technical demos and stakeholder workshops.

LatAm-first SSI infrastructure with global patterns

Government provides volume and regulatory urgency; financial services provide transaction value; councils, health, education and agribusiness provide repeatable vertical expansion.

Government

12M+ public servants and 214M Gov.br accounts create a natural identity network.

Finance

Portable KYC and income proofs reduce onboarding cost and fraud in credit workflows.

Councils

42 Brazilian professional councils can become trust anchors and VC issuers.

Agro & ESG

CAR, EUDR, traceability and credit workflows need verifiable compliance without overexposure.

Five revenue layers from infrastructure to vertical apps

Commercial packaging combines SaaS APIs, SDK licensing, managed ledger nodes, implementation projects and revenue share on high-value verification events.

SaaS API

Issue, verify, revoke, ZKP proof, DID resolver, schema registry and webhook/SSE APIs. Pay-per-use plus monthly plans.

SDK & Engine

Mobile SDKs, web components, wallet SDK, DIDComm agents and enterprise developer tooling.

Network-as-a-Service

Managed ledger nodes, steward endorsement, revocation registries and tails infrastructure with enterprise SLAs.

Vertical projects

Government, councils, finance, agriculture, health and education solutions delivered as repeatable accelerators.

Multi-cloud infra

GCP, AWS, Azure, OCI, Kubernetes, on-premises and sovereign deployment options.

Unit economics

Target NRR around 120%, gross margin around 74% by year 3 and enterprise LTV/CAC above 10x.

Build the next trust layer for digital identity

Talk to us about government pilots, council trust anchors, financial KYC portability, sovereign deployments and investment participation.