The trust framework, explained

What is iSHARE — and our certified role in it.

iSHARE is a European trust framework for data spaces, governed by the independent iSHARE Foundation. It gives organisations one shared set of legal, operational and technical agreements for exchanging data — so every participant can verify who a counterparty is and what it is allowed to do, without bilateral contracts for every connection.

The framework in one paragraph

Every participant in an iSHARE data space holds a verifiable credential that proves its identity, and every data right is recorded in an authorization registry. When one party requests data from another, both sides can check — automatically, per request — that the requester is a certified participant and that the request is within its granted rights. The result is data exchange with evidence: who accessed what, under which terms, decided by whom.

That evidence layer is what regulators, auditors and counterparties increasingly ask for — and it is the part most organisations do not want to build or certify themselves.

From open-source development to live operations

Protium spent years developing open-source components for the iSHARE ecosystem. Today, we also operate iSHARE-based managed services in production, providing the technology and operations behind our customers' own offerings.

Protium's certified roles

Participant Credential Issuer (PR v3)

Protium is certified to issue the participant credentials that establish who an organisation is inside an iSHARE data space. This is the entry ticket for every participant — people, systems and AI agents.

Authorization Registry

Protium is certified to operate the registry that records what each participant is allowed to do with which data. Access decisions can be verified against it in real time and retained as evidence.

Both roles are certified on iSHARE v3. Certification scope and conformance evidence are part of the due-diligence pack shared during architecture and compliance review. Protium also participates in the iSHARE Foundation's standards development.

Why certification matters

Certification is audited, not self-declared

iSHARE roles are certified against the framework’s conformance requirements by the iSHARE Foundation scheme. A certified operator has proven its implementation, not just claimed it.

One agreement, many counterparties

Participants sign up to the framework once and can then exchange data with any other participant under the same legal and technical rules, instead of negotiating bilateral integrations each time.

Built for machine-to-machine trust

The framework is designed for automated, API-level data exchange — which is exactly what partner systems and AI agents need. Human portals are the exception, not the rule.

How you consume it

Telcos, MSPs and integrators offer the certified services to their own customers under their own brand through the wholesale managed service. Sectors move data-sharing initiatives into operation with the managed data space. Enterprises get governed access for AI agents, partners and customers through the enterprise service — normally via their partner, directly where none is appointed.

Common questions

Is iSHARE only a Dutch initiative?+

It started in the Dutch logistics sector, but the iSHARE Foundation now positions the framework for European data spaces, and it is used across sectors including logistics, energy and mobility. The scheme is framework-agnostic about geography: any organisation with an EORI-style identifier can participate.

Do our customers need to understand iSHARE?+

No. In the wholesale model, your customers see your portal and your credentials. iSHARE is the certified machinery underneath — like nobody needs to understand BGP to buy connectivity.

How does iSHARE relate to EUDI wallets and eIDAS 2.0?+

They are complementary. iSHARE governs organisation-to-organisation data exchange; EUDI wallets carry credentials for (legal) persons under eIDAS 2.0. Protium builds on shared standards — OID4VCI and SD-JWT — so credentials can flow between both worlds.

What does "iSHARE v3" mean?+

Version 3 of the framework moves to verifiable credentials as the native format. Protium is certified on v3 for the Participant Credential Issuer and Authorization Registry roles, implements the full v3 credential vocabulary against the official schema index, and supports both issuance protocols the framework uses (OpenID4VCI and DCP).

Can we run iSHARE services without Protium?+

Yes — the framework is open and the PR base code is open source (AGPL 3.0). What Protium adds is certified operation as a managed service: the issuing logic, registry, multi-tenant platform, runbooks and 24/7-capable operations you would otherwise build and certify yourself.

Want certified trust services without building them?