For telcos, MSPs and system integrators
Trust infrastructure, operated wholesale.
Add governed data exchange to your portfolio without building the trust layer yourself. Protium operates the credential services and tenant platform behind your brand. You keep the customer contract and first-line relationship.
What's in the wholesale service
Certified managed trust service
Certified operations on the iSHARE v3 trust framework: onboarding portal, credential issuance, authorization registry, governance flows. 100% Protium IP on the PR Issuer and Authorization Registry.
White-label or co-branded
Your customers see your brand on the portal, the credentials and the support flow. Our trust infrastructure runs underneath.
A dedicated tenant per customer
Each of your enterprise customers runs as a dedicated, isolated tenant on the Ozone platform — own database, own auth tenant, own domain. Isolation by architecture, not by configuration.
Operating model, not custom build
Automated tenant provisioning — from signup to a running, branded tenant with DNS, auth and first users, every step idempotent and retryable, with suspend and resume built in. Documented runbooks, SLA tiers and onboarding playbooks. No bespoke engineering per deal.
How the wholesale model works
The split is simple.
You bring the channel, the brand and the customer relationship. We bring the certified trust infrastructure, the credential issuers, the platform and the managed operations.
The economics are tenant-based.
Each of your enterprise customers becomes a tenant in our multi-tenant trust stack. You invoice your customer. We operate the service. Pricing models are discussed under NDA.
The integration touches your existing stack.
Your B2B sales sells the service. Your billing platform invoices (we provide per-tenant usage telemetry). Your customer support handles tier-1; we handle tier-2/3 on the trust layer. Your IAM, OSS/BSS and sovereign cloud all integrate.
The brand experience is yours.
Customer-facing portals, credentials, support emails and contracts carry your brand. Where preferred, the relationship is co-branded as a powered-by partnership.
Why telcos and MSPs are the natural operator
Telcos and MSPs already contract with enterprise customers, operate support under SLA and understand regulated infrastructure. Protium supplies the certified trust components and the operating playbooks behind that relationship. AI authorization can be added in a scoped rollout when a customer use case is ready.
How onboarding works
Architecture & integration review
Map your enterprise services, IAM and B2B billing. Define the wholesale tenancy model.
Sandbox deployment
Your team is trained. Integration with your OSS/BSS is validated. First test tenant is onboarded.
Production deployment
First pilot customer goes live. Operations handover. Joint go-to-market materials.
Scale
Repeatable customer onboarding. Joint references where customers agree. Expansion into adjacent services (Ozone licensing, AI agent authorization).
Built on certified infrastructure
Certifications
iSHARE v3 Participant Credential Issuer and Authorization Registry. Certification scope and current status are included in the due-diligence evidence pack.
IP position
100% Protium IP on the Participant Credential Issuer (PR v3) and Authorization Registry. The PR base code comes from iSHARE Foundation as open source (AGPL 3.0). The Ozone platform is proprietary Protium IP.
Deployment posture
EU deployment, tenant-level separation and documented operating procedures. Region, SLA and audit evidence are agreed per deployment.
Operational evidence
Operating since 2014
Experience across enterprise data sharing, trust frameworks and regulated ecosystems has been converted into reusable platform and operating playbooks.
iSHARE evidence available
Certification scope, conformance evidence and the current service status are available during architecture and compliance review.
References with context
Relevant project references are shared with the role, scope and delivery period clearly stated. Customer names are only published with permission.
Buyer questions, answered
Can we white-label this entirely?+
Yes. Portals, credential UX, support flows and contracts can carry your brand. Co-branded "powered by Protium" is also available.
How does tenant isolation work?+
Every customer gets a dedicated tenant runtime: its own database, its own auth tenant and its own domain. There is no shared data store between tenants to misconfigure. Provisioning is automated and reversible (suspend/resume), and we provide usage telemetry per tenant.
What is your dependency on iSHARE Foundation?+
The PR base code is iSHARE Foundation open source (AGPL 3.0). The PR v3 Issuer logic, the Authorization Registry and all deployment tooling are Protium IP.
What integrations do you support out of the box?+
Standard SAML/OIDC IAM, REST + webhook integration with OSS/BSS, telco-grade observability, EU sovereign cloud deployment options.
Where is the data?+
EU-only. Specific region and residency arrangements are confirmed in the architecture review.