Trust, ecosystems and autonomy
Trusted collaboration starts with participant autonomy.
Every ecosystem depends on participants knowing who they work with, which rights they grant and how they retain control. Those questions guide our architecture and operating agreements, from the first connection to ongoing service delivery.
Principles we apply to everything we build
Trust that can be checked
Identify who is acting, verify their rights and retain evidence of the decision. Assign responsibility for policies and their enforcement before participants connect.
Ecosystems with shared rules
Use common standards and agreed governance so organisations can cooperate across their existing systems. The ecosystem leader and participants define how collaboration works.
Autonomy throughout participation
Make data-use boundaries explicit. Agree the process for changing access, revoking credentials, exporting data and ending or transferring a service relationship.
Offering these capabilities to your own customers? Explore trust services for trusted service providers →
Certifications
Certified roles are audited against the iSHARE Foundation conformance scheme — they are verified, not self-declared. Scope and evidence are part of the due-diligence pack. Read the iSHARE explainer →
iSHARE v3 — Participant Credential Issuer
Certified by the iSHARE Foundation scheme to issue participant identity credentials.
iSHARE v3 — Authorization Registry
Certified to operate the registry of data rights that access decisions are verified against.
Standards & compatibility
Alignment and compatibility positions — distinct from certifications, and stated as such.
EUDI Wallet ARF-aligned
Built on OID4VCI and SD-JWT, the credential standards of the European Digital Identity Wallet architecture. We track ARF releases as the framework evolves.
MCP-compatible
Authorization layer that validates credentials at the Model Context Protocol boundary.
ISO 27001-aligned practices
Security management aligned to ISO 27001. Current certification status and audit roadmap are shared under NDA.
EU Data Act position
The Data Act applies since 12 September 2025. It gives users of connected products rights to their data and obliges data holders to share it under fair, documented terms. The Act does not prescribe a technology — what it demands in practice is that you can show who received access, under which terms, and on what basis. Our stack makes that operational: verifiable identity, recorded data rights, documented usage terms and a full audit trail. How the components map to your specific obligations is detailed in the security & compliance whitepaper and confirmed in the architecture review.
Read the whitepaper →EU AI Act position
The AI Act applies in phases: rules for general-purpose AI models apply since August 2025, the transparency obligations of Article 50 since August 2026, and the high-risk obligations — logging, human oversight, deployer accountability — from December 2027 (December 2028 for AI embedded in regulated products). An authorization layer does not make an AI system compliant, and we will not claim it does. What it provides is the accountability groundwork those obligations assume: per-agent identity, scoped rights, and a retained record of every access decision.
GDPR position
We operate as data processor by default. Controller arrangements, sub-processor disclosures and specific data flow agreements are confirmed per deployment in the architecture review and contract phase.
NIS2 and supply-chain requirements
Telcos and other essential entities under NIS2 must manage security across their supply chain, including suppliers like us. We support that: documented incident response and change management, contractual security commitments, audit and telemetry access per tenant, and EU-only operations. Our NIS2 supplier questionnaire responses are available during evaluation.
DORA (financial sector)
Financial entities engaging us — directly or through a partner — must bring ICT third parties under DORA contract requirements, which apply since January 2025. We are familiar with the register-of-information and contractual provisions this requires and support them in the service agreement.
Data residency
EU-only deployment. The Netherlands is the primary deployment region. Specific region and residency requirements are confirmed per deployment.
Audit and observability
Every credential issuance, every authorization decision, every administrative action is logged. Logs are available to customers and to auditors under contract. Tenant-level telemetry is available to wholesale operators.
Security operations
Penetration testing is performed on a regular cadence by an independent specialist; the most recent report, vendor and date are shared under NDA in the compliance review. Security operations follow documented incident response and change management processes.
Standards we use
W3C Verifiable Credentials
The open credential model at the core of the stack.
OID4VCI
OpenID for Verifiable Credential Issuance.
DCP
Decentralized Claims Protocol — issuance and presentation for data-space participants.
SD-JWT
Privacy-preserving, selectively disclosable credentials.
EUDI Wallet ARF
Aligned with the European Digital Identity Wallet reference architecture.
iSHARE v3
European trust framework for data spaces — Protium is certified on two roles.
MCP-compatible
Authorization layer for the Model Context Protocol ecosystem.
EU Data Act
Applies since 12 September 2025 — our stack makes its data-access obligations operational.