The decision layer

Verified is noteligible.

A credential proves who someone is. Something still has to decide what they are allowed to do. That gap sits under every interaction the internet runs: opening an account, signing a contract, letting an agent move money or change your production platform.

KeyFlux closes it. For people, and for machines.

ISO 18013-5/OID4VP/W3C VC/SD-JWT VC/eIDAS 2.0

The gap, in three parts

People are verified in a dozen fragmented ways.

A licence held up to a camera. A password. A security question your mother could fail. A wet signature on a scan of a scan. Every one of them adds risk to a transaction that was supposed to be private, and every one of them is verified again from scratch next time.

Machines are verified barely at all.

An agent files a change to production. A pipeline pushes to a cluster. A workflow pays an invoice. Standing keys and long-lived tokens say a machine is known. They cannot say which machine acted, on whose authority, or inside what limits.

And valid is not eligible.

You can cryptographically prove a credential is real and still not know whether the holder qualifies. Over 18 is not the same as allowed to buy. Employed is not the same as authorised to approve. Verification confirms. Something else has to decide.

What we decide

Six answers, one thesis underneath.

Is this person who they say they are?

Verified Onboarding

A state credential, verified in seconds. No upload, no review queue.

Is this really them, right now?

Verified Authentication

Sign-in bound to the device. Phishing and SMS interception get nowhere.

Are they old enough?

Verified Age

Prove someone is over 18 without learning who they are.

Do they hold that authority?

Verified Authority

Confirm the approver actually holds the power to approve, not just that they are logged in.

Which agent acted, and on whose authority?

Verified Agent

Every machine action traced to a human who answers for it.

Are they qualified to do this work?

Verified Practitioner

Credential a clinician, an installer, a broker in minutes instead of weeks of chasing paper.

Why now

Machines started acting.

Agents already operate production systems, ship code and move money. Adoption is not waiting for trust to catch up.

Governments started issuing.

eIDAS 2.0 and ISO 18013-5 mDLs are moving from mandate to circulation. Hundreds of millions of people are about to carry a credential a business can actually verify.

Where the waves meet, nobody stands.

The layer that decides what a verified party is allowed to do, human or machine, is unclaimed. It gets built once, and whoever builds it runs it.

Two credential markets. One technology.

Foundational credentials.

Governments and their PKI providers issue the root: national IDs, mobile driving licences, residence and professional credentials. National or private PKI, ISO and W3C formats, standards conformance that has to survive audit.

Derived credentials.

Banks, telcos, insurers and credit bureaus take a government credential and issue their own on top of it. A verified customer becomes a reusable asset instead of an onboarding cost repeated forever.

Same engine. Different scale, different implementation architecture. And in both markets the value is not the credential. It is the decision made over the top of it.

AI does the work. A human answers for it.

Everyone wants agents to run operations, ship changes and settle payments. Almost nobody trusts them to, and the news keeps explaining why. Dependence on agents will only grow.

The missing piece is the human trust chain: every machine action pinned to a person or an organisation with the authority to have permitted it, inside a scope, inside a window, with a record that stands up afterwards. The question underneath is eligibility, asked of a machine: is this agent, this action, this request allowed right now, given the conditions?

That is REMIT.

How REMIT works

How it fits together.

Two engines. One question: eligibility.

Is this actor allowed to do this thing, right now, in this context? Core asks it of people and organisations. REMIT asks it of agents and workloads. That shared question is why the two belong in one company.

Authority for agents and workloads

REMIT

Is this agent, this action, this request eligible right now, given the conditions? Short-lived, scoped authority issued for one piece of work, pinned to a person or an organisation who answers for it.

  • SPINE. Self-hosted in your own cluster. The full policy surface, inside your boundary.
  • Cloud. Hosted, scoped to CI/CD pipelines. Free community tier to start a team on.
  • Transact. Financial authority for non-human actors. Mandate as a credential, enforced over every rail, with no custody of funds.
Credentials for people and organisations

Verifiable Credential Core

Does this holder qualify, given the verified attributes they just presented? Issues, holds and verifies the credentials people and organisations carry, built on the ISO and W3C stacks, for foundational issuance and for derived issuance.

  • Resolve. Eligibility decided over verified facts. The answer, not the credential.
  • TrustGrid. Cross-border and cross-issuer trust routing.
  • KeyFlux ID. The customer-facing identity surface over a derived credential.
  • Wallet and Wallet SDK. Ship the KeyFlux app, or embed the SDK in your own.
  • Sign. Document signing as a function of the wallet, which is also the vault it is kept in.
  • Baseline. Standards monitoring across the framework corpus.

They share a thesis, not a codebase. A credential check and a machine authorisation are different problems with different failure modes, so they are different engines on purpose. Core decides eligibility over a presented credential, through Resolve. REMIT decides eligibility over a proposed action, through its own policy surface. Same discipline, two surfaces, deliberately. Different code, different data, different runtime.

What they share is the thesis that verified is not eligible, the open standards underneath, and the evidence discipline: every decision recorded with the reasoning attached. One seam is real today, and we will not claim more than it. Transact uses credential verification to establish who is paying.

Underneath

Trust anchors

Government PKI, private PKI, registries and trust lists, resolved across jurisdictions.

Put a decision to work.

Tell us the question you need answered and we will walk you through it live.

Request a demo