Secrets shouldn't
outlive theirusefulness.
A cloud-native, open-source studio for digital identity, security, and sovereignty. We help organizations prove who's who — people and the AI agents acting for them — and keep control of their own data, for the citizens and professionals who depend on it. Built in the open.
Verifiable trust, everywhere it's needed — nothing sensitive left lying around.
What we do
One path to identity you actually own.
Learn it, adopt it, own it — three stages of the same relationship, not three products to buy.
01 · Learn
Workshops & training
Hands-on sessions across digital identity, security, and sovereignty — including securing AI systems and the agents that act on them — scoped to your actual context.
02 · Adopt
Adoption & support
We help take a tool from proof-of-concept to production — AI-assisted where it speeds things up — then stay on so a broken upgrade doesn't become your problem alone.
03 · Own
Open-source tooling
Open tooling for identity, security, and sovereignty — for people, workloads, and AI agents alike — open source from the first commit, no asterisk.
Standards & protocols
We speak the standards, not a proprietary dialect.
Interoperable by default. We build on the open, international protocols your stack — and your regulator — already expect, so nothing here locks you in.
- Identity & access
- OpenID ConnectOAuth 2.1SAML 2.0SCIMFIDO2 / WebAuthnPasskeysJOSE (JWT/JWS/JWE)
- Wallets & verifiable credentials
- EUDI Wallet (ARF)W3C Verifiable CredentialsDecentralized Identifiers (DIDs)OpenID4VC / OpenID4VPSD-JWT VCISO/IEC 18013-5 (mDL)
- Signatures & trust services
- eIDAS 2.0Qualified Signatures (QES)PAdES / XAdES / CAdESX.509 & PKICloud Signature Consortium
- Cloud-native security
- SPIFFE / SPIREMutual TLSZero Trust (NIST 800-207)OPA / RegoOpenTelemetry
- Compliance & sovereignty
- GDPRNIS2ISO/IEC 27001SOC 2Gaia-X
Workshops & training
Hands-on sessions, not another slide deck.
We run practical workshops for engineering and platform teams — digital identity, zero trust, sovereignty, and AI-driven threat detection — scoped to your actual context. Remote or on-site.
Open source, by default
We're new. Everything we ship will be open source.
We don't think identity and security infrastructure should be a black box. We're a new studio and don't have a public tool out yet — but every project we ship will be open source from its first commit, so you can audit it, run it yourself, and contribute back instead of taking it on faith. The same goes for AI: we favour models you can run on your own infrastructure, so identity and personal data stay sovereign — under your control, not a vendor's.
$ credentics status
status: pre-launch
license: Apache-2.0 (planned)
first release: in progressstream: public changelog next: first repository access: open by default