RESEARCH PROJECT

Portable trust without building a social score.

TaraSec ID explores how people can prove relevant identity, contribution and accountable recommendations while controlling what is revealed, to whom, for what purpose and for how long.

Build merit through TaraSec →

CURRENT STATUS

Help shape the model. Share cautiously for now.

TaraSec ID is currently a research and protocol project. Secure personal credential storage and a holder wallet have not yet been established. The present contribution surfaces link to public discussions and public profile evidence; they are not a secure document vault.

It is reasonable to link information you already intentionally publish—for example a public GitHub, LinkedIn, Facebook, Upwork or research profile. Before secure storage is available, do not submit identity documents, private correspondence, access tokens, confidential employment evidence, exact private location or information you would not be comfortable making public.

This is awareness, not a warning against participating. Contributors can begin with public links, infrastructure activity they approve for attribution, proposals and other low-sensitivity evidence.

ONE ID, DIFFERENT EVIDENCE

A profile can combine context and demonstrated work without pretending they mean the same thing.

01

Verified identities

Optional Google, GitHub, LinkedIn, Facebook, Upwork, ORCID, institutional and company-domain evidence can show account control or affiliation. It does not prove expertise by itself.

02

TaraSec operation

Approved links to responsibly operated hotspots, nodes, gateways and servers can show verified deployment, health, tests and useful incident participation without exposing security traffic or private network identity.

03

Demonstrated contribution

Code, research, proposals, reviews, documentation, teaching, translation and verified outcomes build separate areas of merit.

04

Contributor-proposed evidence

People may suggest evidence we did not anticipate, explain its relevance and verification method, choose a domain and request public, reviewer-limited or private visibility.

ACCOUNTABLE RECOMMENDATIONS

Recommendations from people with relevant merit can count strongly.

A recommendation should be a signed, specific claim rather than a transferable popularity score. Its weight can reflect the recommender's verified identity, relevant domain merit, direct experience, supporting evidence, recency and independence.

Recommendations should declare employment, family, financial and organizational conflicts. Reciprocal endorsement circles, duplicated organizational influence and unsupported mass recommendations must not appear as independent consensus.

Later outcomes may confirm or contradict a recommendation. Each attestation should be explainable, expiring, revocable and correctable. The holder chooses whether to reveal the statement, its evidence or only a minimal proof that suitable independent attestations exist.

HOLDER-CONTROLLED DISCLOSURE

The owner decides what the ID may reveal.

A contributor should be able to define normal, private, professional, travel, emergency and custom disclosure policies. Policies can limit the recipient, purpose, credential category, confirmation requirement and expiry.

For example, travel mode could temporarily hide identity, employers, profiles, contribution history, infrastructure and relationships while allowing a narrowly defined proof that the holder satisfies a particular trust requirement. The proof should disclose the claim—not the full evidence behind it—and should avoid a reusable identifier where possible.

“Trustworthy” must remain purpose-specific: identity verified, infrastructure operator in good standing, demonstrated cybersecurity contributor or another clearly defined requirement. TaraSec ID must not issue one universal ranking of a person.

PRIVACY ARCHITECTURE

Verify evidence without collecting everything.

The preferred architecture separates a minimal identity vault, pseudonymous merit records, infrastructure identities and a holder-controlled credential wallet. Verification material should be deleted when practical after an attestation is issued.

Human identity must remain separated from TaraSec security telemetry and the existing anonymized owner/unit model. A breach of a contributor-profile service must not reveal who generated a traffic or security report.

Future research includes selective-disclosure credentials, holder-controlled keys, rotating identifiers, offline proofs, revocation, recovery, coercion resistance and independent privacy/security review.

A PARTNERSHIP PROJECT

Critical trust infrastructure cannot be designed by Taransvar alone.

Banks, governments, universities, telecoms, employers, freelance platforms, standards bodies and civil-society organizations all have relevant expertise and different risks to expose.

The proposed first step is a constrained voluntary contributor pilot: jointly define the threat model and ethical framework, issue narrow credentials such as verified node operator, test selective disclosure and independently evaluate fraud, bias, exclusion, coercion and breach consequences.

Discuss research cooperation → Join the public design discussion →