Trust between organisations is not created here. We make it verifiable.

Behind it stands the trust and credential pyramid on NX fabric: external anchors such as official registers and eID, the nexyo Registry as the trust anchor, self-hosted issuers, participant wallets, verified transactions. Five layers, one stack.

The Trust and Credential Pyramid for Data Spaces

W3C Verifiable Credentials did:web DCP Trusted-Issuer Registry EUDI-ready Self-hosted
The model

Trust flows down, proofs flow up.

Five layers, from external anchors through registry and issuer down to the single transaction. Each layer answers exactly one question. All of them run on the same stack: NX fabric.

The trust and credential pyramid: five layers from external anchors to the transaction E4 · EXTERNAL ANCHORS Registers · eID · EUDI ahead state and third parties E3 · REGISTRY · nexyo Trusted-issuer registry + root issuer accredits issuers E2 · OPERATOR ISSUER Self-hosted issuer per data space issues participant credentials E1 · PARTICIPANTS did:web + wallet hold and present proofs E0 · TRANSACTION Every access verified and logged fabric gateway at the provider trust flows down proofs flow up A proven pattern from iSHARE, Catena-X and DCP. The only new part: all layers from one stack.

The layer everyone verifies against is the Registry. nexyo operates that position itself.

The product family

Three products, three verbs: Onboarding verifies, Badge issues, Registry anchors.

nexyo Trust is the umbrella name. Underneath sit three building blocks, each covering one layer of the pyramid.

Verifies · E4

nexyo Onboarding

Identifies an organisation against official registers and eID, such as ID Austria or USP. An invited party becomes a verified participant.

See the journey →
Issues · E2 · live

nexyo Badge

The self-hosted credential issuer. Signs with its own keys, runs its own did:web identity, revokes when the underlying fact no longer holds.

badge.nexyo.io →
Anchors · E3 · new, live

nexyo Registry

The trusted-issuer registry. The nexyo root issuer accredits operator issuers, and the registry makes each accreditation queryable for any verifier.

registry.nexyo.io →
How it works

Identified once, verifiable everywhere: four steps to a verified access.

The proof carries itself. No call to the issuer, no query to nexyo.

1

Identify

The organisation identifies itself through nexyo Onboarding: official registers, eID or a reviewed document.

2

Receive a credential

nexyo Badge issues the proof as a W3C Verifiable Credential, signed and revocable.

3

Present it in the data space

The participant presents the credential from their own wallet. The verifier checks it against the registry.

4

Access verified

Every transaction is verified at the gateway, checked against policies and logged.

Standards, not promises

Anyone can verify every proof. Because everything is an open standard.

No proprietary format, no blockchain, no foreign governance. The pyramid stands on standards the market already carries.

Format

W3C Verifiable Credentials

Proofs as signed W3C credentials with did:web identities. A verifier checks signature and issuer, nothing else.

Protocol

DCP

Presentation via the Decentralized Claims Protocol, the standard of the data-space world. Participants bring their own wallet.

Regulation

eIDAS-2.0-aware, EUDI-ready

The pyramid's external anchors are designed for eIDAS 2.0. When the EUDI wallet arrives, it docks on top, no rebuild required.

Live today

The pyramid is not an announcement. Two layers run today.

Issuer and registry are in operation, publicly reachable and machine-readable.

Live

Badge Console

The console of the credential issuer: issue, manage and revoke credentials.

Live

Registry

The root issuer's DID and the trusted-issuer list, machine-readable for any verifier.

Coming soon

Demonstrator

The full credential journey, hands-on, from accreditation to verified access, at demo.trust.nexyo.io.

20+data-space projects
60+hubs in operation
8+enterprise clients
78,000+managed assets

The trust pyramid is not a prototype. It grew out of running data-space infrastructure in production.

Become an operator: your own issuer, accredited in the nexyo Registry.

You run your issuer self-hosted, with your own keys. nexyo accredits it and lists it in the registry every data space verifies against. In one conversation we define what your issuer looks like.