Behind it stands the trust and credential pyramid on NX fabric: external anchors such as official registers and eID, the nexyo Registry as the trust anchor, self-hosted issuers, participant wallets, verified transactions. Five layers, one stack.
The Trust and Credential Pyramid for Data Spaces
Five layers, from external anchors through registry and issuer down to the single transaction. Each layer answers exactly one question. All of them run on the same stack: NX fabric.
The layer everyone verifies against is the Registry. nexyo operates that position itself.
nexyo Trust is the umbrella name. Underneath sit three building blocks, each covering one layer of the pyramid.
Identifies an organisation against official registers and eID, such as ID Austria or USP. An invited party becomes a verified participant.
See the journey →The self-hosted credential issuer. Signs with its own keys, runs its own did:web identity, revokes when the underlying fact no longer holds.
badge.nexyo.io →The trusted-issuer registry. The nexyo root issuer accredits operator issuers, and the registry makes each accreditation queryable for any verifier.
registry.nexyo.io →The proof carries itself. No call to the issuer, no query to nexyo.
The organisation identifies itself through nexyo Onboarding: official registers, eID or a reviewed document.
nexyo Badge issues the proof as a W3C Verifiable Credential, signed and revocable.
The participant presents the credential from their own wallet. The verifier checks it against the registry.
Every transaction is verified at the gateway, checked against policies and logged.
No proprietary format, no blockchain, no foreign governance. The pyramid stands on standards the market already carries.
Proofs as signed W3C credentials with did:web identities. A verifier checks signature and issuer, nothing else.
Presentation via the Decentralized Claims Protocol, the standard of the data-space world. Participants bring their own wallet.
The pyramid's external anchors are designed for eIDAS 2.0. When the EUDI wallet arrives, it docks on top, no rebuild required.
Issuer and registry are in operation, publicly reachable and machine-readable.
The console of the credential issuer: issue, manage and revoke credentials.
The root issuer's DID and the trusted-issuer list, machine-readable for any verifier.
The full credential journey, hands-on, from accreditation to verified access, at demo.trust.nexyo.io.
The trust pyramid is not a prototype. It grew out of running data-space infrastructure in production.
You run your issuer self-hosted, with your own keys. nexyo accredits it and lists it in the registry every data space verifies against. In one conversation we define what your issuer looks like.