The 7 Evidence Dimensions
The Nutrition Label Model (Truth Over Scores)
Section titled “The Nutrition Label Model (Truth Over Scores)”Why DID.is Rejects Synthetic 0–100 Trust Scores
Section titled “Why DID.is Rejects Synthetic 0–100 Trust Scores”Most conventional security tools attempt to reduce complex trust vectors into a single synthetic scalar—such as Trust Score: 88/100 or a colored “Safe” badge. DID.is fundamentally rejects this paradigm as dangerous security theater:
┌────────────────────────────────────────────────────────────────────────┐│ THE FALLACY OF THE 0-100 TRUST SCORE │├────────────────────────────────────────────────────────────────────────┤│ Scenario A: Autonomous Pairwise Agent ││ • Uses did:key (Ed25519) ││ • Intentionally ephemeral, no website, no domain linkage ││ • Cryptographic Integrity: 100% | Update Authority: SELF_CERTIFYING ││ ❌ A synthetic score penalizes it for lacking a website (e.g. 45/100) ││ ││ Scenario B: Phishing Domain with Free Let's Encrypt Cert ││ • Uses did:web on newly registered scam domain ││ • TLS Valid: Yes | Domain Linkage: Present | Keys: Valid ││ • Real-World Legal Standing: Fraudulent ││ ❌ A synthetic score awards it 95/100 because all technical boxes pass│└────────────────────────────────────────────────────────────────────────┘Synthetic scores create false liability and gameable metrics. An identity that is 100% appropriate for an ephemeral agent-to-agent session is completely inappropriate for an enterprise supplier onboarding workflow. Collapsing multidimensional cryptographic evidence into a single number conceals critical risk factors.
Interactive 7-Dimension Evidence Inspector
Section titled “Interactive 7-Dimension Evidence Inspector”Experience the orthogonal evidence strip below. Toggle through the test vectors to observe how states transition across ESTABLISHED, SELF_CERTIFYING, NOT_ESTABLISHED, and FAILED:
Possession of valid private key at issuance
Current operational control without live resolution
Bitstring index bit 0 (unrevoked) at query time
Real-time state if cache-control max-age unexpired
Valid verificationMethod mapping in resolved DID document
Real-world institutional legal entity identity
Strict syntactical conformance to W3C JSON-LD / JSON Schema
Factual or semantic truthfulness of payload claims
Current UTC timestamp within valid nbf/exp window
Immunity from retroactive key compromise before exp
Cryptographic self-assertion or ecosystem registry record
Sovereign jurisdiction endorsement unless pinned
Root-to-leaf cryptographic capability delegation chain
Authority beyond explicitly bounded capability scope
Every dimension is orthogonal: a change in one dimension’s status never implicitly mutates another. For example, a failure in Revocation does not invalidate Signature validity at signing time, nor does self-certifying mathematics in did:key confer web server origin authority.
The Orthogonal Evidence Philosophy
Section titled “The Orthogonal Evidence Philosophy”DID.is models verification after the FDA Nutrition Facts Label:
| Nutrition Label Metric | DID.is Equivalent | Function |
|---|---|---|
| Total Sugars | control: NOT_ESTABLISHED |
Discloses raw, unvarnished risk factors without moral judgment. |
| Serving Size | source: HTTPS (1,234 bytes) |
Bounded measurement of the exact data retrieved. |
| Ingredients List | keys: Ed25519 (Multikey) |
Concrete breakdown of constituent cryptographic elements. |
| % Daily Value | Relying Party Policy Engine | The consumer decides if the evidence satisfies their criteria. |
Each dimension evaluated by DID.is answers two explicit questions:
- What it proves: The precise technical fact established by the test.
- What it does NOT prove: The operational or legal boundaries beyond which the test provides zero guarantees.
The organization dimension is mathematically pinned to NOT_ESTABLISHED across all methods. DID.is does not consult state corporate registries, DUNS numbers, or trademark offices. Any relying party requiring legal jurisdiction binding must enforce it through an external verified credential layer.
Auditable, Falsifiable, and Reproducible Findings
Section titled “Auditable, Falsifiable, and Reproducible Findings”Every statement made in the DID.is web interface is directly falsifiable. The frontend never synthesizes verdicts client-side; every verdict, dimension state, and graph node originates from deterministic execution in resolver-core.
At the bottom of every dossier, DID.is displays the exact curl command to reproduce the findings:
1
# Reproduce the exact verdict and dimensions using the public API
2
curl -s "https://did.is/api/v1/resolve/did:web:identity.foundation" | \
3
jq '{verdict, dimensions: [.dimensions[] | {id, state, statement}]}'
1
# Inspect the underlying DAG graph nodes and verification edges
2
curl -s "https://did.is/api/v1/graph/did:web:identity.foundation" | jq .
1
import { DidisClient } from '@didis/client';
2
3
const client = new DidisClient({ baseUrl: 'https://did.is/api' });
4
const { verdict, dimensions } = await client.resolve('did:web:identity.foundation');
5
6
console.log('Verdict:', verdict);
7
for (const dim of dimensions) {
8
console.log(`[${dim.id}] ${dim.state}: ${dim.statement}`);
9
}
The Seven Evidence Dimensions
Section titled “The Seven Evidence Dimensions”Every resolution independently evaluates seven orthogonal dimensions:
┌───────────────────────────────────────────────────────────────────────────────────────────────┐│ THE SEVEN EVIDENCE DIMENSIONS │├──────────────┬───────────────────┬──────────────────────────────────┬─────────────────────────┤│ Dimension │ Label │ What It Proves │ What It Does NOT Prove │├──────────────┼───────────────────┼──────────────────────────────────┼─────────────────────────┤│ integrity │ Document Integrity│ Document matches identifier hash │ Control of underlying ││ │ │ chain or self-certifying data. │ web servers or hosting. │├──────────────┼───────────────────┼──────────────────────────────────┼─────────────────────────┤│ keys │ Key Material │ Published keys are well-formed │ Real identity or holder ││ │ │ and lie on valid curve points. │ legal authorization. │├──────────────┼───────────────────┼──────────────────────────────────┼─────────────────────────┤│ control │ Update Authority │ Updates require cryptographic │ Web host security on ││ │ │ signatures (e.g. did:webvh). │ did:web identities. │├──────────────┼───────────────────┼──────────────────────────────────┼─────────────────────────┤│ origin │ Origin Binding │ Web domain signed a valid DIF │ Corporate registration ││ │ │ configuration binding this DID. │ or trademark rights. │├──────────────┼───────────────────┼──────────────────────────────────┼─────────────────────────┤│ transport │ Transport Security│ Leaf TLS cert validity, SAN, │ Key ownership or host ││ │ │ and trusted WebPKI chain. │ internal security. │├──────────────┼───────────────────┼──────────────────────────────────┼─────────────────────────┤│ history │ Verifiable History│ Immutable, hash-chained log of │ Real-world conduct of ││ │ │ all document versions (webvh). │ the identifier subject. │├──────────────┼───────────────────┼──────────────────────────────────┼─────────────────────────┤│ organization │ Real-World Identity│ Fixed: Always NOT_ESTABLISHED. │ Any corporate identity, ││ │ │ DID.is never checks registries. │ KYC, or legal standing. │└──────────────┴───────────────────┴──────────────────────────────────┴─────────────────────────┘Dimension States & Severity Tones
Section titled “Dimension States & Severity Tones”Dimensions transition deterministically between six normative states:
| Dimension State | Semantic Meaning | Visual Tone | Hex / Token |
|---|---|---|---|
ESTABLISHED |
Passed an active cryptographic or procedural check. | ok (Green) |
#10B981 |
SELF_CERTIFYING |
Inherently verified by identifier math (did:key, did:jwk, SCID). |
self (Soft Indigo) |
#6366F1 |
NOT_ESTABLISHED |
Property is absent or cannot be verified (e.g., no domain linkage). | neutral (Muted Slate) |
#64748B |
FAILED |
Check was attempted and explicitly failed (invalid signature, bad hash). | fail (Crimson Red) |
#F43F5E |
INDETERMINATE |
Check could not finish conclusively (network timeout, unreachable list). | warn (Amber) |
#F59E0B |
NOT_APPLICABLE |
Property does not apply to this method (e.g., TLS on did:key). |
na (Subtle Sunken) |
rgba(255,255,255,0.2) |