Skip to content

The 7 Evidence Dimensions

The Nutrition Label Model (Truth Over Scores)

Section titled “The Nutrition Label Model (Truth Over Scores)”

Why DID.is Rejects Synthetic 0–100 Trust Scores

Section titled “Why DID.is Rejects Synthetic 0–100 Trust Scores”

Most conventional security tools attempt to reduce complex trust vectors into a single synthetic scalar—such as Trust Score: 88/100 or a colored “Safe” badge. DID.is fundamentally rejects this paradigm as dangerous security theater:

┌────────────────────────────────────────────────────────────────────────┐
│ THE FALLACY OF THE 0-100 TRUST SCORE │
├────────────────────────────────────────────────────────────────────────┤
│ Scenario A: Autonomous Pairwise Agent │
│ • Uses did:key (Ed25519) │
│ • Intentionally ephemeral, no website, no domain linkage │
│ • Cryptographic Integrity: 100% | Update Authority: SELF_CERTIFYING │
│ ❌ A synthetic score penalizes it for lacking a website (e.g. 45/100) │
│ │
│ Scenario B: Phishing Domain with Free Let's Encrypt Cert │
│ • Uses did:web on newly registered scam domain │
│ • TLS Valid: Yes | Domain Linkage: Present | Keys: Valid │
│ • Real-World Legal Standing: Fraudulent │
│ ❌ A synthetic score awards it 95/100 because all technical boxes pass│
└────────────────────────────────────────────────────────────────────────┘

Synthetic scores create false liability and gameable metrics. An identity that is 100% appropriate for an ephemeral agent-to-agent session is completely inappropriate for an enterprise supplier onboarding workflow. Collapsing multidimensional cryptographic evidence into a single number conceals critical risk factors.


Interactive 7-Dimension Evidence Inspector

Section titled “Interactive 7-Dimension Evidence Inspector”

Experience the orthogonal evidence strip below. Toggle through the test vectors to observe how states transition across ESTABLISHED, SELF_CERTIFYING, NOT_ESTABLISHED, and FAILED:

7-DIMENSION EVIDENCE STATUS STRIPdid:web:identity.foundation
D1
SignatureESTABLISHED
D2
RevocationESTABLISHED
D3
DID BindingESTABLISHED
D4
SchemaESTABLISHED
D5
TemporalESTABLISHED
D6
GovernanceSELF_CERTIFYING
D7
DelegationESTABLISHED
ORTHOGONALITY INVARIANT
DID.is Specification §2.1

Every dimension is orthogonal: a change in one dimension’s status never implicitly mutates another. For example, a failure in Revocation does not invalidate Signature validity at signing time, nor does self-certifying mathematics in did:key confer web server origin authority.


DID.is models verification after the FDA Nutrition Facts Label:

Nutrition Label Metric DID.is Equivalent Function
Total Sugars control: NOT_ESTABLISHED Discloses raw, unvarnished risk factors without moral judgment.
Serving Size source: HTTPS (1,234 bytes) Bounded measurement of the exact data retrieved.
Ingredients List keys: Ed25519 (Multikey) Concrete breakdown of constituent cryptographic elements.
% Daily Value Relying Party Policy Engine The consumer decides if the evidence satisfies their criteria.

Each dimension evaluated by DID.is answers two explicit questions:

  1. What it proves: The precise technical fact established by the test.
  2. What it does NOT prove: The operational or legal boundaries beyond which the test provides zero guarantees.
ORGANIZATIONAL IDENTITY BOUNDARY
Normative Invariant #6

The organization dimension is mathematically pinned to NOT_ESTABLISHED across all methods. DID.is does not consult state corporate registries, DUNS numbers, or trademark offices. Any relying party requiring legal jurisdiction binding must enforce it through an external verified credential layer.


Auditable, Falsifiable, and Reproducible Findings

Section titled “Auditable, Falsifiable, and Reproducible Findings”

Every statement made in the DID.is web interface is directly falsifiable. The frontend never synthesizes verdicts client-side; every verdict, dimension state, and graph node originates from deterministic execution in resolver-core.

At the bottom of every dossier, DID.is displays the exact curl command to reproduce the findings:

reproduce-verdict
Run

                1
                # Reproduce the exact verdict and dimensions using the public API
              
                2
                curl -s "https://did.is/api/v1/resolve/did:web:identity.foundation" | \
              
                3
                jq '{verdict, dimensions: [.dimensions[] | {id, state, statement}]}'
              

                1
                # Inspect the underlying DAG graph nodes and verification edges
              
                2
                curl -s "https://did.is/api/v1/graph/did:web:identity.foundation" | jq .
              

                1
                import { DidisClient } from '@didis/client';
              
                2
                 
              
                3
                const client = new DidisClient({ baseUrl: 'https://did.is/api' });
              
                4
                const { verdict, dimensions } = await client.resolve('did:web:identity.foundation');
              
                5
                 
              
                6
                console.log('Verdict:', verdict);
              
                7
                for (const dim of dimensions) {
              
                8
                console.log(`[${dim.id}] ${dim.state}: ${dim.statement}`);
              
                9
                }
              

Every resolution independently evaluates seven orthogonal dimensions:

┌───────────────────────────────────────────────────────────────────────────────────────────────┐
│ THE SEVEN EVIDENCE DIMENSIONS │
├──────────────┬───────────────────┬──────────────────────────────────┬─────────────────────────┤
│ Dimension │ Label │ What It Proves │ What It Does NOT Prove │
├──────────────┼───────────────────┼──────────────────────────────────┼─────────────────────────┤
│ integrity │ Document Integrity│ Document matches identifier hash │ Control of underlying │
│ │ │ chain or self-certifying data. │ web servers or hosting. │
├──────────────┼───────────────────┼──────────────────────────────────┼─────────────────────────┤
│ keys │ Key Material │ Published keys are well-formed │ Real identity or holder │
│ │ │ and lie on valid curve points. │ legal authorization. │
├──────────────┼───────────────────┼──────────────────────────────────┼─────────────────────────┤
│ control │ Update Authority │ Updates require cryptographic │ Web host security on │
│ │ │ signatures (e.g. did:webvh). │ did:web identities. │
├──────────────┼───────────────────┼──────────────────────────────────┼─────────────────────────┤
│ origin │ Origin Binding │ Web domain signed a valid DIF │ Corporate registration │
│ │ │ configuration binding this DID. │ or trademark rights. │
├──────────────┼───────────────────┼──────────────────────────────────┼─────────────────────────┤
│ transport │ Transport Security│ Leaf TLS cert validity, SAN, │ Key ownership or host │
│ │ │ and trusted WebPKI chain. │ internal security. │
├──────────────┼───────────────────┼──────────────────────────────────┼─────────────────────────┤
│ history │ Verifiable History│ Immutable, hash-chained log of │ Real-world conduct of │
│ │ │ all document versions (webvh). │ the identifier subject. │
├──────────────┼───────────────────┼──────────────────────────────────┼─────────────────────────┤
│ organization │ Real-World Identity│ Fixed: Always NOT_ESTABLISHED. │ Any corporate identity, │
│ │ │ DID.is never checks registries. │ KYC, or legal standing. │
└──────────────┴───────────────────┴──────────────────────────────────┴─────────────────────────┘

Dimensions transition deterministically between six normative states:

Dimension State Semantic Meaning Visual Tone Hex / Token
ESTABLISHED Passed an active cryptographic or procedural check. ok (Green) #10B981
SELF_CERTIFYING Inherently verified by identifier math (did:key, did:jwk, SCID). self (Soft Indigo) #6366F1
NOT_ESTABLISHED Property is absent or cannot be verified (e.g., no domain linkage). neutral (Muted Slate) #64748B
FAILED Check was attempted and explicitly failed (invalid signature, bad hash). fail (Crimson Red) #F43F5E
INDETERMINATE Check could not finish conclusively (network timeout, unreachable list). warn (Amber) #F59E0B
NOT_APPLICABLE Property does not apply to this method (e.g., TLS on did:key). na (Subtle Sunken) rgba(255,255,255,0.2)