One trust fabric for humans, apps, and AI agents.
Affinidi is a connected system — issue verifiable identities, hold them under user control, verify them anywhere, and govern who to trust, across every boundary. Here's how the pieces fit together.
Four building blocks, one loop.
Each product owns one job — and hands off to the next. Together they form a single trust loop that works the same whether the actor is a person or an AI agent.
Affinidi Trust Fabric→
The identity-first Agent Gateway. It governs how agents, apps, and services connect — with policy enforcement, observability, and cross-boundary trust tunnels. Every actor gets a verifiable identity at birth.
- Agent Gateway→
- Agent Stream→
- Agent PaySoon
Affinidi Elements→
Issue, hold, verify, and privately exchange W3C Verifiable Credentials. Elements Services covers issuance and verification, the Vault keeps credentials under the owner’s control, and Messaging moves them over encrypted DIDComm — with zero PII stored on our side.
Affinidi Radix→
Decide who to trust. Governance frameworks, registries, and runtime trust queries (TRQP) that tell any verifier whether a party — human, organisation, or agent — is legitimate.
- Trust Registry→
- Trust ResolverSoon
- Trust CommunitySoon
Affinidi Forge→
Build on all of it. Multi-language SDKs, CLI, and docs to embed issuance, verification, and agent trust into your stack — in a few lines, on open standards.
Open standards, no lock-in.
Everything above is built on open specifications and standards bodies — so credentials and identities interoperate across vendors, borders, and ecosystems.
- DIDComm v2.1
- Trust Spanning Protocol (TSP Rev2)
- DID:WebVH
- Selective Disclosure (SD-JWT)
- Digital Credentials Query Language (DCQL)
- European Digital Identity (EUDI)
- MCP
- A2A
- OID4VCI
- OID4VP
Trust you can verify, not just claims.
- DIDComm v2.1
- Trust Spanning Protocol (TSP Rev2)
- DID:WebVH
- Selective Disclosure (SD-JWT)
- Digital Credentials Query Language (DCQL)
- European Digital Identity (EUDI)
- ISO 27001 certified Independently audited (SAC & UKAS), backed by a public Trust Centre.
- Zero PII stored User-consented by design — no central honeypot of personal data.
- End-to-end encryption DIDComm v2.1 encrypted channels for every exchange.
- Data residency & self-host Run in your own cloud or on-prem — data never leaves your domain.