Skip to content
StimuliZ Digital

StimuliZ Digital

Public and non-profit

Phase 1 delivered, phase 2 in build

A self-sovereign identity platform, built as an MVP a government buyer could evaluate

StimuliZ Digital needed the first working version of a decentralised digital identity platform: a mobile wallet a person actually holds their credentials in, the issuing and verification infrastructure an institution runs behind it, and a public site to put the whole proposition in front of buyers. We delivered phase one, and phase two is in build.

stimuliz.ca

Phase 1

Delivered: the identity application and the public site

2

Sides built: the holder's wallet and the issuer and verifier stack

W3C

Verifiable credentials and DIDs, with nothing proprietary invented

eIDAS 2.0

The regulation the credential model was designed against

A rendering of a distributed compute cluster

The challenge

Self-sovereign identity is a field with no shortage of whitepapers and very few things a procurement officer can hold. The buyers here are governments and large organisations, and they do not evaluate an idea: they evaluate a working system against standards they already trust, with an answer for what happens when a credential is revoked, when a device is lost, and when a regulator asks where the personal data sits. So the MVP had a harder job than most. It had to be small enough to build and complete enough to be judged, and every architectural shortcut that would have made it faster to ship was a shortcut that would have made it unbuyable.

What we did

We started by fixing the standards rather than the features, because in identity the standards are the product: W3C verifiable credentials and decentralised identifiers, a blockchain trust layer holding only what has to be public, and a design aimed squarely at eIDAS 2.0 and GDPR from the first diagram rather than retrofitted after a compliance review. Nothing proprietary was invented where an open specification already existed. From there we built both sides of the exchange, because one without the other proves nothing: the holder's mobile wallet, and the multi-tenant issuing and verification services an institution runs. Selective disclosure was treated as core rather than a later feature, since proving a claim without handing over the underlying data is the entire argument for the model. The public website was built alongside it, so the proposition and the product arrived together.

The result

Phase one is delivered: the identity application and the public site at stimuliz.ca, which is live. StimuliZ can now show a government or enterprise buyer a credential being issued, held, and verified, on open standards, rather than describing it. That moved the conversation from whether the model works to what it would take to run it in a specific institution, which is the only conversation worth having in this market. Phase two is in build with us on the same terms: their name on the domain, the repositories, and the intellectual property throughout.

The engagement

Every piece of it, stage by stage.

  1. 01

    Discovery and standards

    Deciding what the MVP had to prove to a public-sector evaluator, and settling the standards it would be built on before any code existed. W3C verifiable credentials and decentralised identifiers, chosen because interoperability is not a feature you can add later.

  2. 02

    Trust architecture

    The ledger's role, what is written on-chain and what is emphatically not, how issuers are anchored, and how a credential is revoked in a way a verifier can check without phoning anyone. The decisions that are impossible to reverse later, made first.

  3. 03

    Mobile wallet application

    The holder's side: receiving credentials, storing them under keys the person controls, presenting them, and recovering when a device is lost. The place where a specification either becomes usable by an ordinary person or does not.

  4. 04

    Issuer and verifier services

    The institution's side, built multi-tenant from the start so one deployment can serve several organisations without their data or their trust relationships touching. Issuance, verification, and the APIs a client's existing systems call.

  5. 05

    Selective disclosure

    Proving a claim without surrendering the document behind it: over the age threshold without the birth date, resident in the jurisdiction without the street address. The privacy argument for the whole model, so it belonged in phase one.

  6. 06

    Public website

    The site at stimuliz.ca, covering both the firm's services and the identity platform, in multiple languages and with the analytics needed to see which parts of a genuinely unfamiliar proposition land.

  7. 07

    Security and compliance

    Key handling, transport and storage, and a data model designed against eIDAS 2.0 and GDPR rather than reviewed against them at the end. In this market a compliance answer is not paperwork, it is the first question asked.

  8. 08

    Phase 1 delivery

    Handover of a working platform: the application and the website live, the repositories and cloud accounts in the client's own name, and documentation written for the people who would be demonstrating it.

  9. 09

    Phase 2, in build

    Deepening the platform from something that demonstrates well into something an institution can run: the work now under way, on the same footing as phase one.

Scope of the engagement

  • Discovery and standards
  • Trust architecture
  • Mobile wallet application
  • Issuer and verifier services
  • Multi-tenant infrastructure
  • Selective disclosure
  • Public website
  • Security and compliance
  • Phase 2 roadmap

Wherever you’re starting from, let’s figure out the next step.

Tell us what you’re building. We’ll tell you honestly whether we’re the right team for it.