
StimuliZ Digital
Public and non-profit
Phase 1 delivered, phase 2 in build
A self-sovereign identity platform, built as an MVP a government buyer could evaluate
StimuliZ Digital needed the first working version of a decentralised digital identity platform: a mobile wallet a person actually holds their credentials in, the issuing and verification infrastructure an institution runs behind it, and a public site to put the whole proposition in front of buyers. We delivered phase one, and phase two is in build.
stimuliz.caPhase 1
Delivered: the identity application and the public site
2
Sides built: the holder's wallet and the issuer and verifier stack
W3C
Verifiable credentials and DIDs, with nothing proprietary invented
eIDAS 2.0
The regulation the credential model was designed against

The challenge
Self-sovereign identity is a field with no shortage of whitepapers and very few things a procurement officer can hold. The buyers here are governments and large organisations, and they do not evaluate an idea: they evaluate a working system against standards they already trust, with an answer for what happens when a credential is revoked, when a device is lost, and when a regulator asks where the personal data sits. So the MVP had a harder job than most. It had to be small enough to build and complete enough to be judged, and every architectural shortcut that would have made it faster to ship was a shortcut that would have made it unbuyable.
What we did
We started by fixing the standards rather than the features, because in identity the standards are the product: W3C verifiable credentials and decentralised identifiers, a blockchain trust layer holding only what has to be public, and a design aimed squarely at eIDAS 2.0 and GDPR from the first diagram rather than retrofitted after a compliance review. Nothing proprietary was invented where an open specification already existed. From there we built both sides of the exchange, because one without the other proves nothing: the holder's mobile wallet, and the multi-tenant issuing and verification services an institution runs. Selective disclosure was treated as core rather than a later feature, since proving a claim without handing over the underlying data is the entire argument for the model. The public website was built alongside it, so the proposition and the product arrived together.
The result
Phase one is delivered: the identity application and the public site at stimuliz.ca, which is live. StimuliZ can now show a government or enterprise buyer a credential being issued, held, and verified, on open standards, rather than describing it. That moved the conversation from whether the model works to what it would take to run it in a specific institution, which is the only conversation worth having in this market. Phase two is in build with us on the same terms: their name on the domain, the repositories, and the intellectual property throughout.
Every piece of it, stage by stage.
- 01
Discovery and standards
Deciding what the MVP had to prove to a public-sector evaluator, and settling the standards it would be built on before any code existed. W3C verifiable credentials and decentralised identifiers, chosen because interoperability is not a feature you can add later.
- 02
Trust architecture
The ledger's role, what is written on-chain and what is emphatically not, how issuers are anchored, and how a credential is revoked in a way a verifier can check without phoning anyone. The decisions that are impossible to reverse later, made first.
- 03
Mobile wallet application
The holder's side: receiving credentials, storing them under keys the person controls, presenting them, and recovering when a device is lost. The place where a specification either becomes usable by an ordinary person or does not.
- 04
Issuer and verifier services
The institution's side, built multi-tenant from the start so one deployment can serve several organisations without their data or their trust relationships touching. Issuance, verification, and the APIs a client's existing systems call.
- 05
Selective disclosure
Proving a claim without surrendering the document behind it: over the age threshold without the birth date, resident in the jurisdiction without the street address. The privacy argument for the whole model, so it belonged in phase one.
- 06
Public website
The site at stimuliz.ca, covering both the firm's services and the identity platform, in multiple languages and with the analytics needed to see which parts of a genuinely unfamiliar proposition land.
- 07
Security and compliance
Key handling, transport and storage, and a data model designed against eIDAS 2.0 and GDPR rather than reviewed against them at the end. In this market a compliance answer is not paperwork, it is the first question asked.
- 08
Phase 1 delivery
Handover of a working platform: the application and the website live, the repositories and cloud accounts in the client's own name, and documentation written for the people who would be demonstrating it.
- 09
Phase 2, in build
Deepening the platform from something that demonstrates well into something an institution can run: the work now under way, on the same footing as phase one.
Scope of the engagement
- Discovery and standards
- Trust architecture
- Mobile wallet application
- Issuer and verifier services
- Multi-tenant infrastructure
- Selective disclosure
- Public website
- Security and compliance
- Phase 2 roadmap
Wherever you’re starting from, let’s figure out the next step.
Tell us what you’re building. We’ll tell you honestly whether we’re the right team for it.
