Identity, keys and permission

Control begins with the keys.

Your profile does not begin in our database. It begins with you. Civic Ledger is designed as an interface to participant-controlled identity and civic information.

These are the architecture's access requirements. The current website accepts registrations and inquiries; it does not yet connect identity wallets or process Civic Missions.

Self-Sovereign Profile

You control the VerusID and associated civic profile used by compatible applications. Your values, preferences and civic instructions remain yours to manage.

Application Access

Bring your civic identity. Grant only the access required for the interaction you choose. Applications receive specific information or capabilities under your authorization, rather than ownership of your profile.

Portability

The profile can be brought into compatible applications that support its data types. You direct that portability. Sharing a VerusID does not automatically grant one application access to another application's private fields.

Mission Authorization

A Civic Pulse requires a specific decision about a disclosed mission. Registering interest, connecting an identity or authorizing one application is not blanket permission for every research use.

Decryption

Civic Ledger may receive mission-scoped decryption capability only when the participant authorizes a mission requiring readable data. The mission must say which data can be processed, for what purpose and under which retention and output rules.

Root Control

The participant should never be required to hand Civic Ledger the master private key controlling their VerusID simply to participate in a Civic Mission. Mission access must be scoped to the agreed work rather than transferring root identity control.

Retention

Ending future permission does not cryptographically erase information already legitimately decrypted and incorporated into completed aggregate outputs.

Every mission must disclose retention, withdrawal timing, aggregation cut-off, deletion policy and completed-report treatment. Review those limits before authorizing access.

Porting to RMR

You may choose to use selected profile information in Rate My Representatives where compatible data types are supported. Civic Ledger does not automatically push your profile into RMR, and a shared identity does not itself authorize sharing.

Read the privacy information · Review the participant agreement framework

FOUNDING MIRROR CITY — Help shape a proposed municipal pilot with verified participants, disclosed research and separate process experiments. Explore the Founding Pilot →