Die eIDAS 2.0-Referenzplattform, gebaut mit reiner Kryptografie.
SD-JWT VC + ISO 18013-5 mDoc, persistente 3-Level-CA, LOTL-Parser, EU-AI-Act- und DSGVO-konform. Ohne Abkürzungen. Ohne Mocks.
Sechs Säulen · ein Government-Stack
SD-JWT VC Issuer
RFC 7515 R‖S JWS, `_sd`-Digests, KB-JWT, Status-List mit LRU-Cache.
ISO 18013-5 mDoc
COSE_Sign1 (Tag 18), MSO Payload (Tag 24), RFC 3339 UTC-Zeit (Tag 0).
Persistente 3-Level-CA
Root → Intermediate → Signer, AES-256-GCM verschlüsselt in MongoDB.
Multi-Country Federation
11 Adapter mit einheitlichem Protocol, DSGVO-konformes ID-Hashing.
Compliance Cockpit
SHA-256 hash-chained Audit-Log, AI-Act Art. 13/14, DSA-PDF-Export.
Trust-Pipeline
ETSI TS 119 612 LOTL-Parser, X.509-Kettenprüfung nach RFC 5280.
Fünf Ebenen. Zehn Bausteine. Ein Public-Goods-Stack.
Von der modularen GovStack-Ebene über den Excellent Hub bis zur institutionellen Verankerung — die Blaupause macht jede Schicht, jeden Prüfpfad und jeden Datenfluss sichtbar. Keine Blackbox, kein Vendor-Lock-in, volle Nachvollziehbarkeit.
Klick, valide, sieh den Live-Ticker leuchten.
Drei sofort einsatzbereite Beispiel-Payloads gegen GDPR, DORA und den EU AI Act. Jede Validierung erscheint sofort im flüchtigen Live-Ticker rechts — schließe den Tab, und alles ist weg.
{
"controller": "PNIA Reference Ltd.",
"processing_purpose": "user auth"
}{
"ict_governance": "board approved",
"ict_risk_register": "documented",
"incident_classification": "tier1..3",
"incident_reporting_timeline": "4h/1M",
"digital_operational_resilience_testing": "annual",
"third_party_ict_register": "yes",
"critical_third_party_designation": "assessed",
"business_continuity_plan": "RTO 4h"
}{
"ai_system_role": "provider",
"risk_classification": "high-risk",
"technical_documentation": "annex-iv v1.2"
}27 nations. One CountryAdapter Protocol.
From France Connect+ (INSEE) to Swiss Swiyu (AHV) to AAMVA mDL (US) — every jurisdiction speaks the same interface, with GDPR-compliant SHA-256 pseudonymisation of national IDs at the boundary.
Explore federation