[CHROME_DAO_INITIATIVE] / SMART-SSI
Your runs, your missions, your reputation already exist, locked inside platforms. Smart-SSI turns them into proofs anyone can verify, without exposing your data and without depending on a platform.
- RAW DATA ON-CHAIN
- 0
- RAW DATA ON-CHAIN
- LAYERS: PROVE, INTERPRET, ATTEST
- 3
- LAYERS: PROVE, INTERPRET, ATTEST
- TOKEN. FUNDED BY THE DAO
- NO
- TOKEN. FUNDED BY THE DAO
{ "athlete": "camille.r", "email": "c.r***@mail.com", "session_token": "eyJhbGciOiJIUzI1...", "activities_total": 312, "first_activity": "2024-09-03", "avg_runs_per_week": 3.0, "home_lat": 48.8566, "home_lng": 2.3522, "heart_rate_avg": 152, "last_route": "Parc des Buttes...",}
ATTESTATION · SOLANA
REGULAR RUNNER
3× / WEEK · SINCE 2024-09
- SUBJECT
- did:sol:7xKX…q9Fd
- SOURCE
- strava
- PROOF_REF
- 0x9f3c…e21a
- RAW_DATA
- NOT STORED
01 // THE_PROBLEM
Today you either declare or expose.
Proving who you are online forces a choice between not being believed and showing everything. Pick a mode and watch what the landlord gets.
VERIFIER_QUERY: "DO YOU EARN MORE THAN €3,000 A MONTH?"
Illustrative scenario.
DATA POINTS HANDED OVER
93
THE LANDLORD NOW KNOWS WHERE YOU SHOP, EAT AND HEAL.
01
SILOED IDENTITIES
Years of runs, hundreds of freelance jobs, a reputation: locked in each service, gone if the account closes.
02
DECLARING IS NOT ENOUGH
With generative AI a credible fake profile costs almost nothing. One actor can pass for hundreds.
03
VERIFYING COSTS PRIVACY
To prove an income you send three full bank statements. The verifier keeps far more than it needs.
04
EXISTING ANSWERS ARE PARTIAL
DIDs and Verifiable Credentials need an issuer. Strava, Spotify or your bank will never issue one.
02 // THE_PROTOCOL
Three layers.
Data in, proof out.
Smart-SSI builds a bridge between the data that already exists and attestations anyone can verify.
LAYER_1 · PROOF
The data really comes from the source
You log in to the service as usual. With zkTLS, an attestor run by the DAO on open-source code watches the encrypted exchange without seeing its content, and you generate a proof that the server’s response contains the data. Nobody gets your credentials. Only the useful fact is revealed.
NEVER SHARED
login · password · session token
OUTPUT
π = proof(response contains activities_total)
LAYER_2 · INTERPRET
The data becomes a useful claim
“312 recorded activities” tells a verifier little. An AI model turns proven data into a readable, dated claim. It produces derived facts, never personality traits: every claim traces back to the proven data it rests on.
activities_total = 312
weeks = 104
avg = 3.0 / week
DERIVED CLAIM
REGULAR RUNNER · 3×/WEEK · 2 YEARS
✓ derived fact ✗ “disciplined person” ✗ “health profile”
LAYER_3 · ATTEST
The claim is bound to your identity
The claim is signed and recorded on Solana, attached to your decentralized identifier. Only the claim goes on-chain, never the data. Any service can verify it in milliseconds, without contacting you or the source.
ON-CHAIN
claim · date · source · signature · expiry
bound to did:sol:7xKX…q9Fd
ANY VERIFIER
verify(attestation) → PENDING…
no call to you, no call to Strava
03 // PRIVACY_&_TRUST
Your device is
the perimeter.
Credentials, raw data and history never leave the phone. Only the claim crosses the line, and you can take it back.
YOUR DEVICE
NEVER LEAVES
SOLANA
PUBLIC · VERIFIABLE
YOU_STAY_IN_CONTROL
You choose which proofs to generate, approve each claim before it is issued, decide who sees it, and can revoke it at any time. Revoking does not erase the on-chain record; it makes the attestation invalid for every verifier.
TRAIL CLUB · VERIFIER
verify("runner.regular", did:sol:7xKX…q9Fd)
→ VALID
Two trust levels, made explicit
Every attestation rests on two kinds of trust. Each phase of the roadmap shrinks what you still have to take on faith.
LEVEL_1
DATA PROOF
The data really comes from the stated service. Trusted today: zkTLS attestors.
ONE DAO-RUN ATTESTOR
SEVERAL INDEPENDENT ATTESTORS
DAO-SELECTED NETWORK
Bar = trust you still extend (qualitative) →
LEVEL_2
INTERPRETATION
The claim correctly follows from the data. Trusted today: the Smart-SSI issuer.
PUBLIC MODEL + RULES
TRUSTED EXECUTION (TEE)
zkML
Bar = trust you still extend (qualitative) →
GDPR: claims cover activity facts, never psychological traits or sensitive data (health, opinions, religion), and rest on explicit consent at each step. No personal data goes on-chain in clear; the fit with the right to erasure is still to be confirmed with a lawyer.
04 // USER_JOURNEY
The cryptography
stays invisible.
Users only see badges they control, share and can remove from their profile. Here is Camille.
NEW IDENTITY
did:sol:7xKX…q9Fd
✓ READY · NO SEED PHRASE
05 // USE_CASES
First the DAO.
Then anyone who needs trust.
Smart-SSI serves the Chrome DAO itself first, then opens to every service that has to know something about you.
DAO · ANTI_SYBIL_VOTING
One person. One voice.
However many wallets someone controls, a verified person votes once. Governance gains legitimacy.
VOTES COUNTED
64
Illustrative simulation.
DAO · METAVERSE_ACCESS
Doors that open on proof
The 3D hub already gates The Source for Ring holders. Spaces can open on proof: a studio for verified artists, a club for regular athletes.
DAO · INITIATIVE_SELECTION
Fund proven talent
Project leads prove their track record (jobs delivered, audience, sporting or artistic consistency) instead of just declaring it.
Beyond the DAO
Each verifier gets exactly the answer to its question, and nothing more.
AIRDROPS
Web3 projects
ASKS
Unique person, active on 3+ services?
→ TRUE
Never sees: which wallets, which accounts
FREELANCE
Platforms, clients
ASKS
100+ jobs delivered, rated 4.8+?
→ TRUE
Never sees: clients, rates, messages
INCOME
Landlords, lenders
ASKS
Income above 3× the rent?
→ TRUE
Never sees: exact amount, every transaction
COMMUNITIES
Clubs, Discord, events
ASKS
Climbs at least twice a month?
→ TRUE
Never sees: gym, schedule, location
HIRING
Companies
ASKS
Shipped Rust code in the last 12 months?
→ TRUE
Never sees: private repos, employer
Example questions, for illustration.
06 // POSITIONING
Not who you are.
What you did.
Legal identity is getting its standard. Proven reputation does not have one yet. That is the empty corner.
Chrome DAO's reading of the landscape. Tap or hover a point.
SMART-SSI
PROVES
What you did, as readable claims
HOW
Own open-source zkTLS + AI interpretation + attestations on Solana
ROLE
The layer that turns data proofs into an identity humans and apps can read.
W3C standards (DID, Verifiable Credentials) are followed, keeping the door open to the European wallet.
07 // ECONOMICS_&_GOVERNANCE
A public good.
No token. No raise.
Auctions fund the protocol, the protocol strengthens the DAO’s governance, and verifier revenue feeds the treasury.
CHROME_HOLDERS_VOTE_ON
- 01Which data sources come first
- 02Issuance rules: thresholds, validity
- 03Who joins the attestor network
- 04How the initiative’s budget is spent
USERS
FREE
VERIFIERS
PAY PER CHECK OR SUBSCRIBE
REVENUE
BACK TO TREASURY
08 // ROADMAP
Four phases.
Each one voted.
The DAO approves every phase before the next one starts.
- 1 NOW
PHASE_1
PROOF OF CONCEPT
- ›DID on Solana
- ›First source: Strava or GitHub
- ›DAO-run zkTLS attestor, open source
- ›First attestations for DAO members
- 2GATE · DAO VOTE
PHASE_2
INTERNAL USES
- ›Anti-sybil voting
- ›Proof-gated Metaverse access
- ›5 to 10 supported sources
- 3GATE · DAO VOTE
PHASE_3
OPENING UP
- ›Public SDK for verifiers
- ›First paying partners
- ›Full security audit
- 4GATE · DAO VOTE
PHASE_4
DECENTRALIZATION
- ›Network of independent attestors
- ›Interpretation in a TEE
- ›Interop with the EU wallet
! SOURCE_DEPENDENCY
If a site changes its interface or blocks access, that source has to be adapted.
! RESIDUAL_TRUST
Until interpretation is proven cryptographically, the issuer stays a trusted party, held in check by transparency and governance.
! ADOPTION
An attestation is only worth something if verifiers accept it. That is why the first uses are inside the DAO.
! LEGAL_FRAMEWORK
The status of attestations and their fit with the GDPR must be validated before opening to third parties.
09 // FOR_BUILDERS
One public schema.
Zero raw data.
Attestations live on the Solana Attestation Service, the shared standard for credentials on Solana. Only the proof hash is kept, for later audits; the data itself is never stored.
{ "credential": "<Smart-SSI credential>",ISSUER "schema": "runner.regular v1",WHAT "nonce": "<user wallet>",WHO "signer": "<issuer key>", "expiry": "2027-10-05",EXPIRES "data": { "since": "2024-09", "frequency_per_week": 3, "source": "strava",FROM "proof_ref": "<hash of the zkTLS proof>",AUDIT "model_version": "<hash of the rules>",TRACE "issued_at": "2026-10-05" }}
VERIFY_ON_SOLANA
- The zkTLS proof is checked off-chain by the issuer. Only its hash goes on-chain.
- Verifiers check the account, the Smart-SSI credential, the schema, the signer and the expiry.
- Revoking closes the account. The DAO pays the accounts, so users need no SOL.
- Same standard as other Solana issuers (KYC, work, gaming): verifiers can combine them.
[END_OF_TRANSMISSION]
Your reputation,
proven. Portable. Yours.
Read the full white paper, follow the build on GitHub, or hold a Chrome to vote on what Smart-SSI proves first.