About

A team that has built this layer before.

We are a team with deep experience in trust technologies, going back to the invention of SSL — the certificate infrastructure behind every padlock in every browser, the security layer built for web services after it, API governance after that, and media systems at scale. Every trust gap described on this page, we have worked inside, including the parts that did not work.

Our team's provenance
VerisignSymantecSun MicrosystemsIntertrustOracleGoogleApigeeAmberpointApiaryLinkedInNetflixDatadogRokuMovieLabs

Origin

It started as a proof of concept with Carnegie Mellon.

Noosphere began as a proof of concept built in partnership with Carnegie Mellon University, testing whether this trust layer could be made to work on real artifacts rather than in an academic paper. The design work from it settled the questions the platform still answers: how to identify the entities that actually exist in published media — artifacts, the creators who control them, the organisations creators publish for, and the intermediaries who annotate work after publication — and how to link an amendment to what it corrects, so a record extends rather than replaces.

It also put the decision about whose claims to accept with the relying party rather than the platform. That is the choice everything else follows from, and it is why this is a trust graph built from relationships organisations publish about themselves rather than a registry we operate.

Every shift in how systems communicate opens a trust gap

An application cannot bootstrap trust from the objects it is trying to authenticate. That is why browsers, certificate authorities, trust stores and policy engines exist — and we have watched the same abstraction error get made three times.

The browser era

No way to verify who you were talking to.

When the web went commercial, browsers connected to servers with no way to verify identity and no way to encrypt the connection. We were part of the team that built the first root certificates and the PKI that made HTTPS possible. That infrastructure still runs today, behind every padlock in every browser.

The web services era

Machines talking to machines across organisations.

You cannot put a padlock icon on an API call. Enterprises needed to connect systems across organizational boundaries, so we built Trust Gateway and worked on WS-Security, WS-Trust and XKMS — signing, encryption, federated identity and key management at the message level rather than the transport.

The API era

REST replaced SOAP and the problem moved again.

The web services stack gave way to lighter-weight APIs, but the trust problems did not disappear. We built API gateways and policy-based governance for the explosion of internal and external APIs enterprises suddenly had to manage.

The agent era

Agents reason, plan, delegate and act.

Agents do not just call APIs. They cross organizational boundaries and make decisions on behalf of people. The same pattern, a fourth time — except now the internet also has an authenticity crisis, so agents inherit a world where nobody can tell what is real.

Provenance is only as good as its governance.

Tell us what your workflows look like and where the work travels, and we will show you what governing them looks like in practice.