Operator and continuity
We Are 14 Inc. operates the Emabled reference issuer and is coordinating the initial XCIM v0.x sandbox.
Current operator scope
The deployed reference environment includes the Emabled public console, issuer API, hosted consent surface, lifecycle worker, Cloud SQL persistence and an OIDC-backed reference exchange. The shared XCIM registry, public roots, anchors and resolver remain outside the active surface.
Isolation and key custody
Services run in the dedicated emabled namespace with
separate workload identities and least-privilege access. Receipt, relay,
revocation, batch and webhook signatures use distinct Ed25519 keys held
in Google Cloud KMS. Public verification material is available from the
issuer key set.
Public and private boundaries
Public material is limited to verification keys and future protocol metadata, roots and proofs. Recipient addresses, OAuth secrets or tokens, private application keys and predictable email hashes are not public network data.
Continuity model
Signed historical evidence is designed to remain independently checkable. If an issuer or shared network component is unavailable, cached evidence is bounded by verifier freshness policy and current state eventually becomes indeterminate. The reference sandbox is not a production trust root.
Participation
Independent issuer and verifier participation still requires published conformance criteria, canonical schemas and shared vectors. Registry presence will publish facts; trust remains local policy.