Trust Over IP Foundation
Trust Over IP Foundation is a Linux Foundation-hosted standards body that develops open specifications and governance frameworks for Internet-scale digital trust, serving technology vendors, governments (e.g., Bhutan NDI), and enterprises building decentralized identity and verifiable credential systems.
- Company typePrivate
- Founded2020
- HeadquartersSan Francisco, United States
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Trust Over IP Foundation does
Trust Over IP Foundation is an independent standards development organization launched in May 2020 and hosted within the Linux Foundation Decentralized Trust Foundation umbrella, with its legal seat at Joint Development Foundation Projects, LLC (a Linux Foundation affiliate) in the United States. Its mission is to define a complete architecture for Internet-scale digital trust, producing open specifications, governance frameworks, white papers, templates, and educational resources rather than commercial software products. The foundation serves technology vendors building self-sovereign identity (SSI) platforms, governments implementing national digital identity programs, and enterprises requiring interoperable digital trust infrastructure.
The foundation's core technical contribution is the ToIP four-layer architecture, which combines cryptographic trust at the machine layer with human accountability at the business, legal, and social layers, structured around the Hourglass Model with the Trust Spanning Protocol (TSP) as the universal spanning layer analogous to IP in the TCP/IP stack. Key specifications include the Technology Architecture V1.0 Specification, the Trust Spanning Protocol, the Trust Registry Query Protocol (TRQP), KERI (Key Event Receipt Infrastructure) for verifiable digital identity, ACDC (Authentic Chained Data Containers) for verifiable data provenance, CESR for cryptographic encoding, and the DID:WEBS DID method. The governance portfolio includes the Governance Metamodel Specification plus templates for risk assessment, trust criteria, assurance/certification, and governance framework matrices, supported by case studies such as Bhutan's National Digital Identity program and the Good Health Pass Interoperability Blueprint.
The foundation operates a community-led go-to-market model: membership contributions from organizations and individuals, working groups across technology architecture, governance, and emerging areas, public review of specifications on GitHub, and downstream commercial implementations by member organizations that may generate licensing or royalty revenue. Pricing for membership tiers is not publicly disclosed; the foundation does not sell commercial products and does not operate a traditional SaaS revenue model. Named adopters include the Kingdom of Bhutan for its National Digital Identity program, and strategic positioning is anchored by the Linux Foundation ecosystem, a global contributor base, and recent specification releases including KERI/ACDC/CESR V1.1 in January 2026 and TRQP V2.0 in April 2026.
Trust Over IP Foundation firmographics
Firmographics- Name
- Trust Over IP Foundation
- Legal name
- Trust Over IP Foundation
- Website
- https://trustoverip.org
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Trust Over IP Foundation is a Linux Foundation-hosted standards body that develops open specifications and governance frameworks for Internet-scale digital trust, serving technology vendors, governments (e.g., Bhutan NDI), and enterprises building decentralized identity and verifiable credential systems.
- Ownership category
- akta.pro rank
Trust Over IP Foundation industry classification
Industry- Product category
- Digital Identity Standards
- NAICS
- Financial Transactions Processing, Reserve, and Clearinghouse Activities (522320)
- SIC
- Finance Services (6199)
- akta.pro primary industry
- Smart Contract Frameworks & SDKs (developer kits, templates, standards) (FSAPABAB)
- akta.pro secondary industry
- On-Chain Reputation, Identity & Attestation for Governance (DID, badges, sybil resistance) (FSAPAHAF)
Keywords
Where Trust Over IP Foundation is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Trust Over IP Foundation business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Others
Revenue model
- Membership Contributions: Trust Over IP Foundation operates as an independent project within the Linux Foundation Decentralized Trust Foundation. Organizations and individuals join as members to contribute to and influence the development of open standards and specifications.
- Specification Adoption: Organizations implement ToIP specifications in their products and services, potentially generating revenue through commercial implementations of the open standards.
Go-to-market motion1 record
Distribution channels2 records
Marketing channels6 records
Trust Over IP Foundation product offering
Product offeringCore offering
Trust Over IP Foundation is a non-profit standards development organization that produces open technical specifications and governance frameworks for Internet-scale digital trust infrastructure. The foundation develops the ToIP four-layer architecture combining cryptographic trust at the machine layer with human accountability at business, legal, and social layers, anchored by the Trust Spanning Protocol as a universal spanning layer for digital trust relationships.
Product overview
Trust Over IP Foundation is a standards development organization hosted under the Linux Foundation Decentralized Trust Foundation. Rather than a traditional software product company, they produce a comprehensive suite of specifications, governance frameworks, templates, and educational resources for Internet-scale digital trust infrastructure. The core deliverable is the ToIP Technology Architecture Specification defining a four-layer model combining cryptographic trust at machine layers with human accountability at business, legal, and social layers. Key technical specifications include the Trust Spanning Protocol (analogous to IP for digital trust relationships), Trust Registry Query Protocol, KERI, ACDC, and CESR specifications. The governance portfolio includes the Governance Metamodel Specification and accompanying templates (Risk Assessment, Trust Criteria Matrix, Trust Assurance, Governance Framework Matrix). Foundational documents include white papers on ToIP principles, digital trust, SSI, and AI trust. Educational offerings include the Bite-Size Trust video series and case studies like Bhutan NDI.
Differentiator
Problem solved
Functional benefit
Products and services
- ToIP Technology Architecture Specification Normative architectural requirements for the ToIP technology stack defining how cryptographic trust at machine layers combines with human accountability at business, legal, and social layers. Available as an open specification for technology organizations, governments, and enterprises implementing digital trust infrastructure.
- Trust Spanning Protocol (TSP) Specification The first protocol explicitly designed as a universal spanning layer for digital trust relationships between any two parties, analogous to how IP serves as a spanning layer for data packets between networks. For technology vendors and governments building interoperable digital trust infrastructure.
- Trust Registry Query Protocol (TRQP) Specification A simple and consistent way to programmatically query authoritative ecosystem sources for information about entity authorization and cross-ecosystem recognition. For technology implementers building trust registry lookup functionality.
- KERI (Key Event Receipt Infrastructure) Specification An identity system-based secure overlay for the Internet that provides verifiable authorship (authenticity) of any message or data item via secure cryptographically verifiable attribution. For developers and vendors building decentralized identity systems.
- ACDC (Authentic Chained Data Containers) Specification A protocol providing granular provenanced proof-of-authorship of contained data via a tree or chain of linked protocol elements, delivering a verifiable chain of proof-of-authorship. For systems building verifiable credential infrastructure.
- CESR (Composable Event Streaming Representation) Specification KERI's encoding protocol for cryptographic primitives, providing universal encoding with dual text and binary domain representations via composable conversion. For developers building KERI-compatible identity systems.
- DID:WEBS Method Specification A DID method that combines the ease of discovery of did:web with the security power of KERI for decentralized identity resolution. For implementers building decentralized identifier resolution infrastructure.
- Governance Metamodel Specification Specifies the required, recommended, and optional components of a ToIP-compliant governance framework document set. For governance architects and trust framework operators building compliant digital trust ecosystems.
- Risk Assessment Worksheet Template A guided template to help complete a ToIP-recommended Risk Assessment in advance of a governance framework construction. For governance architects and framework designers.
- Trust Criteria Matrix Template A container to organize and operationalize the accountability of governance framework mandates. For trust framework operators and auditors.
- Issuers Requirements Guide for Governance Frameworks of Verifiable Credentials A Working Group Approved guide for including ToIP recommended issuer requirements within a governance framework conforming to the Trust Over IP governance metamodel. For organizations issuing verifiable credentials.
- Good Health Pass Interoperability Blueprint ToIP Approved deliverable for an open, inclusive, cross-sector initiative focused on reopening global travel through digital credentials. For governments and travel industry stakeholders.
Quantifiable outcome
- The ToIP Architecture enables cryptographic trust at machine layers combined with human accountability at business, legal, and social layers
Companies that use Trust Over IP Foundation
Customer profileNamed customers1 record
Segments3 records
Ideal customer profiles3 records
Trust Over IP Foundation technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature8 records
Trust Over IP Foundation partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- Linux Foundation Decentralized Trust FoundationcoreTrust Over IP Foundation is an independent project hosted within the Linux Foundation Decentralized Trust Foundation umbrella. The Linux Foundation provides organizational infrastructure, governance support, and cross-project collaboration opportunities for ToIP.
Scale indicators4 records
Recent moves6 records
Expansion highlights5 records
Trust Over IP Foundation competitors and assessment
Company assessmentBroad incumbents
- GS1: The global standards organization for supply chain identifiers (barcodes, EPCIS). ToIP's supply chain provenance and verifiable origins use cases overlap directly with GS1's existing traceability standards, making it both a complementary and competing standards venue for digital trust in goods.
- Internet Engineering Task Force (IETF): The premier internet standards body responsible for protocols like TCP/IP, TLS, and HTTP. ToIP's Trust Spanning Protocol ambition to be a 'universal spanning layer' directly adjacent to IETF's domain means IETF is the incumbent infrastructure whose standards processes ToIP must interoperate with or be adopted into.
Direct peers
- Sovrin Foundation: A non-profit organization that governed the Sovrin Network for self-sovereign identity using verifiable credentials. Though its operational scope has changed, Sovrin is a historical peer in the same decentralized identity governance space and uses overlapping technology (Indy/Aries).
- OpenID Foundation: An open-standards body that develops identity and authentication protocols (OpenID Connect, OAuth). ToIP competes for influence on how digital identity, authentication, and trust are standardized — particularly for enterprise and government adoption where OpenID has deep installed bases.
- Open Wallet Foundation: A Linux Foundation project developing open-source interoperable wallets for digital credentials and identity. Sister project under the Linux Foundation umbrella with overlapping membership and complementary scope on the credential-presentation side of ToIP's stack.
- Decentralized Identity Foundation (DIF): An engineering-focused standards organization developing foundational infrastructure for decentralized identity, including DIDs, DIDComm, and Sidetree protocols. As a peer standards body in the same decentralized identity space, DIF competes with ToIP to define the interoperability layer for verifiable credentials and SSI ecosystems.
- W3C Credentials Community Group: The W3C group that developed the Verifiable Credentials Data Model and core DID specification. As the most widely adopted identity standards body, WG/W3C represents both a competing standards venue and a complementary reference architecture for ToIP's verifiable credential specifications.
- Kantara Initiative: A non-profit standards and certification organization focused on digital identity, privacy, and consent receipt frameworks. ToIP and Kantara both operate at the intersection of identity governance and technical standards, with overlapping member communities in government and enterprise.
Others
- Trust over IP Foundation Working Group on AI Trust: Internal ToIP community initiative around AI-trust extensions to TSP. Listed as adjacent context rather than a separate peer — illustrates how ToIP's own working groups generate the future spec roadmap that competing decentralized identity bodies will need to respond to.
Emerging players
- IDunion: A German-based consortium building production SSI infrastructure using Hyperledger Indy/Aries. IDunion is an emerging deploying consortium in the European government digital identity space, partially overlapping with ToIP's verifiable credentials and governance framework work.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
Trust Over IP Foundation social profiles
Digital presenceTrust Over IP Foundation financial estimates
Financial estimateRevenue estimate
Valuation estimate
Trust Over IP Foundation leadership team
Management profileNumber of profiles
Trust Over IP Foundation funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Trust Over IP Foundation M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Trust Over IP Foundation
What does Trust Over IP Foundation do?
Trust Over IP Foundation is a non-profit standards development organization that produces open technical specifications and governance frameworks for Internet-scale digital trust infrastructure. The foundation develops the ToIP four-layer architecture combining cryptographic trust at the machine layer with human accountability at business, legal, and social layers, anchored by the Trust Spanning Protocol as a universal spanning layer for digital trust relationships.
When was Trust Over IP Foundation founded?
Trust Over IP Foundation was founded in 2020. It employs 1 to 10 people.
Where is Trust Over IP Foundation based?
Trust Over IP Foundation is headquartered in San Francisco, United States, in the North America region.
How does Trust Over IP Foundation make money?
Two revenue lines are on record. Membership Contributions are the primary driver. The others are specification Adoption.
Who are Trust Over IP Foundation's main competitors?
Broad incumbents on record are GS1 and Internet Engineering Task Force (IETF). Direct peers are Sovrin Foundation, OpenID Foundation, Open Wallet Foundation, Decentralized Identity Foundation (DIF), W3C Credentials Community Group and Kantara Initiative. Trust over IP Foundation Working Group on AI Trust is listed as an others. IDunion is listed as an emerging player.
Does Trust Over IP Foundation have an API?
No public API is recorded for Trust Over IP Foundation.
What industry is Trust Over IP Foundation in?
Trust Over IP Foundation's product category is Digital Identity Standards. Its primary akta.pro industry code is FSAPABAB, Smart Contract Frameworks & SDKs (developer kits, templates, standards), with a secondary code of FSAPAHAF, On-Chain Reputation, Identity & Attestation for Governance (DID, badges, sybil resistance). Its NAICS code is 522320 and its SIC code is 6199.