Coming Soon
Built on AWS Nitro Enclaves

VettID

Secure. Private. Trusted.

Your personal concierge — protecting your identity, your connections, and your AI agents.

Your identity should be portable. Your devices should be disposable. Privacy should not be a luxury.

Membership opens soon — join the list

While you're waiting for VettID, see what you can do right now — free Privacy Playbooks →

Introducing

VettID

Your Personal Concierge for Digital Life

A good concierge keeps your keys safe, watches the door, and acts only on your instructions. VettID does the same for your digital life — your identity, your secrets, your connections, and your AI agents, all guarded in a vault only you control. Here's what that looks like.

What You Can Do with VettID

Your vault isn't just secure storage — it's a foundation for a truly private digital life.

Private Connections

Connect directly with friends and family. Send encrypted messages and make secure calls — no middleman can read your conversations.

Learn more →

Service Connections

Connect with businesses that run VettID Service Vaults. Share only what you choose, revoke access anytime, and keep full control of your data.

Learn more →

Identity Credentials

Store verified credentials in your vault. Prove who you are without revealing more than necessary — age verification without sharing your birthdate.

Learn more →

Secure Secrets

Keep passwords, API keys, and sensitive notes encrypted in your vault. Access them from your phone, protected by hardware security.

Learn more →

Democratic Voting

Participate in cooperative governance with privacy-preserving votes. Your vote counts, but no one can see how you voted.

Learn more →

Encrypted Backup

Back up your vault so only you can unlock it. Recover your digital life on a new device without exposing your secrets.

Learn more →

AI Agent Access

Give your AI agents secure access to vault secrets — API keys, tokens, and credentials — without ever exposing them. You approve every connection and control exactly what each agent can see.

Learn more →

Bitcoin Wallet

Generate and manage Bitcoin wallets inside your hardware-isolated vault. Private keys never leave the enclave. Share your address privately with your connections and send Bitcoin directly to them.

Learn more →

Encrypted Agent Messaging

Talk to your AI agents over end-to-end encrypted channels of your own — no third-party chat app in the loop. Messages and approval requests appear in your feed with verified agent identity.

Learn more →

Location on Your Terms

Share your live location with the people you choose — a friend you're meeting, family on a trip — and cut access the moment you're done. No ad networks tracking you in the background.

Learn more →

For Businesses: Service Vaults

Organizations can run VettID Service Vaults to interact with members securely. Reduce your risk exposure by never storing sensitive customer data — access it on-demand from the customer's vault, with their explicit consent.

  • Shrink breach exposure — you can't leak what you don't store
  • Reduce fraud with verified, customer-controlled identity data
  • No data caching — access on-demand with clear consent
  • Customers revoke access instantly when they choose
  • Build customer trust through verified privacy practices

For Developers: Agent Connector

The VettID Agent Connector is an open-source sidecar binary that gives AI agents secure, owner-controlled access to vault secrets and encrypted messaging. A single command connects your agent to a vault — the owner defines exactly what it can access, and revocation is instant. The agent never touches encryption keys or credentials.

  • Zero-trust for the agent — never holds encryption keys or messaging credentials
  • Owner approves scope, rate limits, and auto-approval rules from their phone
  • Secrets pass through, never cached
  • E2E encrypted messaging — agents send messages and approval requests directly to user's feed
  • Single Go binary with local-only REST and WebSocket API
  • Platform-bound credentials — cannot be decrypted on any other machine
  • Open source (AGPL-3.0) — view on GitHub

Everywhere You Work: Desktop Client

VettID Desktop extends your vault to macOS, Windows, and Linux. Sessions are time-limited and capability-scoped — your phone stays in control. Browse connections, read feeds, and view audit logs independently. Sensitive operations like retrieving secrets or updating credentials require real-time phone approval.

  • Time-bounded sessions with automatic expiry and phone-controlled renewal
  • Independent access to connections, feeds, messages, and audit logs
  • Machine fingerprinting binds credentials to a specific device
  • E2E encrypted — desktop never holds the vault master key
  • Open source (AGPL-3.0) — view on GitHub

For Web3: Onboarding Without Seed Phrases

The hardest part of bringing users on-chain is key custody: seed phrases get lost, custodial wallets defeat the point, and one phishing click drains an account. VettID gives every member a hardware-isolated vault that generates and holds their keys — so your users onboard with an app install and an approval tap, not a twelve-word ritual.

  • Keys are generated inside the enclave — never written down, never exported
  • Users approve signing from their phone; private keys never leave the vault
  • No custodial liability — you never hold user keys or recovery material
  • Connections are revocable by the user, instantly
  • Lose the phone, keep the account — encrypted backup makes devices disposable
New — Position Paper

LEASH

Lightweight Encrypted Agent Secret Handling

MCP (Model Context Protocol) has become the de facto standard for connecting AI agents to tools, but it has no native mechanism for secure secret management. We're proposing one. LEASH is a companion protocol where secrets never leave the vault, humans approve every access, and every operation is auditable.

Security Without Compromise

VettID protects your data with hardware isolation and cryptographic proof — not promises.

Hardware-Isolated Vaults

Your vault runs inside AWS Nitro Enclaves, hardware-isolated environments that even AWS employees cannot access. Your secrets are decrypted only in protected memory.

Nitro Enclaves

Cryptographic Attestation

Before connecting, your app verifies the exact code running in the enclave. You don't have to trust us — you can verify it mathematically.

AWS Attestation

End-to-End Encryption

All communication between your device and your vault is encrypted using keys that only exist at the endpoints. Infrastructure sees only encrypted blobs.

X25519 + ChaCha20
?

Zero-Knowledge Design

VettID infrastructure only sees encrypted data. We literally cannot read your messages, access your keys, or view your secrets, even if compelled.

Zero Access

The Trust Model

Traditional services ask you to trust them. VettID lets you verify instead: your app cryptographically checks the vault before sharing any data.

Security Architecture

Your Device

Holds encrypted credential

Nitro Enclave

Decrypts and processes

Desktop Client

Phone-approved sessions

Agent Connector

E2E encrypted sidecar

Trusted Boundary

VettID Servers

Routes encrypted blobs

Cloud Storage

Stores encrypted data

VettID Staff

No key access

Hardware Attestation

AWS Nitro provides cryptographic proof of the exact code running in your vault. Published attestation measurements (PCR values) let you verify independently.

Memory Isolation

Your vault's memory is hardware-isolated. Not even hypervisor-level access can read your decrypted secrets.

Sealed Storage

Encryption keys are sealed to the enclave's code. If anyone modifies the code, sealed data becomes permanently inaccessible.

Want the full architecture? Read the security deep-dive.

What We Can and Can't See

Transparency about our access. This isn't a policy choice — it's a technical guarantee enforced by hardware.

What VettID Can See

  • Encrypted blobs (opaque ciphertext)
  • Your messagespace address — not what flows through it
  • User account identifiers
  • Vault activity patterns (not content)

What VettID Can Never See

  • Your messages and communications
  • Private keys and seed phrases
  • Vault encryption keys
  • Contact lists stored in your vault
  • Any plaintext vault data

A Cooperative Built for You

VettID is not a corporation. We are a member-owned cooperative where every voice matters. Our governance is transparent, our priorities are aligned with yours, and our mission is simple: protect our members.

When you join VettID, you're not just a customer — you're an owner with voting rights on how we operate, what services we offer, and how we protect our community.

Democratic Governance

One member, one vote. Major decisions are made by the community.

Transparent Operations

See how your membership fees are used to protect the community.

No Profit Motive

We exist to serve members, not shareholders seeking returns.

Shared Values

Built by privacy advocates, for people who value their digital freedom.

How It Works

1

Become a Member

Sign up and choose the membership that fits you.

2

Create Your Vault

Your personal vault is provisioned inside a hardware-isolated enclave. Only you control the keys.

3

Verify & Connect

Your app cryptographically verifies the vault before connecting. No trust required, just math.

Stay in the loop

Be First Through the Gate

Membership opens soon. Leave your email and we'll tell you the moment it does.

You'll receive a confirmation email from Amazon Web Services (our email provider) — click it to confirm your spot. No spam, no sharing, and you can leave anytime.