This is the most important article in the series, so I recommend not summarizing it.
6100 words
The Digital Self-Sovereignty Revolution
Trust Mesh: anonymous accounts backed by unique humans
Trust Mesh begins from a simple premise: the internet gives us identity accounts controlled and stored by institutions, and bearer-key wallets controlled by whoever holds the key, but neither provides a private account backed by one unique human whose real-time authorization of consequential actions is its own security layer.
A Trust Mesh sovereign account gathers back the identity you have scattered across corporations along with the usernames and passwords for every account you have at the bank, the newsletter, the marketplace, the social venue, the crypto wallet, and moves them into one encrypted vault on your phone that only your living body can open, so no server anywhere needs to hold a copy of you. The businesses you deal with keep the records their service requires, the Trust Mesh network keeps blinded enrollment markers and logs without names, and the master copy of your digital life is in your pocket. The surest way to prevent a data breach is to have no centralized honeypots to hack.
Each Trust Mesh integrated business you deal with would hold a public key that answers only to the private key sealed in your phone that works nowhere else, plus whatever personal details you chose to tell it. A data breach at that business leaks its own records but nothing about you that opens a door elsewhere. A breach of the vault on your phone yields only ciphertext because opening it requires the phone's sealed hardware and your living body in front of it. Your face or fingerprint is measured by the phone's own sensors and matched against a template that stays in the phone's secure chip, the same one that unlocks it for actions; Trust Mesh never receives it, and no server holds a copy.
Enrollment derives a separate blinded marker from a one-time capture so the network can refuse a second enrollment. The operators compare blinded markers, never faces: the marker answers one question, whether this body has enrolled before, and it cannot be run backward to a face or forward to a name. So the thing that opens the vault is the one thing no attacker can download: you. That encrypted vault is the building block of the next era of the internet, and no corporation, government, or blockchain has built it or is positioned to. An open standard running on a decentralized network that nobody owns offers the most privacy and security possible. Privacy here means the logins and identifiers you use at one service cannot be linked to those at another; content you publish under different names can still be connected by a bot as the same person.
This sovereign account type, one human, one Slot, opens a path out of the machine that turned us into products for advertisers.⁸ ⁹ ¹⁰
How We Became the Product
In 1994, Netscape engineer Lou Montulli invented the browser cookie so a shopping site could remember your cart between pages, but his team refused to give each browser a permanent ID number precisely because it would let outsiders track people from site to site.¹ Within two years DoubleClick found a way around that. When its ad server delivered a banner on a news page, loading that page was also an invisible visit to DoubleClick, so it set a cookie under its own name in your browser, which it recognized on every other site carrying its ads, and that let it track you. By 1997 it had issued forty million cookies, most without users' knowledge, then in 1999 it bought Abacus Direct to merge browsing records with real names and addresses.² ³ ¹¹ The plan died under an FTC inquiry in 2000, but the industry drew the opposite lesson: matching a real name to internet browsing after the fact was the hard way. Having the name first was how tracking could be done.
Google bought DoubleClick in 2008 and in 2016 rewrote its privacy policy to combine the cookie trail with the Google account. Facebook's Like button and pixel did the same for every page that carried them. The login that let you into a website became the thing every tracker attached to. When a site lets you sign in with Google today, Google checks your password on its own server, tells the site you are who you claim, and learns which site asked, with the same Google ID for you at every one of them.¹² It feels like a convenience, but it is also a record that tracks you at every site you signed in to.
Then tracking migrated onto phones through an advertising identifier, one random string the operating system assigns to the device and then hands to every app you allowed, along with a location, a contact list, and ready-made code from Facebook and Google inside most apps. A 2025 study of 6,203 popular Android apps found Meta's ad code in nearly half of them, and among the apps carrying Meta's core toolkit, more than eight in ten were sending the phone's advertising ID to Meta on the default setting the developer never changed, with more than a quarter of those saying nothing about it in their privacy label.²⁶ Data brokers pay app developers a few cents per user to embed a tracker. A weather app reports your coordinates stamped with your phone's advertising ID, and a broker holding that ID trades with a broker holding your name until the two files line up.
An Irish civil liberties group found that the average American's location and activity data was being broadcast to the ad market 747 times a day.²³ The FTC sued Kochava in 2022 over its location data showing visits to clinics and places of worship, then it barred X-Mode in 2024 and settled with Kochava in 2026.¹⁴ ¹⁵ ¹⁶ Apple made apps ask permission first in 2021 and most people said no, at a cost Meta estimated to be ten billion dollars; Android never asked, and in April 2025 Google dropped its five-year plan to remove third-party cookies from Chrome, citing feedback from publishers and the advertising industry that runs on the cookie.¹⁷ ¹⁸ Most people now believe their phone is listening, but a 2018 study of 17,260 apps found no apps switching on the microphone for ads because the tracking was already precise enough without it.¹³ ¹⁹
This business model evolved on its own, and until now there has been no alternative to it, but seen from outside it is bizarre. Imagine this same arrangement in the physical world. A tracker on your ankle reports every place you go to a data broker, who sells it to buyers who then stake a sign in your lawn the morning after you visited a car dealer, or install a perforated living room window graphic for a Big Mac at McDonald’s, or place a sample divot repair tool on your porch because you played golf. Online we call that a business model. In person, we call it invasive. None of this came from bad intent. Advertising paid for a lot of free service websites that needed revenue, but attention quickly became a product to sell.
That is how we became the product in a business model that rewards profiling and engagement to the point of addiction, and incentivizes the creation of conflict. Attention, relationships, and ideological worldview became inputs into a machine tuned to entice clicking for revenue, and the most valuable piece of that machine depends on being able to track you across services with an identity account.⁴
How the Trust Mesh Sovereign Account Works
The internet itself is neutral about people. Its protocols move packets from one numbered machine to another. The domain name system exists only to turn an address you can type, like nytimes.com, into the number of one of those machines. Nothing in that stack knows a human exists. When businesses came online in the 1990s, each one had to distinguish one visitor from another inside its own server, so the username and password were born as a row in its database. Trust Mesh replaces that row in a way that is unlinkable between services, and no company owns the root. Your wallet makes a key for that one website, which keeps the public half as your account; when you come back, your phone signs a challenge with the half you keep, and the half the site stored confirms it. No password exists to steal, no email is needed to hash and match against an advertiser's list, and a receipt proves one enrolled human stands behind the key without saying which one, so there is no identifier to follow you from one service to the next like a corporation that tracks you. Your phone signs the action and the network has already signed your enrolled key, so a business checks both signatures against public keys it downloaded earlier, the way a browser checks a website's certificate without phoning the authority that issued it. This is both more secure and more private.
That receipt rests on a primitive the native internet stack never had. A Slot is a place in the Trust Mesh network that belongs to one human with standing that no company issued and no server stores as a record of you; the network keeps an anonymous marker to refuse a second enrollment, along with the public keys, commitments, and logs any network needs to run, and none of them names you; it is the smallest directory that a count of humans can be built on. The Slot is the position; the marker is the network's entry for it. A wallet is where you act: the signing keys that approve a payment, or release a record, are sealed in the phone's secure hardware, where nobody, including you, can read or remove them. A vault is the record of your relationships, subscriptions, permissions, and receipts, encrypted and held by you.
Two things live in the vault. The Trust Mesh keys are sealed: they sign when your face or finger says so and cannot be copied out. Your other secrets are also stored. Usernames and passwords stay for every service along with seed phrases for every bearer-key wallet. Everything is encrypted under a key the hardware holds. The vault is a password manager on day one, with no master password to forget because it unlocks with your biological uniqueness, and recovery by a network ceremony rather than a secret. Lose the phone and you enroll from a new one; the operators find your marker, move your Slot to the new device after a waiting period, and the old device is dead. The face check is the same liveness test that keeps a photo from unlocking your banking app, and a person forced to open the vault can use a registered duress gesture that lets the act appear to go through while the network quietly freezes the account's next actions until the person is cleared.
It becomes a sovereign account as each service starts accepting a key alongside a password. Consequential acts, a wire, a key change, a new permission for an agent, add a step-up ceremony that layers a second check on the first.
The internet still carries packets. The web still hosts pages. What migrates with Trust Mesh is where the account lives. Today the login, the relationships, and the history sit on a company's server, and the company decides what you may do with them. Under Trust Mesh, the keys that act and the vault that holds your history live in your phone, encrypted, under your control, so every service sees a different key with no link between them. This is how power shifts from corporations to the individual, and digital self-sovereignty is born.
The platforms will keep running the accounts they built, and keep tracking people on them until enough of us opt into sovereign accounts that businesses have to ask for details they once extracted for free. The first adopters will be the ones with the most to gain: creators whose subscribers do not belong to them, sellers whose ratings cannot leave the marketplace that issued them, and drivers, hosts, and freelancers whose reputations are their livelihood on the current platform but worth nothing if they leave or get deplatformed.
Why No One Else Can Build It
A corporation can build the features, and several already have, but every one of them still hands you an identity account as a row on the company's server with a tracking history, so the question to ask is: where does the account live? In Trust Mesh it lives on your phone and is portable. Sign in with Apple gives each app you log into a different ID and a relay email, which is the right idea, but Apple keeps the link between them, and the account works only on Apple's devices, because Apple has no reason to make it work anywhere else. Apple could ship every piece of this tomorrow except the root because a root one company owns can be bought, subpoenaed, repriced, or abused, which is why it is essential that it is decentralized. Apple and Google supply the chip and the face scan, but the authority over who counts as human and which receipts are valid has to sit somewhere no single company owns, or the company that ships the chip can assemble the ultimate dossier of every enrolled human on earth into a database that would violate the privacy of everyone in it and become a honeypot to hack, which is why governments or the public would never allow it.
A government also cannot build it, but the reason is reach rather than motive. Each person needs one account everywhere Trust Mesh operates, across jurisdictions that do not cooperate with one another, so no single state can govern uniqueness beyond its own border or past its next election. A state root is also compellable by the very state that holds it, which is the identity database this design exists to remove. Europe's wallet framework and India's Aadhaar show governments can build local wallets with selective disclosure, but neither can be the count for people outside its jurisdiction.
A blockchain cannot build it because its account is a bearer key, so it cannot know whether one person holds a thousand keys or just one. Many chains have tried to figure out a way past that. World scans your eye with a device one company builds and operates, so the company is the root. Proof of Humanity has other members vouch for you, but a bot farm can vouch for itself once it has enough members. Gitcoin Passport adds up your Google, Twitter, and bank logins, which are the exact identity accounts this replaces. And any chain that lets stakers vote on who is human in the system has put capital in charge of the count. A chain can verify a Trust Mesh receipt in one small contract, but it cannot produce one.
What is left is an open standard anyone can verify on their own hardware, run by a committee of operators under no shared legal control so nobody owns the root, anchored in the secure hardware already in two billion pockets.
Where Today's Decentralized Social Media Accounts Live
Today's decentralized social networks spread storage across federated servers, personal data servers, or relays, and every one of them still stores the account on a server.⁵ ⁶ Three questions separate one kind of decentralization from another: where the account itself lives, who proves the person behind it is one person, and what happens when the key or the server goes away.
A Trust Mesh creator-centered account has to pass four tests: the account survives the venue, one person holds one standing, a key alone cannot act, and the relationship moves with the person. None of today's decentralized networks passes them. On Mastodon the account lives on the server you joined, and when a server shuts down, as many have since 2022, every account on it is lost unless the owner migrated to another server ahead of time, and even then the posts stay behind. Bluesky lets the whole account move between hosts, followers included, but the directory that says where every account lives is run by the company, so moving needs the old host's cooperation or a recovery key the user set in advance.²⁰ On Nostr the key is the account, so a stolen key is a stolen life and a lost key is a lost account. None of the three can tell whether the person behind an account is one person, so spam has no limit, one-member-one-vote is impossible, and none of them is governed by its members. They are decentralized hosting for the two legacy account types.
The paid subscriber relationship, the thing a creator lives on, was never on their servers to begin with. In all three networks it sits with Stripe, Patreon, or Apple, whoever bills the card, so moving to a new server moves the posts but leaves the paying subscribers behind. The difference with Trust Mesh is where the account lives. Because the account lives in the vault on your phone, the subscriber relationship lives there with it: the subscriber's wallet signs a permission like this creator may charge this tier each month, and both sides keep a copy. A processor is something the creator hires to carry that instruction out, the way a bank carries out a standing order, but it never owns the subscriber list. If you change processors, or venues, or get thrown off one, all your subscriber permissions come along; the new venue honors the tier the subscriber authorized, and the charge to the card is still processed on the original instruction.
World ID comes closest to something new. Each app gets a different proof, so no app can track a person's behavior across apps, but there are no receipts binding a human to an action, no vault of relationships, and enrollment runs through a scanning device one company designs, builds, and deploys. A centralized onboarding device attached to a token produces a centrally admitted account, however private each proof is afterward.²¹ Trust Mesh is the only design that answers uniqueness and authority together, admits a person through a check no single company runs, and holds the relationships on the person's own device. It is an entirely new network with the individual at the center of it. Our accounts live with us.
The Trust Mesh Creator-Centered World
On the night of January 18, 2025, TikTok went dark in the United States for about fourteen hours, so a hundred and seventy million accounts sat behind a screen that said the app was unavailable. Creators with millions of followers had no way to reach them, no list to export, and no place to send them because their followers were never actually theirs. The app came back the next day but the lesson did not go away: everything those creators had built lived on a server they did not control, in a country that could switch it off.24
An identity account feels like ours because the profile has our name and face on it, but the platform controls the relationship, sets the rules, and holds the operational record. The platform decides how much reach a creator’s work has. It owns and guards their subscribers, so the reputation a creator spent years building is lost with their account if they get deplatformed. In a digital marketplace, a seller's rating, earned over a decade, is worth nothing outside it. If YouTube closes your channel, for a strike you cannot contest or a policy that changed under you, you lose the channel and every subscriber, and there’s no road to reach them or the years of watch history that told the algorithm who to show your work to. Your ad revenue disappears with the record of your standing, all in one afternoon, with no appeal that a person answers. What you keep is the videos on your own hard drive and the name you were born with. Many creators mitigate this risk by having multiple channels for essentially the same content. The platform grants access to other people in exchange for dependence on it, which is the business model they are protecting by making it difficult to leave, but ultimately creators earn a living inside somebody else's venue with rules they have little or no vote in, so they cannot take their histories and reputation with them because their accounts aren’t sovereign. That all changes with Trust Mesh accounts.
Three groups are most affected by the legacy identity account model beyond creators:
Sellers on marketplaces. More than sixty percent of the units Amazon sells come from third-party sellers,25 and Amazon never gives them their customers’ emails; messages go through Amazon's own system; marketing off the platform is prohibited; and the seller rating built over a decade of good service cannot be exported or shown anywhere else. Etsy and eBay work the same way. A suspension, sometimes by an algorithm, ends their business the same afternoon, with their customers still there but unreachable.
Workers rated by platforms. An Uber driver's 4.9 rating, an Airbnb host's Superhost badge, an Upwork freelancer's job history and reviews are valuable within the platform, but carry no standing anywhere else, a screenshot at best, because each is an identity account owned and controlled by the platform and lives on its servers.
Small businesses that sell through apps. A restaurant whose orders come through the DoorDash app gets a first name and a last initial but no email or phone number, and the platform's terms keep the restaurant from contacting the customer on its own. A developer selling subscriptions inside an iPhone app never learns the buyer's name or email unless the buyer types it in. Apple bills the customer, keeps the account, and sends the developer the money and a transaction record with no person attached, so a developer with fifty thousand subscribers has fifty thousand transactions and no list of people. The business serves the customer but the platform keeps the relationship.
The subscriber holds the same signed permission, and can read it, revoke it, or carry it when they follow the creator to the next venue. The venue still hosts the posts and runs the feed; what it no longer holds is the only copy of the agreement, and a new venue receives only what it needs to honor the tier. That takes the sting out of deplatforming without touching a venue's right to run its own house, and it leaves creators being courted for their content rather than locked in by it.
While creators would want this first because they have their livelihoods at stake, sovereign accounts work the same for anyone with photographs, friendships, and years of history on a platform that they don’t own. The pictures of your children sit on a server whose terms you did not write. The group chat that carried a family through an illness can be closed by a policy change. A Trust Mesh vault gives you ownership of your online relationships and puts the record of your life on the device in your pocket, encrypted, which leaves the platform with what it needs to run its service and nothing more.
Creators, influencers, newsletter writers, and media publishers are all incentivized to onboard with Trust Mesh and encourage their subscribers and followers to do the same, which becomes one of the engines of adoption.
User Centered Social Media
Imagine a social platform stripped of the profit engine that’s geared for engagement, addiction, and ad targeting, created and governed by its members. Maximizing screen time today means stuffing feeds with content that alarms, flatters, or enrages, and speaks to the extremes. While echo chambers will always form around humans seeking confirmation bias, profit-driven social media amplifies them and contributes to social division through a reduction of nuance into simplified ideologies that inflame bias.
A member-created social venue would let its users decide how posts are ranked, how many ads appear in an hour, what evidence earns an accuracy label, which engagement tactics are permitted, and how the developers are paid. Removing the incentive to amplify outrage would not guarantee accuracy or good judgment, but it would change the system's objective from ensnaring attention to serving the best interest of the people using it.
The principle underneath it all is: who are the stakeholders that keep the profit? To keep decentralized social media from devolving into exactly what it is today, the answer has to be no one owns it. If it were owned by the developers, it wouldn’t take long for them to justify increasing the ad count, or a little more screen-time maximizing, or just a wee bit of inflammatory engagement. Since every Trust Mesh account stands for one human and one Slot, a community vote counts real people, not bots, so the members can trust the result, which is what lets a piece of software run without an owner, with the members who use it deciding what the algorithm optimizes for.
Trust Mesh enables the option for the community to run the fewest ads necessary to pay the network’s cost, or generate more income for other purposes, determined not by the corporate need to produce profits for shareholders but by a community vote on how to allocate the funds. With the ease of migration due to sovereign Trust Mesh accounts, if a big enough segment of people don’t like the direction of one community, they can break away and form their own, and take their followers and subscribers with them. What would result is a set of social networks organized around community preferences and niches, so the ads a community deems necessary reach the actual people who are most interested in that topic, and never bots. And every account in the comments would have a real person behind it, even if they let a bot speak in their name.
Social media is more of a public health matter than a media matter. A social venue that does not need to keep you scrolling has no reason to build the infinite feed, the autoplay, the streak, or the notification timed to pull you back at eleven at night. Members could vote for a chronological feed or to emphasize balance, nuance, or whatever policies the community decides are best, including a set of customizations so everyone can create their feed exactly as they want it, so if someone just wants friends and sports, that is in their control.
The days of the current design are numbered. Meta recently agreed to a settlement of about eighteen billion dollars with a bipartisan group of state attorneys general over teen safety, and the terms are exactly the kind of rules a member-run venue would have written for itself: default time limits, nighttime blocks, stronger age assurance, parental controls.7 Since Trust Mesh accounts are opened with biological uniqueness, a teen cannot open another account to get around a limit. An age range, or a parent's authorization, is a provable fact their account can present without their name using zero knowledge proofs, so the venue could require an age-range proof and a parent's receipt before a teen's protected settings can change.
The direction of travel is already in motion. Trust Mesh sovereign accounts simply give it a place to land. I am not the only one with ideas like this, but the Trust Mesh one human, one Slot, decentralized architecture where no one owns the root and all the participants can be verified as human is the only known way to make portable relationships and member-governed social media work.
Proof of Publication
A venue built for truth needs a way to prove who published what. A newsroom, a campaign, or a creator binds their recognized publishing account to a Trust Mesh receipt path, so a receipt attached to one of their media releases cryptographically proves an enrolled human authorized these exact bytes under that account. It does not prove the content is true. What it proves is the source. As deepfakes continue to get cheaper and more convincing, every content creator and media publisher will need a way to prove provenance of their content and to stop fraudsters from marketing scams using their name. A Trust Mesh receipt attached to their content does both.
The Vision
Picture Trust Mesh built out as an opt-in network. You search the web and the search engine sees a pseudonym for you instead of an account, one that matches nothing else you do, so it cannot track your browsing. The same holds for an AI assistant: signed in through Trust Mesh, Claude or Codex holds a key that exists only there and a receipt that names no one, so it has nothing to match against your bank or your social venue. An AI assistant is the richest content record anyone will ever hold on you, richer than a search log, because you tell it things in full sentences and it keeps a memory file to serve you better. That is the content problem again, the one a separate key for every service cannot solve: what you write can identify you even when your login cannot, and an assistant holds more of what you write than any site ever has. No design stops it while the memory lives on the provider's server. The Trust Mesh answer is where that memory lives. If the assistant's memory of you lives in your vault and the provider gets it on lease for the session, switching from Claude to Codex means carrying your context with you. A Trust Mesh lease would forbid the provider from keeping a copy, and its published policy would have to say the same; an audit and a contract hold it to that, since it sees the text while it serves you. When the lease ends it gets nothing new, and what it saw carries no key that joins it to any other account of yours.
Today a consumer's conversations are training data by default unless they opt out, but the providers already sell no-training terms to enterprise customers, so a lease puts an individual on the corporate terms. What makes them agree is the same thing that makes any business accept a receipt: enough people asking.
Trust Mesh integrated social venues run on rules the members and creators write and maintain. Email travels between Trust Mesh accounts through relays that hold only ciphertext. A browser built for Trust Mesh refuses cookies outright. Nothing the network itself runs tracks you. Ads still exist, but they are capped by the members and aimed at the information you chose to release, never at a profile of you, because none exists. It’s a private network that offers a way to unplug from the extraction economy and isn’t engineered for engagement addiction driven by conflict. It’s a neutral media platform designed for truth, balance, and nuance that functions like a nonprofit public utility for the world.
A day inside it is ordinary. You open a social venue and it knows you as a pseudonym that exists nowhere else. Every account you hold is in your pocket, and no server anywhere holds the master copy of you. You follow a creator and the signed relationship goes into your vault. You buy a ticket to a concert and at the gate reveal the ticket is valid and yours. When the venue changes its rules and you don’t like them, you authorize a move and all of your relationships go with you. The old venue can remove your posts from its own walls but you keep your own copy to publish again.
I imagine a network that pays its own way and can afford documentaries and long-form work, with whatever degree of activism its members choose. An independent collective with the weight to balance what is happening in the world today, such as removing money from politics through a system of publicly funded campaigns.
None of the current machinery stops anytime soon. Google login keeps reporting your logins to Google, Ticketmaster keeps your email, the weather app keeps selling your location, and the businesses you already deal with keep the accounts they built on you. What changes first is the size of the population carrying a sovereign account. Over time it becomes its own market, so a business that wants those customers re-onboards them the Trust Mesh way: it receives a pseudonym that appears nowhere else, a receipt that proves an accountable human is behind the account, and it gets more details only if you agree.
Businesses have accepted this before. Since 2019 Apple has required any app that offers Google or Facebook login to offer Sign in with Apple too, and the apps adapted: the ones that needed a real name, a pharmacy filling a prescription or a store shipping a package, added a field and asked for it, so the customer gave their name knowingly instead of having a login hand it over behind the screen.²²
Everything above runs inside an ordinary app, on the chip Apple and Google already ship, using the same attestation and biometric interfaces every banking app uses, so it needs no new permission from either company beyond distribution through their stores. What Trust Mesh cannot reach is the operating system's own channels: the advertising identifier, the location permission, and the browser's cookies. You can turn off the first two yourself in settings on current phones, and a Trust Mesh browser refuses the third. What remains is the apps you keep outside the network and what a site can infer from the visit itself, since even a browser that refuses cookies shows the website your network address and enough about your device to make a rough fingerprint. Only Apple and Google can close that. What Trust Mesh changes is the size of the crowd asking them to. A network of people who carry their own accounts is a collective agreement, and every service that joins it strips one more leak out of the business model.
What Moves to the Person
Trust Mesh puts the account at the edge so the direction of ordinary processes reverses. This table shows the difference:
How the Sovereign Account Arrives
Trust Mesh enters through two doors. The first is where failures already cost businesses money, like crypto security: the lite launch starts with high-risk withdrawals at one custodian, an exchange that holds customers' coins for them. The next businesses join without having to trust the first because receipts are verified against the shared rules and keys.10
The second door is user demand driven by creators and influencers with an audience worth protecting. They ask their audience to enroll for protection from deplatforming. A third door is opening at the AI labs, which need a composable, universal receipt system to limit the behavior of agents.
The objection everyone will correctly raise is network effects, but that assumes people have to rebuild their social graph from zero. The precedent here is phone numbers. Telecom carriers once owned everyone’s phone number, so leaving one provider for another meant telling everyone in your life a new number, which is a lock-in the carriers priced. But Congress required number portability in 1996, and when the FCC finally made it stick for mobile phones in November 2003, the number became yours and switching became simple. A sovereign Trust Mesh account does to the platform relationship what portability did to the number. Once a subscriber's signed permission sits in the creator's vault, the creator can leave without losing anyone, so a venue has to compete on what it does for its members with all its lock-in strategies stripped away.
Two more things separate this from a cold launch. The same Trust Mesh account works at any participating bank, ticket window, and crypto custodian, so people enroll for reasons that have nothing to do with social media, and no critical mass is needed before the network is worth joining. Creators stay on the current platforms that pay them and simply gain a copy of their own subscribers with the newfound power to leave for something better, so a creator with a million followers enrolls their base for the peace of mind. The standard is open, so YouTube or Instagram can accept receipts too, and keep their members on terms they agree upon.
Trust Mesh sovereign accounts, anonymous where the law allows, identified where the transaction requires, controlled by the human it represents, become the portable base layer of the digital economy. It’s every account you have, in one vault, in your pocket, opened by no one but you. It’s the dawn of a new era of the internet: private and secure. And it can’t be done by a corporation, government, or blockchain.
That is the digital self-sovereignty revolution ahead.
Here are the book, full spec, lite launch spec, and other materials: Trust Mesh
Next week: Questions a Blockchain Investor Should Ask About Trust Mesh & The Patent Portfolio
Following week: Closing Thoughts
Sources
1. Lou Montulli, 'The Reasoning Behind Web Cookies,' May 14, 2013.
2. Kristi Coale, 'DoubleClick Tries to Force Hand into Cookie Jar,' Wired, March 17, 1997.
3. Proposed Settlement Agreement and Release, DoubleClick privacy litigation, 2002.
4. Meta, 'United States Regional Privacy Notice,' effective May 23, 2025.
5. World Wide Web Consortium, 'ActivityPub,' W3C Recommendation, January 23, 2018.
6. Nostr Protocol, 'NIP-01 Basic Protocol Flow Description.'
7. Meta, 'Our Agreement With Bipartisan Attorneys General: Calling on TikTok and YouTube to Join Us in Supporting Teens,' August 26, 2026, updated August 27, 2026.
8. Trust Mesh, The Trust Standard, canonical edition, 2026.
9. Trust Mesh, TrustMesh Combined Specification, canonical edition, 2026.
10. Trust Mesh, TrustMesh Crypto Withdrawal Lite Launch Specification, 2026.
11. 'DoubleClick Backs Off Plan to Merge Data,' NPR, March 2, 2000.
19. Joseph Cox, 'Here's the Pitch Deck for Active Listening Ad Targeting,' 404 Media, August 26, 2024.
20. AT Protocol, 'Account Migration,' developer guide.
21. World, 'World ID Concepts,' developer documentation.
22. Apple, 'Sign in with Apple: Fast, easy sign-in with privacy built in,' white paper, November 2019.
25. Amazon, '2025 Small Business Empowerment Report,' 2026.
26. David Rodriguez, Joseph A. Calandrino, Jose M. Del Alamo, and Norman Sadeh, 'Privacy Settings of Third-Party Libraries in Android Apps: A Study of Facebook SDKs,' Proceedings on Privacy Enhancing Technologies, 2025.