Verification Layers
You never have to prove anything here to read the record, write down where you stand, or be counted. Verification is a set of separate layers you may complete in any order, and each one proves you control a specific thing and nothing beyond that. It is a dashboard, not a door.
What it does
Verification is a dashboard of layers, not a single yes-or-no. Each row names one claim, says whether it is confirmed, and says plainly why it is not when it is not: never attempted, provider failed, expired, not applicable in your region, not built yet. A blank is a typed answer, not an empty box.
The self-serve layers all prove the same kind of thing, which is control:
- The email you sign in with, confirmed from the sign-in itself.
- A public account — an X account or a YouTube channel — proven by an authorization round-trip with the provider, or by putting your handle in the account's bio where anyone can read it.
- A domain, proven by a one-time
TXTrecord on its DNS or a file at a fixed path on the site. - A published body of work, where the corpus itself names the handle.
Two proofs count as two only when they are different kinds: proving one X handle twice by two methods is one proof, because both come out of the same system. Proofs are re-checked on a schedule, and a proof that lapses gets a fourteen-day grace and the remedy written out.
The last layer is the only one that reaches outside the software. A citizen who wants it hands a government photo document and a live selfie to a third-party verification firm. We never receive the document. What is kept is the outcome — the firm, the reference, the result, an expiry a year out — and the facts derived from it: a document verified with a matching selfie, its type, its issuing country, the state that issued a license, whether a US taxpayer identity matched. No image, no Social Security number, no document number in the clear, no date of birth, no address.
The claim always matches the proof. No vendor on the market verifies citizenship, so no pass is ever labeled citizenship. A driver's license proves identity and says so; a US passport is real citizenship evidence and is labeled as evidence. Verifying with a license is never rendered as a negative, because most people verify that way.
Your facts are yours and the movement's admins'. A peer sees only an opt-in badge, off by default, naming the layer and never your name. A seeded trusted list handles bootstrapping: the movement can name people it already trusts by public handle, and that entry confers nothing at all until the person signs in, proves the handle, and is told plainly that they were listed and why.
The goal it serves
A movement that demands a real name before you may speak has assembled a list of its own members for anyone who wants one, and the people most worth protecting are the ones most likely to be punished for signing it. That is not hypothetical here. This site exists to document who Congress is actually working for, and a citizen doing that work in public may be a federal employee, a contractor, a serving officer, or somebody whose employer would rather they stopped.
The other pressure is just as real. A count anyone can join is a count a bot farm can flood, and paid influence operations do it cheaply and on every side at once. Answer that with a real-name requirement and the movement has solved the bot problem by handing over the dissidents.
Proving control of something, without proving who you are, is the way out of that trade. It raises the cost of manufacturing a thousand believable citizens far faster than it raises the cost of being one — the arithmetic behind the mesh of verified citizens. And because every layer is capped as an input, verification can never become the thing that decides who matters here. The rules that keep it honest sets that ceiling low on purpose.
What keeps it honest
- Opt-in forever. No capability requires verification — not voting, not publishing, not community aggregation. There is no admin switch that makes it required, and building one is written down as a violation of the specification.
- Segment, never silence. A verified layer can change how a result is labeled and broken out. It never changes who takes part. Unverified votes are always counted and always shown.
- Pseudonymity survives verification. The pseudonym stays; the real name is never displayed and never stored by us unless the citizen publishes it themselves.
- Failure is private. Who attempted a layer and did not pass is visible to that citizen and, as a count only, to admins. Never on a profile, never in an export, never worded as a judgement.
- Control is not personhood, and the product says so. Two people sharing one account both prove it. These layers raise the cost of minting fake accounts; they do not certify one human per account.
Works with
- The Trust Ladder — the layers feed one capped input into standing, and every rung of that ladder is reachable with no real name at all.
- Where You Stand — the separate walk that records what you think; the two run side by side and neither one blocks the other.
- Groups And Values Blocks — a claim to belong to a group is checked against your own answers, a different question from whether the account is real.
Where to go next
- Trust Scores — the one question a trust score answers, and the many it refuses to answer.
- Meritocracy — how influence here is earned in public, and why it has a ceiling.
- Communities — the shared space where a verified count matters.
- Foreign Intelligence — the operations this defense is built against.
- Get Started — run it on your own machine or use the hosted copy, and prove nothing at all until you decide to.