Real crypto, in your browser — your engine signs, the vault seals, the server never sees a thing.
Store a passkey, sealed with a key derived from your identity. Watch what the server actually receives.
Nothing synced here. You re-enter all three — but only the words are secret (your name & dob are public anyway). Same three rebuild the same identity and open the same blob.
Real WebAuthn — your actual authenticator. Register, then log in for real.
People near you can vouch you in person — and the people who vouched you are the people who can recover you. No company holds anything.
Someone close taps to vouch you (BLE / QR proximity). Their signature raises your trust score.
Forgot your words? Enough of your guardians vouch → you re-authorise a fresh key. Set the threshold when you enrol.
engine primitives already present: meshBuildVouchAttestation · meshVerifyVouchAttestation · txVouch · ceremony.js