Part of the Meridian Special District ecosystem Back to MSD

MSD trusted terminal branch

Meridian
Phone

MandateIdentityTerminalEvidence

Trusted identity terminal · Carries MID · Does not issue identity. A secure access object for a person already recognised by an institution.

A trusted terminal for carrying institution-issued MID and MCID into daily civic action: present identity, approve access, sign records, and recover control when a device is lost.

Identity-based Governed access Privacy by design Audit-ready

Care, Kids and One are role-specific access terminals: elder support, supervised credentials, and adult civic access. Three devices, one bounded trust architecture.

Carries identityMID and MCID remain issued by institutions; the terminal only holds and presents them. Secures accessTEE, secure element and MPC recovery protect daily civic actions. Not a phone pitchNo lifestyle upgrade claim, no speculative account narrative, no consumer electronics hype.
3role-specific editions
TEE + SEhardware root of trust
Path Adevice tenets
0 phrasesMPC threshold signing
PRECEDENTSeal → Letter → Passport → MID
VERBS · What the device doesCarry · Verify · Recover · Separate · Audit
STANDARDSW3C DID/VC · FIDO2 · ISO 18013-5
SECURITYTEE + SE · MPC threshold
BOUNDARYPath A · Carry, do not issue
ROLE IN MSD Meridian Phone is the trusted terminal branch of MSD: institution first, terminal second; identity first, access afterward.

The phone connects issued MID / MCID to Meridian One service access, verified acceptance, M Wallet custody patterns, and Meridian Chain evidence. It remains a terminal, not an issuer, medical device, consumer-electronics campaign, or speculative account surface.

01 · Authority

Institutions issue identity

MID and MCID derive authority from accredited issuers. The terminal never crosses that line.

02 · Terminal

The device carries it securely

TEE, secure element and controlled application layers hold credentials for presentation, approval and presence.

03 · Recovery

Access can be recovered

MPC threshold and guardian flows mean losing a device is not losing identity, with reviewable recovery steps.

04 · Public Use

Services become reachable

Credential presentation, trusted acceptance, corporate representation and civic services operate inside one boundary.

In pilot phases, the terminal layer can run on compliant smart devices. The dedicated Meridian Phone family is the hardware route and procurement-review form of the same architecture.

Why a phone

Every civilisation answers the same quiet question:
how does a person come to be recognised, believed, and treated as themselves?

Once, the answer was a clay seal, a letter of introduction, a passport stamped in steel. Today the same question has moved into a digital world — and it needs to be answered there too. Meridian Special District — an institutional framework for identity and civic services in the digital age — gives the institutional answer; Meridian Phone is what takes that answer out of the archive and into a person's day. It does not invent identity. It only lets MID and MCID be used by an ordinary person, from morning to evening.

Abstract seal, passage document, passport-like credential and Meridian Phone trusted terminal arranged along one civic identity rail
Seal · Letter · Passport · Trusted terminal
01 Recognised

Public systems first recognise who a person is, before turning them into an account.

02 Believed

Trust comes from issuance, verification and audit, not from screenshots or platform promises.

03 Carried

Identity has to move from archive and backend into counters, schools, households and daily services.

04 Bounded

The terminal carries the relationship; it does not own it. It presents qualification, not an entire life.

The harder edge of this question lies on the other side: every system of identity leaves someone out. People without a home, elders who cannot read, migrant workers, people with disabilities, the stateless — those who most need to be recognised are the ones a form, a QR code or a login screen most easily turns away. A digital identity worth trusting has to begin by acknowledging who is being left out; a device that hopes to hold it has to keep a door open for them from the start.

This is also why — in an age where almost everything has become software, and almost nothing is held in the hand — there still has to be an object you can hold. When relationships dissolve entirely into code, they become easy to copy, easy to revoke, easy to forget. An object held in the hand is itself a kind of restraint: it reminds everyone that an identity is not a line of data, but a living person, present.

Problem

Identity has lived in databases, not in lives

For a decade, digital identity has lived inside databases, not inside lives. To use their own identity, a person has had to log into someone else's product.

Shift

The device becomes identity's home

When identity can be carried properly on a personal device, it stops being just an account — it becomes a form of recognised membership. A person no longer logs into someone else's product to be themselves; they walk into a place already carrying who they are.

Boundary

The device carries; the institution issues

A phone never issues identity. It is only the trusted container — what lets an already-issued identity be carried, presented and, when needed, set down again.

Outcome

Every presentation deserves more trust

Verifiers trust credentials, not screens. Holders present a single qualification — they do not hand over a whole file. Each use leaves a trace of being trusted, not a trace of being exposed.

PATH A · DEVICE TENETS

What the device does ·
what it does not.

This boundary is where Meridian Phone becomes willing to be examined, by a government, with care. It is written into the hardware and into the institution. Three lines of commitment, three lines of restraint — a device worth being entrusted with has to say both, clearly.

Carries MID and MCID issued through accredited channels, with selective disclosure and controlled offline use.
Verifies credentials presented by counterparties and produces audit-ready event records.
Recovers via MPC threshold and guardians — losing a phone does not mean losing identity.
Does not issue MID or MCID. Issuance authority remains with accredited bodies.
Does not store source biometric templates or raw identity material in clear text.
Does not provide medical, drug or diagnostic functions — those belong on regulated medical devices.
Abstract institutional boundary model showing authority plates connected to a blank trusted terminal, with closed boundary gates for functions the terminal does not perform
Authority issues · terminal carries · boundary holds
AuthorityIdentity remains institution-issued.

The terminal receives and presents credentials; it never becomes the issuer.

TerminalDaily use becomes reviewable access.

Carry, verify and recover are bounded device functions, not a new identity regime.

BoundaryRestraint is part of the design.

No source-data exposure, no medical claim, no uncontrolled expansion beyond mandate.

Three human interfaces · One system

Three generations in one household.
One institution of trust to hold them all.

A family is more than one relationship. A person grows old; a child grows up; an adult, in between, holds up both ends. We have made three devices, so that the three generations of a household can be held by the same institution of trust — gently. Elders are looked after. Children are accompanied. Adults are entrusted with the day. They share one identity system underneath, and each one focuses on doing only one thing properly.

Meridian Phone trusted identity terminal family in an institutional product setting
Care · Kids · One · three human interfaces, one trust architecture
Designed for elders
Meridian Care Elder edition

Care is not a large-font phone. It is an access terminal for elders: family authorization, emergency support, assisted service entry and a simpler civic console, all bounded so help can arrive without taking dignity away.

  • Family authorization and bounded delegation
  • Fall detection · SOS · medication reminders (advisory, not medical)
  • Call and service entry, remote assistance
  • Simplified civic and utility console
Caresupport tier Care tier
Designed for children
Meridian Kids Child edition

Kids is not a smaller adult phone. It carries parent-derived sub-credentials for school, transit and learning, while institutional issuance stays separate and family use remains supervised.

  • Parent-derived sub-credential (not school-issued)
  • Family allowlist · time windows · gentle location sharing
  • App console without addictive social or unsuitable content
  • School access, transit, reading and learning entries
Kidsentry tier Entry tier
For everyday citizens
Meridian One Standard edition

One carries MID and MCID for adult civic life: identity proof, verified acceptance, business services and recovery on one trusted terminal.

  • MID and MCID carry with selective disclosure
  • Verified acceptance + civic console + business desk in one
  • MPC threshold access — phrase-free recovery
  • Controlled offline acceptance with deferred settlement
Oneanchor tier Anchor tier

Three procurement tiers, not a consumer price ladder. They correspond to three positions inside a household: a child's entry, an adult's anchor, an elder's relationship of care. A family can walk all the way up that ladder — three generations, one same set of trusted relations.

Architecture · MID lifecycle

Identity has a life of its own:
applied for, verified, issued, used, recovered, set down.

Identity is not something that happens once. It has a life of its own — applied for, verified, issued, used through the years, sometimes lost and recovered, finally set down when it is no longer needed. Six stages, four kinds of participant. Meridian Phone is deliberately not an issuance authority on this path; it does only four things — carry, assist, record, protect. That restraint is itself the reason a government can examine it with care.

Conceptual infrastructure image showing identity lifecycle, credential layers, secure chip and evidence ledger
Lifecycle · credential custody · access recovery · auditable evidence
Stage
Apply
Verify
Issue
Daily
Recover
Revoke
Issuer
Meridian Phone
·
Guardian / family
·
·
·
·
Verifier / service
·
·
·
·
·
Primary Assists / carries ○ indirect · · not involved
Authority over identity belongs to institutions; the phone's authority is over one thing only — carrying. That restraint is not a limit; it is the design. A thing entrusted to a person must be both trusted and bounded.
MPC threshold access

No one should lose ten years of relationships
because access depended on memory alone.

Conventional phrase-based recovery has shown the weakness: when a remembered string becomes the only way back, a simple loss can become a permanent lockout. Meridian Phone uses an MPC threshold scheme that splits signing authority across the device, a custodian and a guardian: no one party can act alone, and no single loss is fatal. Identity access is no longer held inside a cold line of text; it is entrusted to a small, human-shaped network of people who know the holder.

And more importantly: access capability is not the identity. It is only a capability MID can open, at a later, regulated stage — identity first, settlement second; relationship first, sums of money afterward.

Concept visual showing a trusted identity terminal, sealed credential dossier, secure chip and reviewable evidence layer on an institutional review surface
Credential evidence · hardware proof · recovery path · reviewable trace
2-of-3
Threshold key
Device · Custodian · Guardian
  • No plaintext key
  • No recovery phrase
  • Distributed generation
Recovery
Device recovery
Social guardian · Re-verification
  • New device pairing
  • Identity re-verification
  • State remains traceable
REVIEW SURFACE Four evidence surfaces show what the system protects, proves and refuses to do.

For governments and institutions, trust should not rest on vendor promises. It should rest on reviewable boundaries, verifiable device state, recoverable access processes and service traces that do not overreach.

01

Issuance boundary

The source, authorization chain and revocation authority of MID / MCID remain with the issuer; the terminal records carrying state only.

02

Device attestation

TEE, SE, device posture and controlled application versions form terminal evidence that can be verified.

03

Recovery record

New-device pairing, guardian participation and re-verification steps leave a traceable audit path.

04

Service trace

Each acceptance event keeps necessary proof, timestamp and signature only; source identity material is not made public.

How it works · verified acceptance and civic console

Trustworthy acceptance,
returned to the counter between people.

Behind every civic or commercial acceptance moment — breakfast in a quiet town, a prescription at a clinic, a contract signed in an office — there is already a relationship: who is present, who is authorized, who vouches for whom. For a decade we have compressed that relationship behind a QR code. Meridian Phone wants to put it back. When MID and MCID are both present, a service moment no longer has to begin from "who you are, who I am" — trust returns to the counter between people.

Civic service counter with a trusted terminal and credential folder used for identity verification
Mutual proof · minimum disclosure · controlled settlement · reviewable trace
STEP 01

Mutual identity

The service party's MCID and the citizen's MID present proof at the same time: who is present, which desk is acting, who carries authority — every link signed.

STEP 02

Minimal disclosure

The holder presents only the qualification the service moment requires — "of legal age," "licensed to sell" — without handing over any of the surrounding personal data.

STEP 03

Controlled settlement

Phase 1 does not open a public external transfer path. Settlement runs through regulated rails. A settlement proof is recorded to the Meridian evidence layer.

STEP 04

Auditable trace

Event hashes, timestamps and signed records are anchored to the memory layer — independently verifiable during compliance review.

Civic console · individual

One-stop service

  • Identity proof, qualification checks, pre-filled forms.
  • Residency notices, authorized obligations, appeals and renewals.
  • Selective disclosure: prove what's needed, no more.
Business desk · MCID

Entity and representation

  • Entity status, authorized representatives and acceptance capabilities — visible.
  • Demonstrate qualifications without exhaustive due diligence.
  • Verified acceptance, receipts and service relationships, structured.
Security · privacy · boundary

Trust cannot be written in advertising.
It has to be written in three places.

A chip. A process. An audit. Trust, on a phone, has never come from a slogan — it has to come from those three places. Meridian Phone writes the trustworthy parts into hardware, the reviewable parts into procedure, and keeps what does not belong on a personal phone inside controlled environments. Only when all three stand up does a device deserve the word entrusted.

Concept image of Meridian Phone secure chips, privacy boundary and audit paths
Hardware root · Privacy boundary · Audit path
Hardware root of trust

TEE + SE, two layers

Critical operations run inside a Trusted Execution Environment; credential keys live in a Secure Element — untouchable by regular apps and unreachable across OS boundaries.

Biometric template protection

ISO/IEC 24745 representation

No raw fingerprint or face image is stored — only a revocable, regenerable protected representation. A lost phone is not a leaked biometric.

Threat model

STRIDE coverage

Cloning, replay, downgrade and supply-chain implantation each map to specific hardware, protocol or institutional controls — documented in the threat model.

Security boundary model Trust is not a single feature; it is a set of boundaries that can be reviewed.

Where identity data lives, where keys live, where biometric representations live, and what may enter the evidence layer all need clear answers. Meridian Phone separates those answers into four boundaries so privacy, institutional responsibility and audit evidence remain in their proper place.

01

Hardware root

Keys and credentials are bound to the TEE + SE device structure. Regular apps may request a result; they cannot read the root material.

02

Local biometrics

Biometrics do not leave as raw images. They remain as protected, revocable and regenerable representations generated locally.

03

Threshold recovery

Recovery, migration and revocation do not depend on one administrator. Sensitive actions require multiple authorisations.

04

Evidence minimisation

The evidence layer records status, signatures and audit trails without moving private personal data into public records or third-party systems.

Design

Built to be reviewed from the outside

BOM, security baseline and threat model are signed off before manufacturing — and made available to independent third-party review from the design stage.

Manufacture

A trusted production line

Secure elements are pre-provisioned on a controlled line; every device can be traced back to its origin — supply-chain tampering has an answer.

Operate

Updates with a visible timeline

Every update is signed; the path from a vulnerability being discovered to being patched is on a public timeline, not in silence.

Retire

Set down with dignity

When a device retires, credentials are securely destroyed and the hardware is recycled — no debris, and no forgotten keys.

Covenant

The boundary is written in a contract

The operator and the institution each carry their own share of responsibility. If anything goes wrong, somebody has signed for it.

Open standards alignment

No reinvented identity.
Standing on rails the world already trusts.

For a phone to be trusted by verifiers anywhere, it has to speak the international language of identity and authentication. That language is not set by any one company. It has been slowly agreed — by W3C, FIDO, ISO, by many nations and many researchers, working alongside each other — and it belongs to this age, and to everyone who lives in it. Meridian Phone aligns with the standards below, so that credentials, authentication and interoperability are never locked to a single vendor.

Concept visual showing a trusted identity terminal inside an international standards interoperability architecture with credential, authentication, assurance and jurisdiction rails
Open standards · credential model · strong authentication · interoperability rails
INTEROPERABILITY RAILS Standards are not decorative citations. They are the interface through which a jurisdiction can be understood by the world.

Meridian Phone separates identity identifiers, credential models, device authentication and assurance levels into four rails. Each rail points to existing international specifications, preventing public identity infrastructure from being locked inside one vendor or one jurisdictional technology island.

01

Identity and credentials

W3C DID / VC define who issues, who receives, what is proven and how selective disclosure works.

02

Device authentication

FIDO2 / WebAuthn bind critical access to hardware and local presence, rather than passwords or SMS codes.

03

Regulated credentials

ISO 18013-5 and related mobile credential standards support counter, offline and regulatory verification.

04

Assurance levels

NIST IAL / AAL / FAL and EUDI alignment help different services map to different verification strengths.

W3C DID Core

Decentralized identifiers

The identifier and resolution model shared by subjects and issuers.

W3C VC 2.0

Verifiable credentials

Signed, structured credentials supporting selective disclosure.

FIDO2 / WebAuthn

Passwordless auth

Device-bound strong authentication; biometrics never leave the device.

OIDC / OIDC4VC

Identity federation

Identity and VC transport protocols for third-party services.

ISO/IEC 18013-5

Mobile credentials

Mobile driver's license and similar credentials, including offline use.

ISO/IEC 24745

Biometric template protection

Protected, revocable biometric representations — no raw templates.

eIDAS 2.0 EUDI

EU digital identity framework

The EU's official framework — a long-term alignment path.

NIST 800-63-3

Identity assurance levels

IAL / AAL / FAL tiers — services map to required verification strength.

Localisation & public access

One procurement framework,
shaped differently in every jurisdiction.

Pilot-stage device tiers are not a retail catalogue. Inside any specific jurisdiction, the framework is localised, subsidised, and reduced — whether an identity institution has reached those most easily left out is not finally a matter of language, but of a procurement schedule and a reductions table. Here is what that framework usually becomes, in practice.

Concept visual showing a trusted identity terminal at the centre of a public access framework, with local procurement, subsidy reductions, accessibility configuration, education, health, social security and care service rails
Public access · local procurement · reduction routes · service channels
Jurisdictional

Set together with the issuer

In each partner jurisdiction, final pricing is determined together with the accredited issuer — not imposed as a global flat rate. A device made to be used in a particular place should be made affordable in that particular place.

  • Priced in local currency · set by issuer and jurisdiction together
  • Volume procurement triggers stepped procurement terms
  • SLA and service terms set under the jurisdictional contract
Equity & reductions

A door for those most easily left out

For people without a home, elders who cannot read, migrant workers, people with disabilities and the stateless, a tiered reductions schedule and accessibility configurations are kept open — whether an identity system can be trusted depends, first, on whether it leaves a door open for these people.

  • Tiered reductions and zero-cost entry routes
  • Accessibility modes (voice, magnification, contrast, one-handed)
  • Verification pathway for people without a fixed address
Public procurement

Civic, education & elder-care

Bulk procurement channels for civic, education, health and social-security systems are aligned with each jurisdiction's budgets and intergenerational programmes. Care, in partner jurisdictions, can be folded into elder-care programmes — shared across government, family and philanthropy.

  • Government framework procurement
  • School / health / social-security pairing schemes
  • Care elder-care three-way cost-share mechanism

The tier labels are not retail prices. They are the starting point of a procurement conversation. In each partner jurisdiction, the subsidy model, procurement framework and reductions schedule are decided together with the issuer and the government — and written into a contract both sides can refer back to.

PUBLIC ACCESS COMPACT Accessibility is not an optional discount. It is a basic delivery condition of an identity institution.

If an identity terminal only serves people who are already easy to serve, it is not public infrastructure. Meridian Phone's localisation framework puts procurement, reductions, accessibility and public-service entry points onto the same institutional table, so every jurisdiction can state who is covered first, who receives reductions, who provides service and who retains final governance authority.

01

Jurisdictional procurement

Reviewable terms shaped by local budget, currency, service scope and issuer responsibility.

02

Reduction routes

Reserved pathways for people without a fixed address, elders, disabled people, stateless people and low-income groups.

03

Accessibility configuration

Voice, magnification, high contrast, one-handed use and assisted counter flows become deployment requirements.

04

Public-service channels

Education, health, social security, care institutions and civic counters define the first acceptance scenarios.

Pilot path

A new city does not appear overnight.

Meridian Phone should not, either. We prefer to begin inside a single, well-defined pilot jurisdiction — in that one city, make identity, verified acceptance, the civic console and the recovery mechanism actually work; let an institution take root, slowly, inside a real set of relationships. Only when it is steady, talk about the next city. A thing made with care deserves to be allowed to be slow. The first city is never a test market; it is a partner — and the patience of a jurisdiction willing to be first is where this whole thing earns its right to be trusted.

Concept visual of a pilot-jurisdiction governance review room with a trusted terminal, procurement dossier, service-network model and implementation evidence
Pilot jurisdiction · procurement review · service network · phase gates
Phase 0

Foundations

Identify the issuer, signing process, Path A boundary and pilot review packet. Hardware BOM, security baseline and threat model are signed off before manufacturing.

Phase 1

One goes live

The standard citizen variant first. MID carry, verified acceptance, civic console and baseline audit run end-to-end — validating the underlying design.

Phase 2

Care and Kids join

Extend to elder and child editions on the same system. Family authorization, guardian recovery and derived sub-credentials open in sequence.

Phase 3

Cross-jurisdiction

Inter-recognition with other jurisdictions on the same standards. Settlement and additional services become regulated extensions, not preconditions.

Every phase corresponds to a set of controls already in place — boundary before feature, audit before scale, trust before expansion. It is a slowness, and it is also the patience required to make something worthy of being trusted.

ADOPTION GATES A pilot does not go live first and explain itself later. It passes four gates first.

Before deployment, each partner jurisdiction should complete four reviews: institutional authority, device evidence, service acceptance and public protection. That makes the pilot a public institution started responsibly, not a market experiment.

01

Institutional mandate

Define the issuer, signing authority, revocation power, operating boundary and the sovereign position retained by government.

02

Device evidence

Complete the hardware BOM, security baseline, supply-chain traceability and independent review materials.

03

Service acceptance

Select the first civic and service scenarios, and define how counters, businesses, schools or care institutions verify credentials.

04

Public protection

Set appeal, revocation, recovery, reductions, accessibility and vulnerable-group access before expanding functionality.

Concept visual of a national deployment review table where a trusted identity terminal sits at the centre, surrounded by legal mandate, device evidence, service acceptance and public protection dossier plates
Deployment dossier · audit evidence · service rails · public protection
REVIEW DOSSIER Government does not receive only a device. It receives a reviewable deployment dossier.

A real pilot review should let every mandate, evidence record, acceptance scenario and public safeguard be traced on the same table. Meridian Phone therefore enters society only where the institution can see it, question it, pause it and govern it.

01

Law and mandate

Issuer, signing authority, revocation power, operating boundary and powers retained by government.

02

Device and supply chain

Hardware list, security baseline, key boundary, production batch and independent review.

03

Service acceptance

Verification and audit flows for the first civic, counter, school, health or care scenarios.

04

Public protection

Appeal, recovery, revocation, reductions, accessibility and vulnerable-group access.

FAQ

Answer the easy misreadings honestly,
so the harder conversations can be about substance.

This section is written for government reviewers and procurement partners. The easier misreadings are addressed first — so the harder discussions can be about substance. An institution that welcomes being questioned first, and discussed afterward, has begun to deserve the trust it asks for.

QUESTION 01

Does Meridian Phone issue identity?

No. The phone does not issue MID or MCID. Issuance authority remains with accredited bodies. The device carries, assists, records and protects.

QUESTION 02

Is Care a medical device?

No. Care offers companionship and advisory prompts (fall alerts, medication reminders) — no diagnosis, treatment or prescription. Medical compliance belongs on dedicated devices.

QUESTION 03

Where does the Kids "student identity" come from?

From a parent-derived sub-credential under explicit parental authorization — not issued directly by a school. This stays within Path A.

QUESTION 04

Does losing the phone mean losing identity?

No. With MPC threshold signing, no single share of the key can act alone. Through guardian and re-verification flows, access is restored on a new device.

QUESTION 05

Does identity data live on a public ledger?

No. Only verifiable proofs — hashes, status and timestamps — are anchored to the evidence layer. Source identity material stays inside controlled environments and can be deleted when required.

QUESTION 06

Which jurisdictions is this for?

Jurisdictions with clear digital identity legislation, an accredited issuer and a willingness to adopt open standards (W3C, FIDO, ISO).

QUESTION 07

Why a phone, and not just an app?

Because identity is not only a sign-in step; it needs a trusted hardware root. An app can be uninstalled, replaced, screenshotted; a device made with care can hold the boundary at the hardware level (TEE + SE), so that "carrying an identity" is no longer just a software promise — it becomes a fact of physical structure.

QUESTION 08

How does this relate to Apple credential containers, EUDI, and others?

Complementary, not exclusive. Apple's credential container is a commercial ticket and credential surface; EUDI is the EU's official digital identity framework; Meridian Phone is a device aligned with W3C, FIDO and ISO standards, and is designed to interoperate with relevant frameworks in jurisdictions where it operates — not locking out, not replacing, and not pretending to solve what they were never meant to solve.

Meridian Phone trusted terminal at the centre of a public review desk, with four review surfaces for product boundary, technical basis, pilot conditions and public authority
Product boundary · Technical basis · Pilot gates · Public authority
Public review record

Before a terminal enters public infrastructure, it must say what it is prepared to be reviewed against.

Meridian Phone's maturity is not only a matter of interface or hardware form. It rests on putting product boundaries, technical basis, pilot conditions and retained government authority on the same review surface.

Scope Carries identity; does not issue identity

Authority over MID / MCID stays with issuers. The terminal only holds, presents, approves and recovers access.

Basis Hardware root, credential standards, recovery flow

TEE + SE, W3C DID/VC, FIDO2, ISO 18013-5 and MPC threshold recovery form the review basis.

Adoption Pilot review before public deployment

Legal authority, device evidence, service acceptance and public protection gates precede scale.

Authority Government retains institutional sovereignty

The adopting jurisdiction keeps final governance authority; operator, supplier and issuer duties are written into agreement.

Next step

Place a digital identity, with care, in a person's hand.

Whether a digital age is worth looking forward to has less to do with how fast it runs than with whether it can gently carry an ordinary person — whether it can keep an elder from facing a new age alone; whether the first piece of identity a child ever holds can be one looked after with care; whether an adult can put the few most important things of a day onto a single device worth trusting. Meridian Phone does not try to replace institutions, and it does not try to replace trust. It only wants to be the thing of this age — a place where a relationship that has already been recognised can be carried, gracefully and safely and across generations, into a single person's hand.