Roadmap

Where we are, and what comes next

MintID is early — deliberately. The full document corpus has been put through an economic-viability audit — performed by Conectia PRO, a related-party service provider to the protocol, and published in full — and re-frozen as v2.0, with every change traceable to a recorded, ratified decision; the chain foundation, issuer machinery and verifier plane are built and have run end to end on the project’s first live network — an internal testnet on our own infrastructure. This page shows the whole sequence honestly, including the gates that matter most: no mainnet before independent audits, no genesis numbers before the independent simulation, and nothing for sale before a MiCA-notified offer.

Build sequence

Seven phases, one launch gate

Each phase builds on the previous one and ends with something testable. Dates are deliberately absent: a security-first project ships when the audits pass, not when a calendar says so.

00
Done

Specifications frozen — now at v2.0

The three normative specifications and the full requirement set are written and locked, so every line of code that follows has a fixed target. After the economic-viability audit, the entire corpus was revised and re-frozen as v2.0 in a single coordinated release — eleven documents, six architecture decision records, every change traceable to a ratified decision.

01
Done

Chain foundation

Stand up the sovereign Layer-1 itself: consensus, the native token, the base modules and chain state. The first thing that runs is a real blockchain, not a demo. Done: the chain builds, runs and finalizes deterministically.

02
Done

Issuers, council, bonds & status

Add the machinery of trust: the accepted-issuer registry, the compliance council, slashable issuer bonds and the on-chain status-root heartbeat. Done: bond-gated activation, 30-second heartbeats with fail-closed freshness — observed live on a devnet — the hard-capped declining emission, and slashed-funds handling with only two exits by construction are merged and tested. External audit gates remain before any public network.

03
Done

Verifiers & online verification

Register accepted verifiers and ship the verification core — the part that checks a 10-second proof against the chain’s latest finalized state. Done, and proven live: the exact-origin verifier registry, cryptographically proven chain reads (no trusted RPC), durable single-use nonces and the nine-condition acceptance pipeline ran end to end on the project’s first live network — an internal, single-validator testnet on our own infrastructure — together with the Verifier SDK in service mode and its MCP server for agent runtimes. A deliberately invalid presentation was rejected with a reason code, and the only thing the verifier retained was the fixed-slot decision record.

04
We are here

Anonymous credentials

Deliver the cryptographic heart: the anonymous-credential scheme and issuance core, so issuers can mint credentials that holders prove in zero knowledge. This is where we are now — and the discipline shows in the running code: until this phase ships with its audits, every deployed component carries a fail-closed stub engine that refuses all proofs by design. Nothing pretends to verify what cannot yet be verified.

05
Upcoming

Holder self-revocation

Implement the proof that lets anyone kill their own credential — after a lost phone, for instance — without revealing who they are or which credential it was.

06
Upcoming

Public adversarial testnet & audits

Invite the world to attack a public testnet, run independent application, cryptography, infrastructure and economic audits, and only then open mainnet. The launch gate is a precondition, not a milestone to skip — and it is measurable by construction: bonded share of supply, an independent-operator count, a Nakamoto-coefficient floor and an attack-cost estimate computed by a published, price-independent methodology. No threshold depends on a market price, and insider genesis accounts do not count toward any of them.

A first live network already exists: an internal, single-validator testnet we use to prove the pipeline end to end. It is a build tool, not the Phase 6 public adversarial testnet — that one comes later, and the world will be invited to attack it.

Staged launch

Verified identity first; funded recourse on a published criterion

The launch is staged where it used to be monolithic — so no stage waits on cryptography it does not need, and no promise ships ahead of its audits.

Stage 1

Verified-identity MVP

Credential issuance, zero-knowledge presentations and free verification — the complete identity rail, none of which waits on the heavy escrow cryptography. This is the scope that ships first.

Stage 2

Funded-recourse dispute rail

The escrow-backed dispute rail activates later, on a published demand criterion, behind its own audit package — with its arbiter market sized by the independent economic simulation, so nobody is asked to bond capital against zero income. Until it activates, funded recourse is a committed design, not a live service.

The flagship x402 integration keeps its honesty clause: the go/no-go for its MVP is gated on a published unit-economics study, segment by segment, before anything ships.

Survivable by design

How the launch is financed

No venture round, no SAFT, no points program. The launch is financed by the project’s own public tranche under EU MiCA Title II, executed completely and in order: the independent economic simulation produces the numbers, counsel drafts the one and only crypto-asset white paper, the AFM — the Dutch regulator, fixed as the competent authority under MiCA by the foundation’s seat — is notified, a public offer exists only after that — and only then comes admission to trading. Until that day, nothing is for sale, and this website says so. This is published here as governance policy, not as an invitation.

Every euro of the raise is pre-mapped in a published budget annex — the audit slate, the counsel workstreams, fiat-denominated service agreements that make professional validators contractable counterparties instead of patrons, and a bug-bounty reserve indexed to the value the chain protects — through mainnet plus twelve months. And it carries a hard rule: if the raise misses the floor, the scope re-stages. The project never launches under-audited.

Critical path

Three engagements stand between here and genesis

Everything on this page that is still a number, a legal text or an offer depends on one of three scoped engagements — deliberately placed outside our own hands.

Independent economic simulation

A scoped statement of work with thirteen deliverables: every fee, band point, emission parameter and the arbiter-market sizing. The genesis numbers are its outputs, constrained to the ratified bands — never ours.

Counsel workstreams

The legal path for the offer and for the disclosure rails — including drafting the single crypto-asset white paper that MiCA Title II requires. Exactly one document will ever carry that name.

MiCA Title II execution

Notification to the AFM — the Dutch regulator — then the public offer, then — and only then — admission to trading. A deliberate, complete run of the European regime, in that order, with no shortcut.

In parallel

The agent layer rides the same sequence

Agent KYC is a ratified scope shipped in the two stages above, not a ladder of promises: issuer-mediated agent credentials, zero-knowledge presentations and the consented disclosure rail ride the verified-identity stage; the self-custodied stablecoin escrow (committed collateral set: USDC/EURC at launch, extending to BTC) belongs to the funded-recourse stage, and its one piece of new cryptography — the proof-of-harm circuit for disputes — ships only after independent audit, never silently. Deferred ideas (a shared liability pool, an insurance backstop) stay explicitly out of scope until they earn their way in.

Adopted product tracks: zero-cost verifier packages (web widget, guest mobile flow, printed-QR mode), an MCP verification server for agent runtimes, a wallet-local identity statement reconcilable against on-chain disclosure receipts, and an x402 agent-payments integration — an identity MVP first (an agent proves it is human-backed, with its assurance grade and delegated scope, to payment facilitators and sellers), with escrow-backed coverage following once the audit gates close. The x402 go/no-go itself is gated on a published unit-economics study, segment by segment, before anything ships.

Early is the best time to join

The network needs three kinds of collaborators, and each can start a conversation today — well before mainnet.

Issuers

KYC organisations that verify people and vouch for them. You keep the customer relationship and the only private link to a person; the chain never sees your files. Early issuers help shape admission, tiers and bonding.

Start the conversation

Verifiers

Businesses that need to check a fact about a person or an AI agent — age, accreditation, a real human behind a bot — without holding their data. Early verifiers define the policies the rail must serve.

Start the conversation

Validators

Operators who run nodes and secure consensus for staking rewards. No identity work, no KYC files — just infrastructure. Early validators join the testnet first and help battle-test the network.

Start the conversation

Follow the build from day one

The whitepaper explains the destination; the specifications, available on request, define every step. If you want to issue, verify, validate — or just understand — we would like to hear from you.