EasytiouTechnical documentation
Public referenceVersion 0.3

Concepts and trust chain

The objects and properties to understand before integrating the API or configuring an Easytiou organisation.

Separate properties

Trust model

A global “trusted” status would hide meaningful differences. Easytiou exposes each established property, its source and its limitation.

IdentityAn external provider verified the identity at a known level.Does not protect against provider error or compromise.
DeviceA non-exportable key authorises and signs the operation.A legitimate device may be compromised or used under duress.
ContextThe event has a purpose and a validity window.The declared context may itself be misleading.
PresenceA fresh challenge is processed during the interaction.Real-time relay and collusion remain possible.
WitnessesEligible devices sign their observations.A quorum is not absolute truth.
EvidenceResults are assembled, signed and timestamped.The report covers completed controls only.
Core object

Event and participants

An event is a context bounded by a start and end time. It carries a requested assurance level, a frozen policy and expected participants. An expired event cannot receive a new challenge.

ObjectPurposeExample
EventContext and time windowExecutive committee, 8 April 2026
ParticipantInvited identity with a roleOrganiser, subject or witness
VerificationRoundAtomic control executionCo-presence challenge
ReportDurable record of collected factsSigned and timestamped bundle
Proportionate assurance

Assurance levels

LevelIndicative useMain controls
NormalSuspicious message or everyday interactionContext, bound device, local biometrics, signed response
HighRemote sale or sensitive meetingMandatory identity, dated event, observed presence, report
CriticalStrategic or irreversible decisionCooling-off period, reinforced control, quorum and timestamping
No compensating average.

The achieved level is capped by the weakest mandatory control. A failure or expiry yields a degraded or inconclusive outcome.

Semantics

Factual outcomes

PendingThe control is unfinished. No sensitive decision should rely on it.
ConfirmedMandatory controls for the stated level succeeded within their window.
Partial or degradedSome facts are established, but the requested level was not reached.
Denied or inconclusiveA contradiction, expiry or missing control prevents confirmation.

A confirmed identity does not establish that a statement is true and does not automatically authorise a payment or business decision.

Traceability

Evidence bundle

The evidence bundle contains a timeline, policy versions, outcomes, file digests, a signature and, depending on level, a third-party timestamp. It is designed for later verification without relying on a screenshot.

  • Statuses describe completed controls, never the general “trustworthiness” of a person.
  • A later revocation does not rewrite valid historical evidence.
  • Unnecessary sensitive data is excluded or pseudonymised.