The protocol · Closed development

Identity and privacy, by architecture.

Bonafide is the open identity and privacy protocol underneath everything Cloud Connected builds. No passwords to steal, no central database to breach — privacy as a property of the design, not a line in a policy.

§ 01

What Bonafide provides

User-held identity

Cryptographic identity owned by the person, rooted in their device — not in a company's database. No password sitting somewhere to be stolen.

Passwordless authentication

Device-native, biometric verification. Account takeover via SIM swap, phishing, or password leak becomes structurally impossible.

Atomic encryption

Per-unit encryption under keys only the user controls, so a provider holds only scrambled data it cannot read.

Scoped, revocable access

Time-bounded institutional access and multiple unlinkable personas — granted narrowly, taken back at any time.


§ 02

The protocol, made visible.

Bonafide is infrastructure — normally invisible, the way TCP/IP or TLS are. The clearest way to see what it does is to look at a product built on it. MyCrypt, our family vault, is the first product on Bonafide; these are its advanced screens, where the protocol underneath comes into view. MyCrypt is designed to peek into a user's vault only as far as their policy allows — never the data itself.

One identity, many faces

Aliases and a sovereignty ladder.

One cryptographic identity presents different aliases depending on context — @alice for personal, @alice.work, @ali for social — each tied to a focus, none linkable to the others without the user's say-so.

And authentication is a ladder the user climbs at their own pace: start with email and a recovery anchor MyCrypt holds, then move recovery offline, escrow it with a provider, or graduate to a hardware-backed key that not even MyCrypt can access. The gentle path and full sovereignty are the same system.

MyCrypt's Identity & management screen: aliases @alice, @alice.work, and @ali each tied to a focus, plus a sign-in ladder from email-and-password up to a hardware-backed authenticator that not even MyCrypt can access.
Cached policy, not your data

Devices, institutions, and an escape hatch.

Every device holds the vault at a different tier of trust — a phone's hardware enclave reaches further than a web session. Institutions peer in through scoped, time-bounded leases: a tax service reads only your receipts, for twelve days; a bank browses only its own branch. They hold cached policy — what they're allowed to reach — never your data.

And the bottom of the screen is the line competitors can't match: a portable export to an open file you can read with a standalone tool, no MyCrypt required. The escape hatch can never be revoked.

MyCrypt's advanced screen showing device trust tiers, peered institutions with scoped read leases, plan and billing, trusts the user belongs to, and a portable export to an open file that requires no MyCrypt account to read.

Why it matters

A foundation, not a feature.

Most privacy is a promise: a company says it won't look. Bonafide removes the company's ability to look at all. That difference — won't versus can't — is the whole point, and it's why every product built on Bonafide inherits the same guarantee.

It began as security architecture engineered to protect personal data inside high-assurance systems, and is now developed and owned by Cloud Connected as a standalone foundation — available, in time, to any product that needs identity without surveillance.

For builders

Building on Bonafide.

Bonafide is currently in closed development. If you're building something that needs identity without surveillance, we'd like to hear from you.