Regula · private go-live

Prove who you are.
Reveal only what you choose.
Not even we can read it.

Regula is a self-custody identity wallet for KYC-verified humans. Your keys live on your device. We hold ciphertext, blind indexes and hashes, never readable personal content. Blind by construction, built in Switzerland.

The pain

Identity today is a copy machine.

Every bank, exchange, telco and platform asks for the same passport, the same selfie, the same address, and keeps its own copy. The model fails everyone involved.

For people

You verify yourself again and again, and lose track of who holds your documents. One breach anywhere exposes data you cannot change: your face, your passport, your home.

For businesses

Identity data is a liability, not an asset. Storing it means breach risk, regulatory exposure, deletion duties and audit cost, for information most teams need only as a yes or a no.

For organisations

"Who approved this, and were they allowed to?" is answered today with e-mails, shared passwords and a spreadsheet of roles that nobody can prove was true on a given day.

The opportunity

Regulation is moving identity into the user's hands.

In both the EU and Switzerland, the law now points the same way: user-held wallets, selective disclosure, and privacy engineered in from the start. Regula was designed for that world.

EU

eIDAS 2.0 and the EUDI Wallet

  • Regulation (EU) 2024/1183 requires Member States to make digital identity wallets available by the end of 2026.
  • From late 2027, regulated private sectors such as banking, telecoms, energy, health and very large online platforms must accept wallet-based identification where strong identification is already required.
  • GDPR Art. 5(1)(c) and Art. 25 make data minimisation and data protection by design binding obligations.
CH

Swiss e-ID and the revFADP

  • Swiss voters approved the federal e-ID Act in September 2025. The state e-ID is user-held and built on self-sovereign principles; launch is expected in December 2026.
  • The revised Federal Act on Data Protection, in force since 1 September 2023, requires privacy by design and by default.
  • Anti-money-laundering rules still require verified identity and long retention, so minimisation must be solved by architecture, not by collecting less.

Regula is a private wallet, not a government e-ID. It complements state wallets with verified-human signatures, consent-based sharing and blind custody for the data around them.

Data blindness by design

What we cannot read, we cannot leak, sell or be forced to hand over.

Blindness is not a policy promise. It is where the keys are. Your personal content is encrypted on your device; the key that opens it never reaches our servers.

Your device
Identity signing key, encryption key, readable personal content.
Only you
Regula servers
Ciphertext, one-way blind indexes for lookup, hashes, consent and agreement records.
Unreadable to us
Blockchain
Hashes, public keys and timestamps that notarise events. No personal content, ever.
Public, and meaningless alone
Relying party
Only the specific verified fields you approve, for that one share.
You decide, each time

A breach yields ciphertext

An attacker who takes our database, our backups or our host gets encrypted blobs and one-way tokens, not identities.

Requests meet a hard limit

When anyone asks us for user data, what we can produce is limited to what we actually hold: ciphertext, metadata and on-chain hashes.

Erasure is cryptographic

Destroy the key and the ciphertext becomes permanently unreadable. Crypto-shredding makes the right to erasure enforceable, even against backups. Where the law obliges us to keep verification evidence for a set period, it is kept sealed and shredded when that period ends.

Core principles

The rules Regula is built on.

  1. Self-custody keys

    Your identity key is generated and kept on your device. Recovery uses Shamir's Secret Sharing, so no single party, including us, can rebuild it.

  2. Blind custody

    The platform stores ciphertext, blind indexes and hashes. Even your email and phone number are held encrypted, with a one-way index for lookup.

  3. Verified humans

    Identity is checked once through a regulated KYC provider. After that, you can prove "a verified human of level N" without repeating the process.

  4. Consent per share

    Nothing leaves your wallet without an explicit, signed approval. Each share names the fields, the recipient and the purpose, and can be revoked.

  5. Minimum disclosure

    Relying parties receive only the fields they need. Integrations are designed so the rest is discarded after transit, not stored.

  6. Notarised, not exposed

    Shares, revocations and signatures are anchored on-chain as hashes and timestamps: evidence that something happened, without saying what.

  7. Responsibility, not origin

    With HumanSigned, a verified human signs a file or an action and answers for it. We do not claim to detect AI; we prove a person stands behind it.

  8. Least-data operations

    Logs carry no readable parameters, backups are encrypted with a key that never touches the server, and expired data is purged on schedule.

  9. Open verification

    Anyone can verify a Regula signature, an organisation or a signed act on a public page, without an app or an account.

Every role — human or agent — is a signed, dated, third-party-verifiable mandate.

Regula for organisations

A company that can't sign. Only its people can.

On Regula, an organisation has no secret key. Every decision — inviting someone, promoting them, freezing an account, handing over ownership — is signed by a real, verified person with a defined role, and recorded on-chain. There is nothing to steal, nothing to delegate in the dark. Anyone can check who did what, and in what capacity.

Create a verified organisation

A verified person (Level 2) creates the organisation and takes responsibility for it: its documents, its name, its people. The organisation is checked, then it exists as a signed record, not as a login.

Give mandates, not passwords

Owner, Admin, Manager, Operator, Supervisor: each member holds a role with a start, an optional end date and a reason. Mandates can be renewed, frozen, handed over or ended. The history stays.

Let your people sign and sign in

Members sign documents and actions in their own name and in their role. Your systems can accept "sign in with Regula" for members only, with the minimum role you set, and the door closes the moment a mandate ends.

Your organisation picks up the tab. Signing costs a tiny network fee. An organisation can prepay a balance so its members never think about it: they sign, the company pays, every fee is itemised. Think of it as postage: the member writes and signs the letter; the company pays the stamp.
Nothing happens in silence. Every act is anchored on-chain as a hash and a timestamp. Automatic events too: when a mandate expires, the record says so, signed by Regula, with a proof anyone can recompute.
People leave, records don't. When someone leaves or is removed, their mandate ends and their signatures stay valid for the period they held it. They can add a signed statement of their own. Nobody rewrites the past.

Where this matters

Schools and universities

Who may sign a certificate, a grade transcript or a letter of enrolment, and until when. Alumni keep a verifiable proof; the school keeps no copy of their passport.

Public offices

Officials act under a mandate with a date and a role. A citizen, an auditor or a court can verify that an act was signed by someone entitled to sign it that day.

Insurance

Brokers, adjusters and agents work under mandates that expire and renew. A signed claim or policy change names a person and a role, not a shared mailbox.

Banking and fintech

Members-only sign-in with a minimum role replaces password lists for corporate accounts. Onboarding keeps a verified answer, not a vault of documents.

Pharma and clinical

Batch releases, protocol approvals and audit trails signed by named, verified people in their role, with a proof that outlives the software that produced it.

Legal, audit and accounting

Engagement letters, filings and opinions signed in the firm's name by a partner with a mandate to do so. Succession is a signed act, not a note in a drawer.

Logistics and supply chain

Who released the shipment, who accepted it, with which authority. A verifiable chain of named signatures across companies.

Associations and boards

Board members, treasurers and delegates with dated mandates. Minutes and resolutions signed by people who demonstrably held the role.

How it works

One organisation, from first signature to audit.

  1. A verified person creates "Acme AG"

    Maria is verified at Level 2. She creates Acme AG in her wallet, uploads the company documents and declares she is entitled to act for it. The organisation is verified and recorded as her signed act.

  2. She invites the CFO as Admin

    The invitation is a signed act with a role and an end date. Paolo accepts it with his own key, from his own verified wallet. Two signatures, one mandate: Admin of Acme AG until 31 December.

  3. The team gets roles, the portal gets a door

    Paolo invites twelve colleagues as Operators and Managers. Acme's internal portal turns on "sign in with Regula, members only, Manager or above". No passwords, no shared accounts, nothing to reset.

  4. Someone leaves, something expires

    An operator leaves: her mandate is frozen the same minute and her portal session ends. Paolo's mandate expires on 31 December: Regula records it, notifies the owner, and Maria renews it with one signature.

  5. An auditor checks, without asking anyone

    Months later, an auditor opens the public verification page of a signed release note: signed by Paolo, Admin of Acme AG, on that date, anchored in that block. No account, no app, no call to KROIN.

What ships in the private go-live

One wallet, four ways to use it.

Regula Wallet

The app that holds your keys, your verified identity, an end-to-end encrypted address book and encrypted payment requests between verified users. iOS now, Android in private testing.

Login with Regula

Standard OAuth 2.0 sign-in by QR code. The user approves the requested fields in the wallet; your service gets a verified answer and nothing more. Members-only mode for organisations.

HumanSigned

A verified human signs any file, from a photo to a PDF, in their own name or in their role. Anyone can check the signature on a public verification page.

Regula for organisations

Verified organisations, roles with dated mandates, succession, members-only sign-in and a prepaid balance for fees. Every act signed by a person, anchored, verifiable.

During this phase the Regula token is a closed-network, non-tradable test token. It has no monetary value and is not an investment product.

Questions

Plain answers.

About Regula

What is Regula, in one sentence?

A wallet on your phone that proves you are a verified human, lets you share only what you choose, and lets you sign things that anyone can check, while the company behind it cannot read your data.

Is it a government e-ID?

No. Regula is a private wallet made by KROIN AG in Switzerland. It is designed to live alongside the Swiss e-ID and the EU wallets, adding verified signatures, consent-based sharing and organisations.

What does "verified" mean?

Your identity was checked once by a regulated KYC provider. Level 1 confirms who you are; Level 2 adds the documents needed to act for an organisation. After that you prove "verified human, level N" without repeating the check.

What do you store about me?

Encrypted content we cannot open, one-way indexes that let us find a record without reading it, hashes, and the records of what you consented to. Your readable data stays on your phone.

Can KROIN read my passport, my face, my address?

No. They are encrypted on your device with a key that never leaves it. A court order, a breach or a rogue employee would get ciphertext.

Is my passport on the blockchain?

Never. The blockchain holds hashes, public keys and timestamps: proof that something was signed at a given time, with no content.

What if I lose my phone?

Your key is split with Shamir's Secret Sharing into shares you keep in places you choose. Enough shares rebuild it on a new phone. KROIN holds none of them.

Can I delete my data?

Yes. Destroying the key makes every copy of the ciphertext unreadable, backups included. Evidence the law obliges us to keep is held sealed for the statutory period, then destroyed.

Signing and sharing

What is HumanSigned?

A verified human signs a file or an action and takes responsibility for it. The signature is anchored on-chain and anyone can verify it on a public page, without an app or an account. We do not claim to detect AI; we prove that a person stands behind something.

What does a service get when I "sign in with Regula"?

Only the fields you approve on the screen, for that service, and the fact that they come from a verified human. You can see every share you ever approved and revoke it.

How do I verify a signature or an organisation?

Open the verification link. The page tells you who signed, in which role, when, and shows the on-chain anchor. For automatic events it also shows the proof you can recompute yourself.

Organisations

Does my company get a wallet or a key?

No, and that is the point. Keys belong to people. Your company is the signed record of who was given which role, by whom, and since when. That record is public and checkable; the keys stay with the humans.

Then how does the company "sign"?

It doesn't. An authorised member signs, and the signature carries their role in your organisation: "Paolo, Admin of Acme AG". If that person leaves, the mandate ends and the history stays.

What is a mandate?

A role with a date. Owner, Admin, Manager, Operator or Supervisor, from a start date to an optional end date, given by someone entitled to give it and accepted by the person who holds it. Both signatures are on record.

What happens when someone leaves, or does something wrong?

A superior freezes or removes the mandate with a signed act and a reason. Their sign-in to your systems stops within a minute. Past signatures stay valid for the period they held the role, and the person may add a signed statement.

What if the owner is unavailable?

Ownership can be handed over with a signed succession: the owner names a successor, who accepts. Everything in between is recorded.

Who pays the fees?

Signing costs a small network fee. People pay their own, or an organisation prepays a balance and covers its members' fees, with a daily limit per member and an itemised ledger. No crypto to manage: it works like a prepaid card.

How is an organisation verified?

By its documents and public registers, checked by a verification partner that sees them so that we don't have to. Regula keeps the encrypted documents and the signed attestation, and shows the verified status on the public page.

For developers and partners

What do I integrate?

Standard OAuth 2.0 with a QR code. You register a client, declare the fields you need, and receive a verified answer. A members-only policy lets you restrict sign-in to your organisation's people, with a minimum role.

Where is the data hosted?

Encrypted content on IPFS-based storage; servers in the EU; the company and the law in Switzerland. Details are in the Privacy Policy and the DPA.

What does it cost?

During the private go-live the wallet is free for people. Organisations pay an annual fee for verification and renewal, plus the network fees they choose to sponsor. Ask us for the current terms.

For you

Three reasons to talk to us now.

Integrators

Onboard verified users and your organisation's members without building a KYC vault. Less personal data held means a smaller breach surface and a simpler GDPR and revFADP posture.

Request sandbox access →

Investors and partners

A regulatory deadline, a category without an owner, verified organisations with verifiable mandates, and a working product built by a team active in blockchain since 2015.

Ask for the briefing →

Invited users

Verify once, hold your own keys, and see every share you have ever approved. If you received an invitation, your wallet is waiting.

Join the private go-live →

Private go-live · by invitation

Be among the first verified humans on Regula.

We are opening Regula to a closed group of users, integrators and partners. Leave your email and tell us who you are; we will send invitations in waves.

Request access