In formation — founding pledges open · no money accepted

A messenger no one owns needs an institution that owns nothing.

The Onym Foundation funds audits and shared infrastructure, awards grants, coordinates standards, and stewards a permanent endowment — for the Onym network of independently owned roles.

01

No single owner

The product splits into independently owned roles. Nobody holds the whole. The product, at onym.app →

Identity stays with the person

Keys are held by the user. No account to seize, sell, or subpoena.

Identity boundary →

Interfaces compete

Any app can present the network. The window is not the gatekeeper.

Interface boundary →

Carriers are designed blind

The contract requires that the courier cannot read the letter. Delivery is a service, not a vantage point.

Message boundary →

Verifiers are designed roster-free

Group decisions are confirmed without seeing who is in the group — that is what the notary contract fixes.

Notary boundary →

Where this stands — plain words

Exists today

  • Native iOS and Android clients, and one replaceable default deployment of message carriage, media storage, and group verification — plus, on iOS only, a live moderation authority and the DeviceCheck enforcement backend that executes its verdicts.
  • Public, technology-neutral contract documents for fifteen seats. The moderation seat's Apple profile is finalized and implemented; its Android sibling is still draft. The device backup seat has a merged Object-HTTP implementation profile but no conforming code at all.

Designed to guarantee

  • The courier cannot read the letter; the verifier never sees the member list; the name is never the identity.
  • These are contract obligations the documents fix — not yet independently verified properties of the running code.

Open and unaudited

  • The system is alpha-grade and has had no independent audit. Identity rotation, forward-secret messaging, and conformance fixtures are explicitly open work.
  • Banking and naming seats are proposals in review. The device backup contract has a merged Object-HTTP implementation profile, but no conforming code exists, so nothing conforms to it yet. Metadata-exposure assumptions are documented in the whitepaper's threat model.

The repository says this itself — read the source →

02

The seat economy

Every role is open to implementation. Payment follows an explicit choice by the person, group, buyer, or legal authority entitled to choose that role. “Seat” is shorthand across protocol, service, application, and organizational layers—not a promise that every role has the same exit boundary.
Explore the seats →
Implementation docs — what's built, seat by seat ↗
Register interest to take a seat — lead@onym.app

The seat economy — fifteen roles on the wheel, two newer seats listed below it Fifteen open roles and one open-ended proposal slot form a circle around the user; two newer seats — the moderation authority and device backup — are listed below the wheel rather than on it. Each role is selected by the person, group, buyer, or legal authority entitled to choose it. Interface app pricing Message carriage subscriptions Media storage storage plans Group verification per-op fees Audit & attestation engagement fees Arbitration dispute fees Discovery find every seat Sponsorship funds the commons anything else... propose a seat Recovery trustee published fees Recruitment milestone fees Acquisition per-order fees Distribution campaign fees Charitable coordination service fees Banking & payments payment fees Naming & credentials issuance fees USER controls personal choices
Every role is open to implementation. Authority and payment follow the actual chooser.

Seat contracts, as proposed in the public repository — Interface · Message carriage · Media storage · Group verification · Audit & attestation · Arbitration · Discovery · Charitable coordination · Distribution · Acquisition · Recruitment · Recovery trustee · Sponsorship · Moderation authority · Bankingin review · Namingin review. Device backupprofile merged, no code. Identity is not a seat — it stays with the person, and seed custody is not a seat either: it is how the recovery trustee's profiles differ. What durable copies cost everyone →

03

User safety without a master switch

Encrypted does not mean lawless. The moderation seat lets users report abuse — child sexual abuse material, credible violence, unsolicited pornography — to an independent authority they accepted when they joined, and lets apps keep banned devices out. The powers stay separate: the authority judges, the app enforces, and neither can reach a message nobody disclosed. What an authority may accept — including photographs — how long it keeps it, when it deletes it, and which classes it preserves and refers to the state are published terms, pinned when a user consents rather than restated later. The moderation contract →
On iOS this now runs in production: an authority adjudicating live reports, and the DeviceCheck backend executing its verdicts — both from the Rust reference implementation → and both currently operated by Onym as the replaceable default, which is one operator holding two halves the contract means to keep apart. The Android device-recall path is draft and not deployed. Nothing is audited.

01 · REPORT

You disclose what you received

Reporting shares the specific offending message — text, or a photograph where the authority accepts them — from your own device, with cryptographic proof of who sent it. Nothing else leaves your phone: no mailbox, no undisclosed message, and nobody scans anything.

02 · CASE

A case, not a black box

The accused is notified, sees the evidence and the exact rule they agreed to at onboarding, and gets a response window before any decision.

03 · VERDICT

Signed, reasoned, expiring

Bans carry written reasons, published durations, and an appeal path — including for a device's next owner. An authority that goes silent means dismissal, never a freeze.

04 · ENFORCEMENT

The app executes, mechanically

A banned device stops working in apps that adopted the authority — marked via Apple DeviceCheck or Google Play device recall, so reinstalling doesn't reset it. The open protocol itself is untouched.

No scanning, no backdoors — evidence exists only when a recipient chooses to disclose it.

Judges never profit from convictions — authorities earn per report adjudicated, never per ban or per case opened.

Consent precedes the case — the rules you can be judged by are the rules you signed, resolved from the manifest you pinned rather than today's.

04

Where the Foundation stands

Outside the transaction ring. Arrows go out — to audits, grants, infrastructure, standards, recognition. Never into the message path or any seat's revenue.

ONYM FOUNDATION outside the ring auditsgrantsconformance infrastructurestandards coordinationrecognition the transaction ring no Foundation arrow enters the message path or any seat's revenue
  • Money flows out

    Audits · grants · conformance infrastructure · standards coordination · recognition.

  • Nothing flows in

    No Foundation arrow enters the message path or any seat's revenue. We take no toll.

We fund the ground everyone builds on. We take no toll.

05

Why sponsors, why now

The network's commons — independent audits, conformance test suites, reference infrastructure, grants to seat pioneers — need funding before the seat economy can pay for itself. Founding sponsors make that possible, and are remembered for it.

Audits

Independent security and conformance examinations, published openly.

Grants

Seeding the first operators of new seats — registries, auditors, couriers.

Endowment

A default share of every unrestricted gift is endowed, and a donor may decline that share. Most of each gift still funds current work, so the commons outlives any single donor without starving its first years.

Become a founding sponsor

06

Money can fund the mission. It cannot buy a majority.

3 sponsor-class directors, 3 ecosystem directors, 3 independent public-interest directors — the supervisory board of an Estonian foundation. No seat has a contribution-linked selection route. Chair and treasurer: never sponsors. Selection, transition, and spending rules →
Proposed governance — no entity or board exists yet.

3 Sponsor-class Directors 3 Ecosystem Directors 3 Independent Public-Interest Chair and treasurer always come from non-sponsor classes.
  • 3 Sponsor-class Directors

    Seats where sponsor affiliation is declared and capped. Selection route undecided; no contribution reaches one.

  • 3 Ecosystem Directors

    Elected by a non-pay-to-enter Ecosystem Council.

  • 3 Independent Public-Interest

    Openly nominated and elected by a separate, non-pay-to-enter Public Interest Council.

Proposed 3·3·3 board with three distinct selection paths.