Skip to main content

Trust tiers

Every claim a system makes about integrity rests on an answer to one question: who else has to agree with you? There are three honest answers, not two — "trust me" and "trust math" are not the only options.

The three tiers​

Tier 3 — Self-assumed (you vouch for yourself)​

One party controls the thing and the claim that the thing is correct. This is the ordinary starting state for almost any new system — not a flaw to be embarrassed about, just the floor everything else builds up from. The honest label for it is "self-assumed," not "trustless."

Tier 2 — Independent provider (someone not you vouches for you)​

A party you don't control attests to something — a timestamp authority, a notary, a certificate authority, a hardware manufacturer's signed attestation. This is completely standard: it's how banking, law, and most of the internet's own trust infrastructure already works. It doesn't require everyone to agree — just one party who isn't you.

Tier 1 — Consensus (several independent parties must agree)​

No single party, not even a trusted outside one, can act unilaterally. The guarantee comes from needing independent agreement among several — in practice, at least four, since Byzantine fault tolerance needs N ≥ 3f+1 to survive even one faulty or malicious participant (f=1 → N=4). Tier 1 isn't a different mechanism from Tier 2 — it's Tier 2, generalized past that threshold. The same kind of independent attestation Tier 2 uses, just from enough parties that no one of them, trusted or not, can unilaterally rewrite the record.

Where Shyware's reference deployment actually sits today​

Precision here matters more than enthusiasm — a system is only as trustworthy as the gap between what it claims and what it's actually running.

LayerTier todayWhat's real
The ledger itself (who can author a vote/transaction)3A single validator, one operator's infrastructure. This is the honest floor every deployment starts from.
Period-close attestation2Every checkpoint gets an independent timestamp from a Time Stamp Authority the operator doesn't control — proof a given tally existed, unaltered, at a given time, from a party with no stake in the outcome.
The protocol's cryptographic key-generation ceremony2 (verified)Run inside hardware-attested confidential computing, with the hardware attestation independently, cryptographically verified against the chip manufacturer's own certificate chain — not merely claimed.
A production multi-validator deployment1, not yet built for this deploymentThe architecture already supports real multi-party Byzantine consensus (N≥4, independent operators, separate jurisdictions). What's missing isn't code — it's recruiting genuinely independent parties to run those other nodes.

The point isn't that Tier 3 is bad. It's that a system should say which tier it's actually in, for which specific layer, rather than claiming the strongest-sounding label available. "Operator-independent" is true of the attestation layer today. It is not yet true of the ledger itself — and a deployment that wants to say otherwise needs Tier 1, not a stronger adjective.

Why this matters more for some deployments than others​

For a civic referendum, Tier 3 at the ledger layer means: an operator could roll back history, but doing so now leaves independent, externally-timestamped evidence of what the tally actually was before any tampering — it's detectable, even if not yet unilaterally preventable. For a hostile-regime deployment specifically built to resist unilateral interference by a government operator, that distinction is not a nuance — it's the entire point of the product, so the tier label has to be exactly right.