OSLP Open Secure Label Protocol
Privacy for data in motion

Send sensitive data through intermediaries that route, store, and deliver it — but can't read it.

An open protocol for sealing data to a reader you choose. The parties in between can carry it, but never open it — and access can expire or be revoked.

Can't, not won't
The idea

Most systems ask you to trust that the middleman won't look. OSLP removes the ability to.

Data is sealed to a specific reader before it enters the pipeline. Everyone along the path can route, store, and deliver it without the keys to open it — so blindness is a property of the system, not a promise on top of it.

How it works

Seal. Relay. Reveal — then revoke.

01 / Seal

Sealed to a chosen reader

The sensitive payload is encrypted to a specific reader before it ever moves. Routing details stay readable; the private data does not.

02 / Relay

Blind intermediaries

Platforms, carriers, and operator infrastructure route, store, and deliver the sealed payload without ever holding the keys to open it.

03 / Reveal

Opened once, revocably

Only the chosen reader can open it, verified at the moment of access. Access can expire — or be revoked as a cryptographic fact, not a support ticket.

Where it stands

Early, and honest about it.

Status

In pilot, not yet a standard

The spec and a reference implementation are in active development and running in pilot. Not yet a ratified standard — and we're candid about where the protocol fits, and where it doesn't.

Governance

It can't be changed quietly

The protocol core evolves only through a governed, documented change process. No single deployment or deadline moves it — that stability is the point.

Access

Designed to be verified, not just believed.

A specification and glossary, a reference implementation, a browser vault, and language SDKs — shared with pilot partners under agreement. OSLP is designed to be independently audited and reproducibly built, so partners can inspect and reproduce it for themselves rather than take the claim on faith.

Access is currently extended to pilot partners under agreement. The specification and implementation are not publicly released.

Operators

A protocol, run by operators.

OSLP itself runs nothing. Independent operators build products and services on top of it — each running its own deployment, with its own identity, keys, and custody.

Reference operator Avritam →