An open protocol for sealing data to a reader you choose. The parties in between can carry it, but never open it — and access can expire or be revoked.
Can't, not won'tData is sealed to a specific reader before it enters the pipeline. Everyone along the path can route, store, and deliver it without the keys to open it — so blindness is a property of the system, not a promise on top of it.
The sensitive payload is encrypted to a specific reader before it ever moves. Routing details stay readable; the private data does not.
Platforms, carriers, and operator infrastructure route, store, and deliver the sealed payload without ever holding the keys to open it.
Only the chosen reader can open it, verified at the moment of access. Access can expire — or be revoked as a cryptographic fact, not a support ticket.
The spec and a reference implementation are in active development and running in pilot. Not yet a ratified standard — and we're candid about where the protocol fits, and where it doesn't.
The protocol core evolves only through a governed, documented change process. No single deployment or deadline moves it — that stability is the point.
A specification and glossary, a reference implementation, a browser vault, and language SDKs — shared with pilot partners under agreement. OSLP is designed to be independently audited and reproducibly built, so partners can inspect and reproduce it for themselves rather than take the claim on faith.
Access is currently extended to pilot partners under agreement. The specification and implementation are not publicly released.
OSLP itself runs nothing. Independent operators build products and services on top of it — each running its own deployment, with its own identity, keys, and custody.