BetterSign™.

BetterSign™

Your keys. Your rules. Your recovery.

Programmable authorization via WACC lock scripts.

Set up a stronger backup key to recover if a key is lost — no company, no support ticket, no permission needed.

Each entry carries WASM lock scripts defining what the next entry must satisfy. Encode threshold signatures, delegation, and revocation policy directly in the log.

  • You choose who can help you recover
  • No support line, no waiting, no gatekeeper
  • Your rules travel with your identity
  • WACC / WASM lock & unlock scripts per entry
  • Lamport threshold group for social recovery
  • delegate and revoke write privileges in-band

A stable name on the outside, freely changeable keys on the inside.

The picture

An open padlock you hand to the world

Your public key is an open padlock you give out freely. Anyone can click it shut on a note, but only your private key — the half you never share — can open it again. BetterSign sets up these locks with modern, quantum-resistant methods, so you never have to think about it.

Encryption establishes a shared secret to the recipient's advertised public key via a KEM; only the holder of the private half can decapsulate. BetterSign supports post-quantum KEMs for forward secrecy against future computers.

What it fixes

What changes for you

Without BetterSign

  • ✕Rotating a key can break every machine that trusted the old one
  • ✕Certificates expire and cause outages
  • ✕Secrets get copied by hand across servers
  • ✕Recovering a lost key means an out-of-band scramble

With BetterSign

  • ✓Your identity stays the same when keys change
  • ✓Renewal and rotation are routine, verified updates
  • ✓Watchers update SSH, TLS, and config automatically
  • ✓Recovery is a built-in, higher-priority backup key

How it works

What happens when you rotate a key

You create a fresh key on your own device

You add it as a new signed page in your logbook

The old key is marked retired, so it can no longer be used

Followers verify the change themselves and switch over automatically

Your VLAD — your identity — never changes through any of it

The building blocks

Four ideas do all the work

◇

Stable identity

A VLAD remains stable while its keys and protected metadata rotate.

⛓

Self-verifying history

Every state transition is hash-linked and authorized by the previous log state.

⇋

Decentralized discovery

VLADemlia helps peers locate current records without becoming the trust root.

↻

Routine rotation

Key changes become signed updates that followers can verify and apply.

The jargon, translated

Plain-English words for the deep stuff

VLAD
your permanent name; short for Verifiable Long-lived Address
plog
the signed logbook behind a VLAD that records every change
rotation
swapping an old key for a fresh one without changing your identity
revocation
marking a key as no longer usable, for example after it leaks
recovery
using a stronger backup key to fix things if a normal key is lost
VLADemlia
the network address book that helps peers find each other; it never decides who to trust

Questions

The things people ask first

Do I need to understand the cryptography?

No. Point your tools at a VLAD and BetterSign keeps the keys current for you — SSH that doesn't break when keys rotate, TLS that renews itself, API tokens you can rotate freely.

What if I lose my key?

Recovery is built in. A stronger, better-protected backup key can fix things if a normal key is lost or stolen — no out-of-band scramble.

Why is changing keys a good thing?

The longer a single key stays in use, the more chances a copy ends up somewhere it shouldn't. Rotating retires old risk — like changing the locks now and then.

Can a company take my identity away?

No. A VLAD is owned by you and no one else, proven by math anyone can check, and still verifiable years later — even offline.

A name you keep. Keys you can change.

Point your tools at a VLAD and BetterSign keeps the keys current for you.