QHermes

Sign.
Trust.

A cryptographic authorization kernel for systems where authority must be proven, not assumed. Issue signed credentials, delegate them across any number of hops, and verify the full chain at any point without a server, without a database, without network access.

Every credential carries its own proof. Verification is a local operation. It holds in an air-gapped facility, on a microcontroller, inside an enclave, or across a network partition. The verifier does not call home.

Scope can only narrow as authority passes through the chain. No party can claim more than it was granted. This is enforced by the cryptographic structure, not by a policy engine checked somewhere else.

For those who build systems
that others depend on.