The story behind VAIRIFY · Part two of four

Safety Had to Be Free

We built the protections first. Then we made a decision that changed the entire business model: safety would never depend on whether a member could afford it.

VAIRIFY safety systems protecting a verified member

Listen · 19 minutes

Read the story Download audio

Two years later, I was ready to finish VAIRIFY.

The first thing I realized was how much had changed. Technology had changed. AI had changed. Cybersecurity had changed. Jake had continued developing ChainPass and was waiting for me.

One thing had not changed: the community still needed better protection.

Job one was clear:

Deliver the maximum protection possible for every encounter.

Expand the framework to bring as much of the community’s activity as possible into one app.

The Architecture of Anonymity

Before we could add anything else, Jake and I had to finish the foundation: the V.A.I. itself.

Now that ChainPass and VAIRIFY were two separate companies, Jake took the process I had designed two years earlier and incorporated it into the ChainPass side.

Jake explained it simply.

“When your platform sends ChainPass a user, we create a session key and send the user to our licensed KYC provider. The KYC provider handles the government-issued ID and selfie entirely within its own secure system. It verifies that the information on the ID is valid and that the person taking the selfie is the person pictured on that ID.
“That proves your user is real.
“When the verification is complete, the KYC provider sends ChainPass the verified photo from that session. We create a unique seven-character alphanumeric V.A.I. number and attach it to the verified image.
“We then give your platform two numbers: the V.A.I. number and the session key. Once the transfer is complete, we delete the session key from our database.
“From that point on, your platform is the only one with the session key. Whenever your platform needs to verify that member, you send us the V.A.I. number together with a new live image. ChainPass compares that image with the verified photograph and confirms whether it is the same person. The entire process takes only a few seconds.”

That was the system I had designed two years earlier.

I asked Jake, “So our anonymity boundaries are still intact?”

“Yes,” he said. “If anything, they’re stronger now.”

Jake walked me through it.

ChainPass could not identify one of our members on its own. It had the V.A.I. and the verified image, but it did not have the member’s identity or the session key connecting that V.A.I. back to the original KYC session.

VAIRIFY could not identify the member on its own either. We had the V.A.I. number and the session key, but we were not the KYC provider’s client and had no direct relationship with its verification record.

There was a path for retrieving an identity, but neither company could use it alone. VAIRIFY retained the original session key. VAIRIFY would have to submit that session key to ChainPass and authorize ChainPass to retrieve the KYC verification session from the KYC provider.

The identity was available if it ever needed to be retrieved, but it was never sitting inside VAIRIFY attached to the member’s V.A.I.

That was the term we coined: zero-knowledge architecture.

ChainPass and the platforms it serves, like VAIRIFY, could not expose what they never possessed. Their users’ personal information simply was never there to reveal.

I told Jake I needed three things from ChainPass:

  1. Every V.A.I. needed a background screening before it ever reached the VAIRIFY platform.
  2. I needed every member to sign a law-enforcement declaration disclosing any affiliation with law enforcement.
  3. I needed ChainPass to administer a Signature Agreement that allowed VAIRIFY to bind agreements to that verified V.A.I.

When we presented what we needed to the lawyers, they explained that there is no general law requiring an undercover officer to reveal that they are law enforcement simply because they are asked.

So there is no “magic phrase” that forces disclosure. You cannot invoke a legal requirement that does not exist.

There is a better way to get the results you are looking for and provide protection for your members.

ChainPass will make it clear that, as a third party issuing a digital identification, it requires a truthful declaration regarding law-enforcement affiliation. The declaration will make clear that intentionally providing false information can create substantial civil exposure, and that ChainPass reserves the right to pursue every civil remedy available to it.

VAIRIFY will issue the Mutual Consent Contract at the time of a meeting between two members. It is a personal contract, and acceptance has no real qualifiers. Any enforcement action would therefore take place after two binding documents had been biometrically bound to the individual, at different times, with two different companies, for an activity they had agreed to participate in as consenting adults.

Any enforcement action taken after that would be the very definition of entrapment. The potential exposure from a multimillion-dollar civil lawsuit is the more effective deterrent. No one can guarantee the outcome of a civil case, but when the alternative is simply to look outside VAIRIFY, the easier choice becomes obvious.

That gave us two independent records, made at two different times for two different companies. If anything happened, an attorney would have a record showing who signed, what they signed, and when they signed it.

Let me stop here for a minute and explain the foundation we had built at this point.

Every V.A.I. was verified through KYC, the most secure and accurate technology available.

Now every encounter could be delivered with a background check, a law-enforcement disclosure, a Mutual Consent Contract, a unique number carrying the user’s history, and the guarantee of anonymity.

The benefits affected everything:

  • Verification was accurate, secure, and fast. About five minutes to get your V.A.I., and seconds to verify any encounter.
  • History could not be faked, restoring trust.
  • Two binding documents—the law-enforcement disclosure and Mutual Consent Contract—established status and consent.
  • Verification happened once a year, eliminating the repeated exposure that came with every new encounter.
  • The architecture guaranteed that the identity of the verified parties could never be compelled or accidentally exposed.

With V.A.I. in place, we could build the rest of Advanced Protection around it:

  • V.A.I. Check
  • TruRevu
  • DateGuard
  • V.A.I. Pulse

V.A.I. Check

Verification came up repeatedly throughout the interviews.

Methods included social media, references, background checks, and a number of other approaches. They were time-consuming, expensive, and had to be repeated with every new meeting.

They were designed to confirm that the person was real, but none offered protection beyond that.

V.A.I. Check took all the protection from the foundation and applied it in four simple steps.

Step one: initiate V.A.I. Check.

There are two ways to start. If the meeting was prearranged through one of VAIRIFY’s connection features, open the queue and select it. If not, tap VAIRIFY Now to begin a new V.A.I. Check.

Step two: scan the QR code.

This confirms that the two members are in the same location and locks the TruRevu history to the verified parties standing in front of each other.

Step three: agree to the Mutual Consent Contract and accept the meeting.

Step four: scan your face.

This finalizes the meeting and biometrically confirms the Mutual Consent Contract.

V.A.I. Check records the encounter: the two V.A.I.s, confirmation that they met, the Mutual Consent Contract they accepted, and biometric confirmation that each was the verified user behind that V.A.I.

Because those protections are already attached to every V.A.I., that same record also carries the verified identity, background screening, law-enforcement disclosure, and Signature Agreement.

That becomes the permanent verified record of the meeting and opens the TruRevu window exclusively to the two verified parties who were there, protecting the integrity of the history that follows.

TruRevu

Reputation drives this community, and reviews are its currency.

They set expectations, preserve history, and provide some of the most important information available to the people who rely on them.

Reviews are broken.

There were so many complaints in my notes that I could write an entire blog about them.

One provider experienced a client who demanded a discount and threatened to leave a bad review if she refused.

Review blackmail.

Several providers complained about escalating rates at the directories where they marketed. When asked why they did not simply leave, the answer was almost universal:

“It’s where I built my business. It’s where my reviews are.”

They were being held hostage by their reputation.

One client said:

“If a review has five stars, it’s fake.”

It is also one of the areas scammers take advantage of most.

I asked five members of my development team to find a directory, create a profile, and populate it with five-star reviews.

Within an hour, all five had completed the experiment successfully.

Most of the problems came back to the same three issues:

  1. There was no standard.
  2. There was no protection against manipulation or retaliation.
  3. The reputation belonged to the platform, not the community member who earned it.

TruRevu was designed to fix all three and restore trust to the review process.

1. A standard

The TruRevu system is deliberately simple: five categories, five stars, and a small comment box.

TruRevu was not designed to describe encounters blow by blow. It was designed to set expectations.

One of the key differences in TruRevu is that both clients and providers have a TruRevu history and a reputation.

Clients rate providers in five categories: punctuality, attitude, communication, hygiene, and overall experience.

Providers rate clients in five categories: punctuality, attitude, communication, hygiene, and financial compliance.

2. Protection against manipulation

Only verified encounters confirmed through V.A.I. Check can produce a review for that encounter.

Both parties have 48 hours to submit their reviews.

If both submit, the reviews post together.

If only one submits, that review is posted when the 48-hour window closes.

The system was designed to prevent retaliation and keep reviews based on the actual experience.

Either party can also submit a dispute. The dispute is decided by five randomly selected members of VAIRIFY.

3. The community member owns the reputation

TruRevu was designed to put reputation back in the hands of the community members who earned it.

Your TruRevu history is displayed on your profile, and your profile has its own URL.

You do not even have to come through the VAIRIFY front door to access it.

You decide who sees it.

It can be public, limited to VAIRIFY members, or restricted however you choose.

You decide where it is displayed, who can access it, and how it is used.

VAIRIFY also provides tools such as custom QR codes and custom badges, allowing members to carry and display their reputation wherever they choose, inside the community or on mainstream platforms.

Ultimately, TruRevu was designed to restore trust within the community by giving members ownership of the reputation they earned and protecting that reputation through verified encounters.

Because every TruRevu begins with a verified encounter, the history behind it cannot simply be created or spoofed.

DateGuard

I wanted to address every problem members of the sex work community could face.

The one we had not addressed yet was what happens when an encounter becomes an emergency.

I used Elizabeth Long’s tragic case as my litmus test.

During the interviews, I asked providers what they already used for protection during an encounter.

Many relied on a buddy system, and two used a driver.

In every case, the idea was the same: if something went wrong, somebody else needed to know and be able to respond.

DateGuard was designed as a custom emergency response system for exactly that situation.

Setup is simple:

  1. Create a three-digit deactivation code. This tells DateGuard the encounter ended safely.
  2. Create a separate three-digit decoy code. It appears to deactivate DateGuard normally but silently triggers the emergency response.
  3. Choose your guardians. These are the people you trust to respond if DateGuard is triggered.

Before an encounter, select the meeting you want DateGuard to protect and choose which guardians you want watching it.

Take a picture of your surroundings and leave a note with anything you think your guardians should know.

Set the expected length of the meeting and add a buffer period so a normal delay does not immediately trigger an emergency.

Activate DateGuard.

Your location is recorded, and the timer begins.

DateGuard can be triggered three ways:

  1. The timer and buffer expire without the correct deactivation code.
  2. You press the panic button.
  3. You enter the decoy code.

Any one of those triggers starts the same emergency response.

Every guardian you selected is notified immediately and brought into one group chat so they can communicate and coordinate.

The chat includes your activation location and the time it was recorded.

As DateGuard receives updated location information from your device, those updates are shared with your guardians.

If a current location is unavailable, the last recorded location remains visible with its timestamp.

DateGuard also provides the nearest police station and its contact information, along with the picture and note you left before the encounter.

DateGuard was also the first time we took an idea that already existed as a standalone personal safety app and rebuilt it specifically for this community.

We looked at services like Life360, HollyGuard, and BeSafe, kept the parts that made sense, and added the protections our interviews told us were missing.

It will not be the last time we do that.

In several places throughout VAIRIFY, functionality that exists elsewhere as an entire app becomes one part of the platform.

V.A.I. Pulse

DateGuard effectively provided protection during an encounter, but there was another part of Elizabeth Long’s story I never forgot.

After she was killed, her phone was allegedly used to continue targeting others in the community.

How could VAIRIFY have helped prevent that?

The answer was V.A.I. Pulse.

V.A.I. Pulse is designed to give members the information they need wherever they are, with one touch, using their location.

It searches current laws, enforcement activity, and recent news involving the community.

Members can also post bulletins and share up-to-the-minute information through the community channel.

Think of it as Waze for the community.

V.A.I. Pulse also shows how VAIRIFY will keep evolving as technology changes.

We will change with it.

Free Is a Safety Feature

Toward the end of development, I had one special interview with a provider who had been active in the community and on social media.

I will not use her name, so I’ll call her V.

Before I stepped away, I showed her the original foundation.

She suggested that I offer it for free until it caught on.

That is when it clicked:

I designed VAIRIFY to be a standard.

By now, you understand that VAIRIFY will always offer these safety features for free.

You understand how we have removed every barrier.

The only requirement is an active V.A.I.

There is no doubt that many platforms will use V.A.I. technology over the next several years, but my main concern is VAIRIFY.

So we made free a safety feature.

There will be times when a VAIRIFY member will arrange a meeting with a person who is not a VAIRIFY member and does not have a V.A.I.

If the non-member declares VAIRIFY as their initiating platform when registering for their V.A.I. with ChainPass, they can complete the five-minute V.A.I. onboarding process and defer payment for 48 hours.

Their annual V.A.I. term still begins when the credential is issued, but they are under no obligation to complete the payment.

VAIRIFY will absorb the cost.

That allows our member to receive the immediate protection and peace of mind of a background screening, the law-enforcement disclosure, a Mutual Consent Contract, and the knowledge that the other party has agreed to be verified and accountable within the VAIRIFY community.

It is VAIRIFY’s way of ensuring that no member should ever have another unverified encounter.

If anonymity, a five-minute onboarding process, and a V.A.I. with no payment obligation are still not enough for the other party to complete the process, one thing is clear:

They do not want to be verified and accountable.

That does not prove they are a scammer, have violent intent, or have any other malicious agenda, but sometimes the information you do not get is as valuable as the information you do.

Our advice: walk away.

Safety was only part of what came out of those interviews. The other part was convenience—the features that help members find each other, communicate, schedule, discover, socialize, and bring the everyday activities of the community together in one place. Everything you have read about so far was built to protect the community, and all of it is free. The obvious question is: what could possibly be worth paying for?

That is where Verify Connect and verify Business begin.

Safety had to be free. - convenience had to be worth it.

That's the next blog.

Next · Part three

Convenience Had to Be Worth It

Safety was the foundation. VAIRIFY Connect and VAIRIFY Business were built around what providers and clients told us would make everyday life easier.

Explore the four-part series →