IDENTITY / SECURITY_MODEL

@dosfi.ai — Unified Secure Identity

One identity system. Every user, agent, node, and enterprise organization secured under @dosfi.ai — with anti-phishing, cross-platform login protection, and mesh-native authentication baked in.

SCOPE / COVERAGEIdentity Covers Every System

DOSFI.ai

Primary mesh OS portal and node management

MeshInfer.ai

Inference routing, node participation, privacy mode

DOSFI Academy

Course access, certification exams, architect tiers

DOSFI University

Degree programs, identity-bound exam tokens

Mesh-Native Apps

App runtime access gated by identity tier

Mesh-Native Agents

Signed agent identities, verified message routing

Enterprise Mesh Nodes

Hardware-bound MFA, org-scoped identities

Partner Portal

Pilot status, integration access, org-level auth

IDENTITY / LAYERSFour Identity Layers

IDENTITY / USERS

User Identity

username@dosfi.ai
  • Auto-provisioned on registration
  • Bound to UserID + DeviceID at creation
  • MFA required for new device linking
  • OAuth2 + OIDC via identity.dosfi.ai
  • Device-bound tokens — no credential replay

IDENTITY / AGENTS

Agent Identity

homeagent@dosfi.ai
  • Agents hold signed identity certificates
  • All agent messages carry identity signatures
  • Routed through MeshInfer with identity verification
  • Scope-limited: agents cannot escalate privileges
  • Revocable via identity.dosfi.ai dashboard

IDENTITY / NODES

Node Identity

node-{id}@dosfi.ai
  • Each mesh node receives a signed NodeID
  • Identity binds: UserID → NodeID → DeviceID
  • Node participation gated by identity tier
  • Privacy mode (Tier 1–3) enforced at identity layer
  • Hardware-bound MFA for enterprise nodes

IDENTITY / ENTERPRISE

Enterprise Identity

admin@company.dosfi.ai
  • Org-scoped subdomains: company.dosfi.ai
  • Maps to enterprise mesh nodes + routing policies
  • Hardware-bound MFA for all enterprise access
  • Identity-signed routing policies
  • Admin, team, and architect role scoping
SECURITY / PILLARSSecurity Architecture
IDENTITY / BINDINGHow Identity Binds Across the Mesh

Email

user@dosfi.ai

UserID

uid_xxxx

DeviceID

dev_xxxx

NodeID

node_xxxx

RoutingPolicy

tier-2-sealed

Every entity in the mesh — user, agent, or node — is bound to a chain of verified identifiers at provisioning time.

IDENTITY / AGENTSAgent Identities

Each mesh-native agent is issued a signed @dosfi.ai identity. All agent messages carry identity signatures and are routed through MeshInfer with verification.

homeagent@dosfi.ai
caragent@dosfi.ai
financeagent@dosfi.ai
devagent@dosfi.ai
secagent@dosfi.ai
IDENTITY / ENTERPRISEEnterprise Identities

Enterprise organizations receive org-scoped subdomains that map directly to enterprise mesh nodes, routing policies, and agent permissions.

admin@company.dosfi.ai
team@company.dosfi.ai
architects@company.dosfi.ai

Hardware-Bound MFA

All enterprise node access requires hardware-bound multi-factor authentication. Software tokens are not accepted for enterprise tier.

MESHINFER / IDENTITYIdentity-Gated Inference

Routing Permissions

Identity tier determines which routing policies apply — public, isolated, or sealed compute paths.

Node Participation

Nodes must present identity certificates to join inference pipelines. Unsigned nodes are rejected.

Inference Privileges

Privacy mode and inference capacity are controlled by the identity's trust tier and MFA status.

Request Your @dosfi.ai Identity

Enterprise and partner organizations can request provisioning of org-scoped identities, agent certificates, and hardware-bound MFA enrollment.