Anima Kernel attests per-message send-intent across voice, SMS, RCS, email, iMessage, OTT, video, voicemail, push, physical mail, web forms, and signed documents — one tamper-evident envelope that wraps DKIM, STIR/SHAKEN, BIMI, C2PA, and eIDAS at once. Wrap, don't compete.
A three-tier spine signs the sender's intent, the gateway's emission, and the anchor — each Merkle-committed and reproducible. Tampering any field, or any wrapped external attestation, moves the root and breaks the signature.
C1 sender-signer → C2 channel-gateway → C3 anchor, mirroring the SecOps T1/T2/T3 spine. Each tier signs its own root independently; the chain is verifiable end-to-end.
Every channel C1 send-intent embeds one envelope locked by c_email_send_intent (decision D3), plus a per-channel extension. One verifier, twelve channels.
The keystone aggregation engine folds DKIM, DMARC, STIR/SHAKEN, BIMI, C2PA, eIDAS and more into one keccak Merkle root — domain-tagged leaves, sorted & deduped, empty→zero.
Enroll, resolve, rotate, revoke, and attester cross-sign. A directory, not a reputation system — no score, rank, or trust field in any signed struct (substrate neutrality I-1..I-7).
SPIFFE SVID → Anima DID, eIDAS QEAA → registry attester (LoA 1–3), C2PA manifest → conversation root. Wrap the world's credentials; never re-issue them.
Recipient identifiers, phone numbers, addresses, and message bodies are hashed before kernel ingress — only *Hash fields cross the boundary. Privacy is structural.
Each channel reuses the commscore envelope plus a per-channel extension carrying its anti-spoof anchor. All twelve are parity-green: Go signer ≡ Rust/WASM digest byte-for-byte on pinned fixtures, with a tamper→RED integration gate.
Voice-call and voicemail intents carry a signed destination and script hash, wrapping STIR/SHAKEN attestation into one envelope. A spoofed voice clone either carries the signed intent or it does not.
The email send-intent binds sender DID, recipient hash, and an external root folding DKIM, DMARC, and BIMI. Every claimed brand stamp is committed by the Anima signature, verifiable at once.
Video-call intents anchor a meeting ID and fold a C2PA manifest into the conversation root. A deepfake either carries a real device/editor C2PA provenance — bundled and anchored — or its absence is itself evidence.
SMS, RCS, and OTT (WhatsApp, Signal, Telegram, …) intents commit the brand/handle anchor and any short URL. Verified-sender channels require the anti-spoof anchor non-zero.
The detached-signature docs channel signs only a document hash — the anti-forgery anchor behind unauthorized carrier/utility/brokerage switches "authorized" by a spoofed PDF.
SPIFFE workload identities map to stable Anima DIDs; eIDAS QEAAs (EUDI wallet, mandatory across the EU Nov 2026) map onto the registry attester at LoA 1–3 — identical encoding to a native cross-sign.
Anima does not compete with these standards — it binds them. The aggregation engine accepts each as a typed leaf (numbering is law, part of every leaf preimage); the adapters named below ship today, the rest follow the same shape on demand.
Bridge your existing DKIM, STIR/SHAKEN, C2PA, and eIDAS attestations into one verifiable envelope. No PII required for evaluation.