Skip to content

Who we serve

Operational ecosystems where trust runs on documents and manual checks.

Many parties. Many systems. No shared trust layer. We are exploring whether one trust orchestration layer fits across ports, logistics, airports, and construction.

Common pattern

Many parties. Many systems. No shared trust layer.

Ports, logistics hubs, airports, and construction sites all run on the same trust problem. Operators verify dozens of organizations, people, assets, and credentials per shift. Today that runs on PDFs, portals, badge scans, and manual approvals.

Ports and terminal ecosystems

A gate verifies thousands of credentials a day on paper and a phone call.

Dutch ISPS-coded terminals clearing 300–2000 external contractors a day. ISPS, AVSEC, and NIS2 Art. 21(2)(d) each demand 7-year cryptographic replay.

A gate operator clears truckers, ship crew, stevedores, hazmat handlers, customs brokers, and inspectors before each shift starts. Each party arrives with a different badge, portal login, paper certificate, or scanned PDF. Verification is a phone call, a fax, or a stamp in a logbook. Hazmat papers expire mid-shift and nobody knows. We are exploring how Havens (Dutch ISPS-coded terminals) move from per-party portals toward one verifiable trust layer at the gate. The pain operators name is slow onboarding, weak assurance, manual checks, compliance friction with port-state control, and queue time at the barrier.

How Thoryn helps

  • Verify organizations, people, assets, and credentials

    One trust layer instead of a portal per party.

  • Orchestrate trust policies

    Operator-controlled rules over who, when, and what.

  • Connect wallets, credentials, and existing IAM

    Federation across the existing stack, not a rip-and-replace.

  • Reduce manual checks and audit friction

    Machine-verifiable claims and a replayable audit chain.

Logistics and distribution ecosystems

Every party in the chain re-verifies the same credential.

Dutch logistiek operators running cross-dock and bonded warehouse flows. Each shipment crosses 5+ companies. CER and NIS2 Art. 21(2)(d) drive the supply-chain audit obligation.

A shipment crosses five companies before it reaches the back of a truck. Each handoff re-asks the same questions: who is this driver, is this carrier still authorized, is the certificate of origin real, did temperature break. The shipper trusts a PDF. The DC manager re-checks the same PDF. The broker re-checks it again. We are validating one verifiable trust layer for Logistiek operators (Dutch distribution centres) running cross-dock and bonded warehouse flows. The aim is to cut repeated checks, document-fraud risk, and onboarding delay. The audit burden falls on whoever happens to keep the file.

How Thoryn helps

  • Verify organizations, people, assets, and credentials

    One trust layer instead of a portal per party.

  • Orchestrate trust policies

    Operator-controlled rules over who, when, and what.

  • Connect wallets, credentials, and existing IAM

    Federation across the existing stack, not a rip-and-replace.

  • Reduce manual checks and audit friction

    Machine-verifiable claims and a replayable audit chain.

Airports

Airside passes expire. The contractor's QR doesn't know.

Dutch luchthavens reissuing airside day-passes under AVSEC (EU Reg. 300/2008) and NIS2 Art. 21(2)(d). Pass-issuance volume runs 1000+ per day at the larger sites.

An airside badge office reissues passes for ground handlers, fuel crews, caterers, cabin crew, contractors, cargo agents, customs, and the Marechaussee. Every pass depends on role, employer, clearance, training, location, and shift. Today the badge office runs on portals, faxed training certificates, manual approvals, and a printer. A contractor changes employer and the old QR still scans for three weeks. We are exploring how luchthavens (Dutch airports) move from per-shift paper to a verifiable trust layer for airside identity. The pain teams name is fragmented identity proofing, compliance burden, manual credential checks, and temporary-access complexity that quietly grows into safety risk.

How Thoryn helps

  • Verify organizations, people, assets, and credentials

    One trust layer instead of a portal per party.

  • Orchestrate trust policies

    Operator-controlled rules over who, when, and what.

  • Connect wallets, credentials, and existing IAM

    Federation across the existing stack, not a rip-and-replace.

  • Reduce manual checks and audit friction

    Machine-verifiable claims and a replayable audit chain.

Construction and built environment

The main contractor carries Wkb liability for certificates they have never seen.

Dutch main contractors under Wkb (Wet kwaliteitsborging voor het bouwen). 50+ subcontractors a morning, each carrying training certs that need to outlive the build by 10–20 years.

A Bouw site under Wkb compliance (the Dutch building-quality act) signs in subcontractors, electricians, scaffolders, crane operators, asbestos teams, and material deliveries every morning. Each one carries a different training certificate, VCA card, work permit, or product datasheet. The site agent checks paper, photographs the card, and hopes the laminator is still warm. Materials arrive with an EPD claim that nobody can verify on-site. We are exploring how main contractors move from binder-and-clipboard to a verifiable trust layer for worker credentials, safety training, permits, materials, and inspection sign-offs. The pain is paper-heavy compliance, unclear provenance, slow onboarding for short-stay crews, and audit pain that resurfaces years later at handover.

How Thoryn helps

  • Verify organizations, people, assets, and credentials

    One trust layer instead of a portal per party.

  • Orchestrate trust policies

    Operator-controlled rules over who, when, and what.

  • Connect wallets, credentials, and existing IAM

    Federation across the existing stack, not a rip-and-replace.

  • Reduce manual checks and audit friction

    Machine-verifiable claims and a replayable audit chain.

Motorsport events

A paddock issues thousands of day-passes across 24 issuers in 72 hours.

A top-tier motorsport paddock issues thousands of day-passes across many credential issuers in 72 hours — teams, broadcasters, sponsors, marshals, medical, hospitality. Verification is manual, the document chain is paper plus PDFs, and the audit trail lives in operator notebooks. We are exploring whether the same trust orchestration layer that fits ports and airports also fits the per-event credential bundle a paddock issues. Talk to us if your event runs into this.

Wallet-less option

For contractors who won't install a wallet app.

Thoryn issues QR-PDF credentials with the same cryptographic substrate as the wallet path. Print, sign, verify. Same audit chain underneath — same seven-year replay, same revocation. No app on the contractor's phone.

Issue and verify

One platform issues a credential; a relying party verifies it.

A tenant signs credentials under its own key. A relying party checks one credential, or N credentials against a single policy, then gets one answer back. The three controls below stay separate on purpose, so trust never reads as more than it is.

Self-issuance
A tenant registers a machine credential and mints under its own issuer URL and Vault key. The credential carries that tenant's signature, not a shared platform one.
Delegated trust root
A verifier onboards a delegated issuer into its own trust registry. Only credentials from an issuer the verifier has accepted clear the trust gate; an unknown issuer reads ISSUER_UNTRUSTED, never silently valid.
Multi-credential policy
A verifier submits N credentials and a policy id, and reads one valid or invalid decision plus a per-credential breakdown. The worst per-credential verdict sets the aggregate.

Honest rendering

A clean pass renders green. A pass where the revocation list was unreachable renders amber, never green. A failed signature, an untrusted issuer, or a revoked credential renders red. The verdict is the one the verifier's policy actually graded.

We are exploring

Trust bottlenecks in operational ecosystems.

Talk to us if verification, onboarding, access, or compliance slows your network down.