Spherity

Spherity Research

Research for the systems we need to trust.

Evidence-led work on Digital Product Passports (DPPs), organizational identity, verifiable credentials, European Business Wallets (EBW), trusted AI, and the cryptographic infrastructure behind the real economy.

Research by Dr. Carsten Stöcker Spherity GmbH

DPP & DBP Identity Data sharing Resilience Trusted AI

Research scope

What questions does Spherity Research answer?

Spherity Research examines how organizations and products can establish identity, authority, provenance, and trustworthy evidence across regulated digital systems. The research agenda includes Digital Product Passports (DPPs), Digital Battery Passports (DBPs), trusted data sharing across Data Spaces and Digital Data Sharing Corridors, European Business Wallet (EBW) policy, Trusted AI, AI-agent authorization, AI Service Passports (AISP), Industrial AI evidence graphs, Physical AI, post-quantum organizational-identity corridors, and operational resilience.

Market position

Spherity in the Gartner Digital Product Passport Emerging Market Quadrant

Read the strategy paper

Gartner® published the Emerging Market Quadrant for Digital Product Passport — Established Vendors on 6 July 2026. Spherity is positioned as the sole vendor in the Pioneers quadrant. [1]

Spherity sees this identity-first position as the foundation for a wider trust architecture that can extend from physical-product DPPs to AI Service Passports for AI systems and services. This extension is Spherity's strategic outlook and was not part of Gartner's DPP evaluation.

Spherity treats the Gartner placement as one independent market perspective. Spherity's own view is that its technology leadership in identity-first and cyber-secure DPP infrastructure rests on its architecture, regulated production experience and partner ecosystem. The strategic objective is to make product data trustworthy, usable across company boundaries and suitable for automated decisions.

[1] Emerging Market Quadrant for Digital Product Passport — Established Vendors, 6 July 2026, Gartner document 8098797.

Trusted Industrial AI

Two trust planes. One accountable system.

Regulated AI needs separate, interoperable evidence for legal authority and for the facts supporting a decision.

01 · Control plane

Who is authorized to act?

European Business Wallets connect legal-person identity, agent identity, bounded mandates, current status, policy decisions, and action receipts.

Read the control-plane paper
02 · Data plane

What evidence supports the action?

Evidence graphs connect provenance, validation, freshness, transformations, conflicts, uncertainty, issuer status, and auditable evidence paths.

Read the data-plane paper

A valid mandate does not prove that an AI output is factually supported. Reliable evidence does not prove that an AI agent was legally authorized to act. Regulated AI systems require both layers.

Quantum-resilient trust

Organizational identity is infrastructure.

B2B, B2G, G2G, machine, and AI-agent ecosystems depend on proving which organization is acting, under which authority, and whether the complete trust chain remains valid as cryptography changes.

01 · Establish authority

Prove the organization and its mandate.

Bind legal existence, representation rights, roles, licenses, delegated authority, purpose, and validity periods into reusable organizational credentials.

02 · Map the trust fabric

Inventory every dependency that makes the proof reliable.

Cover issuers, wallets, verifiers, trust anchors, status, revocation, registries, qVDR functions, DNSSEC, WebPKI, semantics, vendors, and long-term evidence.

03 · Launch a PQC Corridor

Migrate a bounded high-value ecosystem together.

Align actors, assurance, evidence horizons, trust boundaries, hybrid or post-quantum profiles, downgrade rules, lifecycle controls, and reusable conformance evidence.

Algorithm replacement alone cannot preserve legal reliance when counterparties, trust anchors, status services, lifecycle controls, and evidence do not migrate coherently.

Read the PQC Corridor paper

Research library

Current publications

Long-form papers, roadmaps, and visual explainers for decision-makers building trustworthy digital ecosystems.

Cover of European Business Wallets as the Legal Control Plane for Zero Trust AI Agents HTML + PDF
Featured paper

European Business Wallets as the Legal Control Plane for Zero Trust AI Agents

The control-plane architecture for proving who an AI agent represents, which mandate applies, and whether each cross-company action is permitted.

  • European Business Wallet
  • Zero-Trust AI
  • Organizational identity
Preview of Quantum-Resilient Organizational Identity HTML + PDF
Research paper

Quantum-Resilient Organizational Identity

A governance and systems architecture for organizational identity, quantum-safe trust infrastructure, business wallets, and repeatable PQC Corridors.

  • Organizational identity
  • PQC Corridors
  • Trust infrastructure
Visual summary of post-quantum risks for legal-person digital identity HTML
Research paper

Securing Digital Identity and Verifiable Credential Wallets against Quantum Vulnerabilities

An attack taxonomy, macro-economic risk model, and migration strategy for post-quantum identity corridors.

  • Post-quantum cryptography
  • Digital identity
  • Verifiable credentials
European Business Wallet roadmap from 2026 to 2030 HTML
Roadmap

Legal & Operational EBW Roadmap Toward EU-Wide Acceptance

Milestones, dependencies, standards, and adoption gates for the European Business Wallet under eIDAS 2.0.

  • European Business Wallet
  • eIDAS 2.0
  • EU adoption

Research agenda

One trust layer. Five perspectives.

The agenda connects product data, identity, data sharing, technology, law, policy, and operations instead of treating them as separate systems.

01

Digital Product Passports

Trust architectures for DPPs and Digital Battery Passports (DBPs), including identifiers, provenance, lifecycle claims, access rights, and compliance evidence.

02

Organizational identity

Verifiable legal existence, representation, mandates, and accountability for companies, machines, and autonomous agents.

03

Business Wallets & Data Sharing

Legal and operational infrastructure for trusted cross-border processes, interoperable Data Spaces, and Digital Data Sharing Corridors.

04

Cryptographic resilience

PQC Corridors and crypto-agile migration paths for identity, trust anchors, registries, and long-lived evidence.

05

Trusted AI

Legal authorization, evidence provenance, and accountable action receipts for governed Industrial AI, Physical AI, and agentic commerce.

Open research

Read it. Test it. Build on it.

The publication source is maintained openly on GitHub for stable linking, transparent revision, and long-term discoverability.

Open the repository