{
  "schema": "ecz.website_family_site.v2",
  "site": {
    "name": "ECZ-ID IoT",
    "url": "https://iot.ecocitizenz.com",
    "brand_contract": "ecz.website_brand_contract.v1",
    "operator": {
      "legal_name": "EcoCitizenz Ltd",
      "ecz_id": "ECZ-GB-RBS1NW",
      "resolver": "https://resolver.ecocitizenz.org/p/ECZ-GB-RBS1NW",
      "resolver_machine": "https://api.ecocitizenz.com/api/p/ECZ-GB-RBS1NW.json",
      "statement": "The operator's own record is proof about the company that runs this site, not about any visitor or any Passport they hold."
    }
  },
  "family": {
    "slug": "iot",
    "type_code": "IOT_DEVICE",
    "family_code": "IOT",
    "product_name": "ECZ-ID IoT Device Passport™",
    "subject": "connected device",
    "identifier_pattern": "ECZ-XX-XXXXXX::IOT_DEVICE-XXXXXX",
    "subject_law": "One IoT Passport is one physical device, or one device identity module, operated by your organisation. A fleet is many Passports.",
    "not_separate_passports": "Firmware versions, MAC and IP addresses, and the gateways and hubs a device registers with are not separate Passports."
  },
  "free_passport": {
    "price_gbp": 0,
    "price_label": "FREE",
    "includes": [
      "A persistent ECZ-ID for the connected device.",
      "Your organisation on the record as its operator — a free DECLARED Parent is created if you do not already have one.",
      "A public Resolver record anyone can open, and the same record as machine-readable JSON.",
      "A badge, a QR code and a share link.",
      "Basic bindings to the public places your connected device already appears.",
      "Lifecycle and current public state, evaluated on demand.",
      "Claim and recovery.",
      "Basic participation in the Digital Entity Graph.",
      "Essential lifecycle evidence, kept in LedgerCore."
    ],
    "distinctions": [
      {
        "title": "DECLARED ≠ VERIFIED",
        "body": "A DECLARED record states what your organisation says about itself, with the date it said it. It is not the outcome of an independent check."
      },
      {
        "title": "Identity ≠ Binding",
        "body": "The Passport identifies the connected device. A binding records a public place it already appears. Adding a binding never creates a second identity."
      },
      {
        "title": "Binding ≠ Authority",
        "body": "A binding shows that a relationship has been declared. It does not grant, prove or imply authority to act."
      },
      {
        "title": "Parent verification ≠ IoT verification",
        "body": "A VERIFIED or ASSURED Parent verifies your organisation. It does not verify the connected device."
      }
    ],
    "publication_consent_required": true
  },
  "acquisition": {
    "state": "NOT_YET_LIVE",
    "states": [
      "AVAILABLE",
      "TEMPORARILY_PAUSED",
      "NOT_YET_LIVE"
    ],
    "start_url": null,
    "authority": "https://trustops.ecocitizenz.com",
    "configuration": "Set by Operating Command through ECZ_FAMILY_ACQUISITION_STATE. FREE is the price; the state is whether new activations are open."
  },
  "aec": {
    "name": "AEC — Active Entity Capacity",
    "definition": "One AEC is one actively managed production entity with live bindings and current state.",
    "exists_without_aec": "A free Passport exists and resolves whether or not you use any AEC.",
    "counts_for_this_family": "An IoT product, model or fleet identity you actively manage in production.",
    "pooled_across": "AEC is one pool shared across your Agent, MCP, Plugin, API, SDK and logical Service & Workload identities, and your IoT product, model and fleet identities.",
    "device_instances": "Individual device instances are counted in IoT Fleet Capacity, which is separate from AEC and never consumes it.",
    "never": [
      "AEC never makes an identity more verified.",
      "AEC never replaces a Passport.",
      "AEC never changes an ECZ-ID. Your ECZ-ID does not change.",
      "Running out of AEC never deletes, revokes or unpublishes an identity."
    ]
  },
  "commercial": {
    "authority": "TrustOps",
    "trustops_origin": "https://trustops.ecocitizenz.com",
    "configure_url": "https://trustops.ecocitizenz.com/start",
    "prices_published_here": false,
    "statement": "Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal."
  },
  "interoperability": {
    "families": [
      "API_PASSPORT",
      "SERVICE_WORKLOAD_PASSPORT",
      "AGENT_PASSPORT"
    ],
    "systems": [
      {
        "name": "Cloud IoT platforms and device registries",
        "what_it_does": "Provision, connect and manage individual devices.",
        "what_ecz_id_adds": "A public identity for the product, model or fleet that carries no raw serial number, MAC address or location.",
        "replaces": false
      },
      {
        "name": "Device certificates (X.509)",
        "what_it_does": "Authenticate an individual device to your services.",
        "what_ecz_id_adds": "A printable public identity for the product or fleet — never a device's key material.",
        "replaces": false
      },
      {
        "name": "GS1 product identifiers",
        "what_it_does": "Identify trade items across supply chains.",
        "what_ecz_id_adds": "An operator-linked identity for the connected product that can be resolved alongside its product identifier.",
        "replaces": false
      }
    ],
    "boundary": "ECZ-ID complements your frameworks, protocols, OAuth, cloud IAM and workload identity. It replaces none of them and stays outside the execution path."
  },
  "strengthen": [
    {
      "key": "parent-assurance",
      "name": "Parent VERIFIED and ASSURED",
      "prominence": "PRIMARY",
      "phase": "CATALOGUE",
      "adds": "Independent verification of the organisation behind your Passports. VERIFIED suits production use; ASSURED is the higher-assurance posture for larger or more sensitive estates.",
      "boundary": "It verifies your organisation. It never verifies an agent, a server or any other child identity, and it never changes an ECZ-ID.",
      "included_free": "Every Passport starts with a free DECLARED Parent — created for you if your organisation has none.",
      "next_steps": [
        {
          "kind": "EXPLORE",
          "label": "Explore Parent VERIFIED and ASSURED",
          "url": "https://iot.ecocitizenz.com/parent"
        },
        {
          "kind": "TRUSTOPS",
          "label": "Configure in TrustOps",
          "url": "https://trustops.ecocitizenz.com/start#parent-passports"
        }
      ]
    },
    {
      "key": "iot-fleet-lifecycle",
      "name": "IoT Fleet Identity & Lifecycle",
      "prominence": "PRIMARY",
      "phase": "CATALOGUE",
      "adds": "Identity and lifecycle for the device relationships across your fleets.",
      "boundary": "It manages identity relationships — not telemetry, firmware updates or device management — and it never publishes a device's raw identifiers.",
      "included_free": null,
      "next_steps": [
        {
          "kind": "CONTACT",
          "label": "Talk to us",
          "url": "mailto:hello@ecocitizenz.com?subject=IoT%20Fleet%20Identity%20%26%20Lifecycle%20%E2%80%94%20ECZ-ID%20IoT%20Device%20Passport%E2%84%A2"
        }
      ]
    },
    {
      "key": "pulseguard",
      "name": "PulseGuard",
      "prominence": "SECONDARY",
      "phase": "CATALOGUE",
      "adds": "Current-state evaluation for the entities you operate. Paid tiers extend evaluation across more entities and more evaluations each month.",
      "boundary": "It reports state. It is not a safety verdict, and it never changes an identity or its tier.",
      "included_free": "On-demand and event-driven evaluation of your own entities.",
      "next_steps": [
        {
          "kind": "EXPLORE",
          "label": "Explore PulseGuard",
          "url": "https://iot.ecocitizenz.com/pulseguard"
        },
        {
          "kind": "CONTACT",
          "label": "Talk to us",
          "url": "mailto:hello@ecocitizenz.com?subject=PulseGuard%20%E2%80%94%20ECZ-ID%20IoT%20Device%20Passport%E2%84%A2"
        }
      ]
    },
    {
      "key": "evidencecore",
      "name": "EvidenceCore",
      "prominence": "SECONDARY",
      "phase": "IN_V2_BUILD",
      "adds": "The evidence behind each claim on a record: what supports it, where it came from, when it was checked and who may see it.",
      "boundary": "Evidence supports a claim. It does not make the claim true, and it never turns a declaration into a verification.",
      "included_free": "Essential evidence references are part of every free Passport.",
      "next_steps": []
    },
    {
      "key": "ledgercore",
      "name": "LedgerCore",
      "prominence": "SECONDARY",
      "phase": "CATALOGUE",
      "adds": "Tamper-evident retention of decisive lifecycle evidence — issuance, activation, material bindings, authority changes, suspension and revocation — with eligible evidence anchored to a permissioned, append-only ledger.",
      "boundary": "An anchor shows an entry has not been altered since it was written. It does not make the statement inside it true.",
      "included_free": "Essential LedgerCore evidence is kept for every identity, free ones included.",
      "next_steps": [
        {
          "kind": "EXPLORE",
          "label": "Explore LedgerCore",
          "url": "https://iot.ecocitizenz.com/ledgercore"
        },
        {
          "kind": "CONTACT",
          "label": "Talk to us",
          "url": "mailto:hello@ecocitizenz.com?subject=LedgerCore%20%E2%80%94%20ECZ-ID%20IoT%20Device%20Passport%E2%84%A2"
        }
      ]
    },
    {
      "key": "graph",
      "name": "Digital Entity Graph and Graph Intelligence",
      "prominence": "SECONDARY",
      "phase": "CATALOGUE",
      "adds": "The public-safe relationships between your organisation, its Passports and their bindings. Graph Pro, Graph Business and Enterprise Graph Intelligence add scale, history and custom analysis above the free view.",
      "boundary": "A relationship in the graph is a published link, not an endorsement of either end.",
      "included_free": "Basic Graph participation and a current one-hop view.",
      "next_steps": [
        {
          "kind": "PRIVATE_OFFER",
          "label": "Discuss a private offer",
          "url": "mailto:hello@ecocitizenz.com?subject=Digital%20Entity%20Graph%20and%20Graph%20Intelligence%20%E2%80%94%20ECZ-ID%20IoT%20Device%20Passport%E2%84%A2"
        }
      ]
    }
  ],
  "operate": [
    {
      "key": "developer-gateway",
      "name": "Developer Gateway",
      "summary": "Integration reference, schemas and machine-readable documentation for ECZ-ID.",
      "url": "https://developers.ecocitizenz.com"
    },
    {
      "key": "resolver",
      "name": "Resolver",
      "summary": "Resolve any ECZ-ID to its public record — free, with no account and no API key.",
      "url": "https://iot.ecocitizenz.com/verify"
    },
    {
      "key": "machine-json",
      "name": "Machine-readable record",
      "summary": "Every record as JSON at /api/p/{ecz_id}.json, for policy engines, gateways and agents. Shown here on EcoCitizenz's own record.",
      "url": "https://api.ecocitizenz.com/api/p/ECZ-GB-RBS1NW.json"
    },
    {
      "key": "console",
      "name": "ECZ-ID console",
      "summary": "Sign in to TrustOps to reach the Passports your organisation holds. It is where current commercial configuration lives, too.",
      "url": "https://trustops.ecocitizenz.com/console"
    }
  ],
  "related": [
    {
      "type_code": "API_PASSPORT",
      "product_name": "ECZ-ID API Passport™",
      "relationship": "Devices report to, and are managed through, APIs. The API is identified separately from the devices that use it.",
      "acquisition_state": "NOT_YET_LIVE",
      "start_url": null,
      "site": null
    },
    {
      "type_code": "SERVICE_WORKLOAD_PASSPORT",
      "product_name": "ECZ-ID Service & Workload Passport™",
      "relationship": "Fleets report into cloud services and workloads, which are separate enduring subjects with their own Passports.",
      "acquisition_state": "NOT_YET_LIVE",
      "start_url": null,
      "site": null
    },
    {
      "type_code": "AGENT_PASSPORT",
      "product_name": "ECZ-ID Agent Passport™",
      "relationship": "Where an agent acts on devices, the agent is a separate subject with its own Passport — never part of the device's.",
      "acquisition_state": "AVAILABLE",
      "start_url": "https://trustops.ecocitizenz.com/start/agent?source_surface=iot-machine-related-agent",
      "site": "https://agents.ecocitizenz.com"
    }
  ],
  "resolver": {
    "human": "https://resolver.ecocitizenz.org/p/{ecz_id}",
    "machine": "https://api.ecocitizenz.com/api/p/{ecz_id}.json",
    "is_proof": false,
    "recheck_before_reliance": true,
    "statement": "A Resolver record is not proof. It publishes what is currently declared and what evidence exists, with the time it was read — is_proof is false and recheck_before_reliance is true. Re-check before you rely on it.",
    "absence": "No public ECZ-ID found is not a finding. It means the identifier resolves to no published record — nothing more."
  },
  "boundaries": [
    "An ECZ-ID does not make anything safe, certified, approved or compliant, and holding one does not make you compliant with anything.",
    "ECZ-ID complements your frameworks, protocols, OAuth, cloud IAM and workload identity. It replaces none of them and stays outside the execution path."
  ],
  "not_published_here": [
    "No A2A Agent Card and no agent manifest: this host is a website, not an agent endpoint.",
    "No prices, allowances, SKUs or purchase states: TrustOps is the commercial authority."
  ]
}
