Frequently Asked Questions

ROND is a young project in its concept phase. We regularly receive great questions – here are the most common ones. At the bottom, you'll find the questions we don't have answers to yet ourselves.

Common Questions

"Where does my data live – and what gets publicly anchored?"

Your actual content (messages, credentials, documents) is encrypted on your device and stored as shards across federated nodes – never in plaintext, never complete in one place. Only metadata is publicly anchored: hashes, trigger configurations, public keys, authorization rules. None of this is sensitive. Which technology performs that anchoring is the subject of an ongoing architecture decision.

→ Explained in detail under "How It Works"

"But my data still ends up on someone else's servers?"

Yes – just like it already does today. Anyone using Google, iCloud, WhatsApp, or a banking app stores sensitive data on third-party servers. The difference: with these services, the operator can read your data – they just promise not to. With ROND, the node operator shall not be able to read your data, because it will be encrypted client-side and fragmented using Shamir's Secret Sharing. No single node holds enough information to decrypt anything.

"Why do I need ROND if Amazon and others will accept EUDI directly?"

Large platforms will indeed implement EUDI themselves – EU regulation requires it by late 2027. You won't need ROND just to log into Amazon. ROND becomes relevant in three scenarios: First, smaller services that don't want to implement EUDI on their own (clinics, SaaS providers, clubs). Second, authorized communication – no single platform can solve this across platforms. Third, digital legacy – this only works with a cross-platform layer, because your digital life doesn't live with a single provider.

"What happens if ROND ceases to exist?"

That is precisely why ROND is an open protocol, not an app. SMTP has existed since 1982, even though hundreds of email providers have come and gone. An open protocol belongs to no one – as long as at least one node is running, the data exists. The prospective nonprofit foundation structure is intended to additionally ensure that ROND cannot be acquired or shut down.

"Does ROND use a blockchain?"

That is not decided. The Registry needs an integrity anchor: a mechanism that keeps it provable over decades that rules, public keys, and hashes have not been altered after the fact. A database under the sole control of the project would require trusting exactly that entity again – the very trust problem ROND is meant to solve. Which mechanism provides that anchor is the subject of an ongoing architecture decision; the corresponding Architecture Decision Record ADR-003 carries the status "Proposed", not "Accepted". What holds independently of it: ROND has no token, no ICO, and no speculative component. The architecture is cryptographically agile – algorithms can be swapped without rebuilding the system.

→ Status of the architecture decision

"How is this funded long-term?"

The Identity Registry and Authorization Protocol are free – they require minimal storage (just keys and rules). The Legacy Protocol, which involves actual data storage, is funded through tiered fees. Enterprise API access for notary chambers, insurers, and banks generates additional revenue. Node operators are compensated through protocol fees – not token speculation.

→ Funding details in the concept paper v0.5

Open Design Questions

These questions are deliberately open. We are actively working on them – and this is exactly where we need outside expertise. If you can contribute to any of these, .

Storage Model and Capacity

If 450 million EU citizens use the Legacy Protocol – how much storage does the federated network need? What is a realistic per-user limit? Will ROND be a key vault (a few KB per user) or a data vault (MBs to GBs)? Who pays for storage over 50 years – and how?

Integrity Anchor for the Registry

Which mechanism can prove over decades that rules, public keys, and hashes have not been altered after the fact – without having to trust the project itself? What operating cost, what failure scenarios, what legal implications? This decision is open.

Cryptographic Agility Over Decades

ROND must survive quantum computers and unknown future attacks. What does a concrete re-encryption mechanism look like when an algorithm is classified as broken? What happens in the legacy case, when the user is no longer active – who authorises the re-encryption?

Killer Feature vs Native EUDI Integration

Large platforms will implement EUDI directly. ROND's pure login advantage disappears there. What is the cross-platform feature that no single platform can replicate – and that simultaneously gives people a reason to register with ROND?

Guardian Quorum Design

How large should a guardian quorum be? What happens when guardians die, lose contact, or collude? How do you prevent both false-positive and false-negative trigger activations over decades?

Have a question that isn't listed here?

– we answer everything.

← Back to overview