The premise is simple: every document should be verifiable — you should be able to confirm its integrity, who signed it, and who vouches for the signer. DNSSEC already proves this works at internet scale — millions of DNS records, cryptographically signed, verified billions of times a day. TrustDID brings that same architecture to every document, every email, every identity.
Every document and identity cryptographically bound to its author
Anyone can verify, independently, without accounts or platforms
A verifiable trust fabric grounded in the DNS infrastructure we already own
Jacques is a technologist with over 30 years of experience in internet infrastructure, cryptography, and digital trust. He spent more than a decade as Chief Technology and Security Officer at CIRA — the Canadian Internet Registration Authority — where he was responsible for the architecture and security of Canada's .CA ccTLD (country code Top Level Domain), one of the country's most critical pieces of digital infrastructure.
In 2012, he led the implementation of DNSSEC for the entire .CA top-level domain — cryptographically securing Canada's national internet identifier. Over more than a decade, he was also instrumental in helping local communities across Canada stand up new Internet Exchange Points, working with teams in Manitoba, Saskatchewan, Ottawa-Gatineau and elsewhere to keep Canadian internet traffic on Canadian networks.
As the driving force behind CIRA Labs — CIRA's innovation engine — Jacques led research and development into new internet trust architecture, including trust registries and DNS-anchored decentralized identity. He proposed IETF internet drafts on leveraging DNS in digital trust and high-assurance DIDs — the work that forms the direct technical foundation for how TrustDID corroborates a signer's key binding against DNS records under their own domain, and makes DNSSEC-validated binding possible.
A former member of ICANN's Security and Stability Advisory Committee (SSAC), he remains a recognized voice in international internet governance, having represented Canadian interests at local and international forums.
Over a decade leading the architecture, security, and modernization of Canada's .CA ccTLD — country code Top Level Domain. Directed the wholesale rewrite of the .CA registry system from its technology stack through its policies and business operations.
Led the cryptographic signing of the entire .CA top-level domain in 2012. DNSSEC is the internet's largest-scale proof that signing and verification can work at massive scale — the direct philosophical ancestor of TrustDID's document trust architecture.
Founded and led CIRA Labs, CIRA's innovation hub — driving R&D into new Canadian internet architecture including trust registries, DNS-anchored decentralized identity, and the emerging internet trust layer that became TrustDID's technical foundation.
Led CIRA's vision for a pan-Canadian Registry of Registries — a DNS-anchored system enabling any entity to verify another's membership in a trusted ecosystem. This governance work became the trust axis of every TrustDID verification: registries that vouch for their members, so a verifier can ask not only "is it genuine?" but "who vouches for the signer?"
Over more than 10 years, was instrumental in helping local teams across Canada — Manitoba, Saskatchewan, Ottawa-Gatineau, and elsewhere — establish new Internet Exchange Points, reducing Canada's dependence on foreign routing infrastructure.
Former member of ICANN's SSAC — the advisory body that examines matters relating to the security and integrity of the internet's naming and address allocation systems, advising ICANN's Board and the broader global technical community.
Co-authored the landmark CIRA public report identifying the emerging Digital Trust Infrastructure layer for the internet — pairing cryptographic trust (signing and verification) with human trust (governance and trust registries) as the foundational architecture for a more trustworthy internet.
Proposed IETF internet draft defining a method for anchoring Decentralized Identifiers to the DNS using URI and TLSA records — cryptographically binding a DID identity to provable domain ownership. The proposal forms the technical basis for how TrustDID corroborates a signer's key binding — DNS URI and TLSA records under the signer's own domain confirming the key — and is actively progressing at IETF SECDISPATCH.
Proposed IETF draft describing an architecture for trust registry membership verification using DIDs, DNSSEC, and DNS URI/TLSA records. Defines how verifiers can confirm issuer identity and ecosystem membership through a single DNS-rooted cryptographic chain — the basis for TrustDID's trust registry verification, the axis that answers who vouches for the signer.
"The internet was built without a trust layer. We added security on top — encryption, certificates, firewalls — but we never built the foundational infrastructure that answers the question every digital interaction eventually asks: can I actually trust this?"
The internet needs a new layer. Not a patch on top of what exists, but a basic building block: a Digital Trust Infrastructure that changes how the internet works at its foundation. The premise is simple — everything that matters on the internet needs to be digitally signed, with long-lasting signatures that remain verifiable years from now — and every verification should answer two questions honestly: is it genuine, and who vouches for the signer.
But cryptographic signatures alone are not enough. Trusting everything that is technically valid is not trust — it's just verification. What we need is the ability to trust what is inside our sphere of control: the entities we choose to recognize, governed by registries we define and operate. Trust registries are not a directory. They are a governance mechanism. They let organizations say: these are the entities I recognize, and I will verify their signatures accordingly.
DNSSEC proved this idea works at internet scale — billions of DNS records signed and verified daily, invisibly, without anyone thinking about it. TrustDID applies the same architecture to documents, identities, and email: Sign → Verify → Trust. It is not a product feature. It is infrastructure. The same kind of infrastructure that, once it exists and is trusted, becomes invisible — and indispensable.