<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>not.bot blog</title>
  <subtitle>Notes from the team building not.bot.</subtitle>
  <link href="https://not.bot/blog/feed.xml" rel="self" />
  <link href="https://not.bot/blog/" />
  <id>https://not.bot/blog/</id>
  <updated>2026-09-15T00:00:00Z</updated>
  <author><name>Julia Social, Inc.</name></author>
  <entry>
    <title>did:julia is now a registered DID method</title>
    <link href="https://not.bot/blog/did-julia-registered/" />
    <id>https://not.bot/blog/did-julia-registered/</id>
    <published>2026-09-15T00:00:00Z</published>
    <updated>2026-09-15T00:00:00Z</updated>
    <author><name>not.bot</name></author>
    <summary>The identity method behind not.bot is now listed in W3C’s DID Methods registry. Here’s what did:julia does and why the registration matters.</summary>
    <category term="Company news" />
    <category term="Identity" />
    <content type="html">&lt;p&gt;&lt;strong&gt;did:julia&lt;/strong&gt;, the decentralized identifier method behind &lt;strong&gt;not.bot™&lt;/strong&gt;, is now
listed in the &lt;a href=&quot;https://www.w3.org/TR/did-extensions-methods/&quot;&gt;W3C DID Methods registry&lt;/a&gt;.
Our &lt;a href=&quot;https://github.com/w3c/did-extensions/pull/748&quot;&gt;registration was merged on September 1, 2026&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;That gives developers exploring decentralized identity a public entry point to
our method, its specification, and the code that implements it.&lt;/p&gt;
&lt;h2 id=&quot;what-is-a-did-method&quot;&gt;What is a DID method?&lt;a class=&quot;heading-anchor&quot; href=&quot;#what-is-a-did-method&quot;&gt;&lt;span aria-hidden=&quot;true&quot;&gt;#&lt;/span&gt;&lt;span class=&quot;visually-hidden&quot;&gt;Permalink to What is a DID method?&lt;/span&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;A decentralized identifier, or DID, is an identifier whose controller can prove
control using cryptographic keys. A DID method defines how those identifiers
are created, how their state is read, and how they are updated or deactivated.&lt;/p&gt;
&lt;p&gt;Our method is called &lt;code&gt;did:julia&lt;/code&gt;. It uses the Chia blockchain to keep a
verifiable record of an identity’s keys and changes over time. It is the
identity foundation used by not.bot.&lt;/p&gt;
&lt;h2 id=&quot;why-it-matters-for-notbot&quot;&gt;Why it matters for not.bot&lt;a class=&quot;heading-anchor&quot; href=&quot;#why-it-matters-for-notbot&quot;&gt;&lt;span aria-hidden=&quot;true&quot;&gt;#&lt;/span&gt;&lt;span class=&quot;visually-hidden&quot;&gt;Permalink to Why it matters for not.bot&lt;/span&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;When someone checks a signature, they need to be able to connect the signing
key to the identity that used it. They also need that connection to survive
ordinary changes, such as the signer replacing a key.&lt;/p&gt;
&lt;p&gt;With &lt;code&gt;did:julia&lt;/code&gt;, the identifier stays the same when keys change. Its history
can be checked from the blockchain, so an older signature can still be verified
against the identity that made it after a routine key rotation.&lt;/p&gt;
&lt;p&gt;The method also lets a verifier read the identity’s current state from a Chia
node without asking Julia Social to supply that record. We publish the
&lt;a href=&quot;https://github.com/julia-social/julia_did_chialisp&quot;&gt;on-chain implementation&lt;/a&gt;
so developers can inspect the rules governing identity, credentials, revocation,
and recovery.&lt;/p&gt;
&lt;p&gt;These are useful foundations for the question not.bot helps people answer:
who stands behind this interaction or piece of signed content?&lt;/p&gt;
&lt;h2 id=&quot;a-public-specification-developers-can-inspect&quot;&gt;A public specification developers can inspect&lt;a class=&quot;heading-anchor&quot; href=&quot;#a-public-specification-developers-can-inspect&quot;&gt;&lt;span aria-hidden=&quot;true&quot;&gt;#&lt;/span&gt;&lt;span class=&quot;visually-hidden&quot;&gt;Permalink to A public specification developers can inspect&lt;/span&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Registration makes the method easier to discover and evaluate. The registry
links to our &lt;a href=&quot;https://github.com/julia-social/did-julia/blob/v1.0.0/spec/did-julia.md&quot;&gt;method specification&lt;/a&gt;,
which describes the identifier format, lifecycle, security model, and privacy
considerations. Registry inclusion is not W3C certification or endorsement.&lt;/p&gt;
&lt;p&gt;The on-chain protocol is running on Chia mainnet. The specification also
identifies work still to come: publishing and retrieving DID Documents through
Chia DataLayer is specified but not yet implemented. A DID Document describes
an identifier and associated verification information; the current not.bot
flow does not depend on that publication path.&lt;/p&gt;
&lt;p&gt;For a closer look, read our &lt;a href=&quot;/technology/did-julia-specification/&quot;&gt;did:julia technical specification&lt;/a&gt;
or explore &lt;a href=&quot;/learn/overview/&quot;&gt;how not.bot works&lt;/a&gt;.&lt;/p&gt;
</content>
  </entry>
  <entry>
    <title>not.bot selected as a Venture Atlanta 2026 Showcase Company</title>
    <link href="https://not.bot/blog/venture-atlanta-2026/" />
    <id>https://not.bot/blog/venture-atlanta-2026/</id>
    <published>2026-09-15T00:00:00Z</published>
    <updated>2026-09-15T00:00:00Z</updated>
    <author><name>not.bot</name></author>
    <summary>Julia, the company behind not.bot, has been selected as a Venture Atlanta 2026 Showcase Company. The conference takes place October 14–15 in Atlanta.</summary>
    <category term="Company news" />
    <content type="html">&lt;p&gt;Venture Atlanta has selected Julia, the company behind &lt;strong&gt;not.bot™&lt;/strong&gt;, as a
&lt;strong&gt;2026 Showcase Company&lt;/strong&gt;. The conference takes place October 14–15 at the
Woodruff Arts Center and Atlanta Symphony Hall.&lt;/p&gt;
&lt;img src=&quot;/assets/img/blog/venture-atlanta-showcase-2026.1fe8c39969.png&quot; alt=&quot;Venture Atlanta Showcase 2026 official badge&quot; width=&quot;390&quot; height=&quot;533&quot; style=&quot;display: block; width: 195px; max-width: 100%; height: auto; background: #fff;&quot; loading=&quot;eager&quot; decoding=&quot;async&quot;&gt;
&lt;p&gt;You can find us listed as &lt;strong&gt;Julia Social (not.bot)&lt;/strong&gt; in the
&lt;a href=&quot;https://www.ventureatlanta.org/company-lineup/&quot;&gt;Venture Atlanta company lineup&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id=&quot;what-we-are-building&quot;&gt;What we are building&lt;a class=&quot;heading-anchor&quot; href=&quot;#what-we-are-building&quot;&gt;&lt;span aria-hidden=&quot;true&quot;&gt;#&lt;/span&gt;&lt;span class=&quot;visually-hidden&quot;&gt;Permalink to What we are building&lt;/span&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;We build tools that let you verify the human behind an interaction or a signed
piece of content. With &lt;a href=&quot;/&quot;&gt;not.bot Sign My Work&lt;/a&gt;, a recipient can
check who signed an artifact and compare it with the encrypted known-good copy.
&lt;a href=&quot;/verify/&quot;&gt;not.bot Verify&lt;/a&gt; lets a site request and check credentials presented
through the not.bot app.&lt;/p&gt;
&lt;p&gt;We thank the Venture Atlanta team for selecting us, and the investors and
supporters who have helped us reach this point.&lt;/p&gt;
&lt;h2 id=&quot;see-notbot-in-action&quot;&gt;See not.bot in action&lt;a class=&quot;heading-anchor&quot; href=&quot;#see-notbot-in-action&quot;&gt;&lt;span aria-hidden=&quot;true&quot;&gt;#&lt;/span&gt;&lt;span class=&quot;visually-hidden&quot;&gt;Permalink to See not.bot in action&lt;/span&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;You can &lt;a href=&quot;https://www.youtube.com/watch?v=M1QEtgPmPY0&quot;&gt;watch our three-minute Verify walkthrough&lt;/a&gt;
without installing the not.bot app. It shows a site requesting information,
a human responding in the app, and the response the site receives.&lt;/p&gt;
&lt;p&gt;Chia Network will also feature us in its public Community Spotlight on
&lt;strong&gt;September 17 at 11 a.m. Pacific / 2 p.m. Eastern&lt;/strong&gt;.&lt;/p&gt;
</content>
  </entry>
  <entry>
    <title>What If We Get Hacked?</title>
    <link href="https://not.bot/blog/what-if-we-get-hacked/" />
    <id>https://not.bot/blog/what-if-we-get-hacked/</id>
    <published>2026-09-04T00:00:00Z</published>
    <updated>2026-09-04T00:00:00Z</updated>
    <author><name>not.bot</name></author>
    <summary>After 153 million driver&apos;s licenses leaked from a single identity verification vendor, we walk through what a breach of our own systems would and would not expose, and why most of what you&apos;d expect an attacker to find was never stored at all.</summary>
    <category term="Privacy" />
    <category term="Security" />
    <content type="html">&lt;p&gt;You&apos;ve probably seen the story by now: a dark web marketplace called Nexus popped up selling more than 153 million driver&apos;s licenses, front and back, some even in infrared and UV. All of it apparently pulled from one identity verification company that works behind the scenes at hotels, rental car counters, convenience stores, and sportsbooks. Brian Krebs, the security reporter who broke the story, found his own license in the data. So did a sitting U.S. cabinet official. Gizmodo has a good overview: &lt;a href=&quot;https://gizmodo.com/identity-verification-is-broken-the-153-million-drivers-licenses-now-for-sale-are-proof-2000806437&quot;&gt;Identity Verification Is Broken: The 153 Million Driver&apos;s Licenses Now for Sale Are Proof&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This wasn&apos;t a one-off screwup. It&apos;s what happens by default whenever a company scans your ID and keeps the scan. A company that does that is sitting on a stash of your most sensitive documents, and stashes like that eventually get found by someone patient enough to look.&lt;/p&gt;
&lt;p&gt;Privacy is the core ethos behind everything we build at Julia Social. We design systems to avoid collecting sensitive data at all, rather than promising to protect data we didn&apos;t need to have in the first place.&lt;/p&gt;
&lt;p&gt;So when people ask us &amp;quot;what if you get hacked,&amp;quot; we don&apos;t answer &amp;quot;we&apos;re unhackable.&amp;quot; Nobody can promise that. We answer with the specifics: what would and wouldn&apos;t be exposed, and why.&lt;/p&gt;
&lt;h2 id=&quot;if-someone-broke-into-our-computers&quot;&gt;If someone broke into our computers&lt;a class=&quot;heading-anchor&quot; href=&quot;#if-someone-broke-into-our-computers&quot;&gt;&lt;span aria-hidden=&quot;true&quot;&gt;#&lt;/span&gt;&lt;span class=&quot;visually-hidden&quot;&gt;Permalink to If someone broke into our computers&lt;/span&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;They would NOT get:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Your passport or ID information&lt;/li&gt;
&lt;li&gt;Your name, email, or phone number&lt;/li&gt;
&lt;li&gt;Any payment information&lt;/li&gt;
&lt;li&gt;Your location or your phone&apos;s contacts&lt;/li&gt;
&lt;li&gt;The contents of anything you&apos;ve signed or approved through the app&lt;/li&gt;
&lt;li&gt;A list of which websites or people you&apos;ve interacted with&lt;/li&gt;
&lt;li&gt;Which not.bot identity in our system belongs to you (unless you&apos;ve earned a Verified Signer badge, explained below)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;None of that information ever gets saved on our end in the first place, so there&apos;s nothing sitting there to steal. You can&apos;t leak what was never written down.&lt;/p&gt;
&lt;p&gt;What they WOULD get is a much smaller set of details that, on its own, doesn&apos;t tell them who you are: internal ID numbers our system uses to keep track of accounts, a couple of details tied to app subscriptions that can&apos;t be traced back to your Apple or Google account, and encrypted backups (your recovery data, your contacts list) that we can&apos;t read either. If you opted into our anonymous usage statistics, they&apos;d also get weekly aggregate counts that contain no identifiers. None of it links to your real identity by itself.&lt;/p&gt;
&lt;p&gt;One exception: if you&apos;ve earned a &amp;quot;Verified Signer&amp;quot; badge, we do keep a link between your public alias and your account, so we can turn off the badge if a subscription lapses. That&apos;s the one case where we hold more than usual.&lt;/p&gt;
&lt;p&gt;One more caveat: even the small amount of identity data we do keep encrypted and locked away isn&apos;t something one break-in can unlock. Getting to it would require breaking into three separate systems at once, one of which isn&apos;t connected to the internet at all, and even then, unlocking one person&apos;s information takes days of computing work per person. There&apos;s no button that unlocks everyone at once.&lt;/p&gt;
&lt;h2 id=&quot;if-someone-attacked-the-blockchain-part-of-our-system&quot;&gt;If someone attacked the blockchain part of our system&lt;a class=&quot;heading-anchor&quot; href=&quot;#if-someone-attacked-the-blockchain-part-of-our-system&quot;&gt;&lt;span aria-hidden=&quot;true&quot;&gt;#&lt;/span&gt;&lt;span class=&quot;visually-hidden&quot;&gt;Permalink to If someone attacked the blockchain part of our system&lt;/span&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Even less to find here. The blockchain only ever sees random-looking ID numbers and &amp;quot;this credential was cancelled&amp;quot; flags, never your name, your info, or anything personal. We also generate a steady stream of decoy activity that looks identical to real people signing up or recovering their accounts, so even someone watching the blockchain can&apos;t tell which activity is real or connect any of it back to a real person.&lt;/p&gt;
&lt;h2 id=&quot;why-we-built-it-this-way&quot;&gt;Why we built it this way&lt;a class=&quot;heading-anchor&quot; href=&quot;#why-we-built-it-this-way&quot;&gt;&lt;span aria-hidden=&quot;true&quot;&gt;#&lt;/span&gt;&lt;span class=&quot;visually-hidden&quot;&gt;Permalink to Why we built it this way&lt;/span&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Nothing about us should be a single point of failure for who you are. That&apos;s why unlocking anyone&apos;s data takes multiple separate parties acting together instead of one break-in, why using the app day-to-day never has to touch our servers at all, and why most of what other companies collect by default, we never collect in the first place.&lt;/p&gt;
&lt;p&gt;We&apos;d rather show you where the seams are than tell you there aren&apos;t any.&lt;/p&gt;
</content>
  </entry>
  <entry>
    <title>not.bot Verify is available</title>
    <link href="https://not.bot/blog/notbot-verify-is-available/" />
    <id>https://not.bot/blog/notbot-verify-is-available/</id>
    <published>2026-08-26T00:00:00Z</published>
    <updated>2026-08-26T00:00:00Z</updated>
    <author><name>not.bot</name></author>
    <summary>Verify lets your site tell a human from a bot, check an age threshold, and recognize a returning human, without collecting personal information about them and without data leaving your infrastructure.</summary>
    <category term="Verify" />
    <category term="Launch" />
    <content type="html">&lt;p&gt;Your site cannot tell whether the person using an account is human. A
document-and-selfie check at signup establishes who opened the account. It says
nothing about who is using that account a month later, after the credentials
have been shared, sold, or taken over.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;/verify/&quot;&gt;not.bot Verify&lt;/a&gt; checks at every login instead of once at signup, with
about as much friction as ordinary MFA. It answers three questions for your
site: is this a human, does this human meet an age threshold, and have you seen
this human here before. It answers them without collecting personal information
about the person behind the account.&lt;/p&gt;
&lt;h2 id=&quot;site-passes-recognize-a-returning-human&quot;&gt;Site Passes recognize a returning human&lt;a class=&quot;heading-anchor&quot; href=&quot;#site-passes-recognize-a-returning-human&quot;&gt;&lt;span aria-hidden=&quot;true&quot;&gt;#&lt;/span&gt;&lt;span class=&quot;visually-hidden&quot;&gt;Permalink to Site Passes recognize a returning human&lt;/span&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Until now your site had no reliable way to tell that two accounts belong to one
person. A Site Pass is a unique identifier for one human on one site, and
building it gathers no identity information about them. That person can come
back later under a different alias, and the Site Pass still identifies them as
the same human.&lt;/p&gt;
&lt;h2 id=&quot;age-checks-that-gather-nothing-else&quot;&gt;Age checks that gather nothing else&lt;a class=&quot;heading-anchor&quot; href=&quot;#age-checks-that-gather-nothing-else&quot;&gt;&lt;span aria-hidden=&quot;true&quot;&gt;#&lt;/span&gt;&lt;span class=&quot;visually-hidden&quot;&gt;Permalink to Age checks that gather nothing else&lt;/span&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Legislators are writing age-verification requirements into law, and social
platforms have to enforce them. Most age-checking products answer the question
by collecting a large amount of information about the person first.&lt;/p&gt;
&lt;p&gt;Julia Social collects no personal information about your users, and no
biometrics. Your site can check an age threshold at every login without
gathering anything else about them.&lt;/p&gt;
&lt;p&gt;The Meta settlement announced this week puts a clock on this. Meta agreed to pay
up to $18 billion to settle child-safety claims brought by 48 state attorneys
general, and to strengthen how it checks the ages of its users. The rest of the
industry has an incentive to move too: roughly $5.3 billion of that total is
contingent on TikTok and YouTube adopting similar limits. Verify lets a site
meet an age requirement without taking on a pile of personal data to protect.&lt;/p&gt;
&lt;h2 id=&quot;it-runs-in-your-infrastructure&quot;&gt;It runs in your infrastructure&lt;a class=&quot;heading-anchor&quot; href=&quot;#it-runs-in-your-infrastructure&quot;&gt;&lt;span aria-hidden=&quot;true&quot;&gt;#&lt;/span&gt;&lt;span class=&quot;visually-hidden&quot;&gt;Permalink to It runs in your infrastructure&lt;/span&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;The &lt;a href=&quot;https://github.com/julia-social/julia_web_sdk&quot;&gt;Verify SDK&lt;/a&gt; is open source,
and Verify runs inside your own environment. No data about which users your site
interacts with ever leaves that environment.&lt;/p&gt;
&lt;p&gt;Your instance keeps working if our servers slow down or go offline, and you take
a new version when it suits you rather than when we ship one. To install it fast,
point your coding agent at the docs.&lt;/p&gt;
&lt;h2 id=&quot;see-it-work&quot;&gt;See it work&lt;a class=&quot;heading-anchor&quot; href=&quot;#see-it-work&quot;&gt;&lt;span aria-hidden=&quot;true&quot;&gt;#&lt;/span&gt;&lt;span class=&quot;visually-hidden&quot;&gt;Permalink to See it work&lt;/span&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Try the &lt;a href=&quot;/sdk-demo/&quot;&gt;live demo&lt;/a&gt;, or watch the pre-recorded walkthrough beside it.&lt;/p&gt;
&lt;h2 id=&quot;compare-us-to-the-alternatives&quot;&gt;Compare us to the alternatives&lt;a class=&quot;heading-anchor&quot; href=&quot;#compare-us-to-the-alternatives&quot;&gt;&lt;span aria-hidden=&quot;true&quot;&gt;#&lt;/span&gt;&lt;span class=&quot;visually-hidden&quot;&gt;Permalink to Compare us to the alternatives&lt;/span&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;We publish an &lt;a href=&quot;/learn/evaluation-framework/&quot;&gt;evaluation framework&lt;/a&gt;: criteria for
judging any human-verification product, ours included. Point an LLM at it and ask
it to compare not.bot against World ID, Self Protocol, hCaptcha, reCAPTCHA, Yoti,
Persona, Stripe Identity, and Apple and Google ID.&lt;/p&gt;
&lt;h2 id=&quot;where-to-go-next&quot;&gt;Where to go next&lt;a class=&quot;heading-anchor&quot; href=&quot;#where-to-go-next&quot;&gt;&lt;span aria-hidden=&quot;true&quot;&gt;#&lt;/span&gt;&lt;span class=&quot;visually-hidden&quot;&gt;Permalink to Where to go next&lt;/span&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;/learn/human-verification/&quot;&gt;What Verify does and how it works&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;/technology/#verify-docs&quot;&gt;Install instructions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;/learn/&quot;&gt;Learn about not.bot&lt;/a&gt;, or take the deep dive into &lt;a href=&quot;/technology/&quot;&gt;the technology&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For Chia developers, the on-chain protocol is open-source
&lt;a href=&quot;https://github.com/julia-social/julia_did_chialisp&quot;&gt;Chialisp&lt;/a&gt;, described in
&lt;a href=&quot;/technology/#protocol&quot;&gt;the protocol documentation&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you would rather work through this with an LLM, we keep
&lt;a href=&quot;/learn/#for-llms&quot;&gt;machine-readable resources&lt;/a&gt; for that. Every document has a
Markdown twin: append &lt;code&gt;.md&lt;/code&gt; to its URL. &lt;code&gt;llms.txt&lt;/code&gt; lists the corpus, and
&lt;code&gt;llms-full.txt&lt;/code&gt; carries all of it in one file, close to a megabyte of it.&lt;/p&gt;
</content>
  </entry>
</feed>
