Stable identity
A VLAD remains stable while its keys and protected metadata rotate.
Start here
New to BetterSign? Start here. In plain English, this page tells the whole story: what a VLAD is and why a name you can check beats a name you are told to trust, what keys are and why they beat passwords and PINs, how keys actually work without any math, how the same keys let anyone send you private messages, and why changing them is a good thing.
A VLAD remains stable while its keys and protected metadata rotate.
Every state transition is hash-linked and authorized by the previous log state.
VLADemlia helps peers locate current records without becoming the trust root.
Key changes become signed updates that followers can verify and apply.
Start here
BetterSign gives a person, laptop, server, or bot a permanent name made of math. The name never changes, even when you swap out the keys and secrets hiding behind it.
Anyone can check that the name is really yours using math alone. They do not have to trust a company, a website, or a certificate authority to vouch for you.
The easiest way to picture it: a VLAD is like a phone number that stays the same when you get a new phone. You keep the number; the SIM card inside changes. In BetterSign, you keep your name while the keys inside it change.
A stable name on the outside, freely changeable keys on the inside.
Today, your online identity is usually just a key, a long secret. The catch: if you change the key, you look like a completely different stranger to everyone else.
So people avoid changing keys, even when they should. Part of it is risk: rotating an SSH key, a TLS certificate, or an API token can break every system that trusted the old one. But most of it is plain hassle. Once you make a new key, you have to get it out to everyone and everything that relied on the old one, and that distribution is tedious, error-prone, and easy to get wrong. So old keys linger and pile up into a security problem.
BetterSign splits the two apart. Your identity stays put; the keys underneath can change as often as you like. Rotating a key becomes a routine, signed update that everyone else can verify and follow automatically, with no hand-delivering new keys to every machine.
VLAD stands for Verifiable Long-lived Address. Break the name apart and it explains itself: Verifiable means anyone can verify it, Long-lived means it does not change over time, and Address means it is a name that points at you.
Put simply, a VLAD is your permanent handle. Underneath it sits a tamper-proof logbook that records every key you have ever used. Change a key, and a new signed page is added to the logbook, but the VLAD, your identity, stays exactly the same.
Think of it as a mathematically verifiable username that never changes, paired with an unforgeable history of every password you have ever set. People follow the username; the math proves the history is real.
Most of the names you use online are really borrowed. Your email address, your username, your phone number, even your website domain all sit on top of some company that can rename you, lock you out, redirect you, or hand your name to an impersonator. To prove one of those names is yours, you have to ask that company to vouch for you, and hope it is still around and still on your side.
A VLAD is different because it proves itself. It is built from math, so anyone can check that it is really yours by doing a calculation, not by trusting a middleman. No company has to be online. No certificate has to be unexpired. No website has to still exist. The proof lives inside the name and its signed logbook.
And it holds up at any moment, for as long as you like. You can verify a VLAD today, next year, or a decade from now, even with no internet connection, and get the same trustworthy answer. That is what Verifiable and Long-lived really buy you: a name you can check for yourself, anytime, instead of a name you are simply told to trust.
Everything in BetterSign rests on keys, so it is worth saying plainly why keys, and not the passwords and PINs you already know.
A password, a PIN, or a security phrase is a shared secret. To use it, you have to hand it over: you type it into a website, which means the other side now knows it too. If their system is careless, breached, or dishonest, your secret is out, and a leaked password is just as useful to a thief as it is to you.
A key works the other way around. A key lets you prove you are you without ever revealing the secret. You keep the private part on your own device and never send it anywhere. Instead you use it to produce a small piece of proof, a signature, that only your key could have made and that anyone can check. The secret stays with you; only the proof travels.
That single difference is why the serious systems you already rely on, banks, governments, phones, and messaging apps, are quietly built on keys underneath. BetterSign takes that same foundation and makes it something you can own and control in the open.
Here is the whole idea, no math degree required. A key really comes as two matching halves that are made together: a private half you keep secret, and a public half you are happy to give to everyone.
Picture a wax seal. You own a signet ring, your private key, that stamps a mark no one else can reproduce. Everyone else has a picture of your stamp, your public key, so when they see the mark on a letter they can recognize it as yours, yet they still cannot make it themselves. Signing a message is stamping it; checking a signature is comparing the stamp to the picture, and if even one word of the letter changed, the stamp no longer matches.
What makes this safe is a kind of math that is easy to do one way and practically impossible to undo, like stirring two colors of paint together. Mixing them takes a second; separating them back into the original colors could take longer than the age of the universe. Your public half is the mixed color everyone can see; your private half is the recipe only you know. People can use the public color to lock a message so that only you can open it, or to check your stamp, but they cannot work backward to your secret.
You never have to follow the math. The takeaway is simple: a key lets you prove who you are and receive private messages, while the secret that makes it work never leaves your hands.
Made together, used for opposite jobs, and only one of them is ever a secret.
Keys do two jobs, not one. We have talked about proving who you are; the very same pair of halves also lets anyone send you a private message that only you can open.
Picture your public key as an open padlock that you hand out to the whole world. Anyone can drop a note in a box and click your padlock shut, but once it is closed, only your private key, the matching half you never share, can open it again. So a stranger can lock a secret for you without the two of you ever having met or agreed on a password first. Locking the box is called encrypting; opening it with your private half is called decrypting.
That last part is the quiet magic. The old way to keep a message private was for both sides to somehow already share the same secret, which is a chicken-and-egg problem: how do you share a secret secretly? Public-key encryption breaks the loop. You publish the open padlock, anyone can lock a message to you, and only you can unlock it.
BetterSign uses modern, quantum-resistant methods to set up these locks, so your messages stay private even against future computers, but you never have to think about that. The takeaway is simple: your public half lets the world send you secrets, and your private half, which never leaves your device, is the only thing that can read them.
The same two halves prove who you are and keep messages to you private.
If keys are so much stronger, why do we still type passwords everywhere? Mostly habit, and the fact that a password feels simple: one secret, memorized, typed in. But that simplicity is exactly the weakness.
A password has to be shared to be used, tends to get reused across sites, can be guessed or phished, and is only as safe as the least careful place you ever typed it. A key never leaves your device, is different for every identity, cannot be phished in the same way, and proves you without exposing you. You do not even memorize it; your device keeps it safe for you.
Even the best key does not stay perfect forever. Devices get lost, laptops get stolen, backups get copied, and given enough years the strong math of today becomes an easy target tomorrow. The longer a single key stays in use, the more chances there are for a copy of it to end up somewhere it should not.
The fix is the same one we already trust in the physical world: change the locks now and then. Rotating to a fresh key on a regular basis means that even if an old one leaks, it is already retired and worthless, and any damage is contained to a small window instead of your whole history.
The reason people avoid this is the hassle we described earlier: normally, changing a key means racing to tell everyone and everything that relied on the old one. BetterSign removes that fear. Because your VLAD stays the same, changing a key is just a signed note in your logbook that everyone can verify and follow on their own. Rotation stops being an emergency and becomes healthy routine, like changing the batteries in a smoke detector.
Remember the tedious part, getting a new key out to everyone who needs it? BetterSign solves that with a shared network address book called VLADemlia.
Instead of hand-delivering keys, you publish the change once. You add the new key as a signed page in your logbook and announce it to VLADemlia. Anyone who follows your VLAD looks you up there, pulls the update, verifies it themselves, and switches to the new key automatically.
So distribution flips around. You no longer push a secret out to every machine; each follower pulls your latest verified state whenever they need it. VLADemlia only helps peers find each other, it never gets to decide what is true. The math in your logbook does that.
The deeper pages on this site use precise technical terms. Here is what each one actually means in everyday language, so nothing on the other pages should feel like a foreign word.
Keep this handy while reading the Architecture and Cryptography pages.
You do not need to understand the cryptography to get the benefits. Point your tools at a VLAD and BetterSign keeps the keys current for you.
In practice that means SSH access that does not break when keys rotate, TLS certificates that renew themselves, VPN identity keys you can change without reconfiguring every peer, API tokens you can rotate freely, and shared secrets that update on their own instead of being copied around by hand.
When you are ready for the details, the Architecture, Key Lifecycle, and Cryptography pages go deep, and every term they use is defined in the glossary above.