Identity on TrustWeb is proven with PGP — not a badge we hand out. You can verify every claim yourself.
In any centralized system, identity is a promise. The platform says "this vendor is who they claim to be" — and you have to trust that promise. That works until the platform decides to lie, or gets compromised, or quietly hands a badge to a favored vendor.
PGP removes the promise. A vendor either holds the private key that matches their public key — or they don't. There's no gray area, no admin discretion, no way to fake it.
They upload their ASCII-armored PGP public key. TrustWeb extracts the fingerprint.
A unique random string is generated and bound to the vendor's key. It expires after 24 hours.
Using their private key — never shared, never uploaded — they sign the challenge and paste the signature back.
The signature is verified against the public key. If it checks out, the vendor gets a PGP Verified badge. If not, nothing happens.
Every verified vendor on TrustWeb displays their PGP fingerprint. You can independently check it against their profile on any market they use — no middleman required.
Use this to verify any message that claims to come from TrustWeb itself. If it isn't signed with this fingerprint, it isn't us.
TrustWeb will never ask for your private key, your password, or your seed phrase. Anyone who does is not us.
Come to the onion service and check any vendor's fingerprint for yourself.