MAX App

Local identity on iPhone.

Create. Sign. Protect. Access. Communicate.

MAX App is where MAX identity becomes personal: generated locally, reproducible from the same starting point and usable to sign, access, protect data and communicate.

Why this app matters

Today, digital identity almost always starts from a central service: you create an account, enter an email address, choose a password and from that moment your identity exists inside that system.

MAX App starts from a different point

MAX App starts from a local identity first. The functions come after.

The same identity can be used to sign content, protect data, access compatible services, communicate through encrypted chat and interact with authorized devices through MAX IoT.

The point is not to replace one password with another password. The point is to move the center of identity from the server to the user’s device.

Technical note

MAX App does not base identity on the classic email + password + central account model. Identity is generated locally and publicly represented by the MAX ID. The server can support login, relay and verification, but it is not the source of the identity and should not possess personal secrets or read protected content.

What MAX App does

MAX App does not start from separate features. It starts from a local identity and then uses it to sign, protect, access, communicate and interact with devices.

ID
Identity

Local identity

Identity is generated locally and can be reproduced from the same starting point. The MAX ID is its public verifiable root, not a username and not an account.

Sig
Signature

Sign and verify

MAX Signature allows content to be signed and produces verifiable proofs. The point is not to claim: it is to check.

V
Vault

Local protection

MAX Vault stores personal content and data in an environment designed to be local-first and privacy-first.

Login

Compatible access

MAX Login can be integrated by websites and services that want to use MAX identity as a method for access and authorization.

Chat
Communication

Encrypted chat

MAX Chat connects encrypted communication and identity. It is not only messaging: it can become an interface toward other flows.

IoT
Devices

Bridge to MAX IoT

A command can start from the chat and reach authorized devices through MAX IoT, where identity, roles and rules become verifiable also for machines.

How MAX identity is created

The MAX ID is the public verifiable root of the local identity generated by the app.

Deterministic identity

In the MAX model, identity does not begin from an account created on a server. It begins locally, from a starting point controlled by the user.

The MAX method comes from independent research on prime numbers and deterministic structures. In the app, this idea is used to build an ordered and reproducible local identity, not a hand-picked username or a value assigned by a server.

The key point is determinism: if the local starting point is the same and the method is the same, the resulting identity can be reproduced.

The MAX ID is the public verifiable root of this identity. In practice, it coincides with a final Merkle root built from hashes generated in the local process.

The goal is to obtain a stable and verifiable identifier: if the local starting point and the method remain the same, the public root of the identity remains the same.

This makes the MAX ID different from a username: it is not a chosen name, it is not a central account and it is not a password. It is the public result of an identity generated according to the MAX method.

Technical note

MAX Prime Theory inspires the concept of mathematical identity and ordered derivation. This level helps build the identity model and the MAX ID, also through deterministic structures related to prime numbers. It does not replace SPHINCS+, FrodoKEM, Argon2id, hashes, signatures or other known components, which remain the operational cryptographic layer of the app.

What is under the hood

MAX App integrates known and studied cryptographic components inside a MAX-specific architecture. The original part is the integration, not the claim to replace standard algorithms.

For engineers and evaluators

MAX App combines local identity, signatures, hashes, Merkle root, public keys, local protection, encrypted communication and post-quantum components. These elements are used to build a readable and verifiable model, not a promise of absolute security.

SPHINCS+ Post-quantum signature used to produce verifiable proofs connected to an identity.
FrodoKEM Post-quantum component oriented to secret exchange or agreement in communication flows.
Argon2id Robust derivation from user secrets, used as a known and studied component.
Hashes Verifiable fingerprints used for content, payloads and for building the public root of the local identity.
Public keys Elements used to verify signatures and proofs produced by the app.
Merkle root Verifiable root generated from the hashes of the local identity. In the MAX model, this root coincides with the public MAX ID.
MX² MAX-specific cryptographic container integrated with local protection, messages and the app structure.
Support server Can transport, verify or coordinate technical objects without possessing personal secrets.
Verification The model produces controllable elements: signatures, hashes, keys, payloads and observable states.

What this does not mean

These components do not automatically make MAX App a certified or audited system. They make the architecture more readable and more suitable for external technical evaluation.

The server is not the center of identity

MAX App can communicate with a server, but the server should not be confused with the source of personal identity.

Support infrastructure

A server can be useful for login, relay, verification, messages, signed payloads, coordination and connection with MAX IoT.

The correct distinction is this: the server can see technical data required for operation, such as public identifiers, public keys, signatures, signed payloads or operational metadata. In protected flows, however, it should not possess personal secrets or read encrypted content.

This makes MAX different from the model in which the entire identity is born and lives inside a central account.

From MAX App to MAX IoT

MAX App works on the human side: identity, signature, vault, login and communication.

MAX IoT applies the same principle to the machine side: device identity, roles, signed rules, manifests and controlled communication.

The strongest shift is continuity: a person can prove who they are and what they can do; a machine can receive a role and prove that it acts according to verifiable rules.

What already exists

MAX App is a developed iPhone app. It includes local identity, signature, vault, login and encrypted chat. There are flows connected to the website through Login with MAX, support server components and an operational connection with MAX IoT.

The project is not only conceptual: the app, login, signature, chat and connected flows are part of a real system currently being consolidated.

What still needs validation

MAX App requires external validation, independent audit, technical review of the flows, testing with real users, clearer public documentation and further consolidation of the user experience.

These steps do not weaken the project: they are necessary to turn a developed system into a stronger and more evaluable technical asset.

What MAX App is not

MAX App is not based on the classic email + password + central account model. It is not proprietary new cryptography, it does not promise absolute security and it is not yet an audited or third-party certified system.

It is a developed app designed to bring deterministic local identity, signature, vault, compatible login and encrypted communication into a privacy-first, local-first and verification-oriented model.

Login with MAX