FAQ

Frequently asked questions about MAX.

This page collects the main questions about the MAX ecosystem, MAX App, MAX IoT, MAX Prime Theory, MX² and the current status of the project.

The goal is to clarify what MAX is, what MAX is not, what already exists and how it should be evaluated.

Essential answers

These answers are intentionally clear and direct: they are meant to avoid ambiguity about identity, cryptography, project status and technical evaluation.

1What is MAX?+

MAX is a verifiable identity ecosystem.

Its goal is to connect local identity, digital signature, data protection, login, secure communication and device identity inside a coherent model.

MAX is not only an app, not only a chat system and not only a password system.

It is a project that tries to build a common language to answer three questions:

Who you are. What you can do. How you can prove it.
2What does MAX mean?+

MAX stands for Mathematical Authorization eXchange.

Its meaning is:

Who you are. What you can do. How you can prove it.

The name expresses the central idea of the project: identity, authorization and proof.

3What is the MAX ID?+

The MAX ID is the public verifiable root of a MAX identity.

It is not a username. It is not a password. It is not an account created by a server.

In the MAX model, the MAX ID is connected to a local structure and can be used as a public reference for signatures, login, communication, vault and devices.

4Does the server create the MAX ID?+

No.

In the MAX model, identity is created locally.

The server can support some flows, such as login, messages, manifest distribution or technical coordination, but it should not be presented as the origin of personal identity.

5Is MAX a new cryptography?+

No.

MAX is not proprietary new cryptography.

MAX uses known and studied cryptographic components, including post-quantum components, inside a verification-oriented architecture.

The original part of MAX is not an attempt to replace standard algorithms.

The original part is the integration: local identity, proofs, signatures, containers, communication and devices inside a coherent model.

6Does MAX promise absolute security?+

No.

MAX does not promise absolute security. No serious system should do that.

MAX must be evaluated on the components actually used, the implementations, the flows, the keys, the signatures, the hashes, the servers, the formats and the verifications.

7Has MAX already been audited by third parties?+

No.

MAX is an independent project with working prototypes, public material and documented components, but it should not be presented as a system already audited or certified by third parties.

Independent technical evaluation is one of the natural future steps.

8What is MAX App?+

MAX App is the iPhone app of the MAX ecosystem.

It brings MAX identity into the personal context: local identity, signature, vault, login and encrypted chat.

The idea is to allow a person to create, protect, use and prove their digital identity inside a local and privacy-first model.

9Is MAX App a password manager?+

No.

MAX App can protect personal data and material, but it is not a password manager.

The center of MAX App is verifiable identity: signature, access, protection, communication and proofs connected to a MAX ID.

10Is MAX App only an encrypted chat?+

No.

MAX Chat is a module of the ecosystem, but it does not exhaust MAX App.

MAX App also includes local identity, MAX Signature, MAX Vault, MAX Login and other elements connected to verifiable identity.

11Does MAX use post-quantum components?+

Yes.

The MAX model uses post-quantum components such as SPHINCS+ and FrodoKEM.

These components are not presented as proprietary MAX inventions, but as known and studied algorithms used inside a specific identity architecture.

12What is MAX Signature?+

MAX Signature is the module connected to signing content, payloads, documents or approvals.

A signature connects a piece of content to a verifiable identity.

In the MAX model, this matters because identity should not only “exist”: it should be able to produce inspectable proofs.

13What is MAX Login?+

MAX Login is the access model connected to the MAX ID.

The idea is different from classic email + password.

Login can be based on challenge, signature and identity verification, avoiding the treatment of the password as the center of digital identity.

14What is MAX Vault?+

MAX Vault is the module for local protection of personal material.

Its role is to connect data protection and local identity inside MAX App.

It should not be read as a product separated from the rest of the ecosystem, but as one practical way in which MAX identity is used.

15What is MAX Chat?+

MAX Chat is the encrypted communication module of the MAX ecosystem.

It is used to connect secure communication and identity.

In the MAX model, chat can also become a channel for contacts, encrypted flows and commands toward authorized devices.

16What is MAX IoT?+

MAX IoT extends the concept of verifiable identity from people to machines.

A device can have its own MAX ID, a role, signed rules, authorized peers, gateways and observable states.

The goal is to make devices part of a system where identity, authorization and proof are verifiable.

17What is new about MAX IoT?+

The novelty is not simply “controlling a device”.

The novelty is treating machines too as subjects with verifiable identity.

In the MAX model, a person, an app, a gateway and a device can belong to the same ecosystem of identity and proofs.

18Is MAX IoT already an industrially certified product?+

No.

MAX IoT is a working prototype and an evolving technical model.

Real tests have been carried out with Raspberry, device identity, encrypted messages, gateway, roles, signed manifests and communication between people and machines.

This does not mean that it is already an industrially certified product or ready for critical environments without further audit, hardening and validation.

19What is a Fleet Manifest?+

A Fleet Manifest is a signed document describing the configuration of a device fleet.

It can include nodes, roles, peers, gateways, operators and operational rules.

In the MAX IoT model, the manifest helps avoid arbitrary or non-verifiable configurations: a device applies only the authorized rules that concern it.

20What is MAX Prime Theory?+

MAX Prime Theory is independent mathematical research on prime numbers, deterministic sequences and modular structures.

Inside MAX, its role is conceptual and structural.

It inspired the way the project thinks about identity: not as a simple account, but as a local, ordered and verifiable structure.

21Is MAX Prime Theory the cryptography of MAX App?+

No.

This distinction is fundamental.

MAX Prime Theory does not replace the standard cryptographic algorithms used in the ecosystem.

The operational security of MAX App and MAX IoT must be evaluated on the actual components, the implementations, the signatures, the hashes, the public keys, the flows and the verifications.

22Why is MAX Prime Theory on the MAX site?+

Because it is part of the intellectual and mathematical origin of the project.

MAX Prime Theory shows the method that led to MAX: finding structure, making it verifiable and turning it into a usable model.

Those who want to explore the mathematical layer can read papers, demos and public materials.

23What is MX²?+

MX² is a technical container connected to the MAX ecosystem.

It can be described as a structured, portable and verifiable format for protecting and organizing sensitive material inside an inspectable model.

MX² belongs to the practical layer of the architecture.

24Is MX² a new cryptography?+

No.

MX² is not proprietary new cryptography.

It is a format/container that uses known and studied components inside a readable, implementable and verifiable structure.

Its value lies in the format, the technical organization and the integration with the MAX model.

25What already exists?+

These parts exist:

  • MAX App for iPhone;
  • identity, signature, vault, login and chat modules;
  • independent mathematical research with public materials;
  • MX² as a published technical project;
  • working MAX IoT prototypes on Raspberry;
  • real communication tests between person, gateway and devices;
  • signed and approved manifests in test scenarios;
  • public materials for analysis and evaluation.

This does not mean that everything is already a mature, audited or certified commercial product.

26What does not exist yet?+

Full industrial certification does not exist yet.

A complete independent public audit of the whole ecosystem does not exist yet.

Formal standardization of MAX as a public protocol adopted by third parties does not exist yet.

There is not yet a guarantee that MAX is ready for critical uses without further verification.

27How should MAX be evaluated?+

MAX should be evaluated as an independent technical ecosystem in evolution.

An evaluator should look at:

  • architecture;
  • identity models;
  • formats;
  • code;
  • cryptographic components used;
  • signature flows;
  • login flows;
  • key management;
  • recovery;
  • revocation;
  • server;
  • implementation security;
  • declared limits.

MAX does not ask for blind trust.

It should be inspected.

28Is MAX open source?+

Some materials, demos, papers or components are public.

MX² has code and documentation available on GitHub.

MAX is designed to make concrete parts of the system verifiable.

For example, on iPhone it is possible to observe that identity and keys are generated locally, even without a network connection. Also, using the public MX² code, it is possible to compare the behavior of the format and check the consistency between what is generated in the app and what is reproduced by the public code.

This is not equivalent to a complete audit of the whole ecosystem and should not be presented as external certification.

It is, however, an important technical signal: MAX does not only ask for trust, but tries to make its fundamental steps inspectable.

29Why should I take an independent project seriously?+

Because a technical project should not be evaluated on slogans or declared authority, but on what it shows.

MAX should be taken seriously only to the extent that it makes architecture, materials, limits, components, tests and results visible.

The fact that it is independent is not proof of value.

But it is not proof of weakness either.

The correct evaluation is technical.

30Are Tac! and Clo-E part of MAX?+

No.

Tac! and Clo-E are other creative projects by Massimo Russo.

They can remain on the site as “Other projects”, but they are not the center of the MAX ecosystem.

MAX remains the main technical project.

MAX

In summary

MAX should be read as a verifiable identity ecosystem: not as an absolute promise, not as proprietary new cryptography and not as an already certified product.

The correct way to evaluate it is technical: architecture, components, flows, public materials, implementations, declared limits and verifications.

verifiable identity MAX App MAX IoT MAX ID MAX Prime Theory MX² known components technical verification
Login with MAX