Security·@dosfi.ai Identity

One identity.
Every system.

@dosfi.ai is the universal, cryptographically secured identity layer across DOSFI.ai, MeshInfer.ai, DOSFI Academy, DOSFI University, Mesh-Native Apps, agents, and enterprise mesh networks.

Anti-Phishing Enforced
OAuth2 + OIDC
Device-Bound Tokens
MFA on All High-Risk Actions
How it works

From registration to mesh access

Every DOSFI identity follows a secure, deterministic lifecycle — bound to the user, their devices, and their mesh nodes.

01
User registers
username@dosfi.ai provisioned automatically
02
Identity bound
Email → UserID → NodeID → DeviceID
03
Token issued
Signed, device-bound OAuth2 token from identity.dosfi.ai
04
Mesh access
Identity determines routing, privacy mode & inference scope
05
Continuous verification
Every mesh operation is identity-signed and auditable
Security model

Six pillars of identity security

Every layer of the DOSFI ecosystem is protected by the same unified identity architecture.

Coverage

Every DOSFI system protected

@dosfi.ai identity is not a standalone service — it is woven into every platform in the ecosystem.

01
DOSFI.ai
Core mesh operating system login & node management
02
MeshInfer.ai
Inference routing permissions & privacy modes
03
DOSFI Academy
Course access and progress tracking
04
DOSFI University
Certification exams, architect tiers & purchases
05
Mesh-Native Apps
App execution scope & cross-device state
06
Mesh-Native Agents
Agent deployment & signed message authority
07
Enterprise Nodes
Hardware-MFA-gated enterprise mesh access
Transport layer

Secure by default — everywhere

All identity-related communication is encrypted in transit and authenticated at every hop.

  • TLS enforced on all email transport
  • SPF / DKIM / DMARC on all outbound mail
  • Rate limiting & anomaly detection on auth flows
  • Signed JWT tokens with short expiry & rotation
  • Mesh-native challenge–response for high-risk ops
What is explicitly blocked
  • Login screens on any domain other than identity.dosfi.ai
  • Inbound email spoofing @dosfi.ai
  • Credential replay via stolen tokens
  • Agent messages without identity signatures
  • Node access without device-bound MFA
  • Routing policy changes without identity-signed payloads
Enterprise

Org-scoped identities for enterprise mesh

Enterprise customers get sub-domain identities — admin@company.dosfi.ai — that map directly to mesh nodes, routing policies, and agent permissions. Hardware-bound MFA is mandatory for all enterprise node access.

Contact enterprise sales
admin@company.dosfi.ai
Mesh Admin · Full node + routing + agent control
team@company.dosfi.ai
Developer · App deployment + inference scope
architects@company.dosfi.ai
Architect · System design + policy authoring

Your @dosfi.ai identity is waiting

Enroll in any DOSFI course to claim your secure mesh identity and begin building on the platform.