Skip to content
Livingry Services logoLivingry Services
Why ownership matters

Proof should outlive the institution that issued it.

I learned what happens when proof lives somewhere you do not control. Three times, the record of real work I did came down to a single document, a single company, or a single database — and each one eventually failed me. That experience is the reason Livingry is built the way it is.

Editorial illustration reading left to right: a burned, empty picture frame; a hand-drawn solar and systems blueprint; a green document box holding an HVAC training card; and a small locked safe with a key — depicting three credential-loss failure modes (a document destroyed by fire, an issuer that disappeared, a rebranded company) resolving into owner-controlled custody. Illustration, not a photograph or documentary record.
An editorial illustration of the three credential-loss failure modes below — and the owner-controlled custody they argue for. It is a stylized collage, not documentary evidence.
Three firsthand losses

Three times, the proof disappeared before the skill did.

What follows is my own history, in the order it happened. It describes training I completed and work I did. It is not a claim of current licensure or presently valid certification — it is the lived experience that shaped how I think about records.

  1. More than 25 years agoHistorical experience

    A Permaculture Design certificate, lost to a house fire

    I earned a Permaculture Design certification and held the physical certificate. There was no digital backup. A house fire destroyed the document, and the person who issued it has since died. The training happened. The paper that recorded it, and the one person who could have re-issued it, are both gone.

  2. About 15 years agoHistorical experience

    A solar certification stranded when the company closed

    I trained and certified as a solar designer and installer through a private company. That company no longer exists. There is no successor to contact and no database left to query, so the certification became impossible to verify through the ordinary channel — not because the work never happened, but because the only institution that recorded it disappeared.

  3. About 12 years agoHistorical experience

    An HVAC card that survives only on paper

    My HVAC training is documented by a physical, Texas-issued card. It is the one artifact I can still hold. The company connected to that training has a new owner and was rebranded, so the trail behind the card now points to an entity that no longer answers to its old name. The card remains; the context around it has moved on.

The governing principle

One rule holds all three lessons together.

“He who creates, credentials, and custodies ‘It’, controls ‘It’, no matter what ‘It’ is.”

In plain language: when the only record of something lives inside another institution's exclusive system, your access to it — and anyone's ability to verify it — depends on that institution surviving and choosing to cooperate. When the fire came, the company folded, and the brand changed, that dependence is exactly what failed.

From pain to design rules

Each failure became a design requirement.

I did not want anyone I work with to inherit the same fragility. So each way my own proof failed maps directly to a rule Livingry now builds by.

The failure

Physical-only loss

The design rule

Redundant, exportable records and tested recovery

If proof exists in exactly one place, one accident ends it. Records are kept in more than one location, in formats you can export yourself, and recovery is tested so you know it works before you need it.

The failure

Issuer disappearance

The design rule

Portable evidence bundles, provenance, and independent attestations

When the issuer is gone, verification cannot depend on them alone. Evidence travels as a self-contained bundle that carries its own provenance, alongside independent attestations from parties who are not the original issuer.

The failure

Company rebrand or ownership change

The design rule

Durable identifiers independent of a vendor's current name

Names and databases change hands. Records are anchored to durable identifiers that stay stable even when a vendor is renamed, sold, or shut down, so the meaning of the record does not depend on today's corporate branding.

A precise caveat

Hashes and signatures can prove that a record is intact and show where it came from. They do not create legal authority, and they do not prove the underlying claim is true. Establishing that still requires an authoritative issuer or corroborating evidence. Livingry builds for integrity and portability — not for a false impression that cryptography alone makes a claim valid.

The Livingry Client-Control Covenant

What I build for clients — and for myself.

Livingry gives clients the ability to create, credential, custody, export, and control their own client and operational data on systems they control — not systems Livingry controls. We do different things differently: this is the tooling I wish I had, and the tooling I have built for myself.

  1. 01

    You hold the primary accounts, credentials, keys, and admin access

    Systems are built on accounts you own. You keep the top-level credentials, encryption keys, and administrative access — not Livingry.

  2. 02

    Your data and evidence are exportable

    Client and operational data, and the evidence attached to it, can be exported by you in documented, portable formats at any time.

  3. 03

    Workflows, integrations, recovery, and handoff are documented

    How each system is wired, how it recovers, and how it would be handed off are written down and given to you — not held as tacit knowledge inside Livingry.

  4. 04

    Material automation keeps human authority and observable records

    Anything consequential runs behind a human decision, and every material action leaves a record you can see and review.

  5. 05

    Your systems keep operating if the relationship ends

    Because everything lives in tools you control, ending the Livingry relationship does not switch anything off or take your records with it.

Who controls what
Who controls each part of a Livingry system: you, Livingry may operate, and what no single vendor should control alone.
ResponsibilityYou controlLivingry may operate
Primary accounts, credentials, and keysYes — you control this
Client and operational data + evidence exportsYes — you control this
Day-to-day operation of a systemYes — you control thisYes — Livingry may operate this
Configuration and improvement workYes — Livingry may operate this
Sole, exclusive control of any record

No vendor — including Livingry — should hold sole, exclusive control of any record your business depends on.

Map where your business could lose proof.