Privacy infrastructure for physical addresses

Your address is private. Your AddressMask is shareable.

Store your verified US address once. Share a revocable mask instead. Authorized resolvers receive only the fields permitted for a specific purpose and time.

US early access · No address data collected on this page
Illustrative product previewUS · protected flow
Protected source

Taylor Reed

Hidden by default
Your AddressMask Verified

AM-7Q4K-9M2P

Shareable identifier · not a bearer credential
Purpose Shipping · ORDER-10482
Recipient Authorized delivery resolver
Access Full delivery address · single use
Access recorded. You can review it anytime.
01Protected address
02Public mask
03Scoped access
04Controlled resolution
05Audit event
A different privacy boundary

Your street address should not become permanent checkout data.

Most services need an outcome: deliver this order, confirm this service area, calculate this jurisdiction. They do not all need the same address fields forever.

AddressMask separates the identifier you share from the temporary credential that authorizes a specific disclosure.

How it works

A safer way for your address to move.

Five deliberate boundaries replace one uncontrolled copy-and-paste.

  1. Encrypted address version · 01
    Taylor ReedPhysical address protected••••••••••••••••
    Verified · current
  2. Public identifierAM-7Q4K-9M2POpaque · shareable · revocable
  3. Temporary authorization
    Purpose
    Shipping
    Audience
    Resolver · 04
    Fields
    Delivery address
    Expiry
    24 hours
  4. Authorized resolver
    Token checkedPolicy allowedRequired fields6 / 6
    Single-use token consumed
  5. Activity · just nowYour address was shared for this shipment.

    Authorized delivery resolver · ORDER-10482

    Result
    Allowed
    Fields
    Full delivery address
    Recorded
Protected source01 / 05
Encrypted address version · 01
Taylor ReedPhysical address protected••••••••••••••••
Verified · current
Selective disclosure

Share only what the moment needs.

The same protected address can answer different authorized questions without giving every caller the full record.

Permission request
Policy allowedfull_delivery_address
Mask
AM-7Q4K-9M2P
Purpose
Shipping
Audience
Authorized resolver · 04
Expires
24 hours or less
Released to authorized resolver
123 Example Street
Austin, TX 78701

A single-use shipping token releases a verified delivery address to the intended resolver.

No additional fields returned
Your control center

You know who, what, why, and when.

Protection status comes first. Address details stay behind deliberate actions while permissions and activity remain easy to understand.

Protection status

Your address is protected.

Verified
Your AddressMaskAM-7Q4K-9M2P
Active permission

Home delivery · ORDER-10482

Authorized
Who Authorized delivery resolverWhat Full delivery addressWhen One use · expires in 23h
Permission created for this shipment.No address has been resolved yet.
Just now

Illustrative interface using synthetic data. Product behavior is in development.

Privacy starts with the architecture

Access should be explainable before it is allowed.

AddressMask is designed around explicit policy boundaries—not the assumption that possessing an identifier should reveal a home address.

01

Opaque by design

A mask is random and non-semantic. It is not derived from your address, identity, ZIP code, or coordinates.

02

Encrypted source data

The product architecture calls for address payloads to remain encrypted outside authorized resolution paths.

03

Scoped authorization

Every disclosure-capable token names a purpose, audience, explicit fields, and an expiry.

04

Fail closed

Missing or ambiguous authorization inputs are designed to return a denial, with no protected data.

05

Controlled resolution

Only an approved, authenticated resolver can request the fields permitted by policy.

06

Understandable activity

Material decisions are designed to record the result and fields released without logging raw address data.

Trust boundary: architecture requirements are not a certification. Independent security assessment remains a production launch requirement.

For businesses and developers

Ask for the address data your workflow actually needs.

Request a purpose-bound token, pass it to an approved resolver, and receive only the fields allowed for that transaction.

  • Separate environments Sandbox and production credentials stay isolated.
  • Durable events Signed webhooks and an auditable delivery ledger.
  • Explicit contracts Versioned REST endpoints with runtime validation.

Join the business pilot.

Opening soon
Early access isn't open yet.

We're preparing the first US pilot. No email is being collected on this deployment.

Sandbox request Policy allowed
POST /api/v1/masks/AM-7Q4K-9M2P/tokens

{
  "purpose": "SHIPPING",
  "audience": {
    "type": "resolver",
    "id": "rsv_04"
  },
  "shipment_ref": "ORDER-10482",
  "requested_fields": [
    "full_delivery_address"
  ],
  "expires_in_seconds": 86400
}
Token returned once Expires in 24 hours Resolver-bound

Illustrative contract. No live credentials or address data.

Clear answers

What a mask is—and what it is not.

AddressMask adds a controlled disclosure layer. It does not make the surrounding delivery network disappear.

What is an AddressMask?

It is an opaque, shareable identifier mapped to a protected address vault. The identifier itself contains no address information and does not grant permission to reveal an address.

Can anyone use my mask to see where I live?

No. A mask is not a bearer credential. A disclosure requires a purpose-specific, audience-bound, field-scoped, expiring authorization and an approved resolver.

Can I put an AddressMask directly on a shipping label?

Not by default. A merchant or carrier must use a supported AddressMask integration and an authorized resolver. AddressMask does not replace USPS, UPS, FedEx, or other addressing standards.

Does every request reveal my full address?

No. A permitted request can return a smaller result such as service-area eligibility, tax jurisdiction, verification status, or postal code. Full delivery addresses require an authorized full-address flow.

Can access be revoked?

The product model supports revocable masks, permissions, and unused access tokens. Full-address shipping tokens are designed to be single-use by default.

Where will AddressMask launch?

The first product scope is for verified United States addresses. International support and exact production availability are not yet being promised.

US early access

Be early to a more private address layer.

Join the list for product updates and opportunities to participate in the first controlled pilot.

Opening soon
Early access isn't open yet.

We're preparing the first US pilot. No email is being collected on this deployment.