Interviews

Sebastian Mellen: The Power of Verified Data in Non-Obvious Industries

Zack Jones

·

·

2 min read

Today’s guest is Sebastian Mellen, Co-founder and CEO of Cerebrum. His team is building an IDtech product called vID, tackling data and compliance problems in healthcare, HR systems, and even youth sports teams.
In this conversation, we cut right to some meaty topics, including some of the biggest challenges that IDtech products tend to face. Sebastian gives insight into Cerebrum’s trojan horse go-to-market strategy into large corporates, how they’ve translated self-sovereign identity language into “enterprise speak”, how they’ve addressed the chicken-and-egg problem that exists in many IDtech ecosystems, and much more.
Sebastian’s perspective on the importance of forming strategic partnerships to break into regulated industries will be super useful to other IDtech product builders.
Learn more about Cerebrum at https://www.cerebrum.com/. Reach out to Sebastian on Twitter.
Reach out to Riley (@rileyphughes) and Trinsic (@trinsic_id). We’d love to hear from you.

Full Transcript

Transcript lightly edited for clarity.

Riley Hughes: Welcome to the Future of Identity podcast, where we talk to the people building the IDtech products of tomorrow. I’m Riley Hughes, co-founder and CEO of Trinsic, and we build infrastructure for launching identity products. Today’s guest is Sebastian Mellen, co-founder and CEO of Cerebrum. His team is building an IDtech product called VID, spelled V-I-D, tackling data and compliance problems in traditionally overlooked industries such as healthcare, HR systems, and even youth sports teams. In this conversation, we cut right to some meaty topics, including some of the biggest challenges that IDtech products tend to face, Cerebrum’s Trojan horse go-to-market strategy into large corporates, how they’ve translated self-sovereign identity language into enterprise speak, how they’ve addressed the chicken-and-egg problem that exists in their IDtech ecosystem, and so much more. I also think his perspective on how forming strategic partnerships to break into regulated industries will be super useful to other IDtech product builders.

Riley Hughes: I hope that you enjoy this episode with Sebastian as much as I did. His vision for a self-sovereign identity where people no longer need to trade off safety and privacy left me feeling inspired about the future of identity. And now, onto the episode. Sebastian, welcome.

Sebastian Mellen: Thank you for having me.

Riley Hughes: It’s great to catch up. We met, I don’t know, a year or two ago, and I’ve always looked to Cerebrum as a company who is doing something pretty unique in an industry that is, forgive me if you would characterize it differently, but an industry that’s a little bit unsexy to probably most people, right?

Sebastian Mellen: For sure.

Riley Hughes: I’d love to hear a little about your story. How did you land here? I think you’ve got a little bit of a unique background and one that makes you maybe nicely suited, but maybe unexpected to tackle such an industry.

Sebastian Mellen: You know, that all started back in, let’s see, I guess it’s now 2018 when I founded my first startup, which was called Assemble. Basically, what we did there was we built blockchain-based tools for timestamping the provenance of different kinds of research data. So what that would allow a researcher to do is say, I came up with this invention at this date, here’s proof, and they could log that without publicizing it. So it was sort of a private way to keep track of the history of your research. That was a successful startup in the sense that we had users, but it was not a super successful startup in the sense that we got basically to break even, but it wasn’t a lucrative business. Eventually, I realized that a lot of the technology that we built related to identity. Through a story of a lot of serendipitous events, I ended up co-founding Cerebrum with my now CTO, Lance, and another business partner of ours who runs a large company in the employment and compliance space.

Sebastian Mellen: Basically, we spun out Cerebrum with the goal of verifying all kinds of data using some of the principles that I’d built in blockchain verification of timestamp history. And so we leveraged that technology, put it into a few different existing legacy platforms, sort of enterprise-grade platforms for verifying the provenance and legitimacy of different kinds of data. And then we also started spinning that out into different angles. And the first one that we really found success with was with COVID. A lot of organizations were having trouble verifying COVID test results, and there were also some regulatory demands placed on, for example, testing facilities at airports to make their tests verifiable at other locations. And so we realized, you know, this is a great use case for some of the technology that we built. None of this was strictly verifiable credential technology, but we were able to use it to verify COVID tests. So we’d place a QR code on a COVID test. Anyone could scan that.

Sebastian Mellen: It would pull up a web app that would communicate with a blockchain backend and verify the hash of the data in a private way, essentially, and confirm that that COVID test was legitimate and had been issued by a legitimate party. From there, we basically developed this from a basic concept of verifying paper documents into a much more enterprise-grade system where we now deal with all kinds of credential information, everything from vaccination cards to food safety license certificates to background checks and government-issued identity. So the end goal that we’re driving to is where every applicant, let’s say to a new company or a volunteering position, has a digital wallet. And in that digital wallet, they can have all of the necessary information about themselves. That means a background check, a credential that they may have undergone some safety training, a COVID vaccination perhaps, and then any other kinds of credentials that might need to be associated with that user’s identity.

Sebastian Mellen: So it’s really driving in that digital wallet direction, but from a more enterprise kind of perspective.

Riley Hughes: That was a really helpful introduction. You know, one of the big challenges IDtech product builders face is overcoming the cold start problem or the chicken-and-egg problem. You can imagine, of course, wouldn’t it be wonderful if I could go to the airport and scan my digital COVID vaccine card. But unless consumers have that already in their wallet, it’s unclear how to sort of overcome that bootstrapping problem that exists. You’ve compiled some sort of Lego pieces together in a bit of a novel way, maybe to help address that problem. I wonder if you could speak to that a little more and speak to one of these employees that you alluded to, or an applicant or a volunteer or whatever. What does it look like for that person?

Sebastian Mellen: I’ll set the stage a little bit and give you an idea of what it looks like today. Let’s say if I’m an applicant to Fortune 500 major pharmacy chain, for example, I might need to come in and provide a lot of different forms of information about myself to start. That includes a lot of PII, social security number, date of birth, addresses, name, so on and so forth. The purpose of a lot of this information is to run. background checks and other checks on that person. All of that data is collected up front, and it’s usually run through a lot of legacy enterprise systems that connect to different data vendors. This data is pulled in from all sorts of different databases, locations around the U.S., in this case, from different county courthouses. And really that whole process is taking a lot of unnormalized data and turning it into a sort of normalized data that can be applied to the individual. And then that might be the first part of the screening process. So now I know this person’s generally pretty good, and I can bring them on.

Sebastian Mellen: The next step might be to check that they have all of the required data. They have, you know, a license, they have a certification, they have a certain type of training, for example. And all of these regulatory requirements vary and differ by state, county, jurisdiction, and so forth. So a lot of our existing partners today do all of that process on the backend, and they compile regulatory lists, compliance lists, what needs to be done per jurisdiction, per job position, per employment type, and how do we fulfill those requirements. Now, you know, all of that’s great, and in most of these ecosystems that process works pretty well. But there’s also a lot of inefficiency in that process because, for one, sometimes you have people who are moving between positions, and they’ve already completed all of these requirements six months earlier.

Sebastian Mellen: They may already have their background check and all of their credentials verified by another pharmacy chain or another trucking company, and now they need to come in and spend a month redoing that whole process, supplying all of that credential information again. It’s very inefficient in that way. But there’s also another problem, which is that usually all of this data is very loosely tied to the individual. And what I mean by that is there’s really no core concept of a user having a verified identity in most of these employment systems. A user is represented as, you know, a social security number in one place, an employee ID in another place, and first and last name and date of birth in another place. And those are the unique identifiers of that individual. What that means is all this data floats around and it’s not really attached to anybody or anything, and it lives in all sorts of different spreadsheets and HR systems. No one’s really provided a product where a corporation, let’s say, or an organization can come in and get someone to get a base verified identity.

Sebastian Mellen: All right, now we know who this person is. We verified their government-issued PII. We’ve confirmed that with, let’s say, for example, a biometric qualifier like a selfie to match with the photo on the ID. And then we’ve taken in ancillary information to verify that once more through, let’s say, credit bureaus, like a social security number. So what we built in VID is a product that does that. Before a user applies for an employment position or a job within an organization or a volunteering position, they go through our VID app and they first of all verify their identity, you know, scan front and back of your ID card. We run that through verification libraries. We take a photo of their face. We match that up against the photo on the ID. And then we take in other data like their SSN, for example, to verify all of that information through third parties. So now what we’ve done is we’ve given the user, first of all, a login and second of all, a login that’s tied to a verified identity. And that’s really what our VID product is.

Sebastian Mellen: Now, from there, because we have this basis, we have a strong identifier for that user. We have an account that’s tied to their verified identity. We can take that and sort of tie all other kinds of credential data to that base verified identity. And the power of that is that you no longer have all this information floating around, not knowing who the person is. I can’t go into any specifics on the enterprises that we work with because a lot of this is confidential or NDA-bound. But, you know, we’ve worked with very large companies in healthcare, in staffing, transportation, and so forth. Also volunteering, things like youth sports. And all of them share the same problem. It’s really applicable to employment, volunteering positions in general throughout the U.S. That’s what VID was made to address. How do you tie credentials to a verified identity? And then how do you enable that user to store that credential data? VID is an identity verification product first, and then a digital wallet for credentials second. That’s sort of how I’d summarize it.

Riley Hughes: So in a few years, my daughter will be old enough to play youth sports. If I wanted to volunteer where she’s doing that, the place would ask me to get the app. I would download it and do a couple of verifications. What comes next?

Sebastian Mellen: There’s another flip side to this, which I think is even more exciting, and that’s the potential that this enables in the future. As you mentioned, you’re a parent, you’re coaching for youth soccer, and you’ve verified your identity. You’ve gotten those credentials in your VID app. I now have a verifiable credential on my phone, and what that is, is it’s basically a scannable QR code that someone else with the app can scan to verify my status. But more than that, it’s bundle of data that’s issued by a trusted issuer. In this case, let’s say it’s the background screening company and Cerebrum. And what that means is that I can pass that data along to any other party that might need verification, and they can still trust that it’s legitimate without running their own verification process. Unfortunately, we’re not fully implemented with verifiable credentials at this stage. That’s where we want to get. The beauty of this is that it’s incredibly efficient in comparison with existing processes. So let’s say, you know, I believe you have two children right now, correct?

Riley Hughes: That’s right.

Sebastian Mellen: Let’s say, you know, your second child also goes into youth sports, and you’re doing soccer. and hockey and basketball and baseball, right? Maybe you’re going to have to verify yourself for four different leagues or four different organizations. Parents, and especially coaches, volunteers, actively involved people who might work at a school, a few different youth sports organizations, and another volunteering program, they’re going to have to go through the same repetitive background screening process four, five, six times, and that duplicates cost and effort and time. It’s just massively inefficient. With the vid app, you just walk up to a new organization and you say, Hey, I’ll share a presentation of my background screening credential with you and my training credential, and you can get this verifiable presentation, immediately verify it was issued by a trusted source, and then you save money, I save time, and we all jointly save a lot of effort.

Sebastian Mellen: That’s sort of the long-term future of vid, and we see that applying not only in volunteering, but also in much more complex scenarios like travel nursing or physicians who might practice at multiple locations. Oftentimes, these screening and verification compliance processes are very expensive. And if you can make it easy to share already verified data rather than paying to re-verify that data, cost savings are also massive. Potentially, there’s a longer-term future where vid becomes a general-purpose wallet for all kinds of credentials. Instead of just being background screening credentials and so forth, you might have your health insurance card in there. You might have a pharmacy prescription in there as well. And so that’s really the long-term self-sovereign identity wallet vision we’re driving towards.

Riley Hughes: First time in the conversation, we used the term self-sovereign.

Sebastian Mellen: Yes, yeah.

Riley Hughes: It sounds like there’s some key building blocks here. You’re bringing selfie-based document verification in. Sounds like you’ve got a background check verification coming in. There’s probably some other data things going on under the hood. You mentioned verifiable credentials is a direction that you want to go in. What else would verifiable credentials add to this?

Sebastian Mellen: Before I can answer that, there’s a problem that I need to address too in existing circles. Let’s say, like, enterprise employment data. Most of this data right now is not in the state to be a verifiable credential. I think that’s the most complex part of this whole industry and of a lot of these legacy systems. Perhaps the biggest advantage of a verifiable credential, beyond the verification and all of those other great things, is that it enforces a lot of thought about the structure of the data. Right now, a lot of this data is not only unstructured in an organization. Like, an organization might have 10 different Excel spreadsheets that have different structures to manage their COVID data. It’s not only bad at the local level; it’s also bad at a broader level. You’ve got different states and jurisdictions that require different reporting requirements, data storage types, and then you’ve got different organizations that do things completely differently. They might record a background check in a completely different way from another organization.

Sebastian Mellen: Their reporting standards might differ completely. So I think work that needs to be done before we can embrace that self-sovereign identity future is figuring out what data is actually important. What does the structure of that data actually look like? That’s perhaps the biggest advantage of verifiable credentials, is they force people to think like that. How can this data be reused? How can it be portable? How can it be interoperable between organizations and more borders? But getting to that stage requires a lot of thought, effort, understanding, and it doesn’t scale very well to start because all of this data right now, at the core, is actually unstructured. So, for example, if we go into the core of background screening data, every single courthouse in the U.S. essentially stores this data in a different format. Some might store it on CD-ROM, some might store it on paper, some might have a digital access system, and they all name different cases differently. Let’s say, you know, a DUI might be a completely different name in a different state, and this is quite common.

Sebastian Mellen: Same goes for other HR credentialing data. There’s a lot of trainings and certifications that are in completely disparate data structures, even though they fulfill the same regulatory requirements. So I think getting to that SSI future requires this pass-through phase of how do we standardize, normalize, agree on what the structure of this data should be. Verifiable credentials, in a way, are the best razor, if you will, for forcing that thought process.

Riley Hughes: Is that a barrier, though? It doesn’t sound like an easy problem or a straightforward problem to just solve. Seems like if it were easy to solve, it’d be done already. What is it about the fact that this exists now that will cause that problem to be solved in a way that wasn’t solved in the past?

Sebastian Mellen: It’s a good question. One of the biggest advantages of verifiable credentials is that they offer a lot of other advantages. And right now, at least to date, there hasn’t really been a strong incentive or reason to move into this direction. You know, as an enterprise, I have no incentive to normalize my data to standards that fit with other enterprises around the U.S. because I’m my own enterprise. I’m not going to benefit from a big standardization effort. What verifiable credentials offer is a convincing and compelling argument, if it’s presented correctly, for that standardization effort. They say, okay, well, we get that right now you don’t want to standardize your data. However, if you were to accept verifiable credentials, you don’t have to standardize your existing data. Let’s just say a new employee came to you with a verifiable credential that was structured. If you were to accept that, that would be a direct bottom-line benefit to you. in terms of staffing, time, cost, whatever else. That’s an argument that an enterprise can understand.

Sebastian Mellen: And in that way, self-sovereign identity can be presented as a very good business decision. It’s not something that has to be done for, you know, high, lofty, unattainable goals of, oh, users own their own data. I’m an enterprise. I don’t care about users owning their own data. I want to make money. I want more people in my organization. I want to have faster throughput. Interestingly enough, all of those lofty goals of self-sovereign identity make it a lot easier to appeal to that enterprise goal as well. If I say, okay, users own their own data, the enterprise says, great, what does that mean? You say it means that the data is more portable. The data is more likely to be up to date because the users update their own data, and it’s more likely to be correct because it was verified and bound directly to that user’s verified identity. Enterprise says, great. You say the data structure is formatted and it can be traced back to the issuer. The enterprise says, great, what does that get me?

Sebastian Mellen: You say it gets you lower time to staffing because you don’t have to re-verify existing data, faster onboarding, and potentially less cost in verifying that data. Every individual goal that SSI has, we’ve been learning how to rephrase into enterprise speak. And that process is not fast, but I think a lot of the appeal of SSI, when phrased properly, is actually very appealing to, let’s say, your average enterprise consumer. It’s almost a quid pro quo kind of argument of, like, wouldn’t it be great if you could accept these credentials this way? You know, the answer is, of course, yes. I’d love to verify a user in a quarter of the time, a third of the cost, whatever.

Riley Hughes: It’s almost like the classic, how do you find a good spouse? You become a better person yourself. It’s like, how do you accept structured data like this? Well, first, you’ve got to create a system that can accept this structured data, which means you’ve got to structure your data to begin with.

Sebastian Mellen: Right.

Riley Hughes: Am I thinking about it the right way?

Sebastian Mellen: That’s the process in an ideal world, and I think that is still the guiding framework. We also provide enterprise software that helps you manage this structured credential data. That’s sort of our pitch from the enterprise perspective. They understand that. There’s always complexities here, and I think a lot of those are unfortunately oftentimes more political than they are good arguments. I work with a vendor that takes me out to eat nice dinners once a month, and they manage all our HR data, and we’re good to go. Maybe the other one is I’m in HR or I’m in this division, and I see this as a threat to my position perhaps, because I right now manually enter and store all this data, and that’s a kind of job security. That inefficiency is a job security, and so this can appear maybe a little bit threatening. And then even at the higher levels of decision-making in all kinds of organizations, I think there is a really big concern about privacy.

Sebastian Mellen: Even if you explain how the technology works, whenever people hear verified identity, scanning your government ID, take a selfie and we’ll batch that with your photo, all of that sounds frightening, and I can understand that. So I think there’s a number of other sort of less technical, more political barriers to adoption in that sense as well.

Riley Hughes: Yeah, that’s interesting. The strategy that you sort of alluded to of offering enterprise-grade software to manage data reminds me of the story of OpenTable, where they offered a SaaS product for restaurants to manage the bookings and reservations at the restaurant. Once they had enough restaurants using that SaaS product, that’s when they opened up the other end of their now two-sided marketplace, where consumers can now book reservations directly through their product. They seeded one side of the market with a regular old SaaS product, and then they opened up the other side of the market after they had the supply side or whatever built up first.

Sebastian Mellen: I love that analogy, actually, and I think it’s a very good framework through which to think about verifiable credentials, self-sovereign identity in a lot of existing industries. I think it’s maybe a different consideration in developing markets where you can say, you know, let’s just throw something out there. It’s better because there’s nothing that exists right now. In a lot of these organizations that have existing systems, those systems fulfill a lot of important purposes. It’s not, let’s say, table booking. It’s keeping track of who’s getting employed and who’s not, what the decisions on those people are, things like that. And so managing a lot of that, replacing a lot of those systems—and I don’t want to say this in a bad way—but almost hoodwinking those enterprises into adopting SSI.

Riley Hughes: Trojan horsing.

Sebastian Mellen: Trojan horsing. That’s a better term, is a very interesting way to go about it. You know, it’s not that you’re being deceptive. You’re not saying, Oh, we’re going to give you enterprise software and then slip it in the back. But you’re saying, We’re giving you a framework that works today, and here’s these other advantages. And the interesting thing is, when you make that pitch, at least through what we’ve found, most enterprises really disregard those longer-term advantages of SSI. You can woo them by short-term, slightly better basic software. But there’s a few people in most organizations, and I think Clayton Christensen speaks about this in different ways about those early adopters, that 5% of your population, and you notice them when you are in enterprise sales conversations. They see it and they’re like, Wow, this is going to be big. Finding those organizations that are potential to be early adopters, and then also appealing to legacy requirements is, I think, a playbook for success for any IDtech company that wants to go in that self-sovereign identity direction.

Riley Hughes: I like that a lot. Your first startup was related to data. This conversation’s ended up circling back to essentially talking about data as the core problem to be solved before verifiable credentials can scale. At the same time, I’m thinking about the kinds of problems that you’re talking about solving in compliance and things like employment and some of these areas. I want you to connect the dots for me. As you were looking at identity broadly, how did you segment which use cases would be suitable to tackle first, and how did both the industry vertical fit and also the current state of data in those industries factor into your overall calculus of where you’d spend your time as Cerebrum?

Sebastian Mellen: This is something that we thought about a lot because there are a lot of very compelling consumer applications, more B2C, let’s say immediately scalable growth curves that you could take. And I think all of those are still very compelling. I encourage any founder who’s interested in IDtech to pursue them. I think identity as sort of a greenfield market in that sense is very, very open. Ultimately for us, it came down to a number of different things. One was that we had partners who had very good existing bases in these markets. We can get access to conversations with a lot of these enterprises that, let’s say, smaller startups might struggle with getting. That was one big factor, was we got access to these people and when speaking with them, we realized they had addressable problems. But the other piece of it is that this is maybe one of the biggest applications of identity, even though it’s a very hidden one. I think even most people who go through these processes don’t realize how linked to identity the employment process is.

Sebastian Mellen: And that’s because the whole employment process today is very opaque. You’re an applicant. You just submit your data into some portal, and you don’t really know what happens with it after that. And there’s a big chasm of complexity that once you open it up, you realize can be really completely reformatted. That was the other piece of it. We realized no one’s really seen this problem, and we think it’s a burgeoning market to go into. There are a few groups that have seen it. One, for example, is Velocity Network. They’ve done some work in this space. But the biggest reason we chose this market was that it is all-encompassing. Basically every adult in the U.S. has some form of employment. Almost everybody who gets a job, especially in a regulated industry, which makes up a vast majority of our employment base, will get a background check at the very least. In addition, they’ll probably have additional credentials. If you’re in a kitchen, let’s say a commercial kitchen, you’re going to need a food safety license.

Sebastian Mellen: If you’re in a healthcare facility, you’re going to need sanction searches and a bunch of other checks. All of that makes for probably the single biggest identity market in the world, at least as I see it, the biggest contiguous identity market. And that is U.S. employment volunteering organizations. And so if we can standardize data at that level and get adoption through this sort of enterprise-first approach, we will have access to, in essence, the vast majority of the U.S. identity market. And from there, consumer applications open up because you’ve already got people in the system, you’ve already got a compelling use case, and it’s less important to subsidize the growth of it. That’s one other factor. For us, at least at the moment, we haven’t taken on huge amounts of capital. A lot of our work is pretty bootstrapped. And so going with those approaches that address existing problems first helps us to subsidize that growth of the network in a different way.

Riley Hughes: I wonder, on the data piece, was there something about the fact that data is relatively unstructured that was helpful? Was it something about the fact that the data is already being exchanged in existing systems that was helpful? Would it be easier maybe if the data were even more unstructured so that your value proposition was even more compelling? Tell me about how you think about the state of data in an industry as it relates to the benefit of the use case.

Sebastian Mellen: In some ways, it’s a little orthogonal, but it plays a role in, I’ll say, like how much surface area there is to cover. By that I mean, you know, in, let’s say, healthcare credentialing alone, that’s a market segment of the broader employment market. Even within that market, you’ve got really, really niche companies that provide services for very specific credential types and data types. And so the market, it has a lot more, let’s say, surface area to slice in that sense because there are so many different types of data. You could go into finance, you could go into transportation, and then even within transportation, you’ve got airplanes and you’ve got trucks and you’ve got freighters, and there’s so much surface area to cover that you can find a valuable market vertical and scale from there more easily, I would posit, than in like a consumer market where, let’s say consumer verifiable credential SSI applications, you know, there’s many, but maybe one common one that I hear about is like tickets to events.

Sebastian Mellen: That’s so apparent and there’s so many people who are already aware of that problem and probably working on it in different ways, versus you go into healthcare and you say, We’re going to focus on food safety license certifications in four different states, and we’re going to really get that down, and then we’ll scale verifiable credentials from there. It’s a different sort of angle, and it’s one that allows you to be much more omnipresent within that niche. I’ll put it that way. There’s a very small chance that someone else has discovered that problem and knows about the technology that can solve it, in this case verifiable credentials and SSI.

Riley Hughes: This gets back to the very first kind of comment of the call: how sexy is the industry and it sounds like what you’re saying is you can really bring some of these newer technologies to unsexy verticals or niche parts or segments of the market and create something that is compelling, but also something that hasn’t been discovered yet by the general population. If there were other people out there trying to do the same thing, but in an unrelated domain, what would you advise them on? What have you learned?

Sebastian Mellen: One of the stories that I love is, you know, Stripe. They were in a very deeply unsexy industry: payments. When they started working on Stripe, no one wanted to work on payments. And I think in identity, we’re in a similar spot, although identity has started to heat up a lot as a market over the past few years, and I think it will continue to. So I guess the first message to other ID tech founders would be: I think you’re in the right space. I think you’re in a space similar to payments that doesn’t sound that attractive or appealing to most people, but is actually deeply important and will scale massively. So first of all, well done on that. Secondly, identity is really interesting as a space like that because it touches everything. Payments, which is what Stripe dove into, is interesting. Obviously commerce touches a lot and a lot of people, but it’s not as deeply interwoven with all parts of an industry. And I think you can find places for ID tech in almost any industry and application.

Sebastian Mellen: The way that I would evaluate the industry that you’re looking into, let’s say specifically for ID tech, is first of all, how much access do you have to people within that vertical? Like, can you get the conversations that you need? I think that’s been one key determining factor for us. I’m sure it has been for you as well. Second is, can you find a way to scale from a small number of users? There are some industries that we’ve looked at too, even in employment, where to scale effectively, you have to start at 10,000 people. And sometimes that’s not possible. I prefer to scale with smaller groups, and then you understand the market better, and then you can scale it up from there. So I would look for those places where you can start with one person, one organization, get a contact there, really understand the problem, and then you apply that pattern to all the other groups facing that same issue.

Sebastian Mellen: Maybe this is not directly startup related, but I think in identity, at least in applications of ID tech that we’ve seen, one of the most shocking things is how incapable people are, just in general, of managing their own digital identities. And what I mean by that specifically today is logins. We’ve found that just the basics of getting your user on board, even pre-advanced ID tech, is perhaps one of the most challenging pieces to puzzle out. So I would encourage anyone who’s starting in, let’s say, a consumer application of ID tech to really understand that user experience if they’re interacting with end users before they try and scale that too much. Because I think it’s very easy to get yourself into a spot where you’ve got some absolute mess of an authentication and user management process, even if you have a really cool product that’s hidden behind that. Users aren’t going to get to it. And that’s actually one of my biggest gripes, I’d say, with the Web3 movement, is Web3 has completely bungled the authentication and login process for almost everybody.

Sebastian Mellen: There’s very few normal people who have the time to understand why they need a 24-word mnemonic and why they need to store that in their safe and never tell it to anybody. And so solving those really base UX problems around self-sovereign identity, IDtech in general, I think is massively important. And if you do it right, we’ll also bring you perhaps the biggest returns.

Riley Hughes: That’s a really great example, and I think it does pay off to meet users where they are. There’s definitely promised land that a lot of us see in the distance, but sometimes you’ve got to hold people’s hand and guide them there, start with something today that they understand and move along with them over time. I appreciated your comments on Stripe. I was just listening to somebody talk about how at Stripe, it was an unsexy problem. They couldn’t get people to want to work on payments, so they just said, Payments is a really hard problem, so just come work on this hard problem. And that was how they got people to start working on it at first, was just they got smart engineers to work on a hard technical problem. I think identity is in a similar boat, talking about how, man, look how bad this is right now. Why isn’t it better? Well, it’s because it’s really hard. It’s a hard problem to solve. That’s why it’s not solved already. So come join us and let’s crack this nut. Help us figure out how to solve this problem.

Riley Hughes: And that’s been something that I think resonates, and it’s part of the reason why I think we see a lot of the talent that comes into this space stays in this space for quite some time. There are a few things that I noted over the course of our conversation that I want to have a bit of a rapid-fire section here, where I’ll follow up on a few things we said in the past and get your quick take on it. The first thing is, you’ve been able to partner with players that have industry connections, it sounds like. How did you do that? How did you pull it off? And what would you advise for other people who maybe want to strike a strategic partnership, strategic investment, strategic whatever with… Players that can get them plugged into industry to maybe help accelerate their growth. What advice would you give to them?

Sebastian Mellen: The simplest way I could distill that is find smaller companies that provide services in the space that you’re looking at, like, for example, background screening or whatever it is, and contact the companies in that space that appear to be doing the most forward-looking things, at least from what you can see publicly, and say, Hey, we’ve thought of a way to apply ID tech to this space. We’ve got a product we’d love to try. We’d like to partner with you. maybe get an LOI in place, and we’ll build this product in three months. We’ll MVP it with a few of your initial customers and scale it from there. And I think a lot of SMB kind of businesses are very receptive to that because in large service markets and industries, there’s a ceiling of enterprise, and then there’s a lot of SMB companies that address the same problems. They just may not have that breakthrough moment, and you can offer them that if you do it right.

Riley Hughes: Great advice. If you’ve taken some things that are frequently said in the self-sovereign identity circles and rephrased them for enterprise speak, a lot of the result of that process are probably some specific phrases that tend to resonate with your specific audiences. Probably some phrases that maybe you’ve worked hard to learn over time. Probably some other ones that just resonate well with the types of buyers that you talk to. So instead of asking you directly, like, what are your phrases, maybe what was your approach to get to those phrases? Do you have any tips for people who are struggling to break out of the typical own your data, user control, decentralized, this and that, and get into the more brass tacks for an audience that really cares more about dollars and cents?

Sebastian Mellen: That’s a good question. And, you know, I think there’s one sort of general concept and phrase that I’ll center this answer around, and that’s that I think the biggest argument for self-sovereign identity from a more dollars and cents perspective, at least for me, is that when users own their data, things are generally more efficient. And I think— There’s a lot of sort of analogies that you can build here, but the most simple way to explain this is that if you’re an administrator, and let’s say you’re taking care of 3,000 different individuals’ data, you’re not going to be able to actively keep everything up to date, ensure that it’s all accurate, so on and so forth. When an individual manages that data, it scales very well because it’s one person managing their data. When you’ve got massive projects where you need to manage data for millions of people, the most effective way is to let them manage their data. That’s my belief, and I think that translates well too.

Riley Hughes: It’s like when you have a big meal. It’s just so much better if everybody takes their own dishes to the dishwasher.

Sebastian Mellen: Perfect analogy.

Riley Hughes: Yeah. One more rapid-fire question here, and I’m going to go all the way back to the example we gave of me volunteering with my daughters in youth sports. I go get onboarded into the vid app. You mentioned the user experience of showing it to the next place I go, you know, the hockey league instead of the initial soccer league. One challenge that I see come up a lot is how do you convince the soccer league to front the costs for verifying that user the first time? It obviously makes sense for the hockey league to verify something that’s already been pre-verified, but what about that initial onboarding friction? How do you overcome that with the first party?

Sebastian Mellen: Really, really good question, and it strikes at the heart of a lot of the economics of self-sovereign identity, which I think are not fully worked out yet. In the youth sports example, we’re usually saved from that full question because a lot of this is self-pay already. If I go to the soccer league, they’re going to tell me you need to pay an additional $20 to complete your background check. I say, great, I pay that through the vid app. Then when I go to the hockey league or the basketball organization, I can just share my background check. I don’t have to pay that additional fee. That’s the simple way to put it, basically, and there’s a lot of complexity within it, but that’s the simple answer. Now, in larger organizations, it’s an unsolved problem, but I think the most compelling… Model that we’ve looked at so far is basically a consortium approach. You say, hey, we’ll split the costs with organizations that we take these individuals on with, and usually that works better when you’ve got a very transient population in one geography.

Sebastian Mellen: Let’s say you’ve got nurses and there’s four different health systems in one state. The nurses bounce around between those health systems. Those health systems can jointly share those costs. Same if you’ve got, like, travel nurses, except there it’s a little bit different because there’s an intermediary company. There’s a staffing company. The travel nurse gets the background check through that company, then that background check gets shared from that company to the other organizations. Now, that staffing company can either make money themselves and bill the other organizations full cost if they want, or they just discount that price based on all the organizations they work with, because these organizations accept the single background check. At enterprise scale, the full SSI vision is not completely economically worked out yet, but I think there’s a path forward there.

Riley Hughes: Appreciate that.

Sebastian Mellen: For sure.

Riley Hughes: I like to ask folks here, as we approach the end, tell me what the future of identity looks like to you and why it matters for the world. There’s a lot, I think, that’s open to you. You’re clearly very smart and capable. Why work on this project? How do you think it’ll impact the world?

Sebastian Mellen: I don’t want to give a cliché answer and say, like, it’ll impact everything. It will. But let’s say 20 years from now, I think the biggest impact of self-sovereign identity will not be additive. And what I mean by that is we’re in a position right now where I think governments generally are pushing in a direction, and I don’t want to sound like I’m anti-government or anything, but are pushing in a direction that is— The opposite of SSI. It’s global biometric identity through facial recognition. Everyone tracked in central databases.

Riley Hughes: Surveillance.

Sebastian Mellen: Exactly. Surveillance state, surveillance capitalism, whatever you want to call it. There’s a direction that governments, large organizations, corporations are heading in that I think almost everybody is uncomfortable with, even people within those governments or organizations. If you ask them, Hey, would you prefer to have a self-sovereign identity app where you can share your data with anyone, anywhere, privately using zero-knowledge proofs and still be safe? Or would you rather live in a surveillance state, 1984 world where everyone lives in a central database? You’d be very hard-pressed to find someone who’d say, Oh, I prefer to live in the surveillance state. And I think the beauty of self-sovereign identity is we can get a lot of those advantages in a private way. And that’s actually one pitch deck item that we use a lot to organizations and to people who ask privacy questions, is we believe we can have safety and privacy together. The beauty of identity technology like this is that they’re not exclusive. I think it’s often presented as a dichotomy.

Sebastian Mellen: You can have safety, you can have privacy. No, you can have safety and privacy. And so I think that’s really the biggest reason that this technology is important to build and to fight for.

Riley Hughes: Wow, that’s a pretty compelling vision. I appreciate that. It makes me excited about the future of identity, no doubt about it. Sebastian, it’s been great chatting with you, catching up, hearing more about Cerebrum and the product that you’ve built. Do you have anything to plug? If people want to get in touch with you, if people want to collaborate or meet you, where can they find you?

Sebastian Mellen: I’m on Twitter and most social media is @SebMellen. That’s just my name, S-E-B M-E-L-L-E-N. Would love to connect with you there if you want to shoot me a question directly or something. And then our company is Cerebrum, C-E-R-E-B-R-U-M dot com. And, you know, if you’d like to get in touch with us, we have a contact page there. And if you’re an enterprise looking to work with us, we’d love to work with you. If you’re someone who just wants to learn more about what we’re building or try out the vid app, we’d be glad to set that up.

Riley Hughes: Wonderful. Well, thanks, everyone, for listening. You can find us on YouTube, Apple, Spotify, and wherever else you listen to podcasts. Feel free to reach out on Twitter at Trinsic underscore ID or to me directly at Riley P Hughes, and visit Trinsic if you’re interested in building the IDtech products of the future. Subscribe to get new episodes as they drop. Thanks, everybody, for listening.

Zack Jones

Director of Product Partnerships @ Trinsic

Zack Jones leads the product partnerships at Trinsic that together form the connections that make up the world’s largest identity acceptance network. Zack is a published author, expert on digital IDs, and passionate about entrepreneurship.

Newsletter

Subscribe to weekly insights and updates in the digital ID ecosystem.

sphere background icon