NordVPN Promotion

Home / Blogs

Project Jake: A New Model for Domain Registration Data Disclosure

The author would like to thank the members of the Jake Community who helped in the creation of this article: Scott Bradner, Steve Crocker, Kenny Huang, Hsu-Ping, Suncica Rosic, Jo-Fan Yu.

Project Jake in 100 Words

Project Jake is a framework developed by The Edgemoor Research Institute to resolve tensions between privacy and security in domain registration data disclosure. Named after Internet pioneer Elizabeth “Jake” Feinler, it establishes a voluntary system balancing registrant privacy with legitimate access needs for law enforcement, researchers, and businesses. The framework uses group-to-group agreements between Requestors and Data Holders (registrars, registries), with a four-level sensitivity scale. Data Holders retain discretion over what information to disclose based on predefined agreements. Currently in Alpha testing with open-source applications available on GitHub, a Beta version is planned for late 2026 or early 2027. The project invites early adopters to help refine the system before wider rollout

Introduction

Last week, Kenny Huang in his CircleID article: “Beyond Protocol and Policy”, explained “ Why Project Jake is Reshaping the Architecture of Internet Trust”. In this piece, I provide a brief overview of Project Jake’s general workings that should tempt requestors and data holders to engage as early adopters.

Rising Tensions Between Privacy and Security

For decades, WHOIS made all domain registration data publicly visible—names, addresses, phone numbers, and emails. Serving the Internet since the 1980s, WHOIS lacked security features and consistent data formatting. The misuse of registration data, everything from spam to harassment and fraud, became a rising source of tension. A push to keep info private started in the early 2000s and was accelerated by the 2018 General Data Protection Regulation (GDPR). Suddenly, publishing personal data without consent violated European privacy law, but blocking access entirely hurt legitimate oversight.

Data holders—registrars, registries, and other entities managing registrant information—sit at the center of this tension. Legitimate actors (law enforcement, IP attorneys, security researchers, consumer protection entities and businesses) need timely access for lawful purposes. Meanwhile, registrants have privacy rights, and data holders must protect their registrants’ information from malicious actors harvesting data for spam, phishing, and identity theft. Sharing freely exposes data holders to liability; doing nothing leaves both sides in limbo.

Opportunity Knocks

What looks like a protracted challenge at first glance offers an opportunity for data holders and requestors.

Despite this ongoing tension between privacy and security, there is a window of opportunity to make Registrant data disclosure a feature, not a challenge. This becomes particularly relevant for existing data holders and the 1,600 new gTLD applicants who attempt to address the fundamental question: “How can they make their domain special enough that people want to buy in on the second level?” In the era of growing privacy concerns and fragmented markets, highlighting how registrars and registries handle customer data privacy has become a competitive differentiator.

Like consumer demand for healthier products drove parts of the food industry to offer organic products, demand is creating a market for secure registration data handling as a requirement for trust. This offers an opportunity for a new Domain Registration data market segment, built on trust and cooperation between registrants, data holders, and requestors. Trust can be verified and justified—not merely an abstract value. Without verifiable trust, even the best engineering becomes worthless.

Registrants will be motivated to register accurate data rather than using fake “Mickey Mouse” information. If criteria for data storage and disclosure are verifiable and transparent, registrants and data holders will see it as an opportunity rather than a threat.

Fit for Purpose

Enabling verifiable, transparent handling of domain registration data requires a new mechanism based on verifiable trust. An ideal mechanism should:

  • Support and enable existing and new policies.
  • Operate through distributed multi-stakeholder implementation
  • Provide requestors with clarity on what data may be disclosed
  • Enable data holders to assess request legitimacy without exposure to liability
  • Balance privacy/security with ease of use, efficiency, and economic sustainability
  • Remain interoperable with existing frameworks
  • Allow gradual implementation with minimal disruption

New mechanisms must be open and flexible enough to accommodate diverse policies without becoming unwieldy.

Project Jake Overview

Project Jake is a flagship project of The Edgemoor Research Institute (ERI), a U.S. 501(c)(3) nonprofit focused on voluntary technical solutions for complex data-related public policy challenges. Named after Elizabeth “Jake” Feinler, who pioneered early Internet directories, the project brings together requestors, data holders, and subject matter experts to design a sustainable framework for domain registration data disclosure.

The Jake Framework

The Jake framework balances interests among Registrants (Rt), Requestors (Rq), Data Holders (DH), and Policy Makers/Regulators. Its architecture rests on two interrelated elements: a) An Administrative Framework that defines stakeholder interactions (see graphic below), and b) Agreements where Data Holders define what data they are willing to release under what circumstances.

Administrative Framework

The Jake Framework standardizes request validation and disclosure practices considering specific circumstances without the Data Holder ever losing control. Jake uses Requestors (RQ), Requestor Groups (RqG), Requestor Group Administrators (RqGA), Data Holders (DH), Data Holder Groups (DHG), and Data Holder Group Administrators (DHGA) to manage request and disclosure rules.

Requestors, law enforcement, researchers, etc.), requesting access to registration data.

Requestor Groups represent groups of Requestors with specific interests or affiliations such as IP lawyers, law enforcement officers and journalists. Requestor groups give their Requester members access to the terms and agreements in which Data Holders define what data they are willing to release under what circumstances. Requestor Group members jointly govern the group.

Requestor Group Administrator administers the Requestor Group, vets members, maintains the authentication server, and holds agreements with Data Holder Groups. Group Administrators act on behalf of and are accountable to their groups.

Data Holders Data Holders, (registrars, registries), define precisely to whom and under what conditions the DH will release specific non-public data and what safeguards the DH requires to protect the data.

Data Holder Groups are groups of Data Holders that share disclosure agreements. Data Holder Group members jointly govern the group.

Data Holder Group Administrators administer the Data Holder Group. Data Holder Group Administrators act on behalf of and are accountable to their groups.

Both Requestors and Data Holders can belong to multiple groups.

The Agreements at the Heart of Project Jake

Jake resolves privacy-security tension through layered agreements:

Data Holder Disclosure Agreements state terms for disclosure as Request Templates, specifying purpose, identity validation standards, permitted uses, maximum sensitivity levels, and additional parameters.

The Sensitivity Framework applies a four-level scale to each data element:

LevelMeaningDisclosure Standard
0PublicAvailable to any requestor
1PrivateDisclosed only to authorized requestors
2More PrivateRequires higher level authorization
3ProtectedRequires highest level of access; may require legal documents

Critically, Project Jake doesn’t impose these definitions. Data Holders assign sensitivity levels per their own rules and jurisdictional requirements. The framework merely provides the communication scale. Two Data Holders in the same Data Holder Group can have different assignments—and that’s by design.

The Data Holder always retains discretion. The Agreement authorizes disclosure but doesn’t compel it, reflecting the system’s voluntary nature.

Data Holder Group Administrator – Requestor Group Administrator Agreements connect the two groups, defining purposes, request types, authentication requirements, and enforcement mechanisms. This master agreement is entered by the Requestor Group and Data Holder Group Administrators on behalf of all members. Everything downstream flows from this document. Requestor Groups give their requesters access to the agreements.

Requestor and Requestor Group, Data Holder - Data Holder Group Agreements govern individual membership within respective groups, binding participants to rules, security obligations, and liability exposure. The Administrator executes in accordance with rules set by members.

The Jake Applications Suite

Project Jake’s Applications Suite protocols support trusted access to domain registration data:

At ICANN 86, Seville, June 2026, the online version was presented for testing. By the upcoming ICANN 87 in Bali, the suite is now downloadable via GitHub with documentation and online support. All materials are open source. Additional segments and the ability for Requestor Group Administrators and Data Holders to run them as a clone in their own environment will be soon added.

A Quick Overview of Project Jake Framework Operations

The system begins with Data Holders creating Disclosure Agreement Templates tailored to their specific domain. These templates can be customized from samples available in the Jake Application Suite or can be created independently, establishing the terms under which Data Holders define what data they are willing to release under what circumstances and that govern data disclosure within the system.

Creating Agreements

The DHGA publishes templates in a public repository specifying the intended Requestor Group type. A Requestor Group Administrator finds Disclosure Agreement Templates that match their interests. If the terms are deemed acceptable, the Requestor Group Agent completes the required sections and submits for consideration. Upon acceptance, both administrators enter agreements into their databases and begin testing. (Data Holders can initially form a single-member Requestor Group connected to their own Disclosure Agreement using the Jadmin section of the Jaddar Suite, allowing them to test the system internally.) Once activated, groups make agreements available to members.

Requestor Group Membership

To access the full capabilities of the Jake framework beyond publicly available Domain Registration Data, Requestors must join a Requestor Group. Existing members can simply log into the Requestor Groups portal with their credentials and access the appropriate Request Template for their domain, with auto-fill options available.

New or unaffiliated Requestors must apply for membership through the Requestor Group registration process. After selecting a Requestor Group whose Requestor Group - Data Holder Group Agreement aligns with their request purpose, they complete a membership application that includes their attributes such as identity, role, authorization level, and other requirements specified in the agreements. Upon acceptance, Requestors receive membership credentials that enable them to make requests for non-public Domain Registration data based on the Disclosure Agreement associated with their group. Some Requestor Group Administrators may offer services for unaffiliated Requestors, processing membership and enabling the Requestor to send validated requests without referencing specific agreements to any Data Holder independent from their affiliation with the Jake framework.

Group-Based Agreement Model

The Jake framework emphasizes efficiency through group-to-group agreements. Rather than negotiating individual agreements between each Requestor and Data Holder, the system enables Requestor Groups and Data Holder Groups to establish Requestor Group - Data Holder Group agreements based on shared values and requirements for specific request types. This collective approach streamlines the process, particularly when multiple institutions have common interests in specific data categories.

Making a Request

When making a request, the active member logs into the Requestor Group portal and submits a request that includes a reference to the applicable Agreement ID, the stated purpose (which must align with declared purposes), authorized requester credentials, and any additional information. Upon receiving the request, the Data Holder verifies the Requestor’s registered attributes, including identity, role, and authorization level.

After validating the Requestor’s identity and confirming the request conforms to the Agreement, the Data Holder discloses the data they’re willing to provide. Importantly, the Data Holder retains discretion to disclose less than the maximum specified in the Agreement based on their own sensitivity assignments and redaction rules. Finally, the Requestor receives data to use and store according to the security commitments outlined in the Disclosure Agreement.

The Project Jake Invitation

Project Jake has developed and is currently testing the Alpha version of the Framework and the Jaddar Suite. Early adopters are invited to test the Framework and Protocols, available either as a hosted service or as downloads. A Beta version will be made available for wider dissemination and adoption in late 2026 or early 2027.

Project Jake would like to invite interested Requestors and Data Holders to participate in the testing and evaluation of the Jake Framework and Protocols during this Alpha phase. Your involvement would contribute valuable real-world feedback to help refine the system and ensure it meets the needs of the diverse stakeholders it is designed to serve.

Participation during the Alpha phase offers the opportunity to:

  • Gain early hands-on experience with the framework and its protocols.
  • Help shape the development of the system ahead of the broader Beta release.
  • Engage directly with the Jake User Community and other participating organizations.
  • Provide input that can influence the direction and refinement of the platform.

More detailed information about the Jake Framework and the Jake Application Suite is available at https://www.edgemoorresearch.org/jakespage/.

If you are a Requestor, Data Holder or potential new gTLD applicant and would like to arrange a detailed walkthrough of the Jake Framework, we would be very happy to schedule a call at your convenience or meet up with you face to face during ICANN 87. Representatives of Project Jake are also available to give Presentations and Workshops on request. For making the arrangements please contact: [email protected] or [email protected]

NORDVPN DISCOUNT - CircleID x NordVPN
Get NordVPN  [74% +3 extra months, from $2.99/month]
By Klaus Stoll, Digital Citizen

Klaus has over 30 years’ practical experience in Internet governance and implementing ICTs for development and capacity building globally. He is a regular organizer and speaker at events, advisor to private, governmental and civil society organizations, lecturer, blogger and author of publications centering empowered digital citizenship, digital dignity and integrity.

Visit Page

Filed Under

Comments

Comment Title:

  Notify me of follow-up comments

We encourage you to post comments and engage in discussions that advance this post through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can report it using the link at the end of each comment. Views expressed in the comments do not represent those of CircleID. For more information on our comment policy, see Codes of Conduct.

CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

Brand Protection

Sponsored byCSC

DNS Security

Sponsored byWhoisXML API

New TLDs

Sponsored byRadix

DNS

Sponsored byDNIB.com

IPv4 Markets

Sponsored byIPv4.Global

Domain Names

Sponsored byVerisign

Cybersecurity

Sponsored byVerisign

NordVPN Promotion