Active application layer Active Tags Delivered browser-workflow runtime
Federation
Developing connection layer
Trust layer M7 Identity Security-focused CIAM
M7 framework Identity Active Tags Federation

M7 Modular web machinery

Own more of the web.

We're building the stack for people who want to be authors of where the web goes next—modular machinery for identity, active applications, and direct connection, designed to be useful one layer at a time.

01 / The machinery

Back to top

Three pillars. One foundation.

M7 brings Identity, Active Tags, and federation together on one shared foundation without requiring the whole stack. Use what you need. Keep what works. Add more only when it earns its place.

Modular by design

Use one. Combine several. Keep control.

Each M7 layer is built to work on its own and connect cleanly with the others. Use one, snap several together, and keep the rest of your stack on your terms.

02 / M7 Identity

Back to top

Security-focused CIAM / OAuth-compatible

Customer identity built for what happens after login.

M7 Identity is a security-focused CIAM platform for custom applications and federated services. It provides an OAuth-compatible integration path and an M7-aware hardened profile for customer identity, renewable sessions, and lifecycle control.

Customer identity lifecycle

  1. 01

    Register and authenticate

    Create customer accounts, establish identity, and begin a renewable session.

  2. 02

    Protect the renewable session

    Maintain session authority through validation, rotation, and controlled renewal—not login alone.

  3. 03

    Close and recover

    Handle logout, revocation, recovery, and offboarding through one versioned lifecycle contract.

Designed for custom applications

CIAM

Manage the customer identity lifecycle

Bring registration, profiles, sign-in, sessions, recovery, and account closure into one product boundary.

Compatibility

Integrate with OAuth-based applications

Use the supported OAuth-compatible path, or adopt the M7-aware profile when stronger session controls matter.

Control

Keep application policy with the application

M7 establishes identity and session authority; each application controls routes, objects, tenants, permissions, and business rules.

Security focus

Login starts the session. Security has to survive everything after it.

M7 focuses on lineage-scoped session authority, cryptographic continuity, controlled renewal, and explicit closure and recovery across application boundaries.

03 / Active Tags

Back to top

Delivered browser-workflow runtime

Complex browser workflows. No framework takeover.

Active Tags compiles DOM-declared behavior into explicit, inspectable browser workflows—without taking over rendering or requiring a frontend rewrite. The server can keep owning HTML while Active Tags governs execution in the browser.

One execution spine

  1. 01 / DOM + configuration

    Declare the workflow

    Attach behavior through DOM attributes, configuration objects, embedded payloads, or imported modules.

  2. 02 / Compiler + registry

    Compile named jobs

    Normalize declarations into jobs, pipelines, triggers, and execution policy before they run.

  3. 03 / Tickets + VM

    Run with explicit state

    Execute operations through tickets with visible waiting, errors, buffers, targets, and completion.

status
ok, wait, error, complete
buffer
moves results between steps
target
directs DOM work

What it gives the application

Incremental adoption

Keep the renderer you already have

Use it with server-rendered PHP, progressive enhancement, SPA-style navigation, or another view layer.

Structured execution

Give browser workflows one spine

Events, requests, DOM observation, history, waits, and errors run through one explicit execution model.

Open extension

Keep product logic in ordinary JavaScript

Built-in and application-specific operations share the same job, ticket, and pipeline contracts.

Delivered capability

Structured workflows instead of scattered browser glue.

Jobs and tickets coordinate events, HTTP, DOM changes, browser history, waiting, errors, buffers, and targets through one explicit execution protocol.

04 / Federation and adoption

Back to top

Build what you want. Keep what you build.

M7 is designed for independent operators, not platform tenants. Use services others provide, offer capabilities of your own, and keep ownership of the products and customer relationships you create.

01 USE

M7 services

Start with what helps.

Adopt one M7 service without moving the rest of your stack.

Product fit
One useful M7 service
Required boundary
Choose the capability you need while keeping the rest of the application stack in place.
Explore M7 services
02 CONNECT

Your existing service

Bring your own service.

Federate a capability you already own and operate.

Product fit
Existing service + federation
Required boundary
The service remains independently operated and implements the supported federation and identity contracts.
Review federation
03 COMBINE

A larger product

Assemble the product.

Connect M7 services, your services, and capabilities operated by others.

Product fit
M7 + independent capabilities
Required boundary
Each service keeps its own operating, identity, authorization, and business-policy boundaries.
Explore the connected platform
04 OFFER

A capability others need

Let others use what you build.

Set access terms while retaining ownership and operation of the capability.

Product fit
Builder capability + federation
Required boundary
Provider discovery, commercial terms, billing, and settlement remain under development.
Review the provider direction

Keep building through what comes next

Choose one useful starting point.

Bring one concrete identity, active-web, or connection problem. We'll separate what can be used now from what is still being built, then decide whether one small M7 layer earns a place in your stack.

We intend to earn your business, keep it, and stand behind what we build. Exact support, maintenance, migration, and continuity commitments still need to be defined.