💡 What Inspired Us

Somewhere in a pile of 500 applications is a student who actually did the work. She never missed a lecture, led her team's capstone project, and spent a summer interning where her manager called her the best hire of the year.

But on paper, she looks exactly like the other 499. Same AI polish. Same phrasing. Same promises.

The recruiter has six seconds. They can't tell who's real, so they guess. And she gets lost in the noise.

Here's what struck us: the people who could vouch for her already exist. Her professor knows she was in that class and how she performed. Her teammates know who really built the project. Her manager knows what she delivered. That knowledge is the most valuable hiring signal in the world, and today it's trapped in reference calls nobody returns and recommendation letters nobody can verify.

Meanwhile, employers are drowning in the opposite: polished claims with nothing behind them.

So we asked: what if the people who know your work could vouch for it directly, and employers could trust it instantly?

That question became Sweesh.


🛠️ How We Built It

Sweesh is a two-sided trust network that connects the people who know the truth about a candidate with the employers who need it.

🤝 Everyone who knows your work can vouch for it

Who What they verify
👩‍🏫 Professors "This student was in my class, and here's how they performed." They confirm enrollment, rate the student, and endorse course projects.
👥 Peers "I was on this project, and this is what they really did." Teammates confirm roles and contributions.
💼 Managers "They worked under me, and here's what they delivered." They confirm experience, responsibilities, and impact.
🎓 Universities The official record: degree, courses, and dates.

Each endorsement becomes a digitally signed, tamper-proof statement tied to a verified identity. It isn't a text box anyone can fill in.

🔗 Every voucher is verified too

A recommendation means nothing if anyone can write one. So Sweesh checks who is vouching and whether they have the standing to do it:

Endorsement → Professor → University → Accreditor → A root the employer trusts

A professor can only vouch for students in their own classes. A manager can only vouch for people who actually reported to them. A peer can only confirm projects they were genuinely part of. Authority only narrows as it flows down the chain, so at every hop \(\text{scope}i \subseteq \text{scope}{i-1}\). A claim is valid only when every link holds:

$$ \text{valid}(c) = \bigwedge_{i=1}^{n} \Big( \text{sig}i \wedge \text{inWindow}_i \wedge \neg\,\text{revoked}_i \wedge \text{scope}_i \subseteq \text{scope}{i-1} \Big) $$

If any link is broken, expired, or revoked, that claim doesn't pass.

⚖️ Built so both sides win

For candidates 🎒 For employers 🏢
Your real work finally speaks for itself Find genuine people in seconds, not days
One shareable badge, verified by people who know you No more reference calls or chasing old managers
You choose what to share and what to keep private See exactly which claims are backed, and by whom
Honest candidates stand out from AI-inflated noise Spend time on real talent, not detective work

And for the vouchers (professors, peers and managers), it takes a few clicks, once, instead of endless reference requests and recommendation letters.

📊 Honest, at a glance

Recruiters see the truth about every claim instead of a cold pass/fail:

State What it means
✅ Verified Backed by an institution or an authorized professor or manager
👥 Peer-confirmed Confirmed by independent teammates
✍️ Self-reported The candidate's own word, clearly labelled
🔒 Private Exists, but the candidate chose not to share it

⚙️ Under the hood

Backend

  • Node.js runs the API and all core verification logic.
  • Express 4 powers the HTTP server and REST API.
  • JavaScript (CommonJS modules in strict mode) keeps the codebase simple and fast to iterate on.
  • An in-memory registry stores every entity, accreditation, attestation, revocation, badge, and QR sharing session. It keeps the demo fast and self-contained.

Cryptography and identity

  • Ed25519 key pairs for every issuer, generated with Node.js's built-in node:crypto, with no third-party crypto libraries.
  • Digital signatures on every attestation, and signature verification at every link in the chain.
  • SHA-256 content hashes make every attestation tamper-evident. Change one character and the proof breaks.
  • Secure random IDs and nonces so badges and sessions can't be guessed or replayed.
  • did:key identifiers derived directly from public keys, so identity comes from cryptography, not from an account on our servers.
  • Canonical JSON makes identical data always produce an identical signature, no matter how it was assembled.

Sharing

  • Candidates share their verified profile as a badge link or QR code, and employers verify it instantly, with no account and no phone calls.

🧗 Challenges We Faced

Making vouching trustworthy, not just easy. Anyone can type "great student." The hard part was making sure a professor can only vouch for their own students, a manager only for their own reports, and a peer only for projects they were actually on. Authority has to be earned, not claimed.

The signature that broke for no reason. Two JSON objects with the same data but keys in a different order produce different bytes, and different bytes produce a different signature. A perfectly valid credential would fail verification simply because it was serialized differently. We solved it with canonical JSON, so the same facts always sign the same way.

Stopping friends from inflating friends. If two people endorse each other and nobody else, that's a red flag, not a signal. Peer confirmations carry weight only when they come from genuinely independent people.

Fairness at the edges. Not everyone has a famous school or a manager who responds. Unverified doesn't mean false. We judge every claim on its own and label it honestly, so one missing endorsement never sinks a whole person.

Privacy without losing trust. Candidates choose what to share. Someone can show a professor's endorsement while keeping their grade private, and the recruiter sees it was a choice, not a gap.

The data we refused to fake. Real student records are protected by law, and they should be. Every student in our demo is synthetic and clearly labelled, because a product about trust can't cut corners on its own.


📚 What We Learned

The best hiring signal already exists; it's just locked away. Professors, teammates and managers know who's genuine. Hiring only needed a trustworthy way to hear them.

A recommendation is only as good as the person giving it. Verifying the voucher matters as much as verifying the claim.

Cryptography is the easy part; trust is the hard part. Signing data takes one line of code. Deciding who is allowed to sign what, and proving it, is where the real work lives.

Trust should be captured at the moment of truth. Asking a professor to remember a student five years later fails. Letting them vouch at the end of the semester, in a few clicks, works forever.

When both sides win, adoption follows. Candidates get recognized, employers get certainty, and vouchers get fewer interruptions. No one has to be forced to use it.


🌱 Where We're Going

  • Persistent storage to move the registry from memory to a production database.
  • Privacy-preserving proofs that confirm "top performer in an accredited program" without revealing more than needed.
  • ATS integration that puts Sweesh badges directly inside the applicant tracking systems recruiters already use.
  • Pilots with real universities and employers, starting with one registrar and one hiring team.

We believe the people who know your work should be the ones who speak for it, and now employers can finally listen.

Stop guessing. Start verifying. ✨

Built With

  • api
  • blocksearch
  • commonjs
  • cryptography
  • dataprocessing
  • digitalsignature
  • ed25519keypairgeneration
  • express4
  • javascript
  • node.js
  • restapi
  • sha-256
Share this project:

Updates

Submission history