Last updated 20 July 2026
No honest system claims breaches are impossible. What a trustworthy system can promise is that a breach would be contained quickly, disclosed honestly, and would expose as little as possible in the first place. The wallet's architecture is built around that last point.
Why a breach here is different
There is no central vault of readable documents. Identity material is encrypted on your device before transmission; the network stores encrypted payloads and verification results. An attacker who compromised network storage would obtain ciphertext — unreadable without keys that are held separately and rotated. Services you shared with hold only verification answers, not documents.
The notification commitment
- Affected people are notified within 72 hours of a breach being discovered and confirmed.
- Authorities are notified as required by law — in Australia, under the Notifiable Data Breaches scheme.
- The notice states plainly what happened, what categories of data were involved, how many people are affected, what has been done, and what support is available.
- Where biometric data is involved, remediation includes identity-theft protection support for affected people.
What happens internally
- Immediate containment of the breach.
- Investigation and root-cause analysis.
- Key rotation and destruction where compromise is suspected — destroying keys renders encrypted data permanently unreadable.
- Public post-incident summary, because this is open infrastructure.
What you can do right now
The best time to limit breach damage is before one happens: grant consent narrowly, set expiry dates on service access, and revoke consents you no longer need. Data that was never shared cannot leak downstream.
Suspected security issues can be reported to security@virtengine.com. Acknowledgement target is 48 hours; critical issues are triaged within 24.