Last updated 20 July 2026
No honest system claims breaches are impossible. What a trustworthy system can promise is that a breach would be contained quickly, disclosed honestly, and would expose as little as possible in the first place. The wallet's architecture is built around that last point.
Why a breach here is different
There is no network copy of your original document images: they stay on your device. Only minimum derived data that you approve may be sent encrypted for VEID processing. Services receive only the claim or verification result you approve, not the source document image.
The notification commitment
- Affected people are notified within 72 hours of a breach being discovered and confirmed.
- Authorities are notified as required by law — in Australia, under the Notifiable Data Breaches scheme.
- The notice states plainly what happened, what categories of data were involved, how many people are affected, what has been done, and what support is available.
- Where biometric data is involved, remediation includes identity-theft protection support for affected people.
What happens internally
- Immediate containment of the breach.
- Investigation and root-cause analysis.
- Key rotation and destruction where compromise is suspected — destroying keys renders encrypted data permanently unreadable.
- Public post-incident summary, because this is open infrastructure.
What you can do right now
The best time to limit breach damage is before one happens: grant consent narrowly, set expiry dates on service access, and revoke consents you no longer need. Data that was never shared cannot leak downstream.
Suspected security issues can be reported to security@virtengine.com. Acknowledgement target is 48 hours; critical issues are triaged within 24.