identity.org.au

How it works

Your phone holds the evidence. The network holds the proof.

The entire design follows one rule: the sensitive material stays with you, and everyone else gets answers. Here is the pipeline, in plain language.

The pipeline

Sensitive material stays with you. Everyone else gets answers.

The same rule runs through capture, encryption, verification and sharing. Read it as two halves: what happens on your phone, and what the network is allowed to know.

Part one — on your device

  1. Step 1 of 3: Capture happens on your phone

    Document scan (front and back), a selfie with active liveness challenges, and — for the highest level — fingerprint or iris through your phone's secure hardware.

  2. Step 2 of 3: Reading and checking happen on your phone

    The document's text is read automatically (OCR) and quality checks run locally: edges, glare, face confidence, liveness gating. You review everything.

  3. Step 3 of 3: Encryption happens on your phone

    Before anything is transmitted, the evidence is sealed with envelope encryption (X25519-XSalsa20-Poly1305). From this moment, your evidence is ciphertext everywhere except your device.

Part two — on the network

  1. Step 1 of 3: Verification runs inside trusted processing units

    Original document images stay on your device. The wallet performs document OCR and checks locally; only minimum derived data that you approve may be sent encrypted for VEID processing under the relevant scope.

  2. Step 2 of 3: Results are recorded, evidence is not

    The network records the outcome: your verification level and pass/fail results, plus encrypted references. Your documents and biometrics are never written to the chain in readable form.

  3. Step 3 of 3: Your level becomes usable everywhere

    Any participating service can now ask the network to confirm your identity — with your consent, per request — without any service ever holding your documents.

Why split it this way?

Conventional identity systems copy your documents into a central database — and central databases get breached. This design means there is nothing central to raid: your evidence exists in readable form only on your device, and the network holds tamper-proof results.

The evidence

One document, read once.

A passport or licence is captured, checked and encrypted on the phone in one sitting. What moves afterwards is a sealed scope and a result — the paper on the desk stays a photograph on your device.

A passport and identity papers on a desk.

Identity papers, captured and encrypted on the spot — the desk does not keep a copy.

Trusted processing

Inside the trusted processing unit

Your encrypted evidence is opened only inside a hardware-sealed vault whose key is forged in the hardware and never exists outside it — and the chain checks the vault's exact fingerprint before any data enters.

1 · On your device Documents + biometrics Sealed before it moves Your keys never leave this phone Held in secure hardware Cannot be exported IN TRANSIT Unreadable to every network, carrier and server it crosses 2 · The trusted processing unit A hardware-sealed vault — AMD SEV-SNP · Intel SGX · AWS Nitro The attestation gate: the chain verifies the vault's exact measurement before any data enters The key is forged inside Derived from the hardware itself, sealed to this vault — it never exists anywhere outside it Verification runs Document checks, face match, liveness — scored in isolation Source scans stay local The vault keeps nothing: your documents and biometrics are destroyed when scoring ends No window · no console · no operator door Hardware isolation keeps operators outside Result only 3 · The chain Score + tier Pass / fail results Never documents, never biometrics Operators Providers The foundation OUTSIDE THE VAULT NO OPERATOR ACCESS PATH Operators, providers and foundation staff remain outside the processing environment. The hardware boundary has no administrative entry point. Original scans stay on your device · only approved derived data may leave encrypted · results, not document images, are recorded
Original document images stay on your device. Only minimum, user-approved derived data may leave encrypted for VEID verification.
Trusted processing, explained in full — how the vault works and when data is destroyed

Consent in practice

When a service asks about you

Verification happens once. Sharing happens as often as you approve it — and only what you approve. Walk through the complete exchange.

Visibility

What each party ends up holding

What you, the network, and services each hold
Party Holds Never holds
You Everything — your evidence, your keys, your consent history —
The network Encrypted payloads, verification results, consent records Readable documents or biometrics
A service you approve Your verification level and the specific answer you approved Documents, photos, biometric data, unconsented scopes
Everyone else Nothing about you Everything

Want to go deeper?

The technology names every component, and verification levels details what evidence earns each level. Engineers can go straight to the protocol docs.

Start the pipeline

Set up once. Prove anything, without the documents.

The setup takes about ten minutes on a phone. Everything after that is answers, receipts and revocation — never another copy of your licence.