How it works
Your phone holds the evidence. The network holds the proof.
The entire design follows one rule: the sensitive material stays with you, and everyone else gets answers. Here is the pipeline, in plain language.
The pipeline
Sensitive material stays with you. Everyone else gets answers.
The same rule runs through capture, encryption, verification and sharing. Read it as two halves: what happens on your phone, and what the network is allowed to know.
Part one — on your device
-
Step 1 of 3: Capture happens on your phone
Document scan (front and back), a selfie with active liveness challenges, and — for the highest level — fingerprint or iris through your phone's secure hardware.
-
Step 2 of 3: Reading and checking happen on your phone
The document's text is read automatically (OCR) and quality checks run locally: edges, glare, face confidence, liveness gating. You review everything.
-
Step 3 of 3: Encryption happens on your phone
Before anything is transmitted, the evidence is sealed with envelope encryption (X25519-XSalsa20-Poly1305). From this moment, your evidence is ciphertext everywhere except your device.
Part two — on the network
-
Step 1 of 3: Verification runs inside trusted processing units
Original document images stay on your device. The wallet performs document OCR and checks locally; only minimum derived data that you approve may be sent encrypted for VEID processing under the relevant scope.
-
Step 2 of 3: Results are recorded, evidence is not
The network records the outcome: your verification level and pass/fail results, plus encrypted references. Your documents and biometrics are never written to the chain in readable form.
-
Step 3 of 3: Your level becomes usable everywhere
Any participating service can now ask the network to confirm your identity — with your consent, per request — without any service ever holding your documents.
Why split it this way?
Conventional identity systems copy your documents into a central database — and central databases get breached. This design means there is nothing central to raid: your evidence exists in readable form only on your device, and the network holds tamper-proof results.
The evidence
One document, read once.
A passport or licence is captured, checked and encrypted on the phone in one sitting. What moves afterwards is a sealed scope and a result — the paper on the desk stays a photograph on your device.
Identity papers, captured and encrypted on the spot — the desk does not keep a copy.
Trusted processing
Inside the trusted processing unit
Your encrypted evidence is opened only inside a hardware-sealed vault whose key is forged in the hardware and never exists outside it — and the chain checks the vault's exact fingerprint before any data enters.
Consent in practice
When a service asks about you
Verification happens once. Sharing happens as often as you approve it — and only what you approve. Walk through the complete exchange.
Visibility
What each party ends up holding
| Party | Holds | Never holds |
|---|---|---|
| You | Everything — your evidence, your keys, your consent history | — |
| The network | Encrypted payloads, verification results, consent records | Readable documents or biometrics |
| A service you approve | Your verification level and the specific answer you approved | Documents, photos, biometric data, unconsented scopes |
| Everyone else | Nothing about you | Everything |
Want to go deeper?
The technology names every component, and verification levels details what evidence earns each level. Engineers can go straight to the protocol docs.
Start the pipeline
Set up once. Prove anything, without the documents.
The setup takes about ten minutes on a phone. Everything after that is answers, receipts and revocation — never another copy of your licence.