How data is protected
Encryption at rest
Issuers sign credentials with their own keys and encrypt them to the holder before upload. DStorage holds ciphertext; AIR and storage providers cannot read the payload.
User consent
The user approves each disclosure during verification. Without that approval, the verifier receives nothing.
Data minimization
A Verification Program requests only the claims it needs. A ZK proof can establish a condition, such as an age threshold, without disclosing the underlying value.
Separation of roles
Issuers hold source records, holders hold their credentials, and verifiers receive only the approved result. No single party sees everything.
What each party receives
Encryption and ZK proofs reduce exposure but do not remove personal-data obligations. See the Compliance FAQ.
Next steps
Data privacy
Where data lives and who can access it
Verifying credentials
Result shape, selective disclosure, and proofs
Selective disclosure
Attribute-level presentation controls