Skip to main content
AIR Kit stores encrypted credential payloads and metadata, while raw source documents remain with the issuer. Users control decryption and disclosure. Verification Programs define requested claims, optional ZK proofs, and off-chain or on-chain verification. Successful verification returns a Verifiable Presentation with approved claims and any required proof. When zkMe issues credentials (for example through Veriff powered by zkMe), the cryptographic protections behind that Issuer — zkPassport, zkVault, and related zkMe Protocol components — are summarized for partners in KYC (Veriff powered by zkMe) — zkMe security architecture.

How data is protected

Encryption at rest

Issuers sign credentials with their own keys and encrypt them to the holder before upload. DStorage holds ciphertext; AIR and storage providers cannot read the payload.

User consent

The user approves each disclosure during verification. Without that approval, the verifier receives nothing.

Data minimization

A Verification Program requests only the claims it needs. A ZK proof can establish a condition, such as an age threshold, without disclosing the underlying value.

Separation of roles

Issuers hold source records, holders hold their credentials, and verifiers receive only the approved result. No single party sees everything.

What each party receives

Encryption and ZK proofs reduce exposure but do not remove personal-data obligations. See the Compliance FAQ.

Next steps

Data privacy

Where data lives and who can access it

Verifying credentials

Result shape, selective disclosure, and proofs

Selective disclosure

Attribute-level presentation controls