> ## Documentation Index
> Fetch the complete documentation index at: https://docs.air3.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy & Compliance

> How AIR Kit protects sensitive user data through encryption, zero-knowledge proofs, and explicit user consent.

AIR Kit stores encrypted credential payloads and metadata, while raw source documents remain with the issuer. Users control decryption and disclosure. Verification Programs define requested claims, optional ZK proofs, and off-chain or on-chain verification. Successful verification returns a Verifiable Presentation with approved claims and any required proof.

When **zkMe** issues credentials (for example through **Veriff powered by zkMe**), the cryptographic protections behind that Issuer — zkPassport, zkVault, and related zkMe Protocol components — are summarized for partners in [KYC (Veriff powered by zkMe) — zkMe security architecture](/solutions/kyc/zkme-security-architecture).

***

## How data is protected

<CardGroup cols={2}>
  <Card title="Encryption at rest" icon="lock">
    Issuers sign credentials with their own keys and encrypt them to the holder before upload. DStorage holds ciphertext; AIR and storage providers cannot read the payload.
  </Card>

  <Card title="User consent" icon="user-shield">
    The user approves each disclosure during verification. Without that approval, the verifier receives nothing.
  </Card>

  <Card title="Data minimization" icon="filter">
    A Verification Program requests only the claims it needs. A ZK proof can establish a condition, such as an age threshold, without disclosing the underlying value.
  </Card>

  <Card title="Separation of roles" icon="arrows-split-up-and-left">
    Issuers hold source records, holders hold their credentials, and verifiers receive only the approved result. No single party sees everything.
  </Card>
</CardGroup>

***

## What each party receives

| Party | Receives | Does not receive |
| - | - | - |
| **Issuer** | Its own source records and the claims it issues | The holder's decryption key |
| **AIR / DStorage** | Encrypted credential payloads and metadata | Plaintext credential content |
| **Verifier** | The claims its program requests and the user approves, plus any required proof | Undisclosed claims or the issuer's source documents |
| **Holder** | Their credentials and control over disclosure | — |

Encryption and ZK proofs reduce exposure but do not remove personal-data obligations. See the [Compliance FAQ](/solutions/compliance-faq).

***

## Next steps

<CardGroup cols={3}>
  <Card title="Data privacy" icon="lock" href="/technicals/architecture/data-privacy">
    Where data lives and who can access it
  </Card>

  <Card title="Verifying credentials" icon="magnifying-glass" href="/products/identity/verify">
    Result shape, selective disclosure, and proofs
  </Card>

  <Card title="Selective disclosure" icon="eye-slash" href="/products/identity/selective-disclosure">
    Attribute-level presentation controls
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.