Trust model
AIR Kit separates issuer source data and signing authority from encrypted credential storage and holder-controlled disclosure:Security layers
Zero-knowledge proofs
The Verification Program determines the requested claims, whether ZK proofs are required, and whether verification is off-chain or on-chain. Successful verification returns a Verifiable Presentation with user-approved claims and any required proof. A ZK proof can confirm a condition without disclosing the underlying value.MPC-based key management
User accounts are backed by multi-party computation (MPC). Private keys are never held in one place — shards are distributed so that no single party (including Moca) can reconstruct the key. Keys are only assembled in a secure execution environment at the moment of signing.On-chain anchoring
The issuer’s signature makes the credential tamper-evident. Programs that require on-chain verification can submit proofs to Moca Chain; other programs verify off-chain. DStorage object metadata is distinct from these optional verification records.Encrypted storage
Raw source documents remain with the issuer. Encrypted credential payloads may be stored in DStorage, while users control decryption and disclosure. Credential payloads are encrypted by default. See Privacy & Compliance.Account abstraction
User wallets use smart accounts (ERC-4337 account abstraction) with paymaster-sponsored gas. Users interact with the chain without managing private keys or gas tokens directly.Further reading
Credential security
How credentials are signed, encrypted, and verified with user-controlled disclosure.
Data privacy
Where data lives, what is encrypted, and who can access it.
Security checklist
Integration best practices for partners.
Privacy & Compliance
Encryption, ZK proofs, and user consent.