Skip to main content
Moca Network is an identity infrastructure platform. Security is foundational to every design decision — from how credentials are issued to how keys are managed and how data flows between parties.

Trust model

AIR Kit separates issuer source data and signing authority from encrypted credential storage and holder-controlled disclosure:

Security layers

Zero-knowledge proofs

The Verification Program determines the requested claims, whether ZK proofs are required, and whether verification is off-chain or on-chain. Successful verification returns a Verifiable Presentation with user-approved claims and any required proof. A ZK proof can confirm a condition without disclosing the underlying value.

MPC-based key management

User accounts are backed by multi-party computation (MPC). Private keys are never held in one place — shards are distributed so that no single party (including Moca) can reconstruct the key. Keys are only assembled in a secure execution environment at the moment of signing.

On-chain anchoring

The issuer’s signature makes the credential tamper-evident. Programs that require on-chain verification can submit proofs to Moca Chain; other programs verify off-chain. DStorage object metadata is distinct from these optional verification records.

Encrypted storage

Raw source documents remain with the issuer. Encrypted credential payloads may be stored in DStorage, while users control decryption and disclosure. Credential payloads are encrypted by default. See Privacy & Compliance.

Account abstraction

User wallets use smart accounts (ERC-4337 account abstraction) with paymaster-sponsored gas. Users interact with the chain without managing private keys or gas tokens directly.

Further reading

Credential security

How credentials are signed, encrypted, and verified with user-controlled disclosure.

Data privacy

Where data lives, what is encrypted, and who can access it.

Security checklist

Integration best practices for partners.

Privacy & Compliance

Encryption, ZK proofs, and user consent.