Security & Compliance
Every architectural decision made with a compliance officer's requirements as the constraint.
How we protect your users' data
GDPR
No personal data on-chain. Retention windows are fixed and enforced by an automated daily purge. No independent GDPR assessment has been performed: no DPIA, no DPO, no records of processing.
Not assessedSOC 2 Type II
No auditor engaged or selected, and no audit has been performed. Independent certification sits on a 2027 horizon.
Not heldISO 27001
No information security management system exists, and no certification body has been engaged. 2027 horizon, not started.
Not heldBIPA
No written-consent capture exists in the verification flow. A facial template is derived and stored with the verification record. No independent assessment of BIPA compliance has been performed.
Not assessedMiCA
We provide an identity-proofing input. MiCA-specific capability is not built, and whether it satisfies any requirement is the relying party’s assessment, not ours.
Not builteIDAS 2
We issue SD-JWT VC, an IETF draft that the EU framework also accepts. That is format compatibility, not recognition: we hold no qualified trust service provider status and no Member State recognises what we issue.
Not heldFATF Travel Rule
No Travel Rule or IVMS 101 implementation exists anywhere in the codebase, confirmed by search.
Not builtPCI-DSS
Not applicable — no card data processed.
N/APrivacy by architecture
Biometric data handling
A face template is derived from your document photo and stored with the verification record. Document and selfie images are deleted after 30 days, session recordings after 365, by a purge that runs in production.
Data Minimization
Only cryptographic proofs are stored on-chain — never names, passport numbers, or photos.
User-Controlled Credentials
Credentials live in the user's DID wallet. You cannot access them without the user's consent.
Erasure and retention
Verify has no end-user accounts, so there is nothing here for a data subject to delete themselves. An operator can erase everything this organization holds about one subject through an audited endpoint, and the receipt states what could not be removed. Erasure is partial where anti-money-laundering evidence is append-only and legally retained. Document images are held 30 days and recordings 365, then deleted by an automated daily job. The on-chain hash cannot be reversed to PII. Subjects who hold a Solidus identity account can remove that account themselves from its settings.
Consent, Honestly
There is no signed consent transaction. A per-organisation consent toggle exists in the dashboard, but no backend code reads it, so obtaining and recording consent is currently your responsibility.
Open Source
All credential issuance logic is open-source and independently auditable.
Regulatory compliance, mapped
Audit Roadmap
Solidus is pre-mainnet and no third-party audit has been commissioned yet. This is the scope and sequence we intend to complete before mainnet — published so the gap is visible rather than implied. We do not list audits that have not happened.
BBS+ Selective Disclosure Audit
Cryptographic review of BBS+ over BLS12-381 issuer + verifier flows (live on testnet since May 2026)
Not commissionedProtocol Security Audit
Validator consensus, on-chain credential issuance, slashing logic
Not commissionedFor audit-related inquiries: [email protected]
Responsible Disclosure
We take security seriously. If you discover a vulnerability in Solidus Verify, report it responsibly. We commit to acknowledging reports within 24 hours and resolving critical issues within 7 days. We will not pursue legal action against good-faith security researchers.
Security reports: [email protected] · PGP key available on request · Response within 24 hours