Security & Compliance
Every architectural decision made with a compliance officer's requirements as the constraint.
How we protect your users' data
GDPR
No personal data stored on-chain. Right to erasure: supported.
CurrentSOC 2 Type II
Audit in progress. Report available post-Year 2.
PlannedISO 27001
Information security management system.
PlannedBIPA
Written biometric consent flow. No biometric template stored.
CurrentMiCA
Credential attestation satisfies MiCA KYC requirements.
CurrenteIDAS 2
W3C VC credentials compatible with eIDAS 2 wallet standard.
CurrentFATF Travel Rule
Credential attestation model satisfies VASP Travel Rule.
CurrentPCI-DSS
Not applicable — no card data processed.
N/APrivacy by architecture
Zero Biometric Storage
Liveness images are processed in-memory and discarded. No facial template is ever written to disk.
Data Minimization
Only cryptographic proofs are stored on-chain — never names, passport numbers, or photos.
User-Controlled Credentials
Credentials live in the user's DID wallet. You cannot access them without the user's consent.
GDPR Right to Erasure
Deleting an account removes all off-chain data. The on-chain hash cannot be reversed to PII.
Consent-First
A signed consent transaction is required before any verification begins.
Open Source
All credential issuance logic is open-source and independently auditable.
Regulatory compliance, mapped
Audit Roadmap
Solidus is pre-mainnet. Independent audits are scoped, scheduled, and will be published in full when complete. We do not list audits that have not happened.
BBS+ Selective Disclosure Audit
Cryptographic review of BBS+ over BLS12-381 issuer + verifier flows (live on testnet since May 2026)
Planned Q3 2026 · NLnet / NGI Zero work-packageProtocol Security Audit
Validator consensus, on-chain credential issuance, slashing logic
Engagement in progress with Trail of Bits / Sigma Prime · ~10-12 week long pole to mainnetFor audit-related inquiries: [email protected]
Responsible Disclosure
We take security seriously. If you discover a vulnerability in Solidus Verify, report it responsibly. We commit to acknowledging reports within 24 hours and resolving critical issues within 7 days. We will not pursue legal action against good-faith security researchers.
Security reports: [email protected] · PGP key available on request · Response within 24 hours