Security & Compliance

Every architectural decision made with a compliance officer's requirements as the constraint.

How we protect your users' data

User's Device
TLS 1.3
Document images deleted after 30 days. A derived face template is retained with the record.
Solidus API Edge
BLAKE3 hash
Validatorsconsensus
BLS signature
Solidus Blockchaincredential hash anchored
User's DID Walletcredential stored by user

GDPR

No personal data on-chain. Retention windows are fixed and enforced by an automated daily purge. No independent GDPR assessment has been performed: no DPIA, no DPO, no records of processing.

Not assessed

SOC 2 Type II

No auditor engaged or selected, and no audit has been performed. Independent certification sits on a 2027 horizon.

Not held

ISO 27001

No information security management system exists, and no certification body has been engaged. 2027 horizon, not started.

Not held

BIPA

No written-consent capture exists in the verification flow. A facial template is derived and stored with the verification record. No independent assessment of BIPA compliance has been performed.

Not assessed

MiCA

We provide an identity-proofing input. MiCA-specific capability is not built, and whether it satisfies any requirement is the relying party’s assessment, not ours.

Not built

eIDAS 2

We issue SD-JWT VC, an IETF draft that the EU framework also accepts. That is format compatibility, not recognition: we hold no qualified trust service provider status and no Member State recognises what we issue.

Not held

FATF Travel Rule

No Travel Rule or IVMS 101 implementation exists anywhere in the codebase, confirmed by search.

Not built

PCI-DSS

Not applicable — no card data processed.

N/A

Privacy by architecture

Biometric data handling

A face template is derived from your document photo and stored with the verification record. Document and selfie images are deleted after 30 days, session recordings after 365, by a purge that runs in production.

Data Minimization

Only cryptographic proofs are stored on-chain — never names, passport numbers, or photos.

User-Controlled Credentials

Credentials live in the user's DID wallet. You cannot access them without the user's consent.

Erasure and retention

Verify has no end-user accounts, so there is nothing here for a data subject to delete themselves. An operator can erase everything this organization holds about one subject through an audited endpoint, and the receipt states what could not be removed. Erasure is partial where anti-money-laundering evidence is append-only and legally retained. Document images are held 30 days and recordings 365, then deleted by an automated daily job. The on-chain hash cannot be reversed to PII. Subjects who hold a Solidus identity account can remove that account themselves from its settings.

Consent, Honestly

There is no signed consent transaction. A per-organisation consent toggle exists in the dashboard, but no backend code reads it, so obtaining and recording consent is currently your responsibility.

Open Source

All credential issuance logic is open-source and independently auditable.

Regulatory compliance, mapped

Requirement
Solidus Implementation
Article 5(1)(e) — Storage limitation
A face embedding is derived from the document photo and written to the verification record. The verification result is stored as a BLAKE3 hash. Source images are kept 30 days and recordings 365, then deleted by an automated daily purge; the embedding is not covered by that purge.
Article 17 — Right to erasure
Partially implemented. Retention windows expire on a fixed schedule and a daily job deletes the data; the on-chain hash is one-way and cannot be reversed to recover PII. An operator-actioned erasure endpoint now removes what this organization holds about a subject and returns a receipt naming what it could not remove, because anti-money-laundering records are append-only. Verify has no end-user accounts; a subject with a Solidus identity account can remove that account themselves.
Article 25 — Privacy by design
No personal data is stored on the Solidus protocol layer. That is an architectural property, not an assessed compliance position: no independent assessment has been performed.
Article 32 — Security of processing
TLS 1.3 in transit. BLAKE3 hashing for verification results. BLS signatures for validator consensus. No external security audit or penetration test has been performed.
Requirement
Solidus Implementation
Article 68 — KYC for VASP operators
KYC Level 2 produces the identity-proofing input a crypto-asset service provider needs for the identification leg. Whether that satisfies Article 68 is the relying party’s assessment, and the rest of what MiCA requires is not built.
FATF Travel Rule (via MiCA)
Not built. Mapping credential metadata onto the concepts of originator and beneficiary is not IVMS 101, and adjacency to a capability is not the capability.
Requirement
Solidus Implementation
EU Digital Identity Wallet (EUDIW) compatibility
We issue SD-JWT VC, one of the two credential formats the EU framework accepts. Sharing a format is not being part of the framework, and no format claim implies recognition.
Electronic Attestation of Attributes (EAA)
Not held. Electronic Attestation of Attributes has a legal meaning under eIDAS 2 that requires qualified trust service provider status, which we do not hold in any Member State.
Requirement
Solidus Implementation
VASP originator/beneficiary identification
Not built. No Travel Rule implementation and no IVMS 101 message construction, parsing or transmission exists in the codebase.
Counterparty VASP lookup
Not built. Counterparty discovery is an unsolved industry problem and we have not implemented any part of it.
Requirement
Solidus Implementation
Written informed consent (740 ILCS 14/15(b))
Not built. There is no consent transaction, on-chain or otherwise. The dashboard exposes a "require consent" toggle that no backend code reads, so the written-consent duty rests entirely with you.
Biometric data retention prohibition
A facial template IS written to storage: the face embedding is persisted on the verification record. It is not covered by the image retention purge. No independent assessment of BIPA compliance has been performed.
Destruction schedule
A biometric template is retained and no destruction schedule currently applies to it — the purge deletes images and recordings, not the derived embedding. Whether that meets §15(e) is a legal assessment nobody has performed for us.

Audit Roadmap

Solidus is pre-mainnet and no third-party audit has been commissioned yet. This is the scope and sequence we intend to complete before mainnet — published so the gap is visible rather than implied. We do not list audits that have not happened.

BBS+ Selective Disclosure Audit

Cryptographic review of BBS+ over BLS12-381 issuer + verifier flows (live on testnet since May 2026)

Not commissioned

Protocol Security Audit

Validator consensus, on-chain credential issuance, slashing logic

Not commissioned

For audit-related inquiries: [email protected]

Responsible Disclosure

We take security seriously. If you discover a vulnerability in Solidus Verify, report it responsibly. We commit to acknowledging reports within 24 hours and resolving critical issues within 7 days. We will not pursue legal action against good-faith security researchers.

24-hour acknowledgment guaranteed
7-day resolution target for critical issues
No legal action against responsible researchers
SeverityReward
Critical(RCE, auth bypass)
Up to $10,000
High(data exposure, privilege escalation)
$2,500
Medium(CSRF, stored XSS)
$500
Low(information disclosure)
Acknowledgment
Submit Report

Security reports: [email protected] · PGP key available on request · Response within 24 hours

Powered by the Protocol

Solidus Verify is one product on the Solidus Network.

Explore the consensus, the validator economics, and the other products on the same identity layer.

Security and Compliance — Solidus Verify