Security & Trust
Security by Design.
Not by Policy.
ONEPROOF combines protocol-appropriate security checks with customer-controlled deployment options across ISO mdoc, OpenID4VP, browser presentation, ICAO travel documents, signed QR credentials, and physical identity formats.
Pillar 1: Cryptographic Model
Cryptographic Verification Without a Required ONEPROOF Cloud Service
ONEPROOF software validates supported credential signatures and security properties inside the deployment boundary selected by the customer.
Format-Specific Signatures
Compatible mdoc issuance uses COSE. Other supported formats retain their applicable signature and assurance models.
Issuer Authentication
Verification software checks credential signatures using issuer public-key material supplied through the customer's trust process.
Selective Disclosure
Supported credential formats allow verifiers to request the fields needed for a transaction and let compatible wallets present a limited data set.
Customer-Controlled Data Policy
Customers control retention and data-handling policy inside their own deployment environment.
Each supported credential format is evaluated against its applicable published security and assurance model. Cryptographic credentials and parsed physical barcodes are reported as different assurance classes.
Pillar 2: Deployment Isolation
Your Data Stays Yours
ONEPROOF supports deployment models that eliminate cloud dependencies entirely. Air-gapped deployments can keep credential processing off public networks.
Pillar 3: Standards Compliance
Standards-Based Security Model
Published standards and profiles define the relevant data structures, transports, trust models, and security checks. Implementing against those sources gives customers a documented basis for technical review.
ISO/IEC 18013-5, ISO/IEC TS 18013-7, and ISO/IEC 23220 define supported proximity, online, and credential-profile behavior across applicable products.
Supported wallet redirect and browser-mediated presentation paths follow the applicable OpenID and W3C interfaces and credential profiles.
Applicable ePassport and eMRTD workflows use the security structures defined for machine-readable travel documents.
MiDNI signed QR and AAMVA physical barcodes retain their own verification semantics. Parsed-unsigned data is not represented as cryptographic proof.
Standards Aligned. Partner Ready.
Questions About Our Security Architecture?
Our technical team is available to walk through the cryptographic model, deployment isolation options, and compliance documentation.
Talk to Our Security Team