Security, plainly.
No badge wallpaper, no "military-grade" anything. This page answers the questions that matter: where your ID goes, what we keep, and what happens when things go wrong.
The life of your ID, minute by minute.
You verify once. Here is everything that happens to your document - including the part where most of it stops existing.
Verify ID + face
Your phone reads the ID's chip or an ID provider, then a short selfie. Everything travels encrypted. The chip reader is open source - audit exactly how it works.
Checks run
Selfie deleted
Selfie and document images gone. What's kept is a face vector: numbers that describe your face, not a picture.
Passwave ID remains
The details your ID proved, plus a face vector, held in our vault. It answers questions on your behalf; a fresh selfie every few months confirms it's still you.
Where things live.
Three places hold three very different sets of minimal data.
Your app
WHERE YOU APPROVE
Our servers
HOLD WHO YOU ARE
The website
HOLDS ANSWERS, NOT IDENTITY
What we use each data point for: full breakdown in our privacy policy.
Built for a bad day.
We don't pretend a breach can't happen to us. We built so the worst haul is a box with no map: the identity vault knows who you are, and no record of where anyone browses exists anywhere.
We hold who you are. Sites hold where you go. Nothing joins the two: a share lives in memory for at most ten minutes and is erased the moment the site collects its answer. What we keep afterwards is a list of the services you chose to share with, for you to see and revoke, never a list of the sites you visit.
Two sites can't compare notes about you.
Every site sees you as a different random token. One person becomes a different identifier everywhere you go.
One person fans out to three sites; each site sees a different, unmatchable token. site-a.com: tok_9f31…c2; site-b.com: tok_4ae8…7d; site-c.com: tok_e07a…13.
Found a problem?
Tell us before you tell the internet, and we'll fix it fast and credit you. Write to security@passwave.com.