Security, plainly.

No badge wallpaper, no "military-grade" anything. This page answers the questions that matter: where your ID goes, what we keep, and what happens when things go wrong.

The life of your ID, minute by minute.

You verify once. Here is everything that happens to your document - including the part where most of it stops existing.

MIN 0

Verify ID + face

Your phone reads the ID's chip or an ID provider, then a short selfie. Everything travels encrypted. The chip reader is open source - audit exactly how it works.

MIN 1

Checks run

Is the document genuine?
Does the face match the chip?
Has this document verified before?
MIN 2

Selfie deleted

Selfie and document images gone. What's kept is a face vector: numbers that describe your face, not a picture.

FOREVER AFTER

Passwave ID remains

The details your ID proved, plus a face vector, held in our vault. It answers questions on your behalf; a fresh selfie every few months confirms it's still you.

Where things live.

Three places hold three very different sets of minimal data.

Your app

WHERE YOU APPROVE

A signed-in session of your account, approvals only happen inside one
Requests appear here and you approve each one.

Our servers

HOLD WHO YOU ARE

Your account: your email and your Passwave ID
Your vault: your name, birth date and legal gender as printed on your ID, the document's type, issue date, expiry date and country of issue, and a face vector
The email is how you sign in and how we reach you about your account. It never goes out to any site
One-way hashes that stop the same document opening a second account

The website

HOLDS ANSWERS, NOT IDENTITY

The answers it asked for: over 18, age band, country of ID issue, legal gender
A code it can use, for 24 hours after the share, to ask whether a name it holds matches yours: yes, partly or no, never the name itself
A token unique to that site, useless anywhere else

What we use each data point for: full breakdown in our privacy policy.

Built for a bad day.

We don't pretend a breach can't happen to us. We built so the worst haul is a box with no map: the identity vault knows who you are, and no record of where anyone browses exists anywhere.

We hold who you are. Sites hold where you go. Nothing joins the two: a share lives in memory for at most ten minutes and is erased the moment the site collects its answer. What we keep afterwards is a list of the services you chose to share with, for you to see and revoke, never a list of the sites you visit.

THREE SYSTEMS, NO BRIDGE
The identity vaultsecure
Your email, name, birth date, document number, face vector. Knows who you are, and which services you chose to share with. Never where you browse.
The open share10 minutes
Held in memory while a check is in flight and erased the moment the site collects its answer. What survives is a record that the share happened, for you, and a code the site can use to ask one follow-up question.
Your sign-inyours only
Approvals only happen inside a signed-in session of your account. Nothing gets approved as you unless you're the one logged in.

Two sites can't compare notes about you.

Every site sees you as a different random token. One person becomes a different identifier everywhere you go.

One person fans out to three sites; each site sees a different, unmatchable token. site-a.com: tok_9f31…c2; site-b.com: tok_4ae8…7d; site-c.com: tok_e07a…13.

Found a problem?

Tell us before you tell the internet, and we'll fix it fast and credit you. Write to security@passwave.com.