Back to work
Privacy-first identity for relying parties
Challenge
Banks, delivery and logistics apps need to know who their users are, but holding sensitive identity data centrally is a risk.
What we built
Sensitive identity data lives only in Android and iOS secure storage; the server keeps non-sensitive metadata. Relying parties request authentication and receive verified identity, OAuth-style. Registration by national ID, resident ID or passport is mapped to identity assurance levels.
Outcome
Relying parties get verified identities through a familiar flow, while sensitive data never leaves the user's device.
Stack
- Android
- iOS
- OAuth 2.0
- JWT
- PostgreSQL