Security
Two boundaries, drawn deliberately
Identiq is built around two rules that don't bend for convenience: it never takes custody of a user's signing keys, and it never stores the raw evidence behind a credential. Here's exactly how each one holds up in practice.
Boundary one
Your keys never touch our servers
Identity registration and permission grants are actions only you can authorize. Here's the exact flow, every time:
Identiq drafts the transaction
When you register an identity or grant an app permission, the API builds the transaction — but leaves it unsigned. It never has the ability to sign on your behalf.
Your wallet signs it
The unsigned transaction is sent to your own Stellar wallet (e.g. Freighter). You review and sign it there, on your device, with your key.
The signed result is submitted
Only the already-signed transaction comes back to Identiq, which submits it to the network. At no point does a private key pass through Identiq's servers.
The one exception: Identiq's own operational signer, used only to sign credentials Identiq itself issues as an attester (e.g. confirming your KYC check passed). That's a platform key, scoped to platform actions — it is never used to act as a user, and never could be, since it has no relationship to any user's wallet.
Boundary two
We store a fingerprint, never the file
When a credential is issued, Identiq runs the evidence that was checked through a one-way hash function (SHA-256) and keeps only the result — a fixed-length string that could only have come from that exact evidence, but reveals nothing about what the evidence actually was.
That hash is anchored both in Identiq's database and on-chain, alongside the credential's type, issuer, and expiry. Anyone who independently holds the original evidence can confirm it matches — without Identiq ever having stored, transmitted, or been able to reconstruct the original file.
This is enforced by design, not policy: the code path that issues a credential never accepts or persists a document, image, or file — only a reference and its hash.
Verify it yourself
Nothing here is a claim you have to trust
The identity contract, API, SDK, and CLI are all open source. The non-custodial transaction flow lives in the Stellar integration module; the evidence-hashing logic is a few lines you can read end to end.
View the source on GitHub