Public Verification Should Reveal
- Proof status
- Disclosed claim
- Proof type
- Issuer or trust level
- Network
- Asset
- Creation date
- Expiration date
- Revocation state
Public Verification Should Not Reveal
- Full wallet history
- Exact total income unless explicitly disclosed
- Total wallet balance
- Unrelated payments
- Spending activity
- Hidden sender addresses
- Hidden source transactions
- Raw authentication signatures
Backend Storage
The backend may need sensitive data to evaluate proof conditions. Storage should minimize exposure:On-Chain Storage
Contracts must not store personal financial data. Store only:- proof ID hash,
- commitment hash,
- issuer address,
- status,
- expiration,
- schema version,
- timestamp,
- public metadata hash.
Trust Levels
Logging Restrictions
Logs must not contain:- secret keys,
- full credentials,
- exact income values,
- raw signatures,
- complete wallet transaction history,
- webhook secrets,
- API keys.