Pairwise pseudonyms
Each relying party receives a pseudonym derived specifically for that
user-and-service pair. Two services holding records for the same person hold two
unrelated identifiers.
No shared identifier to leak
There is no wallet ID, account number or national identifier travelling between
services, so there is nothing for a data broker to join on — even after a breach at
a relying party.
One-way biometric matching
Duplicate enrolment is prevented by comparing non-invertible feature hashes. The
original face image is never stored and cannot be reconstructed from what we hold.
Additive revocation
Revoking an assertion appends a revocation record rather than editing history. The
audit trail stays complete and internally consistent.
No dependence on a national scheme
IDoro does not require a state identity wallet to function, so availability is not
tied to any one government's rollout, policy change or outage.
Breach containment by design
There is no central store of documents or biometrics to exfiltrate. The worst case
is bounded to isolated assertion revocations, not a population-scale identity leak.