Security and operations

Operate wallet deployments with accountable controls.

Give administrators a controlled workspace for access, wallet status and operational visibility—without placing wallet credentials in the backend.

The operational need

Make access and responsibility visible.

Government and enterprise programs need to know who can administer each organization, how wallet status is handled and which changes have been recorded.

Protect administration

Password authentication, TOTP for application administrator accounts, session expiry and protected form actions support controlled access.

Keep organizations scoped

Organization administrators and API keys are restricted to their assigned organization context.

Control integrations

API keys can be limited to specific operational scopes and are stored by digest rather than in clear text.

Manage wallet status

Wallet instances are linked to attestation status references that can be administered and published.

Review operational change

Audit records capture administrative actions with organization, actor and timestamp context.

Respect wallet custody

Credentials and private keys held in the mobile wallet remain outside backend administration.

Wallet trust lifecycle

From onboarding to status management.

A signed Wallet Instance Attestation binds the wallet key to a status reference. The backend records the wallet instance and publishes status for ecosystem checks.

Onboard

Authorize wallet setup for a member or guest flow.

Attest

Issue a signed, key-bound Wallet Instance Attestation.

Operate

Track the instance and administer its WIA status.

Evidence, not slogans

Security claims stay within the implemented product.

This website does not claim certification, “zero trust”, a particular hosting model, HSM support, an SLA or absolute security. Deployment controls must be assessed for the customer environment.

Request a security review ↗

Review the control model for your program.

Bring your administrative roles, integration boundaries and trust policy to a project discussion.

Talk to our team ↗