ISSUE · REGULATED FINANCE
You already did the expensive part. It is called KYC.
Every regulated bank runs full know-your-customer checks because the law leaves it no choice, and then lets the result sit in a compliance archive doing nothing. The pattern that works — proven at national scale by bank-led schemes — is to hand the customer a signed proof of what the bank already verified. Issuance happens inside onboarding the bank already runs. Zero new proofing infrastructure.
The re-verification loop, before and after
What happens today
Your customer opens an account and passes KYC. Then a landlord, a lender, a broker and a payment platform each verify the same person again, from scratch, each holding a fresh copy of the same passport photo — and each new copy is a breach you cannot contain, of a check you already ran better than any of them.
What happens with a bank-issued proof
The bank signs what it verified — "this person is our customer", "this account is in good standing" — once. The customer carries it. Whoever asks can check the signature without calling the bank and without the bank learning who asked. The bank's check stops being a cost centre and becomes the thing only a bank can sell.
One answer travels. The account stays home.
A proof of standing is not a statement. The verifier receives the one fact they asked for, signed; the account number, the balance and the history were never put into the message at all.
Illustration · a credential, drawn
- customer_in_good_standing shared
- account_number never sent
- balance never sent
- transaction_history never sent
- date_of_birth never sent
What the verifier received:
Why the liability model favours the bank
Banks already stand behind the identities they verify — AML and KYC liability sits with them today, credential or no credential. The bank-led schemes that reached national scale made that explicit: the bank carries the liability anyway, so the bank issues the proof. Recovery follows the same logic — a customer who loses a device re-verifies at their bank, the channel that already knows how to check them. Re-issuance, not key escrow.
What a bank would actually be adopting today.
No bank issues on this platform today, and this page does not pretend one does. Issuance for a tenant is operator-run — an organization cannot yet self-serve its own credential types. Sector schema packs are planned work. The rows below are the measured state of the pieces a bank programme would stand on.
- PLANNED A wallet a person installs from an app store. wallet-native You cannot hold a credential on a phone you own. Everything a person would do with a proof waits behind this.
The register holds 17 live · 2 partial · 2 planned · 5 not yet.
4 of the 5 capabilities this page depends on have no row in the register yet, so this page will not print a state for them. They are named rather than dropped, because a slice that silently shortens itself is the same defect as a claim with no receipt.
- vc-issuance
- selective-disclosure
- partner-certification
- self-service-onboarding
The register route serves, but it carries no row for these yet. List what it does carry:
curl -s https://id.orbis.id/api/site/register | jq -r '.entries[].slug'