Skip to content

Security & Support

DID.is is engineered from the ground up on the principle of Zero-Trust Cryptographic Verification. Every assertion is backed by deterministic, falsifiable code paths in the hardened resolver-core Rust engine.

  • No Personal Identifiable Information (PII): DID.is never stores names, emails, national identification numbers, IP addresses, or payment cards in the public resolution ledger.
  • Client-Side Hashing: Credential verification can be performed entirely client-side using WebCrypto, with only cryptographic digests transmitted when remote status list lookups are needed.
  • Ephemeral Storage Options: Resolution sessions can be conducted with cache: no-store to prevent any disk persistence.
  • Outbound requests to remote DID origins, MCP servers, and status lists are strictly mediated by SafeHttpClient.
  • All IPv4 and IPv6 private, loopback, link-local, and cloud metadata addresses (such as 169.254.169.254) are blocked at the socket level.
  • Pre-resolved DNS addresses are pinned to prevent Time-of-Check to Time-of-Use (TOCTOU) DNS rebinding attacks.

We welcome security researchers and auditors to review our codebase and report any vulnerabilities responsibly.