Security & Support
Security Model & Trust Architecture
Section titled “Security Model & Trust Architecture”DID.is is engineered from the ground up on the principle of Zero-Trust Cryptographic Verification. Every assertion is backed by deterministic, falsifiable code paths in the hardened resolver-core Rust engine.
Zero-PII Guarantee
Section titled “Zero-PII Guarantee”- No Personal Identifiable Information (PII): DID.is never stores names, emails, national identification numbers, IP addresses, or payment cards in the public resolution ledger.
- Client-Side Hashing: Credential verification can be performed entirely client-side using WebCrypto, with only cryptographic digests transmitted when remote status list lookups are needed.
- Ephemeral Storage Options: Resolution sessions can be conducted with
cache: no-storeto prevent any disk persistence.
Egress & Anti-SSRF Defenses
Section titled “Egress & Anti-SSRF Defenses”- Outbound requests to remote DID origins, MCP servers, and status lists are strictly mediated by
SafeHttpClient. - All IPv4 and IPv6 private, loopback, link-local, and cloud metadata addresses (such as
169.254.169.254) are blocked at the socket level. - Pre-resolved DNS addresses are pinned to prevent Time-of-Check to Time-of-Use (TOCTOU) DNS rebinding attacks.
Vulnerability Disclosure Policy
Section titled “Vulnerability Disclosure Policy”We welcome security researchers and auditors to review our codebase and report any vulnerabilities responsibly.
- Security Contact: [email protected]
- Encryption: PGP Key available on keybase / did.is/.well-known/security.txt
- Response SLA: Initial triage within 24 hours; critical fix deployment within 48 hours.
Support & Community
Section titled “Support & Community”- GitHub Discussions & Issues: https://github.com/did-is
- Documentation Source: https://github.com/did-is/docs
- Main Platform: https://did.is