Security you can ask about.
How Cylinder keeps verification safe by design — and an honest account of what is in place today versus what is still planned. We don't claim certifications we have not earned.
The cryptography that makes a credential trustworthy is the hardest part to get right. We don't reinvent it — Cylinder runs the business layer on the same open protocols behind Europe's digital identity wallet.
The Cylinder layer
The product your team and customers actually touch — and where your data lives.
- Flow configuration & branded journeys
- Hosted pages, QR flows, embeds & plugins
- Result routing & dashboards
- Append-only audit records
- Team & role-based access
The open-standards foundation
We don't roll our own cryptography. The credential layer speaks the same open protocols behind Europe's digital identity wallet.
- OpenID4VP / OpenID4VCI — proof presentation & issuance
- W3C Verifiable Credentials data model
- ISO/IEC 18013-5 — mobile driving licence (mDL)
- SD-JWT — selective disclosure of a single claim
- eIDAS 2.0 / EUDI Wallet interoperability
- Live validity & revocation checks
Certifications, honestly scoped
The credential layer runs on IBM-operated, standards-based infrastructure, which carries its own certifications — assurance for that layer, which we rely on as a subprocessor. Cylinder's own independent assurance (external penetration testing, ISO / SOC 2 readiness) is on our roadmap, and we only present it as fact once it is earned.
A verification stores the outcome you asked for and the audit trail around it — a derived claim like “over 18 = true”, not a date of birth or a document. So if a record is ever exposed, there is very little in it to misuse.
Traditional checks ask people to upload a photo of their ID, which then sits on a server as a permanent target. Cylinder verifies a cryptographic proof instead — so there is no scanned document to leak in the first place.
Every check is run against the issuer's live status — is the credential current, has it been revoked — at the moment it happens. You're trusting the credential's state today, not a snapshot captured on onboarding day.
Cylinder is multi-tenant by design. Every record is owned by a single organisation, and access is checked on every read and write — so one customer's verification activity is never visible from another customer's account.
Verifications, exports, and access changes are written to a time-stamped, append-only audit log — every entry attributable to who did it and when. It's organisation-scoped, role-aware, searchable, and exportable, so you can produce a complete record when compliance asks.
We would rather answer your questions directly than hide behind a badge we have not earned yet.