Resources · Security

Security you can ask about.

How Cylinder keeps verification safe by design — and an honest account of what is in place today versus what is still planned. We don't claim certifications we have not earned.

Security guide6 sections~2 min read
The foundation

The cryptography that makes a credential trustworthy is the hardest part to get right. We don't reinvent it — Cylinder runs the business layer on the same open protocols behind Europe's digital identity wallet.

The Cylinder layer

The product your team and customers actually touch — and where your data lives.

  • Flow configuration & branded journeys
  • Hosted pages, QR flows, embeds & plugins
  • Result routing & dashboards
  • Append-only audit records
  • Team & role-based access

The open-standards foundation

We don't roll our own cryptography. The credential layer speaks the same open protocols behind Europe's digital identity wallet.

  • OpenID4VP / OpenID4VCI — proof presentation & issuance
  • W3C Verifiable Credentials data model
  • ISO/IEC 18013-5 — mobile driving licence (mDL)
  • SD-JWT — selective disclosure of a single claim
  • eIDAS 2.0 / EUDI Wallet interoperability
  • Live validity & revocation checks

Certifications, honestly scoped

The credential layer runs on IBM-operated, standards-based infrastructure, which carries its own certifications — assurance for that layer, which we rely on as a subprocessor. Cylinder's own independent assurance (external penetration testing, ISO / SOC 2 readiness) is on our roadmap, and we only present it as fact once it is earned.

Data minimisation

A verification stores the outcome you asked for and the audit trail around it — a derived claim like “over 18 = true”, not a date of birth or a document. So if a record is ever exposed, there is very little in it to misuse.

Nothing to steal

Traditional checks ask people to upload a photo of their ID, which then sits on a server as a permanent target. Cylinder verifies a cryptographic proof instead — so there is no scanned document to leak in the first place.

A live check

Every check is run against the issuer's live status — is the credential current, has it been revoked — at the moment it happens. You're trusting the credential's state today, not a snapshot captured on onboarding day.

Kept apart

Cylinder is multi-tenant by design. Every record is owned by a single organisation, and access is checked on every read and write — so one customer's verification activity is never visible from another customer's account.

Provable history

Verifications, exports, and access changes are written to a time-stamped, append-only audit log — every entry attributable to who did it and when. It's organisation-scoped, role-aware, searchable, and exportable, so you can produce a complete record when compliance asks.

Talk to us

We would rather answer your questions directly than hide behind a badge we have not earned yet.