01 research
The question
Digital infrastructure keeps demanding stronger identity — to prevent Sybil attacks, satisfy AML/CTF obligations, and gate high-stakes operations — while every strengthening step has historically meant more personal data pooled in more central databases. The research question is whether the trade-off is real: can verification strength and data minimisation increase together?
The foundation's constitution forces this question rather than merely permitting it: clause 39 mandates privacy-by-design, minimised collection, minimised central custody, encryption and selective disclosure where feasible, and independent auditability.
02 research
Approach
VEID, the VirtEngine identity layer, is the working testbed. The privacy-preserving design keeps source document images and full OCR output on the user's device. Any minimum derived fields or features submitted for verification require separate, purpose-specific approval; other evidence follows its own scope notice.
The intended disclosure model is to share a verification result or selected proof rather than source documents. The x/veid module tree in the open repository includes a zero-knowledge proof package (x/veid/zk); capabilities described in repository designs should not be read as a guarantee that every proof flow is deployed or available.
03 research
Current work and artifacts
The open repository carries the on-chain modules (x/veid, x/veidregistry, x/mfa, x/roles), a mobile capture reference application (mobile/veid-capture-app), and public documentation including a biometric hardware attestation design document, a consent framework, and a biometric data addendum. The identity.org.au property presents the citizen-facing account of the same work.
Open problems under active study include: liveness robustness against generative-AI presentation attacks, the recoverability/unlinkability tension in credential re-issuance, and how relying services should consume tiered verification scores without re-identifying users across contexts.
Artifacts — verify, don't trust
- x/veid + x/veid/zk modules on-chain identity scoring and zero-knowledge proof verification, Apache 2.0
- Biometric hardware attestation design docs/veid/biometric-hardware-attestation.md in the open repository
- VEID capture reference app mobile/veid-capture-app — document, selfie, liveness, attestation flows
- Identity program page the foundation's program account of VEID — pipeline, tiers, consent, service
- identity.org.au public plain-language home of the VEID research