Security
DKAM is built to earn institutional confidence. This page states our public security posture in plain language. Deeper architecture, control mappings and assurance evidence are shared with named counterparts during commercial and institutional discussions.
Holder-centric by design
Sensitive credential material is held on the holder side of each Bluck, not broadly centralised by DKAM. DKAM acts mainly as a trust, verification, permissions, scoring and discovery layer. Where verification is possible from a proof, a hash or a status check, we prefer that over holding the raw document.
- Layer 1. Holder / Bluck. Self controlled identity, encrypted holder-controlled credential references, disclosure controls.
- Layer 2. DKAM coordination. Discovery, trust relationships, scoring, permissions, minimal searchable metadata, consent events.
- Layer 3. Integrity and proof. Hashes, issuance anchors, revocation status, tamper-evident logs.
What we commit to publicly
- Encrypted transport and storage across the platform.
- Real authentication with password protection, email verification and one-time codes.
- Role-scoped access between individuals, organisations, universities and recruiters.
- Consent-controlled, time-bound access to any personal data.
- Tamper-evident audit trails for verification, issuance and access events, visible to the individual.
- Biometric liveness at onboarding.
- Every sensitive administrative review is logged.
Wallet infrastructure
Each Bluck is wallet-bound. Today DKAM provisions a wallet-class identifier per holder as an anchor. The wallet layer is designed to accept institutional custody, including MPC-secured key management, without changes to the user experience or the underlying records. We are future-ready for custody integration and will not describe custody as live until it is.
Certifications
DKAM's controls are designed against recognised industry baselines. Independent certifications are a stated roadmap milestone. We will not claim a certification we do not hold.
Reporting a security concern
Please use the Contact page and choose the appropriate enquiry type. Security reports are routed to a named DKAM contact.
For investor, institutional or strategic partnership discussions, additional infrastructure and assurance detail is shared in the appropriate discussion context.