Trust, Security & Compliance

Holder-controlled. Proof-based.

DKAM is built as a trust, verification, permissions, scoring and discovery layer for wallet-bound Blucks. Sensitive credential material stays with the holder. DKAM anchors integrity through hashes, issuer references and status, not through central storage of raw documents. This page sets out how that works in plain English.

Holder-controlled data

Raw identity documents, transcripts and evidence are held on the holder side of the Bluck and disclosed only on the holder's terms.

Proof-based verification

DKAM anchors hashes, issuer references and status. Verifiers check proofs rather than downloading archives of raw documents.

Self controlled identity

Each Bluck is anchored to an identifier you control for life. Future-ready for institutional custody where required.

Tamper-evident audit

Every issuance, verification and access event is logged. Individuals see who has seen what. Sensitive admin review is itself logged.

Minimal central handling

DKAM stores only what is needed to run the ecosystem: wallet linkage, hashes, status, consent events and discovery metadata.

Accessibility

Designed against WCAG 2.2 AA principles. Keyboard navigation, semantic structure and colour contrast are part of the design system.

GDPR, in plain English

The individual is the data subject. Consent is the default.

Personal data on DKAM belongs to the individual. Institutions and organisations contribute verified facts about that individual. Recruiters and partners only see what an individual has consented to share, for as long as that consent stands.

  • Consent is purpose-bound, time-bound and revocable.
  • Rights of access, correction, restriction, portability and deletion are honoured through in-product controls and a privacy request route.
  • Sensitive identity evidence is held under tighter access than general profile data.
  • Data processing agreements are available to institutional and organisational customers on request.
Cross-border by design

Credentials follow the individual across borders without bilateral data-sharing deals.

Source-issued is verifiable

Institution-issued credentials are time-stamped and bound to a verified individual. Provenance is preserved.

Honest about the roadmap

Independent certifications are a stated roadmap milestone, not a current claim. We will publish certifications only when they are actually held.

Named security contact

Security concerns can be reported through the Contact page and are routed to a named DKAM contact.

Controlled Disclosure

Institutional and investor detail is shared in context.

For investor, institutional or strategic partnership discussions, additional commercial, security and infrastructure detail is shared with named counterparts in the appropriate discussion context. Use the routes below to open that conversation.

Named Contacts

Talk to a person.

Trust enquiries are owned by a named DKAM contact. Use the route that fits your remit. While a role is between holders, the DKAM founding team responds directly.

Investor & Strategic

Investor conversations, strategic partnerships, commercial detail.

hello@dkam.io
Institutions

Universities, training bodies and enterprise engagements.

institutions@dkam.io
Trust & Privacy

GDPR, DPAs, data requests and accessibility.

trust@dkam.io
Security

Responsible disclosure and security enquiries.

security@dkam.io

This page is maintained by the DKAM team. It states current platform controls and roadmap intent. It is not an independent certification. Specific commitments are confirmed in writing per institutional pilot.