Security

Security At Digital World

How identity, keys, and communications are designed to be protected, and how to report a security issue.

  1. Home
  2. Security

Member-Held Keys

Your Digital Identity is created on your own device, and the cryptographic keys that control it are generated and held locally rather than on a central server. Recovery uses recovery words generated at setup - see Account Recovery for how that works.

Encryption

Member-to-member communication is designed to be end-to-end encrypted, and the personal vault stores documents and records under keys only the member controls. By design, this means Digital World does not have the ability to access private keys, decrypt private communications, or reset or override identity custody - see Privacy Policy for the full detail.

Independent Providers

Digital World is a network of independent providers rather than a single hosted platform. Each provider is responsible for the security of its own app or service; see Digital Providers for the current directory and the Engineering Specification's security section for the underlying architecture.

Reporting A Security Issue

If you believe you've found a security vulnerability affecting Digital World infrastructure or a reference implementation, see Responsible Disclosure for how to report it.