01 / Capture
Raw images die at the sensor.
Near-infrared and 3D frames are transformed locally and overwritten before the next capture.
Trust & security
HamsaID never retains a database of raw palm captures. Biometric-derived templates leave the sensor only after transformation and are encrypted at rest.
The security model
01 / Capture
Near-infrared and 3D frames are transformed locally and overwritten before the next capture.
02 / Authority
The phone holds the root of authority. HamsaID does not keep a master seed that can impersonate everyone.
03 / Matching
The current deployment uses an attested enclave with per-context partitions. See how the layers separate.
04 / Disclosure
Each response is scoped to one relying party, one purpose and one moment. No universal identifier follows the person around.
Trust boundaries
Capture, user authority, biometric resolution and the relying-party answer are kept separate. The diagram distinguishes the current deployment’s controls from the distributed-custody target.
Plain language
Regulatory alignment
HamsaID’s architecture is designed to support privacy and identity programmes operating under Europe’s demanding regulatory environment.
Data protection
Data minimisation, explicit purpose, revocable consent and no raw biometric repository.
Digital identity
User-controlled authority and selective, context-bound assertions rather than broad disclosure.
Biometric systems
Bounded use, auditable flows and an architecture built to avoid indiscriminate identification.
Regulatory alignment depends on the full deployment, operating context and customer configuration. This page describes architectural design goals, not legal advice or a blanket certification.
A shorter audit begins with fewer things that can go wrong.
The whole model fits on two pages: what each layer holds, what it never receives, and what happens if one party is breached. Take it to your security team before you take a meeting with ours.
Bring us your security teamDownload the architecture brief