Ask for less
Design the request around the claims required for the transaction instead of collecting a complete source record.
Trust & privacy
A trustworthy journey limits what is requested, makes the purpose visible, gives the holder meaningful choice and governs what the relying organisation retains.
Privacy principles
Design the request around the claims required for the transaction instead of collecting a complete source record.
Show who is asking, what evidence is required, why it is needed and what happens next.
Selected formats and platforms may support presenting specific claims or derived facts rather than an entire credential.
A verified outcome does not automatically justify retaining every claim that was presented.
Credential data
The reference architecture places credential content in the holder’s wallet or the issuing organisation’s controlled environment rather than treating DiligenceID as a universal central identity database.
Operational metadata—such as issuance, status and presentation events—may still be required for security, support, assurance and legal obligations. The exact data boundary and retention period must be defined for each deployment.
DiligenceID does not make an absolute “no personal information” claim. Processing depends on the configured issuer, verifier, wallet and business journey.
A trust decision
The holder can present supported evidence for a defined purpose, while the relying organisation remains responsible for its decision and retention policy.
The verifier describes the evidence needed and the purpose.
The holder reviews the request and chooses whether to present.
Issuer trust, integrity, relevant claims and current status are checked.
The relying service applies its own policy and retains only what is justified.
Holder control and selective disclosure depend on the credential format, wallet and configured journey. An operational audit need not mean centrally collecting the complete credential content.
Security approach
Supported credentials use digital signatures and verifiable proof mechanisms so relying parties can validate integrity and issuer trust.
Platform administration is designed around strong authentication, role-based access and controlled operational responsibilities.
Revocation, expiry and operational events support current verification decisions, investigation and assurance.
Ongoing monitoring of issuance, verification and revocation activity over time—rather than a single point-in-time check—is a Vigilance concern.
New Zealand context
MAITS Limited operates in New Zealand and the reference policy identifies the Privacy Act 2020 as a governing privacy obligation. Deployments may also need to account for public-record, information-security and sector-specific requirements.
Privacy responsibilities are shared across MAITS, credential issuers, wallet providers, verifiers and relying organisations according to their role and the configured service. A production use case should document those responsibilities explicitly.
Privacy rights, including access and correction, depend on which organisation holds the relevant information. Questions about DiligenceID privacy practices can be sent to privacy@maits.co.nz.
Report a suspected security issue to security@maits.co.nz. Do not include sensitive credential content in an initial email.
This public Astro site is separate from the DiligenceID platform application. It contains no authentication, wallet, issuer, verifier or administrative runtime code. Following an application link takes you to the separately operated platform environment.
Put trusted evidence to work
Define the minimum evidence, holder experience, verifier policy and retention boundary for the use case.