How we build Digital IDs with privacy and security at their core

profile picture Rachael Trotman 6 min read
An illustration of a padlock with the Yoti logo sitting at the centre. Alongside this are three smaller icons showing that the app is free (represented by a pound sign that has been crossed out, cannot be hacked (represented by a pickaxe that has been crossed out) or seen by any third parties (represented by an eye that has been crossed out).

We’re committed to making the digital world safer for everyone. Yoti was created as we wanted to give every person a secure way of proving their age or identity. It’s quite literally why we exist. So it only made sense that we’ve built our Digital ID apps with privacy and security at their core.

We’re building technology that makes it easier and safer for you to go about your business, but that doesn’t mean we have to know your business. Just as the right to an identity is a fundamental human right, so is the right to privacy. And we’ll never forget that.

 

We keep your data secure

Compared to showing physical documents every time you need to prove your identity, our Digital ID apps give you a safer, more private way to prove who you are. The apps have been carefully designed to put you in control of your personal data, protecting your privacy at all times.

The technology behind our Digital ID apps means that it is impossible for anyone other than you to control your data.

 

How do we do this?

Well, we’ve taken a radical new approach to protecting personal information. We store each individual piece of your data separately instead of storing it as a single record in one big database.

Each piece of data is encrypted, made unreadable and then stored individually. Think of each piece of data being locked in its own safe, which only you can unlock. You literally hold the key – your own private one called an encryption key that gives you, and you alone, access to your information. The only place that this encrypted key is stored is within your phone. The key to your data is in your hands, and your hands only.

We can’t and never will identify you when you use your Digital ID to share personal information with a business or another person. We can’t see the specific information you’ve shared, and we can’t track you once you’ve downloaded the app. We put you in charge of your data and you always have to consent to share your information – because that’s how it should be.

 

We’re a hacker’s nightmare

If hackers broke in, they still wouldn’t be able to open all the individual safes, because they’d need the encryption keys from every user’s phone. To do this, they’d need to physically have every user’s phone.

Our database is protected by high-level security and the hottest of firewalls. We also follow the highest standards of security. We’re certified to meet SOC 2 Type II and ISO/IEC 27001, the global gold standard for information security management.

 

We’re not in the business of selling data

We can’t sell your information to third parties for marketing or any other purpose. Because of how the technology is built, it’s literally impossible for us to do it. We can’t send you emails or texts as we can’t access your personal information.

Instead, we give you the power to control what information to share, who to share it with and when to share it. You’ll then get a receipt to confirm what you’ve shared and who you’ve shared it with. At no point during this do we get access to your personal data, nor do we want to.

 

We make it safer for you to prove who you are

A Digital ID is actually more private and secure than showing a physical identity document. Every time you show an ID you reveal so much personal information about yourself – your date of birth, full name, passport number, photo and so on. Our apps allow you to share specific information, such as your age or that you’re ‘over 18’. It’s an easier, safer, and more private way to prove your age or identity.

You’re also protected if you lose your phone or if it ends up in the wrong hands. Your Digital ID is protected by multi-factor authentication. It’s linked to your phone, protected by a PIN that only you should know, and linked to your personal biometrics for added security. Hopefully, you’ve also got a lock screen on your phone with a strong code or biometrics.

This means you’re actually more protected against the risks of identity theft compared to if someone were to find your passport or driving licence – as they would have all of your personal details in their hands.

 

Privacy: it’s what we do

Privacy and security are at the heart of everything we do at Yoti. From the way we build our products, our security certifications and audits, our unique approach to data storage and our ethical principles – we are committed to upholding the highest security standards throughout every part of our business.

Our seven principles guide our everyday decisions and ensure that we always strive to do the right thing. They have a strong focus on how we enable privacy and anonymity, how we keep sensitive data secure, and how we’re transparent and held accountable.

To ensure that we’re always held accountable we’re advised by our Guardian Council, an independent ethics board made up of experts in human rights, data privacy and last mile tech. They help us to navigate the complex world of identity. They bring their expertise to the table, help us to stay consistent with our mission, and ensure that your data stays safe.

We hope this gives you some insight into why our Digital ID apps are as privacy-preserving and secure as possible. If you’ve got any more questions that we’ve not answered, you can get in touch with us here.

Keep reading

An image showing three icons, which represent face matching, multi-factor verification and document authenticity checks. These are three of the methods discussed in the article.

Strengthening existing age verification methods to meet modern challenges

In today’s digital landscape, effective age verification is key to helping us build a safer, more trusted online world. Whether it’s ensuring young people have age-appropriate experiences or preventing underage sales of age-restricted items, accurate age checks are crucial for safeguarding online users. We’re seeing a wave of age-related legislation come in around the world. With this, online services face the significant challenge of balancing user privacy with user safety. Alongside newer age-checking solutions, existing age verification methods still have their benefits. We look at how these methods can be strengthened for greater security, efficiency and user privacy.  

7 min read
An image showing a comparison between two age results on a mobile phone screen. On the left hand side is a screen showing an age result that has been verified with Yoti's facial age estimation. The right hand side shows a screen with a showable Digital ID card that has been verified with a UK driving licence. Both screens show an "18+" age result.

Age estimations in our Digital ID app

Digital ID users can have their age estimated in the app, and then anonymously share the age result. This gives them a secure, private and easy way to pass age checks. – With lots of legislation being introduced to improve online safety, including the UK Online Safety Act and the EU Digital Services Act, more businesses are looking at how to verify the age of users. People should have a choice in how they prove their age, so they can choose the method that works best for them. They might use their identity document, complete a facial age estimation

5 min read
An image of a man sitting in a darkened room and using his mobile phone.

France’s new age verification law: what it means for adult platforms and how to comply

Every month, 2.3 million minors in France access adult content online. In response, the French regulator Arcom has introduced strict new rules to ensure that only adults can access platforms with pornographic content. These measures, which come into full force on 11th April, aim to protect children while protecting the privacy of adults. In this blog, we answer some of the common questions about the new law and explore how our solutions can help platforms to comply.   What are the new rules from Arcom? In October 2024, Arcom, (Audiovisual and Digital Communication Regulatory Authority), announced new rules for

6 min read