Frequently Asked Questions
What is UbID?
UbID is a governed digital trust fabric for identity proofing, verifiable credentials, holder-controlled custody and presentation, adaptive access, protected recovery, interoperability, and operational evidence.
Is UbID a centralized identity database?
No. UbID uses institutional services where authority and operations require them, but it does not define identity as one universal profile controlled by one database. Credentials, holder custody, issuer responsibility, verifier policy, public identifiers, and operational evidence have separate roles and lifecycles.
Does UbID replace governments, universities, banks, or other trusted institutions?
No. Those organizations remain authoritative for the claims they issue. UbID changes how evidence is issued, carried, disclosed, verified, governed, and recovered.
Who owns a credential?
The issuer remains accountable for the claims and status it issues. The holder controls custody and presentation of the credential. Applicable law and contract determine other rights and responsibilities; “ownership” alone is often too imprecise.
Is the holder always the subject?
No. A representative, guardian, employee, organizational wallet, or authorized agent may hold or present a credential about another subject under policy.
Does a valid signature mean a verifier must accept the credential?
No. The verifier must also evaluate issuer trust, key status, credential status, freshness, audience, holder binding, disclosure, assurance, purpose, and institutional policy.
What is selective disclosure?
Selective disclosure allows the holder to present only the claims required for a transaction rather than the complete credential or source document.
Can selective disclosure prevent all correlation?
No. It reduces unnecessary disclosure, but identifiers, rare attributes, timing, network data, repeated patterns, or verifier collusion can still create correlation risk. Scoped identifiers, request design, retention limits, and transport protections remain necessary.
Are personal data or private keys stored on a public blockchain?
UbID's public privacy position is that private keys, credential payloads, personal data, biometric templates, recovery shares, and presentation histories remain off public blockchains. A deployment may use a narrowly scoped public cryptographic identifier or integrity reference where justified.
Does blockchain prove that identity information is true?
No. A ledger can provide integrity or timestamp evidence for a value or commitment. Claim truth comes from issuer authority, proofing, signatures, status, holder binding, and verifier policy.
What happens if a device is lost?
A governed recovery process can restore legitimate access through independent authorization and protected recovery mechanisms. Recovery is intentionally more constrained than ordinary login and should rotate affected keys, devices, sessions, or recovery state where required.
Can an administrator recover every user's identity?
The target recovery model avoids a universal administrator secret. Recovery authority is divided and policy-bound so one custodian or support operator should not unilaterally control the complete identity.
Can an issuer revoke a credential?
An issuer can suspend, revoke, supersede, or replace credentials according to its published lifecycle policy. A verifier must check the relevant status and failure behavior.
Is deleting a wallet the same as revoking a credential?
No. Deleting a local copy removes holder-side data. Revocation changes issuer-managed status. Account closure, biometric deletion, verifier-record deletion, and privacy-right requests are also separate actions.
Does UbID use biometrics?
UbID can integrate biometric evidence for approved proofing, authentication, or recovery use cases. Each deployment must establish necessity, lawful conditions, alternatives, isolation, security, retention, deletion, human review, and accessibility.
Does a biometric match prove identity?
Not by itself. It is one evidence signal. Source-document provenance, liveness, quality, account or device state, issuer policy, and review can also be required.
Does UbID automatically make an organization compliant?
No. UbID can support minimisation, security, evidence, rights workflows, and policy enforcement. Institutions still need legal bases, notices, contracts, role allocation, assessments, retention, incident procedures, rights handling, and any required registration or certification.
Is UbID certified or legally recognized?
No platform-wide certification or legal status should be inferred from this portal. Any current claim must identify the exact product, deployment, scheme, assessor, scope, jurisdiction, and validity period.
What is a jurisdiction profile?
It is a versioned policy overlay for country, state, sector, role, purpose, biometrics, rights, retention, transfers, incidents, and regulated status. It is an implementation baseline, not a legal opinion.
Can UbID work with external wallets, issuers, and verifiers?
UbID is designed around open standards and versioned profiles. Actual interoperability depends on the exact format, protocol version, optional features, trust policy, metadata, and test results supported by both parties.
Does supporting a standard mean every feature is available?
No. Specification maturity, architectural alignment, implementation, product availability, partner access, and independently tested conformance are different statements.
What is the difference between authentication and credentials?
Authentication establishes a session or proves control of an authenticator. A credential conveys signed claims from an issuer. Authentication does not automatically prove every claim, and a credential does not automatically create a session.
Can an AI agent issue credentials or recover identities autonomously?
High-impact actions should not be granted as unrestricted AI operations. Agents can discover, prepare, validate, and recommend, while execution remains controlled by explicit authorization, deterministic services, policy, and evidence.
What information is public?
Public documentation covers concepts, products, responsibilities, standards position, lifecycle, governance, and integration patterns. Customer schemas, production metadata, credentials, trust lists, key configuration, recovery procedures, security thresholds, incident records, and internal topology remain controlled.
What do Available, Preview, and Planned mean?
They are capability states. They are separate from editorial states such as Outline, Foundation, and Approved. See Content and Capability Status.
Why is the portal still non-indexed?
The portal remains non-indexed while content, translations, specialist review, and publication approval are incomplete. A successful build does not itself authorize public indexing.
Where can I find primary sources?
See References and Source Standards. Regulatory summaries always require current official-source and deployment-specific review.