Production readiness
Environment checks, readiness checks, and deploy checks are built into the release workflow.
Security posture
Nyvarra treats issuer identity, credential proof, public API protection, lifecycle status, and auditability as launch-critical surfaces. This page describes the controls currently represented in the product and the security work still on the roadmap.
Fail closed
Environment checks, readiness checks, and deploy checks are built into the release workflow.
A public endpoint confirms that the application can serve a response without leaking operational secrets; it is not dependency or uptime monitoring.
Verification URLs, JSON-LD payloads, PDFs, hashes, and issuer context are separated from the dashboard UX.
Expensive artifacts fail closed on limiter-store failure; durable reads use a bounded local fallback.
Current controls
When the registry cannot complete a check, Nyvarra returns an unavailable state with retry guidance instead of treating the credential as trusted.
Credential payloads are signed and checked against stored SHA-256 hashes before a public result is shown.
Public verification includes issuer DID/key context and issuer profile links where available.
Revocation, correction, supersession, and expiration are part of the verification result, not dashboard-only metadata.
Public credential, issuer, and Passport APIs are bounded by server-side rate limits and controlled unavailable states.
Public views avoid internal IDs, private emails, private Passport settings, and issuer administrative records.
Issuer actions, billing events, credential verification events, and lifecycle changes are recorded for operational review.
V1 recipient identity is limited to name, email, optional registration number, and issuer-held evidence. CNIC/passport capture is intentionally excluded from V1.
Public APIs return explicit HTTP statuses for not found, rate limited, and temporarily unavailable results. Verification events are tracked without exposing private holder data.
Incident response policy is documented in the security operations runbook, and public status posture is available from the status page.
Independent assurance
Nyvarra does not claim SOC 2, ISO 27001, penetration-test completion, or a published uptime history on this page. Buyers should evaluate current evidence against their own requirements.
Review boundary
Confirm before procurement