Skip to main content

Security posture

Institution-safe credential verification starts with boring controls.

Nyvarra treats issuer identity, credential proof, public API protection, lifecycle status, and auditability as launch-critical surfaces. This page describes the controls currently represented in the product and the security work still on the roadmap.

Nyvarra control plane
Review scope

Fail closed

01

Production readiness

Environment checks, readiness checks, and deploy checks are built into the release workflow.

02

Route liveness

A public endpoint confirms that the application can serve a response without leaking operational secrets; it is not dependency or uptime monitoring.

03

Credential durability

Verification URLs, JSON-LD payloads, PDFs, hashes, and issuer context are separated from the dashboard UX.

04

Abuse response

Expensive artifacts fail closed on limiter-store failure; durable reads use a bounded local fallback.

Current controls

The public verification path is designed to fail closed.

When the registry cannot complete a check, Nyvarra returns an unavailable state with retry guidance instead of treating the credential as trusted.

01

Cryptographic credential proof

Credential payloads are signed and checked against stored SHA-256 hashes before a public result is shown.

02

Issuer proof material

Public verification includes issuer DID/key context and issuer profile links where available.

03

Lifecycle enforcement

Revocation, correction, supersession, and expiration are part of the verification result, not dashboard-only metadata.

04

Public API throttling

Public credential, issuer, and Passport APIs are bounded by server-side rate limits and controlled unavailable states.

05

Public data minimization

Public views avoid internal IDs, private emails, private Passport settings, and issuer administrative records.

06

Audit-oriented operations

Issuer actions, billing events, credential verification events, and lifecycle changes are recorded for operational review.

01

Data boundaries

V1 recipient identity is limited to name, email, optional registration number, and issuer-held evidence. CNIC/passport capture is intentionally excluded from V1.

02

API behavior

Public APIs return explicit HTTP statuses for not found, rate limited, and temporarily unavailable results. Verification events are tracked without exposing private holder data.

03

Incident response

Incident response policy is documented in the security operations runbook, and public status posture is available from the status page.

Independent assurance

Ask for the evidence your review requires.

Nyvarra does not claim SOC 2, ISO 27001, penetration-test completion, or a published uptime history on this page. Buyers should evaluate current evidence against their own requirements.

Review boundary

Confirm before procurement

01Required certifications and independent assessments
02Backup, recovery, and key-rotation evidence
03Availability, incident, and support commitments
04Data location, retention, and deletion requirements