TamgaNetwork

Transparency

Known shortcuts

The first release takes a few deliberate shortcuts. Each one is numbered, written down and closed before the pilot; no other shortcut exists. Closed items stay here with their date.

Open (14)

  • S-1 Open

    The institution's signing key is held in Tamga's environment.

    Why for nowThere is no pilot institution yet.

    How it closesThe key moves to the institution's own key vault (KMS / HSM); the old certificate is revoked.

  • S-2 Open

    Revocation lists are published every 2 minutes.

    Why for nowSo that demonstrations need no waiting.

    How it closesHourly in the pilot; publication stays at fixed times only.

  • S-4 Open

    Credential data comes from a sample register in the Institution Console (fictional people).

    Why for nowNo institution has connected its own records yet.

    How it closesData is read from the institution's own lookup endpoint; the contract is published (API reference).

  • S-5 Narrowed

    The wallet has been tested on iPhone only.

    Why for nowTime.

    How it closesAndroid: native modules and build settings are ready; testing on devices follows.

  • S-6 Open

    The trust list is signed with a single key.

    Why for nowTime.

    How it closesA second, rolling signing key.

  • S-7 Open

    Privacy notice and data-protection texts are not published yet.

    Why for nowOnly fictional data is processed today.

    How it closesPublished before the pilot.

  • S-8 Open

    No independent security audit yet.

    Why for nowEarly stage.

    How it closesBefore the pilot.

  • S-9 Narrowed

    Wallet keys are kept in software, not in the phone's secure chip.

    Why for nowThe development app cannot reach the secure chip.

    How it closesStore app: keys in Secure Enclave / StrongBox — the code is ready.

  • S-10 Open

    Sample diplomas can be issued without a real identity check.

    Why for nowThere are no real people in the demo.

    How it closesEvery credential requires a real remote identity check or an in-person registration desk.

  • S-14 Narrowed

    Device attestation is not yet required; every wallet is treated as “software”.

    Why for nowNo store build yet.

    How it closesApp Attest / Play Integrity becomes mandatory with the store app; the verification code is ready.

  • S-15 Open

    The identity service can run with a simulated identity-check provider.

    Why for nowDemonstrations without real identities.

    How it closesReal provider only.

  • S-16 Open

    At a turnstile the pass is shown without a PIN; the consent given at registration lasts at most 6 months and every use is logged in the wallet.

    Why for nowA two-second turnstile experience.

    How it closesDurations set with pilot data; reviewed again with in-person presentation (ISO 18013-5).

  • S-17 Narrowed

    When signing up to websites, the same document fingerprint goes to every site (daily sign-in uses a passkey).

    Why for nowPer-site pseudonyms are not built yet.

    How it closesA different pseudonym for each site.

  • S-19 Open

    The wallet starts the gate-pass registration itself.

    Why for nowOne phone is enough for demonstrations.

    How it closesThe registration desk or the institution's page starts the request.

Closed (5)

  • S-11 Closed

    The wallet's local storage was unencrypted.

    Closed on2026-09-28

    What was doneEncrypted with AES-256-GCM; the key stays on this device only.

  • S-3 Closed

    Notifications were shown inside a Tamga portal.

    Closed on2026-09-29

    What was doneThe institution sends the offer through its own channel; Tamga never sees contact details.

  • S-18 Closed

    The mdoc session transcript followed a non-standard profile.

    Closed on2026-09-29

    What was doneNow the OpenID4VP standard handover with detached device signature.

  • S-12 Closed

    The wallet checked a verifier's domain in its certificate without full parsing.

    Closed on2026-09-26

    What was doneFull certificate parsing.

  • S-13 Closed

    The wallet read verifier registrations from an unsigned view of the list.

    Closed on2026-09-26

    What was doneOnly from the signed trust list, checked against keys built into the app.

A new shortcut is added here before it is taken. Security findings: security@tamga.network.