Transparency
Known shortcuts
The first release takes a few deliberate shortcuts. Each one is numbered, written down and closed before the pilot; no other shortcut exists. Closed items stay here with their date.
Open (14)
- S-1 Open
The institution's signing key is held in Tamga's environment.
Why for nowThere is no pilot institution yet.
How it closesThe key moves to the institution's own key vault (KMS / HSM); the old certificate is revoked.
- S-2 Open
Revocation lists are published every 2 minutes.
Why for nowSo that demonstrations need no waiting.
How it closesHourly in the pilot; publication stays at fixed times only.
- S-4 Open
Credential data comes from a sample register in the Institution Console (fictional people).
Why for nowNo institution has connected its own records yet.
How it closesData is read from the institution's own lookup endpoint; the contract is published (API reference).
- S-5 Narrowed
The wallet has been tested on iPhone only.
Why for nowTime.
How it closesAndroid: native modules and build settings are ready; testing on devices follows.
- S-6 Open
The trust list is signed with a single key.
Why for nowTime.
How it closesA second, rolling signing key.
- S-7 Open
Privacy notice and data-protection texts are not published yet.
Why for nowOnly fictional data is processed today.
How it closesPublished before the pilot.
- S-8 Open
No independent security audit yet.
Why for nowEarly stage.
How it closesBefore the pilot.
- S-9 Narrowed
Wallet keys are kept in software, not in the phone's secure chip.
Why for nowThe development app cannot reach the secure chip.
How it closesStore app: keys in Secure Enclave / StrongBox — the code is ready.
- S-10 Open
Sample diplomas can be issued without a real identity check.
Why for nowThere are no real people in the demo.
How it closesEvery credential requires a real remote identity check or an in-person registration desk.
- S-14 Narrowed
Device attestation is not yet required; every wallet is treated as “software”.
Why for nowNo store build yet.
How it closesApp Attest / Play Integrity becomes mandatory with the store app; the verification code is ready.
- S-15 Open
The identity service can run with a simulated identity-check provider.
Why for nowDemonstrations without real identities.
How it closesReal provider only.
- S-16 Open
At a turnstile the pass is shown without a PIN; the consent given at registration lasts at most 6 months and every use is logged in the wallet.
Why for nowA two-second turnstile experience.
How it closesDurations set with pilot data; reviewed again with in-person presentation (ISO 18013-5).
- S-17 Narrowed
When signing up to websites, the same document fingerprint goes to every site (daily sign-in uses a passkey).
Why for nowPer-site pseudonyms are not built yet.
How it closesA different pseudonym for each site.
- S-19 Open
The wallet starts the gate-pass registration itself.
Why for nowOne phone is enough for demonstrations.
How it closesThe registration desk or the institution's page starts the request.
Closed (5)
- S-11 Closed
The wallet's local storage was unencrypted.
Closed on2026-09-28
What was doneEncrypted with AES-256-GCM; the key stays on this device only.
- S-3 Closed
Notifications were shown inside a Tamga portal.
Closed on2026-09-29
What was doneThe institution sends the offer through its own channel; Tamga never sees contact details.
- S-18 Closed
The mdoc session transcript followed a non-standard profile.
Closed on2026-09-29
What was doneNow the OpenID4VP standard handover with detached device signature.
- S-12 Closed
The wallet checked a verifier's domain in its certificate without full parsing.
Closed on2026-09-26
What was doneFull certificate parsing.
- S-13 Closed
The wallet read verifier registrations from an unsigned view of the list.
Closed on2026-09-26
What was doneOnly from the signed trust list, checked against keys built into the app.
A new shortcut is added here before it is taken. Security findings: security@tamga.network.