Product · Issuance with Credence

Turn verified identity into credentials your citizens carry and any verifier can trust.

IwC covers the entire digital ID journey - apply, prove, review, sign - and delivers a cryptographically signed digital ID straight to the user's mobile wallet, with full lifecycle control in your hands.

Built on ISO/IEC 18013-5 · W3C VC 2.0 · OpenID4VCI · ICAO 9303 · FIPS 140-3

The problem with issuing digital ID yourself

Setting up a credential program from scratch means building cryptographic signing infrastructure, an identity-proofing pipeline, a reviewer workflow, lifecycle management, and standards conformance - before you issue a single credential. Get any layer wrong and the whole chain of trust breaks.

IwC gives you all of it as one platform. You bring the authority to make statements about people. We handle the machinery that turns those statements into credentials the rest of the world will accept.

How it works: enrollment to wallet

Every credential moves through four stages, and the applicant is kept in the loop at each one.

The four-stage issuance flow: automated checks (six checks, seconds), human and automated review (approve, reject or ask), credential creation (built and signed in an HSM), and delivery to the wallet (OpenID4VCI, under 60 seconds).
Four stages, from submitted documents to a credential in the wallet
  1. Automated checks

    The applicant's submission - documents plus a selfie - runs through six machine checks in sequence. Text extraction, face match, liveness, document authentication, a system-of-record lookup, and a fraud screen. Each returns pass, fail, or needs-review. The whole battery finishes in seconds, not minutes.

  2. Human / Automated review

    Results land in the IwC Review Dashboard, where a reviewer sees the automated scores next to the submitted documents and biometrics. They approve, reject, or ask the applicant for more information. Machines do the heavy lifting; a person makes the call.

  3. Credential creation

    On approval, the Issuance Service builds the credential from the template you configured - exactly which fields go in, how they're structured - and signs it inside a hardware security module. Any later tampering becomes detectable the moment a verifier checks the signature.

  4. Delivery to the wallet

    The holder gets an OpenID4VCI credential offer by email, SMS, or push. They tap it, the wallet proves possession of the device key, and the signed credential lands in hardware-backed storage. Under 60 seconds, start to finish.

The six checks behind every credential

This is the part most platforms gloss over. Identity proofing is only as good as the checks underneath it, so here's exactly what runs on every submission.

Six cards describing the automated identity checks: OCR, biometric match, liveness, document authentication, system of record, and fraud screen.

One credential, both standards

Here's a decision most platforms force on you: mDoc or W3C Verifiable Credential? Pick one, and you cut off half the wallets and verifiers in the world.

IwC doesn't make you choose. You define identity attributes once in the Credential Template Designer, and the Issuance Service builds both a CBOR-encoded ISO 18013-5 mDoc and a JSON-LD W3C VC 2.0 credential from that single source - in the same issuance operation. Same attribute values, same timestamp, same trust chain. Two representations of one credential, not two credentials to keep in sync.

You maintain one source of truth. You reach every wallet and every verifier. Nobody has to compromise.

A single Credential Template Designer data model branching into two outputs: a CBOR-encoded ISO 18013-5 mDoc read by any ISO 18013-5 reader, and a JSON-LD W3C VC 2.0 credential read by any VC 2.0 verifier.
One data model, two credential formats, one issuance

Signing you can actually trust

Every credential is signed inside a FIPS 140-3 Level 3 validated hardware security module, using ECDSA on the P-256 curve. Private keys are generated in the HSM and never leave it. Not to a config file, not to memory, not to a backup. That’s what makes the signature unforgeable - the material needed to forge it exists only inside tamper-protected hardware.

Per-claim SHA-256 digests mean a verifier can confirm each attribute independently, which is also what lets holders share one field without revealing the rest.

A hardware security module containing a private key that cannot exit, labelled FIPS 140-3 Level 3 validated and ECDSA P-256, producing a signed credential.
Keys are generated inside the module and never leave it

Lifecycle control, long after issuance

A credential isn't done the moment it's issued. Things change - people move, statuses change, devices get lost. IwC gives authorized operators full control over the whole life of a credential.

Four operations acting on an active credential in the holder wallet. Renewal is automatic as expiry nears, sending a fresh offer with no re-enrollment, and returns the credential to active. A lost or stolen device revokes the credential at once, and a new offer binds to the new device key, returning it to active. Suspension pauses a credential under review and reinstates it if the review clears, so it can return to active. Revocation is final and one-way: a revoked credential cannot come back.

For offline scenarios, mDoc credentials carry pre-generated Mobile Security Objects with staggered validity windows, so an offline verifier always has a fresh, valid object to check - even if the holder's phone hasn't seen the network in a while. The wallet quietly refreshes them in the background.

Who issues with IwC

The issuer role is broad on purpose - plenty of organizations have the standing to assert facts about a person.

Five kinds of issuer. Governments issue digital driving licences and national IDs. Banks issue proof-of-account and KYC credentials. Universities issue degrees and student IDs. Hospitals issue health cards and vaccination records. Transport authorities issue travel passes and permits. All five share the same cryptographic responsibility - verify a real-world fact, sign a credential attesting to it - and IwC is multi-tenant, so each issuing organization gets its own templates, keys and trust settings, isolated from the rest.

Every action, on the record

Seven lifecycle events - issuance, activation, renewal, suspension, reinstatement, revocation and device migration - each writing one audit log entry. The entry records who did it, why, when and which credential, and is append-only. From there it goes two ways: viewable in the Admin Portal, and exportable by API into your own compliance or SIEM systems.

What your organization gets out of it

Lower operating cost

Less paperwork, fewer in-person visits, faster reviews. Your team spends less time on each application.

A better experience for people

Credentials live on the phone, ready to share in seconds. No cards to carry, no documents to print, no office to visit.

Faster, safer issuance

Built-in identity checks and standards-based trust cut fraud and shorten the road from application to issued credential.

Issue once. Trust everywhere. Manage for life.

Let's issue digital IDs to your users.
Tell us your requirements & we'll setup a demo for you.