Mobile-ID / Certificates & scope
RAR/C06 · eID / SSO / ShareInfoISO/IEC 24745:2022
Platform capability

Privacy & evidence

Explicit purpose, controlled lifecycle and traceable evidence.

Privacy & evidence

Target model from the specification. Actual product scope requires approval.

Record enough, not everything

Evidence should contain references, policy versions and results. Do not put raw images, biometric templates or clinical records in default logs.

Design evidence access

Evidence readers may differ from device operators. Audit viewing, export and reconciliation, with integrity checks defined in the approved profile.

Reference implementation - Trusted PalmPay
Privacy & evidence
Privacy & evidenceSelect to enlarge ↗

Evaluation & evidence requirements

AreaRequirement
Context bindingOrganization, purpose, device, session and policy
Exception statesMissing data, ambiguous identity, expiry and fallback
Required evidenceVersioned report, scope, reviewer and limitations
Publication statusNo product test report supplied in the website package; deployment is not inferred.

A controlled biometric data model.

Within the customer environment

Biometric vault

biometricRef

Reference protected under the profile.

bindingRefControlled binding

Business identity store

subjectRef

HIS / SIS / HRM / eGov

Tenant + purpose scoped. No cross-customer sharing by default.
Capture image
No default retention; exceptions need approval
Evidence
Minimal references, no image or palm payload
Lifecycle
Retain, revoke, re-enroll, delete
Explore the data model →

Search Trusted Palm ID

Selected interface