Manav.id
Trust

You do not have to trust us to check our math.

Most security pages ask you to believe a list of controls. This one says what we hold, what we never hold, and what is not done yet. Manav is designed so that an outage on our side does not stop verification, and a breach on our side cannot forge a receipt.

Last updated 24 September 2026

The short version

Posture at a glance

The controls a security questionnaire asks about, on one screen. The whitepaper and the conformance suite, with every command and its expected output, go to evaluating customers: talk to an engineer.

ControlStatusDetail
Key custodyUsers' keys never reach usSigning happens in the person's authenticator. Our issuer keys are kept out of the web root with owner-only permissions; signing refuses to run if a key is missing or exposed.
SignaturesHybrid, fail-closedEd25519 + ML-DSA-87 (FIPS 204). A verifier checks both halves and rejects if either is missing, so a downgrade is a reject.
What gets signedThe text the person sawThe action is canonicalised with RFC 8785 (JCS), and every machine-readable field must also appear in the human-readable text.
Rotation & revocationScriptedBoth keys rotate together under one key ID; retired keys keep verifying until they expire. The revocation list is re-signed at least every 5 minutes.
TransparencyRFC 9162 Merkle logAppend-only, with a signed tree head; inclusion proofs can be exported to your auditor.
Verification uptimeDoes not depend on usVerifiers cache the public keys and revocation list; a static key set is served even if the issuer is down.
TransportTLS 1.2/1.3, HSTSHTTP redirects to HTTPS; CSP, X-Frame-Options, Referrer-Policy and Permissions-Policy on every response.
MonitoringChecks every 5 minutesFailures page a person and update the status page.

What we can and cannot see

We holdWe never hold
The receipt: what was signed, by which credential, whenYour private key — it stays in the authenticator
The issuer's own signing keys, outside the web rootBiometric templates. There is no biometric vault
Hashed IP for abuse control on the waitlistBehavioural telemetry or cross-site tracking
Account email and the profile fields you authorise at sign-inThe contents of systems you gate with Manav

You cannot leak what you never hold. That is a design property here, not a policy promise.

Compliance status

ItemStatus
SOC 2 Type INot started
SOC 2 Type IINot started
ISO 27001Not started
Independent penetration testNot yet commissioned. When it is, we will publish the attestation letter: firm, scope, dates and severity counts.
Independent cryptographic reviewNot yet commissioned
CSA STAR Level 1 self-assessmentNot started
SubprocessorsPublished
Vulnerability disclosure policyPublished

We would rather say this plainly than imply a certification we do not hold. Until an audit is done, we hand the conformance suite to every security reviewer who asks.

Reporting a vulnerability

Send it to [email protected]. Our policy, response targets and safe-harbour language are on the disclosure page, and the machine-readable version is at /.well-known/security.txt.

Request the evidence pack

Everything a security review needs, in one reply: the conformance suite with expected outputs, the completed questionnaire, the DPA and subprocessor list, and an architecture walkthrough with a named engineer.

By submitting, you agree to the Terms of Service and Privacy Policy. We only use your details to reply to this request.

Send this to your security reviewer

Everything above is either in place, with how it works, or stated as not done yet.