# idOS Documentation > idOS (identity operating system) is a decentralized storage and access management network specifically designed to store user data. \ - [What is idOS?](/index.md) ## search - [Search the documentation](/search.md) ## community-and-marketing - [Community & social](/community-and-marketing/community-and-social.md): Follow idOS across all official social and community channels: ## compliance - [Compliance overview](/compliance/compliance-overview.md): As the identity layer of web3, idOS is designed to enable users to confidently manage and share their identity information in a decentralized environment while assisting key stakeholders to adhere to applicable regulatory frameworks. idOS aims to incorporate multiple regulatory considerations into its architecture, ensuring that profile creation, credential issuance, and data-sharing mechanisms are aligned with global standards. Compliance with key data protection frameworks is embedded in idOS’ design, allowing users to maintain control over their data while ensuring lawful processing. Similarly, key financial regulations are taken into account to support financial institutions in meeting their obligations. - [idOS & Regulatory frameworks](/compliance/compliance-overview/idos-and-regulatory-frameworks.md): This section explores in further detail how idOS implements certain key selected regulatory frameworks presented under the Compliance overview. - [idOS Compliance partners](/compliance/idos-compliance-partners.md): We recognize that compliance in web3 is a collective effort, and we are not working in isolation. We are partnering with different organizations and counting on various legal professionals who share our vision of building a secure, privacy-preserving, and regulation-aligned decentralized identity system. Through strategic collaborations, assessments, and community-driven discussions, we aim to actively shape the regulatory framework for self-sovereign identity reusability in web3. - [idOS Regulatory approach](/compliance/idos-regulatory-approach.md): The development of web3 and decentralized technologies has brought about significant advancements in how we interact with digital assets and identities. While much of the focus has been on the self-custody of funds, the self-custody of data has yet to receive the same level of attention. For web3 to tap into real-world use cases, addressing this gap is essential. However, decentralized identity, especially from a legal perspective, presents various challenges that need to be addressed to unlock its full potential. - [KYC Re-usability](/compliance/kyc-re-usability.md): As covered under the Market focus section, KYC re-usability is a key focus of idOS today and aims to solve one of the most significant pain points for both users and businesses by enabling users to reuse credentials across a diverse ecosystem of applications and services, idOS aims to offer a seamless User Experience while allowing for adherence to stringent regulatory requirements. - [Case studies for KYC re-usability](/compliance/kyc-re-usability/case-studies-for-kyc-re-usability.md): KYC reusability is not a concept invented by idOS—it is rooted in international regulatory frameworks and best practices. idOS aims to align with these global standards and streamline KYC Re-usability between financial institutions and other entities in a secure and compliant manner. Below are some real-world initiatives that illustrate the growing trend toward KYC Re-usability. - [Data ingestion](/compliance/kyc-re-usability/data-ingestion.md): What is Ingestion and Who is Involved? - [Legal Assessment](/compliance/legal-assessment.md): To help validate the compliance and regulatory suitability of the idOS infrastructure, Taylor Wessing, a leading international law firm, conducted an independent legal assessment of our system. - [Legal Considerations](/compliance/legal-considerations.md): Legal Considerations for idOS Issuers and Consumers ## developer-docs - [dApp SDK integration](/developer-docs/dapp-sdk-integration.md): The idOS Software Development Kit (SDK) has been developed to make it easier for dApps and other providers to interact with idOS. Any web3 developer should be able to run the idOS SDK on their own and be able to ask users to share access to their idOS credentials, create new credentials for users, among others. - [Integration technical support](/developer-docs/integration-technical-support.md): Overview ## example-use-cases - [Example use cases](/example-use-cases.md): While idOS is a completely generalized system for storage and secure sharing of user data, we've outlined a few specific flows to help explain how different integrations in the stablecoin/crypto fintech space will look, pursuant to our initial market focus on self-custodial, reusable KYC. - [Financial module integration](/example-use-cases/financial-module-integration.md): Data Issuer and Consumers without direct User Experience requirements - [Neobank/wallet integration](/example-use-cases/neobank-wallet-integration.md): Applications that are directly in control of UX - [TradFi → onchain integration](/example-use-cases/tradfi-onchain-integration.md): Centralized applications with decentralized idOS managed identity data ## how-it-works - [Biometrics & idOS FaceSign (Beta)](/how-it-works/biometrics-and-idos-facesign-beta.md): idOS FaceSign is currently in closed beta, available only on the idOS app while we get it ready for use by third party developers. - [Challenges ahead](/how-it-works/challenges-ahead.md): The following, is a list of technical challenges that we see ahead and few words on how do we plan to approach them. Building idOS is not an easy endeavor, and we will continuously seek to attract the best teams to build with us. in the spirit of decentralization and 'open-sourceness' (is that a word?), if you think you can contribute to any of these challenges, or if you see any other important ones, please do not hesitate to reach to us. - [Encryption](/how-it-works/encryption.md): The idOS uses asymmetric encryption by default to secure user data. For encryption, the user's public key is used that he or she derived when setting up an idOS profile. - [FAQs - Users](/how-it-works/faqs-users.md): Everything you need to know as an idOS user. If you happen to have any other questions, feel free to join our idOS Community Telegram group to talk directly you our team. Please check out official-links.md. - [Functionality](/how-it-works/functionality.md): While the architecture describes how the system works, the functionality describes what stakeholders of the idOS like users, ecosystems and dApps can expect from the idOS in terms of functionality: - [Compliant dStorage](/how-it-works/functionality/compliant-dstorage.md): Compliant, decentralized storage to store identity information is one of the two pillars of the idOS. dStorage allows users to maintain self-sovereignty and privacy while gaining the convenience of cloud storage. dStorage isn't a new concept to web3, but foremost compliance concerns have kept it from gaining widespread adoption for personal data. dStorage has clear advantages over identity wallets in terms of data availability and composability. - [Granting data access](/how-it-works/functionality/granting-data-access.md): The Access Management Protocol is the access rights management system of the idOS. It requires access requests to be authenticated and authorized. It governs who has access to data on the idOS. - [Standard identity formats](/how-it-works/functionality/standard-identity-formats.md): The idOS encourages identity verification providers to issue credentials that follow the W3C Verifiable Credentials standard, as it's the most commonly accepted VC standard today, and our SDK is prepared to work with it. For more information check the W3C Verifiable Credentials section. - [User Data Dashboard](/how-it-works/functionality/user-data-dashboard.md): The User Data Dashboard is one of the tools to allow users to manage their data with the idOS. It is an open-source dApp built on top of the idOS. It is meant to be a resource for teams that want to build their own versions, and individualize their visuals and functionalities. - [Key flows](/how-it-works/key-flows.md) - [Data flows](/how-it-works/key-flows/data-flows.md): How data goes in and out of the idOS. - [Encryption flows](/how-it-works/key-flows/encryption-flows.md): Personal data - End-to-end encrypted - [MPC for encryption keys](/how-it-works/mpc-for-encryption-keys.md): Each user in idOS has their own encryption keys. This is one of the hallmarks of our defense in depth approach, and ensures that even if it were to happen, a data leak would leave an attacker holding on to a bunch of nothing. - [Product roadmap](/how-it-works/product-roadmap.md): Our product roadmap is where you can learn about which features we are working on and when we expect to bring them live. It's divided into phases and It covers both near-term and future plans. Please keep in mind that our plan will evolve over time, based on new information becoming available. - [Progressive decentralization](/how-it-works/progressive-decentralization.md): We see decentralization as an ethos and an ongoing journey, rather than a binary state. The building partners are committed to progressively decentralize idOS as much as possible, while making sure we don't rush important decisions that could hurt its success. - [Security](/how-it-works/security.md): Security in idOS is essential, and we are taking a pragmatic approach to hardening the security posture of the components of the idOS system in order of priority. At the beginning, idOS Storage Network Operators will have to pass a manual KYB process run by the idOS Association. \ - [System architecture](/how-it-works/system-architecture.md): idOS is composed of a dStorage Network of Nodes, secured by the building partners as the initial node providers, and designed specifically to manage identity data compliance and security needs, and an Access Management Protocol, giving self-sovereign control to users of their own data, and allowing them to interact with dApps across the whole web3 space. Additionally, idOS provides an SDK for dApps to integrate idOS and a User Data Dashboard, where users can manage their stored data, credentials, and access grants. - [Data flows](/how-it-works/system-architecture/data-flows.md): The idOS offers many possibilities on how users can access and manage their data. We want to provide four general user flows: - [Decentralized storage](/how-it-works/system-architecture/decentralized-storage.md): The dStorage Network of Nodes is a key part of the idOS. The idOS' data is stored in a decentralized relational database, thanks to Kwil, one of the building partners. Nodes synchronize data using CometBFT. - [Access control](/how-it-works/system-architecture/decentralized-storage/access-control.md): Authentication - [Database overview](/how-it-works/system-architecture/decentralized-storage/database-overview.md): Table structure - [W3C Verifiable Credentials](/how-it-works/system-architecture/decentralized-storage/w3c-verifiable-credentials.md): A Verifiable Credential (VC) is a collection of statements provably made by an issuer regarding their subject/holder and can be presented to a verifier. It contains claims, proofs, and metadata like the schema to which it conforms (e.g. the meaning of keys like "name") and the subject it refers to. - [On-chain access grants](/how-it-works/system-architecture/on-chain-access-grants.md): Access grants allow their grantees to retrieve data at a later point in the future without requiring user interaction, as described in granting-data-access.md. These grants are: - [Roles (main stakeholders)](/how-it-works/system-architecture/roles-main-stakeholders.md): Users - [System design](/how-it-works/system-design.md): Overview - [Tools](/how-it-works/tools.md): Software Development Kit (SDK) ## idos-token-launch - [FAQs - Token](/idos-token-launch/faqs-token-launch.md): Everything you need to know for the IDOS Token. If you happen to have any other questions, feel free to join our Telegram Group to talk directly you our team. Please check out official-links.md. - [Official links](/idos-token-launch/official-links.md): .markdown table th, .markdown table td { word-break: break-word; } - [Token Allocation & Distribution](/idos-token-launch/token-allocation-and-distribution.md): This is a marketing communication. White Paper here. Not reviewed or approved by any EU authority. Issuer solely responsible. Terms apply to community incentives. - [Token Economy & Revenue Streams](/idos-token-launch/token-economy-and-revenue-streams.md): Tokens are not just “fundraising mechanisms” or “incentive machines”. A token is how a decentralized protocol/network coordinates access, captures, and distributes value to become a self-sustainable system. We carefully designed the IDOS Token to become a key part of the protocol and contribute to the long-term vision of idOS: becoming the decentralized identity layer for the stablecoin economy. ## integrate - [Consumer guide](/integrate/consumer-guide.md): Required reading - [FAQs - Developers](/integrate/faqs-developers.md): 1. Architecture & Technical Design - [Issuer guide](/integrate/issuer-guide.md): Required reading - [Journey Overview](/integrate/journey-overview.md): Journeys ## legal-docs - [Data and concepts](/legal-docs/data-and-concepts.md): Self-sovereignty - [Data privacy and protection](/legal-docs/data-privacy-and-protection.md): Within the evolving domain of web3, characterized by its emphasis on decentralization and digital autonomy, the imperative of data privacy and protection cannot be understated. The digital sphere, while filled with potential, also presents unique challenges in safeguarding individual identities and personal information. As the identity layer of web3, the idOS commitment to data protection and privacy means those are part of its foundational principles. - [Data portability](/legal-docs/data-privacy-and-protection/data-portability.md): The right to data portability is regulated by the GDPR under Article 20. In short, it states that data subjects have the right to receive personal data concerning them in a structured, commonly used, and machine-readable format and have the right to transmit these data to another party if the situations described under its number one are fulfilled, including by having the right to have the personal data transmitted directly from one to another, where technically possible. Provisions with a similar effect can also be found under e.g. CCPA. - [Data processing location](/legal-docs/data-privacy-and-protection/data-processing-location.md): Moving carefully to align with data protection laws compliance means that idOS will run a Network of Nodes at launch and Fractal ID together with other foundational partners will be the first parties to this Network of Nodes, as demonstrated in the illustration below. - [Data rectification](/legal-docs/data-privacy-and-protection/data-rectification.md): Under Article 16, the GDPR sets forth the right of data subjects to obtain from the controller without undue delay the rectification of inaccurate personal data concerning them. A similar provision can also be found in other data protection laws, such as the CCPA. - [Legal basis for profile creation and management](/legal-docs/data-privacy-and-protection/legal-basis-for-profile-creation-and-management.md): Profile creation - [Legal basis for sharing data](/legal-docs/data-privacy-and-protection/legal-basis-for-sharing-data.md): There are two relevant concepts here: Authentication, which represents “Who are you?” and Authorization, which in turn represents “What can you do?”. Authentication means that anyone who attempts to perform any query on an idOS node must authenticate with a wallet signature. In turn, the authorization step grants permissions to authenticated parties to do something within the idOS. This means that all queries must include a wallet signature that establishes that a certain caller controls a certain wallet and in parallel, the idOS contains rules setting forth what the parties to the network can or can not do. - [The right to be forgotten](/legal-docs/data-privacy-and-protection/the-right-to-be-forgotten.md): The 'right to be forgotten' is established under Article 17 of the GDPR at an EU level but is also present in other data protection laws around the globe, such as the California Consumer Privacy Act (CCPA). Focusing on GDPR, the latter states that data subjects shall have the right to obtain the erasure of personal data concerning them without undue delay if one of the situations described under the first number of the article applies, such as when the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed, or when the data subject withdraws consent on which the processing is based, for example. - [Third-party data management policies](/legal-docs/data-privacy-and-protection/third-party-data-management-policies.md): Identity verification providers - [User identification and on-chain data](/legal-docs/data-privacy-and-protection/user-identification-and-on-chain-data.md): In the context of access grants, third parties can only access users' data if the user decides so, and this is where the blockchain plays its role. The way a user gives somebody else permission to access their data is via the access grant governed by the Access Management Protocol: a statement from the user giving access to information they control for a pre-defined amount of time or until revocation by the user, which is in turn stored in a list in a smart contract on any chain. - [Identity data for obligated entities](/legal-docs/identity-data-for-obligated-entities.md): The idOS has some key features and mechanisms that make it a robust tool for AML compliance. It supports the storage of verified KYC/AML data and in its initial integration with foundational partners, such as Fractal ID, as well as the possibility of other identity providers becoming a part of the idOS, allows for users' identity data to undergo verification before being stored on the idOS, providing financial institutions with a reliable source of verified identity information, which is crucial for AML compliance. - [Data retention obligations](/legal-docs/identity-data-for-obligated-entities/data-retention-obligations.md): Understanding the intricacies of data retention, especially in the context of AML obligations, is crucial for any financial institution. Within the idOS framework, when a user provides access to their KYC data via an access grant, the duration of this access can be previously set. This predetermined period allows for alignment with the necessary retention periods for compliance, ensuring that the data remains accessible for the required timeframe. - [Identity verification providers as issuers](/legal-docs/identity-data-for-obligated-entities/identity-verification-providers-as-issuers.md): The idOS offers a solution for those who need to navigate the intricate landscape of Anti-Money Laundering and Counter-terrorism Financing (AML/CTF) compliance. Recognizing the significance of AML/CTF in today's digital transactions, the idOS has been designed to address the unique challenges posed by the decentralized web3 environment. - [idOS software license](/legal-docs/idos-software-license.md): The idOS SDK is released under the MIT License, a permissive license known for its minimal constraints on software reuse and notable license compatibility. - [Introduction](/legal-docs/introduction.md): Please don't delete this page but exchange it's content as it's already linked ## market-focus - [Market focus](/market-focus.md): Because of its open-source and permissionless nature, only the community can decide what idOS will be used for. In principle, idOS can be used to store any type of data. However, to foster adoption and usage, the idOS Association core team has prioritized a clear go-to-market focus and use cases for the near term, around KYC re-usability for OpenFi. ## overview - [FAQs](/overview/faqs.md): Is idOS live? - [The idOS Consortium](/overview/the-idos-consortium.md): Building a web3-wide decentralized identity is too big of a challenge for one party to succeed alone. idOS is a collaborative effort across leading ecosystems in web3 to build the right identity solution for actual user adoption. - [What data? How is it stored?](/overview/what-data-how-is-it-stored.md): What is happening with my data? - [What is idOS?](/overview/what-is-idos.md): Introducing the Identity Operating System - [Why is idOS needed?](/overview/why-is-idos-needed.md): A compliant, privacy-preserving and decentralized identity layer is possible. It's never been more needed than it is today. Since its inception, the web3 industry has advocated for a user-centric internet, but we failed to adopt user-centric identity management to this day. ## the-idos-consortium - [The idOS Consortium](/the-idos-consortium.md): Introducing the idOS Consortium ## what-is-self-custodial-data - [What is self-custodial data?](/what-is-self-custodial-data.md): Protecting personal data, in a secure and compliant way. ## why-idos - [Why idOS?](/why-idos.md): Better for users, essential for the onchain economy