// HACKER NEWS — CYBERSECURITY
Show HN: Anonymous age verification with passkey-powered encryption
Sensitive data stays encrypted at rest. No readable Personal Identifiable Information (PII) is stored.
User-held encryption keys unlock reusable, one-tap age verification without exposing
sensitive data.
One-tap, anonymous confirmation that an account belongs to a verified person. Designed for AI platforms working to limit bot accounts and prevent automated model distillation, but useful anywhere an application needs frictionless proof of personhood.
Some applications need to know that a user is old enough to use their product. Others
want confirmation that there is a verified person behind an account. One
returns the required identity proof in one tap, helping businesses meet their
requirements without collecting personal data or putting users through a long and
invasive verification flow.
Users verify their identity once, then reuse it across any application
that uses One. No repeated ID uploads, and no
new processor to trust with sensitive data. Applications receive only the
proof a user approves, not their PII. Their data stays encrypted with a key only they
hold, so even a breach of One would not expose
readable identity data.
No. Age verification is simply the first privacy challenge that
One was built around. The same infrastructure can
confirm that an account belongs to a verified person without revealing who they are.
At its core, One is a new primitive for persisting
sensitive data under user-held encryption. It can power reusable identity presentation
for KYC, private AI chat transcripts, and other applications that require persistence
of sensitive data without surrendering custody to the platform.
One stores ciphertext: encrypted blobs created
with a key held by the user. Never the underlying identity data. This includes
government ID data, as well as the verified email associated with the account.
Only the requested proof and an audit record. For example, that a user is a verified person or is at least 18 years of age, and
when the check was completed. No name, birth date, address, selfie, or ID image.
Applications increasingly need to verify aspects of their users’ identities, but
traditional verification methods create a new privacy problem. Users upload IDs,
selfies, and other PII to providers that can read and retain it, then repeat the
process across multiple applications. That creates friction and spreads sensitive
data across more databases and attack vectors. One
was built around a new primitive to resolve that conflict: reusable identity data
encrypted with keys only the user holds. Businesses get the proof they require, while
users maintain their privacy and custody of their data.
Read more:
The Internet Should Be More Like a Liquor Store
Email [email protected]
to ask a question, discuss an integration, or request access.