I've done KYC something like a dozen times by now. Same passport, same selfie, uploaded to a dozen different companies, sitting on a dozen different servers I'll never see again.
Every one of those is a place my data could leak from.
For years I figured "self-sovereign identity" was mostly a buzzword. IDs, verifiable credentials, wallet logins — none of it seemed to touch what actually matters for finance, which is proving you're allowed to do something without handing over everything about yourself.
Then I read into how Citadel works on Dusk and it landed differently.
It's not really an identity product. It's a license.
You hold a license that says you meet whatever bar matters — accredited, KYC'd, cleared for a specific security. The network checks if you're holding a valid one before letting certain actions through.
Not an exchange's internal database. The protocol itself.
I think that's the part people skip past. Most "compliant" platforms just mean a company stored your documents somewhere and promises to keep them safe.
Citadel seems to flip what actually gets checked. Instead of re-proving who you are every time, you're proving you hold something that was already validated once.
Expiration, revocation, all of it tracked at the license level, not tied to fifteen copies of your passport scattered across random servers.
I'm not sure this fixes compliance on its own. Regulators still have to trust however the initial licensing happened in the first place.
But it does seem to shrink the actual attack surface. Fewer places holding raw identity data, more places just checking a yes or no against a license.
For a chain trying to sit inside regulated finance, that's not a small design choice.
Does moving identity checks to something you hold, instead of something a company stores about you, actually change how institutions think about compliance risk?
$DUSK #Dusk @Dusk #dusk
Every one of those is a place my data could leak from.
For years I figured "self-sovereign identity" was mostly a buzzword. IDs, verifiable credentials, wallet logins — none of it seemed to touch what actually matters for finance, which is proving you're allowed to do something without handing over everything about yourself.
Then I read into how Citadel works on Dusk and it landed differently.
It's not really an identity product. It's a license.
You hold a license that says you meet whatever bar matters — accredited, KYC'd, cleared for a specific security. The network checks if you're holding a valid one before letting certain actions through.
Not an exchange's internal database. The protocol itself.
I think that's the part people skip past. Most "compliant" platforms just mean a company stored your documents somewhere and promises to keep them safe.
Citadel seems to flip what actually gets checked. Instead of re-proving who you are every time, you're proving you hold something that was already validated once.
Expiration, revocation, all of it tracked at the license level, not tied to fifteen copies of your passport scattered across random servers.
I'm not sure this fixes compliance on its own. Regulators still have to trust however the initial licensing happened in the first place.
But it does seem to shrink the actual attack surface. Fewer places holding raw identity data, more places just checking a yes or no against a license.
For a chain trying to sit inside regulated finance, that's not a small design choice.
Does moving identity checks to something you hold, instead of something a company stores about you, actually change how institutions think about compliance risk?
$DUSK #Dusk @Dusk #dusk


