Skip to Content
Identity Verification

Identity Verification

Every deposit (public or private) requires identity verification and sanctions screening. These map to two checks: Proof of Personhood (a real, unique, non-sanctioned human is behind the transfer) and Proof of Innocence (the depositing address is screened against sanctions and watchlists). See how it works for the full deposit and exit flow.

Proof of Personhood

Proof of Personhood means proving a real, unique, non-sanctioned human is behind a transfer, without revealing who they are. Shield requires it on every deposit, so bots, sybils, and sanctioned actors can’t bridge: privacy is earned by proving you are a screened human.

For background on the concept, see Proof of personhood, explained .

There are two ways to satisfy it, and one is required on every deposit:

  • Proof of Clean Hands (PoCH): full verification, unlimited bridging for one year.
  • Human Passport (previously Gitcoin Passport): a humanity score of 20+, for lighter bridging (up to 1,000 USDC per transaction, with a cumulative per-user cap).

Verification is zero-knowledge: no plaintext PII is stored at rest, threshold-encrypted at issuance (see Security).

How this differs from other privacy systems: some privacy protocols don’t verify identity at all; they screen the tokens being moved, not the people moving them. Others gate access through centralized exchange KYC, where a third party collects and stores personal data. Shield verifies that a real, unique, non-sanctioned human is behind the transfer cryptographically, with no plaintext PII at rest.

Proof of Clean Hands (PoCH): Unlimited Bridging

Full verification taking about 5 minutes. Valid for one year.

Steps

  1. Complete government ID check (passport, driver’s license, residence permit, visa, or voter card)
  2. Pass liveness scan (biometric match against ID)
  3. System screens against 23 international sanctions sources automatically

On success, you receive an on-chain Clean Hands SBT. PoCH grants unlimited bridging (public or private mode). Credentials expire after one year; renewal starts at month 11.

Verify at: id.human.tech/clean-hands 

Human Passport: Capped Bridging

Lighter option. Requires humanity score of 20+ to bridge up to 1,000 USDC equivalent per transaction, with a cumulative cap on total deposits per user. Works for both public and private mode.

No government ID required. Score comes from verifying stamps (GitHub, Google, ENS, etc.).

Check score at: app.passport.xyz 

Proof of Innocence (PoI)

Proof of Innocence is a privacy-preserving compliance approach: showing that the funds or address behind a transaction are not tied to sanctioned or illicit activity, without revealing who the owner is. Privacy systems use it to keep illicit money out of a shielded pool while still protecting ordinary users. The term comes from this space, where protocols like Railgun (its “Private Proofs of Innocence”, PPOI) and Privacy Pools screen the funds entering a shielded system.

In Shield, Proof of Innocence (PoI) is the per-deposit sanctions screening of the depositing address, run at attestation issuance. Sanctions and watchlist data change over time, so a one-time check goes stale: PoI re-runs a fresh check on every entry and every exit, keeping sanctioned funds out without a plaintext honeypot.

Every deposit and every exit (public or private, regardless of amount) is screened against 23 international sanctions and watchlist data sources via sanctions.io . If sanctions.io is unreachable, the attestation flow fails closed: no attestation is issued and no deposit is allowed. Exit attestations are nonce-bound and single-use, preventing replay. On-chain verification uses zero-knowledge proofs; no PII appears on chain.

How this differs from other privacy systems: other privacy systems screen the tokens being deposited, at deposit only (for example Railgun’s PPOI). Shield screens the address, at both entry and exit, and pairs that screen with identity (Proof of Personhood), so a freshly funded address can’t enter clean without a sanctions-screened human behind it.

What Is Screened

  • OFAC sanctions lists (SDN, Foreign Sanctions Evaders, Chinese Military Companies, Palestinian Legislative Council, SSI)
  • FATF Black and Grey Lists
  • FBI Most Wanted
  • FINCEN 311 Special Measures
  • Interpol Red Notices
  • US Bureau of Industry and Security (Entity List, Denied Persons List, Military End User List)
  • US Department of State (Defense Trade Controls, Nonproliferation, Cuba Restricted List)
  • Politically Exposed Persons (PEP) data

Full Sanctions Source Codes

CodeList
SDNOFAC Specially Designated Nationals
OFAC-COMPREHENSIVEOFAC Comprehensive Sanctions
OFAC-MILITARYOFAC Military-related Sanctions
OFAC-OTHERSOFAC Other Sanctions Lists
NONSDNOFAC Non-SDN List
NS-MBS LISTOFAC Non-SDN Menu-Based Sanctions List
SSIOFAC Sectoral Sanctions Identifications
PLCOFAC Palestinian Legislative Council List
CAPOFAC CAPTA List
CCMCOFAC Communist Chinese Military Companies
CMICOFAC Chinese Military-Industrial Complex Companies
FSEOFAC Foreign Sanctions Evaders
DPLUS BIS Denied Persons List
ELUS BIS Entity List
MEUUS BIS Military End User List
DTCUS State Dept: Directorate of Defense Trade Controls (Debarred)
ISNUS State Dept: Nonproliferation Sanctions
US-DOS-CRSUS State Dept: Cuba Restricted List
FATFFATF Black and Grey Lists
FBIFBI Most Wanted
FINCENFinCEN 311 Special Measures
INTERPOLInterpol Red Notices
PEPPolitically Exposed Persons data

For authoritative definitions of each code, see the sanctions.io data sources reference .

Last updated on