Identity Verification
Every deposit (public or private) requires identity verification and sanctions screening. These map to two checks: Proof of Personhood (a real, unique, non-sanctioned human is behind the transfer) and Proof of Innocence (the depositing address is screened against sanctions and watchlists). See how it works for the full deposit and exit flow.
Proof of Personhood
Proof of Personhood means proving a real, unique, non-sanctioned human is behind a transfer, without revealing who they are. Shield requires it on every deposit, so bots, sybils, and sanctioned actors can’t bridge: privacy is earned by proving you are a screened human.
For background on the concept, see Proof of personhood, explained .
There are two ways to satisfy it, and one is required on every deposit:
- Proof of Clean Hands (PoCH): full verification, valid for one year. Lifts the $1,000 cumulative limit; per-user daily limits still apply.
- Human Passport (previously Gitcoin Passport): a humanity score of 20+, for lighter bridging — up to $1,000 in cumulative deposits per wallet.
Verification is zero-knowledge: identity data is threshold-encrypted at issuance and human.tech stores none of it in the clear. The identity check itself is performed by a third-party verification provider, which retains its own records under its own policy (see Security).
How this differs from other privacy systems: some privacy protocols don’t verify identity at all; they screen the tokens being moved, not the people moving them. Others gate access through centralized exchange KYC, where a third party collects and stores personal data. Shield verifies that a real, unique, non-sanctioned human is behind the transfer cryptographically, and holds no plaintext PII of its own.
Proof of Clean Hands (PoCH): Higher Limits
Full verification taking about 5 minutes. Valid for one year.
Steps
- Complete government ID check (passport, driver’s license, residence permit, visa, or voter card)
- Pass liveness scan (biometric match against ID)
- The verification provider screens you against its sanctions and PEP data automatically
On success, you receive an on-chain Clean Hands SBT. PoCH lifts the $1,000 cumulative limit in both public and private mode; per-user daily limits still apply. Credentials expire after one year; renewal starts at month 11.
Verify at: id.human.tech/clean-hands
Human Passport: Capped Bridging
Lighter option. Requires a humanity score of 20+, and covers up to $1,000 in cumulative deposits per wallet — not per transaction. Once your total deposits reach $1,000, further bridging needs Proof of Clean Hands. Works for both public and private mode.
The score comes from verifying stamps (GitHub, Google, ENS, etc.).
Check score at: app.passport.xyz
Proof of Innocence (PoI)
Proof of Innocence is a privacy-preserving compliance approach: showing that the funds or address behind a transaction are not tied to sanctioned or illicit activity, without revealing who the owner is. Privacy systems use it to keep illicit money out of a shielded pool while still protecting ordinary users. The term comes from this space, where protocols like Railgun (its “Private Proofs of Innocence”, PPOI) and Privacy Pools screen the funds entering a shielded system.
In Shield, Proof of Innocence (PoI) is the per-deposit sanctions screening of the depositing address, run at attestation issuance. Sanctions and watchlist data change over time, so a one-time check goes stale: PoI re-runs a fresh check on every entry and every exit, keeping sanctioned funds out without a plaintext honeypot.
Every deposit and every exit (public or private, regardless of amount) is screened against 23 international sanctions and watchlist data sources via sanctions.io . If sanctions.io is unreachable, the attestation flow fails closed: no attestation is issued and no deposit is allowed. Exit attestations are nonce-bound and single-use, preventing replay. On-chain verification uses zero-knowledge proofs; no PII appears on chain.
How this differs from other privacy systems: other privacy systems screen the tokens being deposited, at deposit only (for example Railgun’s PPOI). Shield screens the address, at both entry and exit, and pairs that screen with identity (Proof of Personhood), so a freshly funded address can’t enter clean without a sanctions-screened human behind it.
What Is Screened
- OFAC sanctions lists (SDN, Foreign Sanctions Evaders, Chinese Military Companies, Palestinian Legislative Council, SSI)
- FATF Black and Grey Lists
- FBI Most Wanted
- FINCEN 311 Special Measures
- Interpol Red Notices
- US Bureau of Industry and Security (Entity List, Denied Persons List, Military End User List)
- US Department of State (Defense Trade Controls, Nonproliferation, Cuba Restricted List)
- Politically Exposed Persons (PEP) data
Full Sanctions Source Codes
| Code | List |
|---|---|
| SDN | OFAC Specially Designated Nationals |
| OFAC-COMPREHENSIVE | OFAC Comprehensive Sanctions |
| OFAC-MILITARY | OFAC Military-related Sanctions |
| OFAC-OTHERS | OFAC Other Sanctions Lists |
| NONSDN | OFAC Non-SDN List |
| NS-MBS LIST | OFAC Non-SDN Menu-Based Sanctions List |
| SSI | OFAC Sectoral Sanctions Identifications |
| PLC | OFAC Palestinian Legislative Council List |
| CAP | OFAC CAPTA List |
| CCMC | OFAC Communist Chinese Military Companies |
| CMIC | OFAC Chinese Military-Industrial Complex Companies |
| FSE | OFAC Foreign Sanctions Evaders |
| DPL | US BIS Denied Persons List |
| EL | US BIS Entity List |
| MEU | US BIS Military End User List |
| DTC | US State Dept: Directorate of Defense Trade Controls (Debarred) |
| ISN | US State Dept: Nonproliferation Sanctions |
| US-DOS-CRS | US State Dept: Cuba Restricted List |
| FATF | FATF Black and Grey Lists |
| FBI | FBI Most Wanted |
| FINCEN | FinCEN 311 Special Measures |
| INTERPOL | Interpol Red Notices |
| PEP | Politically Exposed Persons data |
For authoritative definitions of each code, see the sanctions.io data sources reference .