Identity Verification
Every deposit (public or private) requires identity verification and sanctions screening. These map to two checks: Proof of Personhood (a real, unique, non-sanctioned human is behind the transfer) and Proof of Innocence (the depositing address is screened against sanctions and watchlists). See how it works for the full deposit and exit flow.
Proof of Personhood
Proof of Personhood means proving a real, unique, non-sanctioned human is behind a transfer, without revealing who they are. Shield requires it on every deposit, so bots, sybils, and sanctioned actors can’t bridge: privacy is earned by proving you are a screened human.
For background on the concept, see Proof of personhood, explained .
There are two ways to satisfy it, and one is required on every deposit:
- Proof of Clean Hands (PoCH): full verification, unlimited bridging for one year.
- Human Passport (previously Gitcoin Passport): a humanity score of 20+, for lighter bridging (up to 1,000 USDC per transaction, with a cumulative per-user cap).
Verification is zero-knowledge: no plaintext PII is stored at rest, threshold-encrypted at issuance (see Security).
How this differs from other privacy systems: some privacy protocols don’t verify identity at all; they screen the tokens being moved, not the people moving them. Others gate access through centralized exchange KYC, where a third party collects and stores personal data. Shield verifies that a real, unique, non-sanctioned human is behind the transfer cryptographically, with no plaintext PII at rest.
Proof of Clean Hands (PoCH): Unlimited Bridging
Full verification taking about 5 minutes. Valid for one year.
Steps
- Complete government ID check (passport, driver’s license, residence permit, visa, or voter card)
- Pass liveness scan (biometric match against ID)
- System screens against 23 international sanctions sources automatically
On success, you receive an on-chain Clean Hands SBT. PoCH grants unlimited bridging (public or private mode). Credentials expire after one year; renewal starts at month 11.
Verify at: id.human.tech/clean-hands
Human Passport: Capped Bridging
Lighter option. Requires humanity score of 20+ to bridge up to 1,000 USDC equivalent per transaction, with a cumulative cap on total deposits per user. Works for both public and private mode.
No government ID required. Score comes from verifying stamps (GitHub, Google, ENS, etc.).
Check score at: app.passport.xyz
Proof of Innocence (PoI)
Proof of Innocence is a privacy-preserving compliance approach: showing that the funds or address behind a transaction are not tied to sanctioned or illicit activity, without revealing who the owner is. Privacy systems use it to keep illicit money out of a shielded pool while still protecting ordinary users. The term comes from this space, where protocols like Railgun (its “Private Proofs of Innocence”, PPOI) and Privacy Pools screen the funds entering a shielded system.
In Shield, Proof of Innocence (PoI) is the per-deposit sanctions screening of the depositing address, run at attestation issuance. Sanctions and watchlist data change over time, so a one-time check goes stale: PoI re-runs a fresh check on every entry and every exit, keeping sanctioned funds out without a plaintext honeypot.
Every deposit and every exit (public or private, regardless of amount) is screened against 23 international sanctions and watchlist data sources via sanctions.io . If sanctions.io is unreachable, the attestation flow fails closed: no attestation is issued and no deposit is allowed. Exit attestations are nonce-bound and single-use, preventing replay. On-chain verification uses zero-knowledge proofs; no PII appears on chain.
How this differs from other privacy systems: other privacy systems screen the tokens being deposited, at deposit only (for example Railgun’s PPOI). Shield screens the address, at both entry and exit, and pairs that screen with identity (Proof of Personhood), so a freshly funded address can’t enter clean without a sanctions-screened human behind it.
What Is Screened
- OFAC sanctions lists (SDN, Foreign Sanctions Evaders, Chinese Military Companies, Palestinian Legislative Council, SSI)
- FATF Black and Grey Lists
- FBI Most Wanted
- FINCEN 311 Special Measures
- Interpol Red Notices
- US Bureau of Industry and Security (Entity List, Denied Persons List, Military End User List)
- US Department of State (Defense Trade Controls, Nonproliferation, Cuba Restricted List)
- Politically Exposed Persons (PEP) data
Full Sanctions Source Codes
| Code | List |
|---|---|
| SDN | OFAC Specially Designated Nationals |
| OFAC-COMPREHENSIVE | OFAC Comprehensive Sanctions |
| OFAC-MILITARY | OFAC Military-related Sanctions |
| OFAC-OTHERS | OFAC Other Sanctions Lists |
| NONSDN | OFAC Non-SDN List |
| NS-MBS LIST | OFAC Non-SDN Menu-Based Sanctions List |
| SSI | OFAC Sectoral Sanctions Identifications |
| PLC | OFAC Palestinian Legislative Council List |
| CAP | OFAC CAPTA List |
| CCMC | OFAC Communist Chinese Military Companies |
| CMIC | OFAC Chinese Military-Industrial Complex Companies |
| FSE | OFAC Foreign Sanctions Evaders |
| DPL | US BIS Denied Persons List |
| EL | US BIS Entity List |
| MEU | US BIS Military End User List |
| DTC | US State Dept: Directorate of Defense Trade Controls (Debarred) |
| ISN | US State Dept: Nonproliferation Sanctions |
| US-DOS-CRS | US State Dept: Cuba Restricted List |
| FATF | FATF Black and Grey Lists |
| FBI | FBI Most Wanted |
| FINCEN | FinCEN 311 Special Measures |
| INTERPOL | Interpol Red Notices |
| PEP | Politically Exposed Persons data |
For authoritative definitions of each code, see the sanctions.io data sources reference .