Skip to Content
Identity Verification

Identity Verification

Every deposit (public or private) requires identity verification and sanctions screening. These map to two checks: Proof of Personhood (a real, unique, non-sanctioned human is behind the transfer) and Proof of Innocence (the depositing address is screened against sanctions and watchlists). See how it works for the full deposit and exit flow.

Proof of Personhood

Proof of Personhood means proving a real, unique, non-sanctioned human is behind a transfer, without revealing who they are. Shield requires it on every deposit, so bots, sybils, and sanctioned actors can’t bridge: privacy is earned by proving you are a screened human.

For background on the concept, see Proof of personhood, explained .

There are two ways to satisfy it, and one is required on every deposit:

  • Proof of Clean Hands (PoCH): full verification, valid for one year. Lifts the $1,000 cumulative limit; per-user daily limits still apply.
  • Human Passport (previously Gitcoin Passport): a humanity score of 20+, for lighter bridging — up to $1,000 in cumulative deposits per wallet.

Verification is zero-knowledge: identity data is threshold-encrypted at issuance and human.tech stores none of it in the clear. The identity check itself is performed by a third-party verification provider, which retains its own records under its own policy (see Security).

How this differs from other privacy systems: some privacy protocols don’t verify identity at all; they screen the tokens being moved, not the people moving them. Others gate access through centralized exchange KYC, where a third party collects and stores personal data. Shield verifies that a real, unique, non-sanctioned human is behind the transfer cryptographically, and holds no plaintext PII of its own.

Proof of Clean Hands (PoCH): Higher Limits

Full verification taking about 5 minutes. Valid for one year.

Steps

  1. Complete government ID check (passport, driver’s license, residence permit, visa, or voter card)
  2. Pass liveness scan (biometric match against ID)
  3. The verification provider screens you against its sanctions and PEP data automatically

On success, you receive an on-chain Clean Hands SBT. PoCH lifts the $1,000 cumulative limit in both public and private mode; per-user daily limits still apply. Credentials expire after one year; renewal starts at month 11.

Verify at: id.human.tech/clean-hands 

Human Passport: Capped Bridging

Lighter option. Requires a humanity score of 20+, and covers up to $1,000 in cumulative deposits per wallet — not per transaction. Once your total deposits reach $1,000, further bridging needs Proof of Clean Hands. Works for both public and private mode.

The score comes from verifying stamps (GitHub, Google, ENS, etc.).

Check score at: app.passport.xyz 

Proof of Innocence (PoI)

Proof of Innocence is a privacy-preserving compliance approach: showing that the funds or address behind a transaction are not tied to sanctioned or illicit activity, without revealing who the owner is. Privacy systems use it to keep illicit money out of a shielded pool while still protecting ordinary users. The term comes from this space, where protocols like Railgun (its “Private Proofs of Innocence”, PPOI) and Privacy Pools screen the funds entering a shielded system.

In Shield, Proof of Innocence (PoI) is the per-deposit sanctions screening of the depositing address, run at attestation issuance. Sanctions and watchlist data change over time, so a one-time check goes stale: PoI re-runs a fresh check on every entry and every exit, keeping sanctioned funds out without a plaintext honeypot.

Every deposit and every exit (public or private, regardless of amount) is screened against 23 international sanctions and watchlist data sources via sanctions.io . If sanctions.io is unreachable, the attestation flow fails closed: no attestation is issued and no deposit is allowed. Exit attestations are nonce-bound and single-use, preventing replay. On-chain verification uses zero-knowledge proofs; no PII appears on chain.

How this differs from other privacy systems: other privacy systems screen the tokens being deposited, at deposit only (for example Railgun’s PPOI). Shield screens the address, at both entry and exit, and pairs that screen with identity (Proof of Personhood), so a freshly funded address can’t enter clean without a sanctions-screened human behind it.

What Is Screened

  • OFAC sanctions lists (SDN, Foreign Sanctions Evaders, Chinese Military Companies, Palestinian Legislative Council, SSI)
  • FATF Black and Grey Lists
  • FBI Most Wanted
  • FINCEN 311 Special Measures
  • Interpol Red Notices
  • US Bureau of Industry and Security (Entity List, Denied Persons List, Military End User List)
  • US Department of State (Defense Trade Controls, Nonproliferation, Cuba Restricted List)
  • Politically Exposed Persons (PEP) data

Full Sanctions Source Codes

CodeList
SDNOFAC Specially Designated Nationals
OFAC-COMPREHENSIVEOFAC Comprehensive Sanctions
OFAC-MILITARYOFAC Military-related Sanctions
OFAC-OTHERSOFAC Other Sanctions Lists
NONSDNOFAC Non-SDN List
NS-MBS LISTOFAC Non-SDN Menu-Based Sanctions List
SSIOFAC Sectoral Sanctions Identifications
PLCOFAC Palestinian Legislative Council List
CAPOFAC CAPTA List
CCMCOFAC Communist Chinese Military Companies
CMICOFAC Chinese Military-Industrial Complex Companies
FSEOFAC Foreign Sanctions Evaders
DPLUS BIS Denied Persons List
ELUS BIS Entity List
MEUUS BIS Military End User List
DTCUS State Dept: Directorate of Defense Trade Controls (Debarred)
ISNUS State Dept: Nonproliferation Sanctions
US-DOS-CRSUS State Dept: Cuba Restricted List
FATFFATF Black and Grey Lists
FBIFBI Most Wanted
FINCENFinCEN 311 Special Measures
INTERPOLInterpol Red Notices
PEPPolitically Exposed Persons data

For authoritative definitions of each code, see the sanctions.io data sources reference .

Last updated on