Path A
Prove locally, verify remotely
The normal way to run AffixIO. Your host holds the personal data, generates a proof against a compiled circuit, and sends the proof rather than the facts.
- What AffixIO receives
- Circuit id, proof bytes, public inputs, an optional idempotency key, and the API key used.
- What AffixIO returns
proof_id,valid,verified,decision,circuit_id,engine,proof_digest,proof_ref,return_value,policy_versionand the ML-DSA-65 attestation.- What never arrives
- Names, dates of birth, document numbers, addresses, images, biometric templates.
- What is written down
- A decision receipt and a Merkle leaf, both digest-based. See the ledger below.