Compliance Model
StellarProof is designed to provide reusable verification evidence and the infrastructure to check it. Final AML/KYC decisions will remain the responsibility of each participating anchor.
Where the regulated copy will live
With the licensed KYC provider that performed the original verification — Didit. Didit will retain the compliance copy under its own regulatory obligations, exactly as it does today. StellarProof is establishing the contractual arrangements needed to confirm evidentiary access for anchors and regulators when required.
A regulator compelling StellarProof would produce approved issuer public keys, revocation roots, and ciphertext StellarProof cannot decrypt, none of which is usable to identify an individual without a key StellarProof does not hold.
What will satisfy an anchor's obligation
The on chain compliance record: a tamper evident, append only, timestamped proof that verification occurred, by which registered issuer, at what time, and against which policy. The anchor will never hold the raw documents. It cannot be compelled to produce what it never had, cannot leak it, and will not have to secure it. This is designed to reduce an anchor's regulatory surface area rather than add to it.
Jurisdiction will be enforced, not assumed
The circuit will prove the holder's document country matches the country the anchor's policy requires. An unsupported country will be refused at issuance rather than silently defaulted, so a credential cannot exist for a jurisdiction StellarProof does not support.