Skip to content
Veterans Crisis Linedial 988, press 1text 838255
Rally Point

Trust & security

Trust you can verify.

Veteran Passport is built so trusting it never means taking our word for it. It's issued by a veteran nonprofit, confirmed against official records, controlled by the veteran, and auditable end to end. Here's exactly what's real today — and where we're headed, honestly.

Why you can trust it

Earned, confirmed, and held by the veteran.

Issued by Rally Point Foundation

A veteran nonprofit is the issuing authority — this is verified service, never self-claimed.

Confirmed against records

Our verification team confirms each veteran's service against their official discharge records.

Held by the veteran

The credential belongs to the veteran. Nothing is presented without their action and consent.

Verifiable, not trusted blindly

Anyone can confirm a presented Passport on the verification page — you don't take our word for it.

Data minimization

What's verified — and what's never shared.

A verification confirms service, not your private life. Some things are structurally impossible to share.

Live today Verified today

Verified veteran Branch of service Service era Service dates Discharge status Verification date Passport ID Disability status (consent only)

Never shared — by construction

SSN Date of birth Home address Original DD-214 Source documents

We keep the verification, not your documents. Originals can never be downloaded by a verifier.

You're in control

Consent and audit, by default.

Every share is your decision, and every check is recorded for you to see.

Live today

Consent

You approve exactly which claims an organization receives, and for how long. No standing access you didn't grant.

Live today

Audit receipts

Every verification produces an immutable receipt — who checked, what they saw, and when — downloadable by you.

Live today

Revoke anytime

Withdraw any organization's access instantly. Identity activity shows your full history.

Security posture

How your data is handled.

The practices in place today — described plainly, without overclaiming.

Encrypted storage

Documents are stored encrypted and served only through short-lived, access-controlled links.

Scoped, logged staff access

Document contents open only from the review screen, and every staff access is recorded.

Immutable audit log

Sensitive actions are written to an append-only audit trail.

Malware scanning

Every uploaded file is scanned before it can be reviewed; infected files are quarantined.

Retention & purge

Physical documents are retained only for a defined window after verification, then purged — we keep the verified result, not the file.

Two-factor for staff

Staff accounts support two-factor authentication, enabled before external rollout.

Standards & recognition

The path to a national standard.

Our ambition is to be the credential institutions are expected to trust. Here's what we're pursuing — labeled honestly, claimed only when true.

NIST 800-63 assurance alignment

Modeling identity- and authenticator-assurance levels per credential.

Pursuing

W3C Verifiable Credentials / ISO mdoc formats

Standards-based, wallet-portable credential formats.

Roadmap

Apple & Google Wallet presentation

Carry and present your Passport from a mobile wallet.

Pursuing

VA / DoD authoritative anchoring

Anchor the record directly to VA and DoD sources.

Roadmap

SOC 2

Independent audit of our security controls.

Pursuing

FedRAMP path

For government adoption, longer term.

Roadmap

We do not claim SOC 2, FedRAMP, Apple/Google Wallet support, VA/DoD data agreements, or government recognition until they are real. Today, trust rests on verification against official records, veteran-controlled consent, and a complete audit trail.

Verify once. Trust for life.

Get a credential you hold, control, and can prove anywhere — without ever over-sharing again.