Trust & security
Trust you can verify.
Veteran Passport is built so trusting it never means taking our word for it. It's issued by a veteran nonprofit, confirmed against official records, controlled by the veteran, and auditable end to end. Here's exactly what's real today — and where we're headed, honestly.
Why you can trust it
Earned, confirmed, and held by the veteran.
Issued by Rally Point Foundation
A veteran nonprofit is the issuing authority — this is verified service, never self-claimed.
Confirmed against records
Our verification team confirms each veteran's service against their official discharge records.
Held by the veteran
The credential belongs to the veteran. Nothing is presented without their action and consent.
Verifiable, not trusted blindly
Anyone can confirm a presented Passport on the verification page — you don't take our word for it.
Data minimization
What's verified — and what's never shared.
A verification confirms service, not your private life. Some things are structurally impossible to share.
Live today Verified today
Never shared — by construction
We keep the verification, not your documents. Originals can never be downloaded by a verifier.
You're in control
Consent and audit, by default.
Every share is your decision, and every check is recorded for you to see.
Consent
You approve exactly which claims an organization receives, and for how long. No standing access you didn't grant.
Audit receipts
Every verification produces an immutable receipt — who checked, what they saw, and when — downloadable by you.
Revoke anytime
Withdraw any organization's access instantly. Identity activity shows your full history.
Security posture
How your data is handled.
The practices in place today — described plainly, without overclaiming.
Encrypted storage
Documents are stored encrypted and served only through short-lived, access-controlled links.
Scoped, logged staff access
Document contents open only from the review screen, and every staff access is recorded.
Immutable audit log
Sensitive actions are written to an append-only audit trail.
Malware scanning
Every uploaded file is scanned before it can be reviewed; infected files are quarantined.
Retention & purge
Physical documents are retained only for a defined window after verification, then purged — we keep the verified result, not the file.
Two-factor for staff
Staff accounts support two-factor authentication, enabled before external rollout.
Standards & recognition
The path to a national standard.
Our ambition is to be the credential institutions are expected to trust. Here's what we're pursuing — labeled honestly, claimed only when true.
NIST 800-63 assurance alignment
Modeling identity- and authenticator-assurance levels per credential.
W3C Verifiable Credentials / ISO mdoc formats
Standards-based, wallet-portable credential formats.
Apple & Google Wallet presentation
Carry and present your Passport from a mobile wallet.
VA / DoD authoritative anchoring
Anchor the record directly to VA and DoD sources.
SOC 2
Independent audit of our security controls.
FedRAMP path
For government adoption, longer term.
We do not claim SOC 2, FedRAMP, Apple/Google Wallet support, VA/DoD data agreements, or government recognition until they are real. Today, trust rests on verification against official records, veteran-controlled consent, and a complete audit trail.
Verify once. Trust for life.
Get a credential you hold, control, and can prove anywhere — without ever over-sharing again.