Skip to main content

VC-I-1 — PID or biometric data exposed in vc issuer logs

Component: vc Platform. Mitigations: Credential claims passed in-process; log level controls. Action: Audit log output of issuer and registry for PII; enforce structured logging with field redaction

PropertyValue
SectionInformation Disclosure
Ownerplatform

Mapped Controls

ControlTitle
SID-AUDIT-02Privacy-Preserving Audit Event Taxonomy
SID-DATA-01SD-JWT Selective Disclosure

Source: STRIDE analysis (April 2026), architecture/stride-threat-model.md