Private identity
at global scale

TACEO IdentityIn production
The problem

Privacy-preserving identity at scale is one of the hardest problems in cryptography.

Three things have to hold at once.

No single point of trust

Centralized identity providers and KYC databases see everything they verify.
One breach, one subpoena, one rogue insider, and the privacy promise is gone.
Federation moves the problem but doesn't solve it.

The whole attack surface

Biometric templates leak. Identifiers link across services. Sybil-resistance breaks under adversarial input.
Most cryptographic identity systems handle one of these well and the others poorly.

Scale that actually runs

Privacy-preserving identity has been "solved on paper" for two decades.
Running it for tens of millions of users, in real time, every day, is a different problem.
Almost nobody has done it.

In production

It's already running.
At over 18 million users.

TACEO Identity is the privacy-preserving identity infrastructure behind World and ZKPassport. Live in production today.

Verification happens cryptographically, distributed across independent operators. No single operator, including TACEO, ever sees the user's data.

How it works

Iris matching at scale

Iris codes matched against the enrolled set of a global personhood network, in real time. Purpose-built MPC protocols, optimised until the cryptography could carry that volume.

No operator ever holds a template. Published in the iris-biometrics paper, co-authored with the World team.

TACEO:OPRF

Turn any user input, a passport hash, a biometric template, a phone number, into a stable identifier that can't be linked back to the input or across services.

The network never sees the input. Same input, same identifier, every time. Not invertible.

TACEO:Match

The same matching, offered as a service. Biometric data is never identical twice, so matching means similarity against a threshold rather than equality.

Templates are secret-shared on the user's device before they leave it and compared directly on the shares. Only the verdict is revealed.

Cryptographic primitives

The work behind it, in the open.

No single protocol paper covers TACEO Identity the way IACR ePrint 2026/850 covers Merces.

The cryptography is published piece by piece; the proof that it works at scale is the production traffic. A unified protocol writeup may follow as the work matures.

Primitives in peer-reviewable form

Iris-biometrics paper

Co-authored with the World team, it describes how privacy-preserving biometric matching runs at the scale of a global personhood network.

See paper

OPRF paper

The OPRF paper specifies the construction behind unlinkable identifiers across services.

See paper
TACEO NetworkMerces compatible

One network. Multiple solutions.

In production18M+ users secured

Already running on TACEO Identity.

World

Privacy-preserving uniqueness for the open internet's personhood network.

World is the largest personhood network on the open internet. Two TACEO services run underneath it. Blind biometric matching checks a new iris code against the enrolled set without any operator ever holding a template, the construction documented in the iris-biometrics paper co-authored with the World team. TACEO:OPRF then produces the stable, unlinkable identifier that lets an application ask "is this a unique human" without learning who.

The deployment is live, distributed across the TACEO Network's operators, and accounts for the bulk of the over 18 million users the network secures today.

Read the full case study

ZKPassport

Verified identity from real-world documents.

ZKPassport lets users prove claims from their existing passports and government IDs, citizenship, age, document validity, without revealing the underlying document data. The zero-knowledge proving is theirs. TACEO:OPRF supplies the nullifier: a stable, unlinkable identifier derived from the document, so one person can't register twice and their activity can't be linked across services.

The end user holds their document. ZKPassport builds the system. TACEO runs the nullifier service inside it. Live in production.

Visit ZKPassport

Need privacy-preserving identity?

We'll bring the privacy layer.