Skip to content

Verify once. Prove compliance everywhere.

Fortgate is the integrated identity and compliance layer for regulated platforms. Verify a user a single time, then let that verified identity travel securely across every product, without repeating the process or exposing the underlying data.

Identity verified

Cleared · biometrics bound

ZK proof
proof · 0x7f3a…c21e · anchored on-chain
PlatformReused
PlatformReused
PlatformReused

One verification, reused everywhere, no data re-exposed.

Built on

Stellar
Midnight

Fortgate ID

One verification, reusable across every platform

Fortgate ID turns a completed identity check into a reusable, privacy-preserving proof. It ends repeated verification and lets platforms trust each other, here is what it does and how.

Verify once, reuse forever

A completed verification becomes a portable proof. Users skip the process on every new platform that trusts Fortgate.

Prove without exposing

A zero-knowledge proof confirms a user is verified and cleared, without revealing the underlying documents or personal data.

Identity you can trust

Biometrics, digital signature, and document capture bind the proof to a real, present person, not a stolen file.

Cleared at the source

Every identity is screened against sanctions, PEP, and watchlists before a proof is ever issued.

Trust that travels

Any connected platform can validate a proof independently, enabling institutions to rely on each other's verifications.

Provable on demand

Each proof is anchored on-chain, giving compliance teams a tamper-evident, verifiable record for any audit.

How it works

From onboarding to reusable proof, in four steps

01

Capture

The user completes onboarding once, with biometrics, signature, document, and data captured in a single flow.

02

Verify

The Fortgate ID Engine runs authorization checks, screens against watchlists, and binds a hardware trust signature.

03

Prove

The engine generates a zero-knowledge proof and anchors it on-chain, verified, private, and reusable.

04

Reuse

Any connected platform validates the proof instantly, with no repeated checks and no exposed data.

Verify once, reuse across every connected platform

<5s

Proof generation, not days of manual review

0

Personal data exposed when a proof is validated

100%

Verifiable audit trail, anchored on-chain

Privacy model

Private by construction, even on-chain

A fair question: if proofs are anchored on-chain, what about privacy? Only a cryptographic proof is ever written on-chain. The documents, biometrics, and personal data never are.

Off-chain, stays with you

Never leaves your control

  • Identity documents
  • Biometrics & signature
  • Personal data fields
Only the proof crosses

On-chain, public & verifiable

Anyone can check, no one can read

  • Zero-knowledge proof
  • Issued & expiry status
  • Revocation status

No document, image, or personal field is ever written on-chain.

Security & compliance

Built to satisfy your risk team

Security is the product, not a feature. Here is how Fortgate handles data, access, and integrity, and where we stand on the standards your auditors will ask about.

Encrypted end to end

Data is encrypted in transit and at rest. Verification material is processed in isolated, access-controlled environments.

You keep the data

Personal data stays under your control. Only zero-knowledge proofs are shared, never the underlying documents.

Granular access & keys

Scoped credentials, per-platform keys, and full revocation. Every access is logged and attributable.

Tamper-evident by design

Each check and decision is anchored to an immutable trail, so integrity is provable, not just asserted.

Compliance posture

  • SOC 2 Type II· In progress
  • ISO 27001· Planned
  • GDPR· Aligned by design
  • eIDAS 2.0· Aligned
  • W3C Verifiable Credentials· Supported

Fortgate AML

Compliance that never stops watching

Fortgate AML extends the same engine from onboarding into ongoing protection. It catches risk continuously, not just at sign-up, and works on the identity you already verified, so screening and monitoring share one source of truth.

Screen in real time

Continuously match identities against sanctions, PEP, and watchlists, updated as the lists change, not once a year.

Monitor after onboarding

Risk does not end at sign-up. Fortgate AML watches for changes in status and behavior across the full lifecycle.

Score, flag, act

Every profile carries a live risk score. Analysts get prioritized alerts instead of noise, so teams act on what matters.

One record, ready for audit

Identity and AML share a single, tamper-evident trail, every check, score, and decision provable on demand.

Risk overviewLive
72/100

Elevated risk

Review

Watchlist match: new sanctions entry

2m ago · score +38

Behavior change flagged for review

17m ago · score +12

PEP status refreshed, no change

1h ago · cleared

Open by design

Built on open standards, not a black box

  • OpenID Connect
  • W3C Verifiable Credentials
  • Decentralized Identifiers
  • ISO/IEC 18013 mDL
  • NIST SP 800-63

Who it's for

For any platform that onboards users

Fortgate fits wherever identity is checked and compliance has to hold, defined by what you do, not by a category.

Platforms that verify at signup

Any regulated platform onboarding users can drop repeated verification and clear people in seconds.

Teams with ongoing obligations

Compliance teams that must keep watching after onboarding get continuous screening on one source of truth.

Ecosystems that share users

Connected platforms can rely on each other's verifications, turning trust into a shared network effect.

Anyone replacing manual review

Swap days of document handling and spreadsheets for an instant, provable, privacy-preserving check.

Developers

Integrate in an afternoon, not a quarter

One endpoint to verify a proof, no PII to store, and a sandbox to build against. The heavy lifting stays on our side of the API.

REST API + typed SDKs

Verify a proof in a single call. First-class SDKs, predictable errors, and versioned endpoints.

Webhooks for status changes

Subscribe to verification, screening, and revocation events, react the moment risk changes.

Sandbox & test identities

A full sandbox with synthetic identities and proofs, so you integrate before you ever touch real data.

verify-proof.sh
POST /v1/proofs/verify
Authorization: Bearer sk_live_…

{ "proof": "zk:0x7f3a…c21e" }

# → 200 OK
{
  "verified": true,
  "cleared": true,
  "expires": "2027-01-01",
  "pii": null
}

FAQ

The questions your auditors will ask

Talk to us

Bring your hardest compliance questions

We work with regulated platforms, not a self-serve funnel. Book a call and we'll walk through architecture, data handling, and how Fortgate fits your obligations.

What to expect

  • A 30-minute technical walkthrough
  • Security & compliance Q&A with our team
  • Sandbox access and test identities

One layer for identity and compliance. Built to be reused.

Verify users once, screen them continuously, and prove it all on demand.