Digital identity is becoming core policy infrastructure. Across benefits, financial regulation, privacy, and elections, better verification can strengthen trust while reducing unnecessary data collection and giving people greater control over their information.
Medicaid’s new community engagement requirements expose a broader challenge for digital government: how to verify facts across fragmented systems. A better model combines data-first verification with portable, privacy-preserving, standards-based digital evidence.
SpruceID submitted comments to CMS on implementing new Medicaid community engagement requirements. Our recommendations focus on maximizing ex parte verification, expanding reliable evidence options, and keeping digital pathways voluntary, interoperable, and privacy-preserving.
Device binding is the cryptographic layer that turns a verifiable digital credential from something that can be copied into something that can only be used by its rightful holder.
Behind every seamless mDL experience at the airport is a chain of cryptographic trust and interoperability standards working quietly in the background.
The same privacy and trust principles that make verifiable digital credentials work in person also need to extend to online interactions. Here, we walk through some of the infrastructure that enables that experience.
Every time a mobile driver’s license is verified in seconds, it’s PKI doing the invisible work of turning cryptographic keys into trusted digital identity.
A verifiable digital credential program's trustworthiness depends not only on the credentials it issues, but on how the signing keys behind those credentials are protected, managed, and governed throughout their lifecycle.
Resident-centric digital identity is not a marketing claim, it is a set of design decisions that determine who controls data, privacy, and participation.
Before a digital credential can be trusted, a system must answer two questions: who is this person, and are they the rightful holder of the credential?