Identity.org.au editorial · Last updated 25 September 2026
A digital identity service is any service that helps establish, hold, or rely on digital information about who a person is. The category is broad on purpose: it covers the app on your phone, the verification performed when you open an account, and the trust infrastructure that lets unrelated services share confidence in a result.
Almost every digital identity service does one or more of four jobs, and naming the job is the fastest way to understand the product.
- Prove. Verification and proofing services establish that an identity claim is genuine and issue a result — the subject of digital identity verification.
- Hold. Wallets store credentials, keys and consent records so the person controls presentation. See what a digital identity wallet is.
- Decide. Policy layers translate risk into required assurance: which tier, which proof, for which action.
- Attest. Registries and trust frameworks publish what has been approved — which issuers, which verifier versions — so a relying service knows what it is checking against.
The question that separates them: what do they keep?
Two services can perform identical checks and have opposite risk profiles, decided entirely by what happens to the evidence. The conventional model retains document images and selfies, which turns every verification into a small archive — and archives of identity evidence are attacked precisely because they exist. That is the honeypot problem, and it is structural rather than a matter of operator care.
The alternative produces results and discards or encrypts the evidence: services receive tiers, pass/fail answers and proofs, while raw material never enters circulation. When evaluating any identity service — including this one — the useful question is not “how good are your checks?” but “what exists in your databases about me today?”
The single most informative question you can ask an identity service: if you were breached tomorrow, what would an attacker hold about me? The answers sort the field instantly.
What to look for, in order
- Minimisation. Does the service receive less than the question requires, or the maximum by default? Threshold answers exist for most yes/no questions.
- Retention, stated in numbers. What is kept, for how long, and what happens at the end of it — “promptly” is not a retention policy.
- Consent you can see and revoke. Structured, purposed, time-limited grants with an auditable history, as described in consent as infrastructure.
- Openness. Can the method be inspected? An identity system that cannot be examined asks for trust it has not earned — see how security claims are evidenced here.
- Honest claims. Accreditation, availability and capabilities stated precisely, with limits named. Overclaiming identity infrastructure is itself a warning sign.
Where identity.org.au fits
This site documents one particular service: the Identity Wallet — a free, open-source digital identity wallet and the verification layer behind it, stewarded by DETIO FOUNDATION LTD, an Australian not-for-profit. It is independent of the Australian Government and claims no accreditation; it states plainly what it is as it rolls out with the VirtEngine network.
For organisations, the verifier-facing side starts at for services — whether the become a verifier path or the integration overview fits depends on where you are in the decision. For everyone else, the get-started guide is the front door.
Quick answers
What is the difference between an identity service and an identity provider?
An identity provider usually means federated sign-in: one platform authenticates you and tells other services who you are. An identity service is the broader category — anything that proves, holds, decides or attests identity. A wallet-based service is identity infrastructure you hold yourself, with no provider sitting in the middle of each interaction.
Is identity.org.au a digital identity service?
Yes — a wallet and verification layer, operated by a not-for-profit foundation as open-source reference software. It is not a government service, is separate from the Australian Government Digital ID System, myID and myGov, and claims no accreditation.
Are digital identity services regulated in Australia?
Partly. The Digital ID Act 2024 established an accreditation scheme for digital identity services used in certain contexts, alongside general privacy law that applies to every organisation holding personal information. The foundation is currently applying for accreditation; accreditation has not been granted and none is claimed.