Operational Capabilities

Auditing and Logging

DIW Gateway provides an audit trail for security-relevant and transaction-related operations and structured application logs for operational diagnostics.

Audit records and application logs serve different purposes. The audit trail provides traceability of operations and technical validation results, while application logs are intended for operational monitoring and troubleshooting.

Transaction data, audit events, and operational application logs are maintained as separate logical data categories.

Audit Trail

Each DIW Gateway component provides an audit trail for relevant operations.

The audit trail records transaction processing, state changes, and the results of relevant technical operations to provide traceability of a particular flow.

Audit records contain information such as timestamps, operation types, operation results or states, and identifiers required to locate the corresponding transaction.

Relevant cryptographic material can be retained to support subsequent ex-post verification.

The audit trail represents the technical processing history. Business decisions remain represented by the corresponding transaction or attestation state and are not made by the audit mechanism.

Audit Events

DIW Gateway creates audit records for relevant operations performed during verification, issuance, and administration.

Audited events include, in particular:

  • creation and processing of transactions,
  • validation of Verifiable Presentations,
  • issuance of attestations,
  • changes to attestation status and revocation,
  • failed cryptographic, certificate, and trust validation,
  • access to administrative APIs.

Audit records contain the result or state of the corresponding operation and identifiers required to associate the event with the relevant transaction.

Application Logging

DIW Gateway provides structured application logs for operational diagnostics and troubleshooting.

Operational logs are logically separated from transaction data and audit records.

Full credential payloads, presentation payloads, PID attributes, and bank attributes are not written to application, tracing, debug, or security logs.

Operational records can use technical identifiers and credential or claim names for traceability without storing the corresponding claim values.

Audit and Log Export

Audit records can be accessed and exported through the audit API.

Operational application logs can be integrated with the organization’s monitoring, log management, and SIEM infrastructure.

DIW Gateway supports OpenTelemetry, Prometheus, and Syslog.

Data Retention

DIW Gateway supports configurable data retention for transaction data, attestation content, audit records, and operational logs.

Retention can be configured according to the deployment model and the data retention requirements of the integrating organization.

Attestation and presentation content is stored separately from the associated metadata and cryptographic material. This allows the original content to be removed while retaining the technical evidence required for subsequent integrity verification.

The integrating organization determines the required retention policy according to its business, security, and regulatory requirements.

Transaction Data Retention

Transaction-related personal data is retained according to the configured retention policy, either for the duration required to process the transaction or for a configured retention period.

For verification scenarios, DIW Verifier can operate in a pass-through configuration. In this mode, presentation data is held temporarily in memory during transaction processing and removed after it has been successfully provided to the integrating system.

Technical transaction information required for traceability can be retained independently of the presentation or credential content.

Attestation Data retention

The content of received and issued attestations is stored separately from the associated metadata and cryptographic material.

For received presentations and credentials, retention is configurable. The content can be removed after completion of the verification transaction while retaining the corresponding cryptographic hashes required for subsequent integrity verification.

For issued attestations, retention is also configurable. Attestation content can be removed after completion of the issuance transaction or retained for record-keeping according to the configured retention policy.

Lifecycle state and relevant cryptographic evidence can be retained independently of the original attestation content.

Audit Data Retention

Audit record retention is configurable.

The required retention period is determined by the integrating organization according to its audit, security, and regulatory requirements.

In a bank-hosted deployment, audit data remains within the organization’s infrastructure and its retention is controlled according to the corresponding deployment and operational configuration.

Application Log Retention

Application log retention depends on the selected deployment model and the corresponding operational configuration.

In a bank-hosted deployment, operational log retention is controlled through the organization’s observability infrastructure.

Data Deletion

DIW Gateway allows presentation and attestation content to be removed according to the configured retention policy.

The content is stored separately from metadata and cryptographic material, allowing the original personal data to be removed while retaining the technical evidence required for subsequent integrity verification.

For verification transactions, the corresponding cryptographic hashes can be retained after the original presentation or credential content has been removed.

After the original content has been removed, a generic transaction record and relevant cryptographic material can remain for technical traceability and subsequent integrity verification.

develop

Digital ID Wallet Gateway