Security Overview

OCME Registry employs enterprise-grade security measures to protect creators, content, and user data. Learn about our comprehensive security architecture and how it benefits you.

Security at a Glance

Passwordless Security

No passwords to steal or compromise

RSA-2048 Encryption

Military-grade cryptographic protection

Tamper-Proof Records

Immutable content verification

Edge Security

Global protection at network edge

Security Features

Passwordless Authentication

User authentication for the OCME ecosystem is handled by the OCMECO app with a passwordless flow. OCME Registry itself does not store user credentials: it validates the resulting session tokens server-side through the Sentinel auth service on every authenticated request.

🔐 How It Works

  • Magic Links: Secure, time-limited authentication links sent to your email
  • JWT Tokens: Industry-standard tokens for secure session management
  • CSRF Protection: Built-in protection against cross-site request forgery
  • Session Management: Automatic token refresh and secure logout

✅ Security Benefits

  • No passwords to be stolen or compromised
  • Eliminates credential stuffing attacks
  • Prevents phishing and social engineering
  • Email-based verification ensures account ownership
  • Automatic security updates without user action

🛡️ Advanced Protection

Authentication flows in the OCMECO app include rate limiting and email-based verification of account ownership. The registry enforces role-based access on every authenticated endpoint and logs security-relevant events for audit.

Privacy Protection

Data Minimization

We collect only the data necessary for service functionality

User Control

You maintain full control over your data and privacy settings

Transparent Processing

Clear documentation of how your data is used and protected

Security Best Practices for Users

✅ Recommended Practices

  • Use a secure, private email account for OCME Registry
  • Enable two-factor authentication on your email account
  • Keep your browser and operating system updated
  • Log out from shared or public computers
  • Verify content authenticity using our verification tools

⚠️ Security Warnings

  • Never share magic links with others
  • Be cautious of phishing emails claiming to be from OCME
  • Always verify URLs before clicking (look for beta.ocmeco.org)
  • Report suspicious activity immediately
  • Don't upload content you don't own or have rights to

Public Data Boundary

Public (unauthenticated) DID resolution endpoints serve a privacy-redacted view: payment and legal-identity material — USDC wallet address, full legal name, country of residence, payment/compliance service blocks, and staff audit-trail emails — is stripped before the response leaves the platform. When anything is redacted, the document's cryptographic proof is removed with it and the response carries an explicit redaction disclosure, so no public consumer can mistake a redacted document for a complete one. Full documents are only served through authenticated resolution paths. See Content Verification for details.

Your Security is Our Priority

Experience the peace of mind that comes with enterprise-grade security