Every big company today on the internet has gotten to where it is by directly and indirectly selling your data. Big search engines like Google or Meta, which owns some of the largest social media in the world Facebook, Instagram, and WhatsApp aren’t charging you any money to use them because you’re the product.
Your attention. Your behavior. Your data is the fee you pay them for using them for free.
For instance, Google knows every search you make, your location, websites you’ve visited, products you search for, etc.
They use the information they collect to help advertisers identify individuals who are likely to be interested in a particular product or service.
In a normal sense, Google didn’t sell your data with this, but if you look at the flow, you’ll see your data is still indirectly being sold to them.
You generate the data for free. Google builds the infrastructure to understand it. Advertisers pay Google to access the resulting audience.
So your data becomes a valuable thing for Google to seek in exchange for money.
In fact, in 2012, the FTC accused Google of circumventing Safari’s default cookie-blocking settings and placing advertising tracking cookies despite telling users they would effectively be opted out. Google paid $22.5 million to settle the Safari case.
The same thing happened with Meta Facebook and Instagram. They track everything you do what
you like
you follow
you watch
you interact
you search for
you interact with, etc.
Meta can use behavioral signals to estimate what you’re interested in, what kind of content you’re likely to engage with, and which advertisements you’re more likely to respond to. And just like Google, they also sell this data to advertisers.
And like Google, in 2019 Facebook paid a record $5 billion penalty to settle FTC charges that it had violated a previous privacy order and deceived users about their ability to control the privacy of their personal information.
Apart from the social media you interact with every day, every time you submit your identity to an app, there’s a risk of your data being sold on the dark web by an employee without you even knowing.
This year alone, crypto has also faced multiple breaches that have exposed customer identities. Just lately, we’ve had a series of hardware wallet data leaks that revealed customer emails, shipping countries, phone numbers, etc.
Hardware that was once preached as the most reliable way to keep your crypto safe has become the most dangerous because, as soon as your data gets breached, you’re at risk of an intruder coming to your house and threatening you to give out your crypto at gunpoint.
Every time I give out my identity, I always panic about what will happen to my data if eventually the project I gave my identity to gets breached.
In as much as your data is stored somewhere, there’s always a tendency for there to be a data breach. In fact, one of the KYC infrastructure companies that serves top leading companies like Bybit, Wirex, and more than 4,000 companies worldwide across different niches got a data breach.
In February 2026, Sumsub disclosed a security incident that occurred in July 2024. An attacker used a malicious attachment through a third-party support-ticketing platform, gaining limited access to a support-related internal environment.
According to their investigation, customer data like phone numbers, names, etc. were revealed during this hack. The interesting part is that the incident wasn’t discovered until a security review in January 2026, roughly 18 months after the activity occurred.
Tell you how long an attacker can stay in a system without getting noticed.
Seeing all this and building @Cr3dentials, our first main focus is to protect your identity. As we’re providing data for our neobank partners that want to offer you unsecured credit, we’ll always want to ensure your sensitive information is safe.
Everyone can be breached. If we’re unfortunately breached, our system exposes nothing.
Every existing method has its own flaws. We built our privacy stack in-house to address one of the critical issues happening to people’s data the moment they submit it and during that process.
Our privacy stack has a three-layer architecture:

Layer 1: 1Frame (browser-isolated session)
Normally, if you want to verify your data, you’d need to upload the full documents that contain almost every detail about your account number, phone number, etc., which can even easily be faked with Photoshop or ChatGPT.
Instead of doing that, maybe you go through a service that lets you log into your bank account and get your full history, which isn’t so different from the first approach.
You’re sharing too much information.
With our approach, we only prove that “this user earns over $5,000” without anyone, including us, ever seeing the underlying data.
We selectively reveal data and only specific values to lenders, while still keeping the underlying data completely private.
When you want to verify your data, you see a secure window inside the neobank/fintech app that integrates with us.
This is an in-app embedded experience with UX customization, so the neobank’s branding is displayed.
You log into the website where you earn- Bolt, Deel, YouTube, etc. inside this window.
With this, we ensure that:
- your passwords and login session never leave your browser
- the company embedding the window cannot see inside it
With this, the company cannot bypass the rules and secretly read your full bank session.
Layer 2: zkTLS
Immediately after you log in, the browser creates a cryptographic seal, like an unbreakable sticker on a package, that proves:
- the data came from a real platform, not a scam
- nobody changed the numbers in between
- the login just happened now, not last year
Before this sealed package is sent anywhere, it’s encrypted with a key that only the next layer can open.
This prevents fake documents or replaced old data.
Layer 3: Hardware-Enforced Schema (GCP Confidential Space)
The encrypted proof is sent to a Trusted Execution Environment running on Google Cloud Confidential VMs (Intel TDX / AMD SEV-SNP).
Inside the enclave:
- The proof is decrypted with a private key that exists only in hardware.
- The schema evaluator extracts only the fields defined in the integration-time schema. It reads the exact question the company is allowed to ask, e.g., “Does this person earn more than $5,000?”
- It writes down only the answer, not the full bank statement.
- It signs the answer with a certificate from Google (GCP-signed JWT) that it came from the exact vault.
- After that, it wipes its memory completely: no logs, no saved files
Everyone our team, Google engineers, and hackers is prevented from ever seeing the raw data. The full information only lives in the vault for a second before it completely vanishes and is gone forever.
That way, every party involved stays protected without seeing your sensitive data.
Fintech/neobanks: just have access to what they asked for, for instance, “income > $5,000: Yes,” without having access to your full bank account transactions, passwords, or anything extra.
Cr3dentials team: we didn’t see anything. We’re just the verification layer.
Google: it was just memory. They didn’t see the actual information because it leaves the vault and gets deleted when the session finishes.
We prove claims about your data without any party, including us, ever seeing anything outside the exact fields you requested.
At @Cr3dentials, privacy isn’t something we added as a feature later. It’s part of how we’re building the entire infrastructure.
We believe users shouldn’t have to expose their entire financial life just to prove one thing about themselves.
We’re building the missing privacy layer between how people earn and how financial institutions underwrite them, while making sure your data doesn’t become the next liability.
Because everyone can get breached.
The goal is to make sure that even if we are, there’s nothing useful to expose