KYC/AML Selective Disclosure
Satisfy KYC/AML requirements with per-attribute ZK proofs instead of sharing customer data, so you can meet compliance and data-minimization obligations at the same time.
Three voices from the front line.
- Bank KYC team
“We only need to confirm a customer's age and eligibility, yet we end up receiving the full originals — passport, proof of address”
- Compliance
“We want to prove only compliance to regulators, without taking on PII leakage risk”
- Platform operator
“Every time we outsource KYC, personal data spreads further outside”
Hand over the source, or just the facts?
Nothing changes on the floor. Everything changes for the receiver.
① Your team just saves, as always.
- The usual step
- Fill in the record and save
- On save
- A proof is attached (API, behind the scenes)
- The document itself
- never sent
② They just open a link.
- Proven fact
- meets KYC / AML requirements
- name, address, date of birth and other identity attributes
- not shown
- Login / keys
- not needed
- The document stays private — the record itself is never sent or disclosed.
- Independent verification — the receiver just opens a link. No account, no keys.
- Edits are detected — even a one-character edit fails verification.
An issuer that has already done the screening (the bank) issues each customer attribute as an independent trail. The original address, date of birth and transaction history stay with the issuer; what the receiving side gets is only the proof of the needed attributes — "18 or older," "resident in Japan," "not on a sanctions list." Without sharing the data, regulators, receiving institutions and the customer can independently verify the attribute's authenticity, issuer, validity and consent.
See the technical details ↗Why the usual methods fall short.
Only work that needs all three at once — pass without exposing, independent verification, tamper-evidence — is Lemma's domain.
| Method | Pass without exposing | Independent verification | Tamper-evident | What happens |
|---|---|---|---|---|
| Access control / permissions | △ | ✗ | ✗ | “Someone inside could have edited it” remains possible |
| Masking / redacted copies | △ | ✗ | ✗ | Redaction work grows; the original is still unproven |
| Encrypt and store / send | ✓ | ✗ | ✗ | To verify, the receiver needs it disclosed after all |
| Lemma (ZK proof)the only one with all 3 | ✓ | ✓ | ✓ | The receiver just opens a link |
How it works — and how to start.
We help design disclosure scope and retention, run the PoC, and support production.
Start with a 30-minute call.
Tell us one workflow where "share to demonstrate compliance" and "minimize data sharing" run in parallel, in the first 30 minutes. No disclosure of sensitive data required.
Related Use Cases
Find the case that matches your industry and problem
Browse all 36 use cases →TRY LEMMA
Run it yourself.
No sales call needed — start hands-on with Lemma's products.