420 Identity security and privacy¶
Minimize public personal data. Prefer hashes/commitments when the underlying content does not need to be public. Never interpret a pseudonymous profile as legal identity unless a specific credential explicitly establishes that claim under an application's policy.
Recheck credential validity, issuer activation and trust class before security-sensitive use. Treat revoked, expired or subject-rejected credentials as invalid immediately.
Do not expose unrelated private Identity fields in support diagnostics.