European Digital Identity Wallet
procurement readiness — Malta
One page mapping Aloaha Limited's shipped EUDIW stack — Personal Wallet, Business Wallet, Wallet Relying Party verifier, Malta eID Card integration, PAdES signing and sovereign-hosted on-premise delivery — onto the capability tables procurement officers evaluate. Every claim links to a live proof surface or a public specification. Nothing on this page is aspirational.
Capability map
Feature grid, each row a link to the underlying page or specification.
Personal EU Wallet
Web PWA + native Android + native iOS. Receives PID + mDL + PhotoID + EHIC + PDA1 issuance. Presents credentials via OpenID for Verifiable Presentations. HAIP-profiled. urn:eudi:pid:1 canonical VCT.
Solution page →Business Wallet
The wallet your accounting / operations team uses. Signs invoices with CSC v2 to PAdES-B-LTA (GoBD-compliant), verifies incoming credentials, sits inside your existing SSO.
API reference →Wallet Relying Party verifier
OpenID4VP verifier registered with registry.serviceproviders.eudiw.dev. Accepts credentials from any EU Reference Wallet. Publishes WRP certificate + intended-use certificate per ARF 3.0 §5.
Malta eID Card — ready today
LoA High authentication over NFC via our native Android integration. Fully implemented PACE (Password Authenticated Connection Establishment, BSI TR-03110) chip-authenticated channel to the eID card. Full backward compatibility with all valid Maltese eID + residence cards in circulation regardless of chip / OS / applet / certificate profile / APDU / PIN / QSCD.
Wallet API →PAdES signing (GoBD, eIDAS AdES)
PAdES-B-B / B-T / B-LT / B-LTA. Cloud Signature Consortium v2 API. Auto-degrade cascade. Every signature carries an RFC 3161 qualified timestamp under a QTSP on the EU LOTL.
CSC v2 API → · GoBD pillar →W3C Digital Credentials API
Browser-native VP transport per WICG Editor's Draft. Manifest at /.well-known/web-identity. Feature-detected client adapter upgrades OpenID4VP calls automatically when the browser supports it; falls back cleanly on everything else.
OpenID Federation 1.0
Entity statement at /.well-known/openid-federation. ES256-signed. Third parties merge us into their federation trust anchor without bilateral configuration.
Access model (6 roles)
superuser (operator-scope), admin (per-tenant), poweruser (elevated quotas), user (default), siponly (SIP-only), guest (sign-in only). Passwordless admin role assignment via credentials=setrole.
Delivery model
Hosting — Malta on-premise co-location, dual data centre
Production tier deploys inside the national dual data-centre configuration with dark-fibre redundant paths, on 42U cabinets with standard 19″ rack-mount HSMs (bidder supplies + installs + maintains). Dev / test / staging / pre-production run off-site per typical large-scale-procurement patterns, keeping the on-prem footprint minimal.
| Environment | Location | Hardware sourcing |
|---|---|---|
| Production | National data centre, Malta (dual DC) | Bidder-supplied hardware + HSMs; maintained by bidder |
| Pre-production | Off-site (bidder facility) | Bidder-owned; mirrors production HSM class |
| Staging | Off-site (bidder facility) | Bidder-owned |
| Development | Off-site (bidder facility) | Bidder-owned |
What is shipping today
Personal Wallet (web PWA + native Android + native iOS) and Business Wallet are live. The Wallet Relying Party verifier is registered on the EU reference registry. PID issuance runs today in three VCT forms including mDoc. Native eID-card NFC login is shipping via our Android integration. PAdES-B-B / B-T / B-LT / B-LTA signing runs today with an auto-degrade cascade. The W3C Digital Credentials API browser transport is wired at /.well-known/web-identity and activated automatically where browser support exists. OpenID Federation 1.0 entity statements, EU Trusted List, DID document and RP metadata are published.
Standards our stack implements
These are the specifications we implement in code. This is not a claim of third-party accreditation or certification. Formal EUDIW wallet conformity schemes are still being finalised by national and EU authorities; where a scheme exists we support the assessment process (see below).
| Standard / specification | Where it lives on our stack |
|---|---|
| eIDAS 2.0 — Regulation (EU) 2024/1183 amending 910/2014 | Wallet Solution scope, WRP entry, PID issuance |
| Architecture Reference Framework 3.0 (ARF 3.0) | arf-conformity.html, WUA, WRPAC, intended-use cert |
| CIR 2024/2977 (PID Rulebook v1.1) as amended by CIR 2026/1731 | PID data-set + issuance, W3C DC API notice |
| CIR 2024/2979 (Wallet Attestations, ARF core) as amended by CIR 2026/1731 | WUA per Annex Ib, pseudonyms per Art 14, Trust Mark per Art 4 |
| CIR 2024/2980 (Relying Party Registrar) as amended by CIR 2026/1731 | WRP registration + intended-use cert lifecycle |
| CIR 2024/2981 (WSCD / RWSCD) | PID secret key in RWSCD; other secret keys can live on device TEE/SE per amended Clause 4.2.3.4.1 |
| CIR 2024/2982 (Presentation) as amended by CIR 2026/1731 | OpenID4VP verifier surface |
| CIR 2025/848 (Trust Services PKI) as amended by CIR 2026/1730 | WRPAC per Annex IV/V; ETSI EN 319 411-8 as benchmark |
| OpenID4VP 1.0 Final | Verifier + wallet; DCQL native; HAIP-strict mode |
| OpenID4VCI 1.0 Final | Issuer + wallet; HAIP-profiled |
| W3C Digital Credentials API (WICG ED) | wallet-api.html #a11; manifest at /.well-known/web-identity |
| ETSI EN 319 142-1 (PAdES B-B/B-T/B-LT/B-LTA) | CSC v2 API |
| ETSI EN 319 122-1 (CAdES) | CMS SignerInfo layout |
| RFC 3161 (Timestamp) | TSA fetch inside every B-T+ signature |
| IETF Token Status List (draft-ietf-oauth-status-list) | /bitstring-status.ashx?format=oauth-token |
| OpenID Federation 1.0 | /.well-known/openid-federation |
| SD-JWT VC + ISO 18013-5 mDoc | Both formats in issuer catalogue + verifier accept list |
Independent proof surfaces
Every claim on this page is machine-verifiable from a third party, not just our word.
- Live EU Reference Registry entry — fetched fresh on every page load from
registry.serviceproviders.eudiw.dev/wrp. - OpenID Federation entity statement — ES256-signed JWT.
- EU Trusted List — ETSI TL XML.
- Wallet Provider attestation — HAIP §5.11 signed JWT.
- RP metadata — machine-readable relying-party JSON.
- W3C DC API wallet-provider manifest — WICG registration doc.
- DID document —
did:web. - Trust Federation statement — bilateral trust JWS.
Certification support commitment
Formal EUDIW wallet certification schemes are still being finalised by national and EU authorities. We commit to supporting the certification process end to end — conformance testing, interoperability testing, security testing and cooperation with the assigned assessor. This is scoped per engagement and can be structured as a milestone-gated commitment.
Data handling & residency
Data stays inside EU jurisdiction end to end. No US cloud, no CLOUD Act exposure. Signing pipeline is memory-only (no temporary files, no server-side PDF retention — see the CSC v2 data-handling section). Audit trail records only cryptographic metadata (hashed username, credential ID, first-8 chars of hash-to-sign, signature length, cert serial — no PDF content, no filename, no reason string). GDPR minimisation compliant (Art 5(1)(c)).
Where to go next
→ Solution page — Malta EU ID Wallet software (Personal + Business + Verifier)
→ Wallet API reference (25 endpoints, includes W3C DC API discovery)
→ CSC v2 signing API (PAdES-B-LTA + GoBD compliance)
→ EU Wallet integrations (verifier surface)