Recovery
Recovery is the most attacked part of any identity system. SmaiID grades the evidence you present and answers with a graduated decision — never a simple yes.
Recovery readiness
Three strong factors configured. Readiness: good.
Recovery codes
8 of 10 unused. Generated 19 Apr 2026.
Trusted passkey on a second device
Pixel — Personal, device-bound.
Backup email
Verified 12 Feb 2026.
Backup phone
Optional. Not configured.
Trusted contact attestation
Optional. Useful for high-assurance identities.
Recovery decision engine
Every recovery attempt resolves to one of five outcomes, recorded as a security event.
ALLOW
Strong evidence from a trusted device in a familiar region.
STEP_UP
Evidence is valid but assurance is below the identity's requirement.
DELAY
New device or region — recovery completes after a waiting period.
MANUAL_REVIEW
Conflicting evidence, or the identity administers entities.
DENY
Evidence fails, or the request matches a known attack pattern.
Start recovery
Recovery never reveals whether an identifier exists, and never authenticates with a value instrument such as SmaiPin.
Not yet enforced: Recovery requires evidence verification, rate limiting, delay timers, review queues and notification fan-out to affected entities.