SmaiID
V1 · AAL2
SH

Recovery

Recovery is the most attacked part of any identity system. SmaiID grades the evidence you present and answers with a graduated decision — never a simple yes.

Recovery readiness

Three strong factors configured. Readiness: good.

Recovery codes

8 of 10 unused. Generated 19 Apr 2026.

Ready

Trusted passkey on a second device

Pixel — Personal, device-bound.

Ready

Backup email

Verified 12 Feb 2026.

Ready

Backup phone

Optional. Not configured.

Optional

Trusted contact attestation

Optional. Useful for high-assurance identities.

Optional

Recovery decision engine

Every recovery attempt resolves to one of five outcomes, recorded as a security event.

ALLOW

Strong evidence from a trusted device in a familiar region.

STEP_UP

Evidence is valid but assurance is below the identity's requirement.

DELAY

New device or region — recovery completes after a waiting period.

MANUAL_REVIEW

Conflicting evidence, or the identity administers entities.

DENY

Evidence fails, or the request matches a known attack pattern.

Start recovery

Recovery never reveals whether an identifier exists, and never authenticates with a value instrument such as SmaiPin.

Not yet enforced: Recovery requires evidence verification, rate limiting, delay timers, review queues and notification fan-out to affected entities.