Skip to content
ADR-0027Architecture decisionAcceptedversion 1.0.02 October 2026

Context ​

SPEC-WALLET-0001 sets two rules:

  • WL4: presentation_log does not leave the device; it is not included in backups.
  • WL2: a backup carries the credentials and the manifest, not the keys.

Rationale: a record of what was shown to which doğrulayıcı (verifier)Gösterilen belgeyi denetleyen taraf: imza, belge verenin güven listesindeki kaydı, durum ve politika. Relying party diye de anılır. is the person's behavioural profile; collected on a server, it becomes a central tracking tool.

The EU position is different:

  • CIR 2024/2979 Art. 9 and 13 and ARF (Architecture and Reference Framework)Rolleri, mimariyi, güven modelini ve kuralları anlatan belge seti. Tamga ARF, AB ARF'sinin düzenini izler. topic 34 (DASH_07, MIG_*): the wallet keeps a transaction log. The person can export a migration object containing the log and the list of their belge (credential)Belge verenin imzaladığı ve kişinin cüzdanında duran dijital belge; kişi yalnız istenen alanları gösterir.s, and import it into a new wallet.
  • TS10: defines the format — a JSON data model, a password-encrypted JWE (PBES2-HS256+A128KW + A128GCM).

The EU gap analysis (H1, P5) left this open. The migration object code was written (wallet-core ts10.ts), but because WL4 was a closed decision the log was not included in the file, and the log export button on the history screen (added for DASH_07) was disabled.

Decision ​

K1 — The text of WL4 ​

The presentation log and the event log leave the device only in an export started by the person themselves:

  • TS10 migration file: encrypted with a password the person chooses; at least 8 characters; PBKDF2 with at least 200,000 iterations.
  • Transaction log export: TS10 §4.1; the same encryption.

The file goes wherever the person chooses through the operating system's share menu.

Under no circumstances:

  • is an export made automatically or in the background,
  • is anything uploaded to a Tamga server or any other party's server,
  • is a server-side backup taken (SPEC-WALLET-0001 §7.1 stays as it is).

K2 — Content limit ​

Credential values, copies and keys do not go into the file. The log contains only:

  • field names,
  • verifier or institution information (from the güven listesi (trust list)Bir ülkenin kök sertifikalarını, belge verenlerini ve kayıtlı relying party'lerini taşıyan imzalı liste. Bugün Tamga'da güven bu listelere dayanır; ortak defter sonra gelir.),
  • time and result.

In the new wallet the credentials are obtained again from the institutions (WL2 unchanged).

K3 — No unencrypted export ​

There is no plain JSON log export (exportLog); the log is exported only in the TS10 encrypted format.

Rationale / alternatives ​

OptionResultWhy
WL4 unchanged, the log is never exportedrejectedThe EU requirement (CIR 2024/2979; TS10) is not met; the person cannot reach their own data
Encrypted log backup on a Tamga serverrejectedBehavioural data accumulates centrally (metadata even if encrypted); against the purpose of WL4
A file only the person starts, encrypted with the person's passwordacceptedEU-compliant; the data stays under the person's control, Tamga never sees it
Plain JSON exportrejectedThe file stays readable in file-sharing apps

Invariants ​

CodeRule
LX1The log leaves the device only in an export the person starts, encrypted with the person's password (TS10 §5); there is no automatic or server-bound export.
LX2The exported log and the migration file contain no credential values, copies or keys.

Status ​

Accepted — 2026-09-29. Approved by project management (EU approach for pending decisions). DECISIONS: D-WALLET-2.

Implementation:

  • the SPEC-WALLET-0001 WL4 text is written according to this decision,
  • log export is enabled in the wallet (TS10 §4.1, password-protected),
  • the migration file includes the log; on import the person is asked whether to restore the log (ARF Mig_07b),
  • there is no plain JSON export.