Back to ResourcesData Protection

The Safest Data Is the Data We Never Collect

7 min read · Updated September 2026

Kred is built offline-first. By default, the identity data your scanner reads never leaves the device — so there is no central archive of your patrons for anyone to breach. Here's what the latest industry breach revealed, and why a collect-less approach changes the math.

The Safest Data Is the Data We Never Collect

In this guide

  • What was reported
  • Why a leaked ID scan is worse than a leaked password
  • Nothing leaves the door — by default
  • We don't keep pictures of IDs
  • Encrypted in transit and at rest
  • Separated for every customer
  • Switching from another provider?

153M+

U.S. and Canadian driver's licenses reportedly offered for sale on a dark-web marketplace tied to a single ID-verification vendor (KrebsOnSecurity, September 2026).

What was reported

In late August 2026, a dark-web service called Nexus began advertising a searchable index of scanned identity documents. According to KrebsOnSecurity, who first traced the operation, the listings included more than 153 million U.S. and Canadian driver's licenses, alongside millions of additional ID cards, travel documents, and medical-program cards.

Reporting by NBC News and Engadget linked the data to a Louisiana-based identity-verification vendor, and the FBI's New Orleans field office confirmed it had opened an investigation. Researchers reportedly connected confirmed samples to routine ID checks at car-rental counters and cannabis dispensaries — and, according to those reports, even the license of a sitting cabinet official.

Important context: the vendor has said it is investigating and has not confirmed the scope or cause, and the headline totals are the marketplace's own claims. What is not in dispute is the shape of the exposure — and it is worth understanding, because it explains why this kind of breach is so damaging.

Why a leaked ID scan is worse than a leaked password

A stolen password can be reset. A cancelled card can be reissued. But the reported material here was not a table of text — it was imagery of the physical documents themselves: the same captures anti-fraud hardware uses to confirm a license is genuine, per CSO Online and Malwarebytes.

You cannot reset your face, your date of birth, or your home address. Once high-fidelity scans of a real ID are circulating, they can be reused indefinitely to assemble convincing synthetic identities and defeat the very checks meant to stop fraud. That is the cost of pooling this data in one place.

Nothing leaves the door — by default

A scan is read and checked on the device in your staff's hands. Unless a venue deliberately turns on multi-location sync, that data is never transmitted to us and never stored in the cloud.

You can't lose what was never collected — and most of our customers never collect it. There is no central pile of patron records for an attacker to find, because Kred doesn't create one.

We don't keep pictures of IDs

Kred reads the barcode on an ID and retains only the specific fields a venue actually needs to do its job. It does not photograph, scan, or store a copy of the license itself.

The exact kind of data taken in recent industry breaches — images of scanned identity documents — is data Kred is simply not built to hold.

Encrypted in transit and at rest

For venues that choose to sync across locations, personal information is encrypted before it is stored and encrypted again every time it moves across the network, using strong, modern, industry-standard encryption.

A stolen copy of stored data is unreadable without the keys that protect it.

Separated for every customer

Each organization's data is protected by its own dedicated encryption key, kept apart from the information it protects. There is no shared master key and no common pool of records spanning customers.

That means no single point of failure can expose more than one customer's data — the opposite of the model behind the headlines.

Switching from another provider?

If a scanning vendor keeps everyone's IDs in one central database, a single breach can expose every patron at every venue at once. Kred is engineered the other way around — fewer copies, in fewer places, each locked separately:

  • The honeypot model — images of IDs pooled together in one place. This is the exact shape of the breaches making headlines.
  • The Kred model — most data never leaves the device, only the fields you need are kept, and anything synced is encrypted and isolated per customer.

Frequently Asked Questions

Was Kred affected by this breach?

No. Kred is not the vendor named in these reports, and our design is fundamentally different: by default, the data your scanner reads stays on the device and is never sent to us, and we don't store images of IDs at all. There is no central archive of Kred customers' patrons to breach.

I only run one location — does this matter to me?

Yes, and the news is good. Kred works the same whether you're a single bar, restaurant, pawn shop, or a national chain. For a single venue, scans are read and checked right on the device and nothing needs to leave your door — you get the fraud protection without ever becoming part of anyone's central database.

Does Kred store photos of my customers' IDs?

No. Kred reads the barcode and keeps only the specific fields a venue needs. It does not photograph or store a copy of the license — which is exactly the type of data exposed in recent breaches.

We use another scanner today. How hard is it to switch?

It's straightforward, and we're glad to walk your team through exactly how it works for your locations. Contact us and we'll map it to your setup.

Sources

Bring your questions — and your attorney

We're glad to walk your team through exactly how Kred handles your venue's data, and how a switch would work for your locations — whether you run a single bar or hundreds of sites. This page describes our approach in general terms; we're happy to review the finer points with prospective customers and their advisors under a confidentiality agreement.

We Value Your Privacy

We use cookies to enhance your browsing experience and analyze site traffic. By clicking "Accept All", you consent to our use of cookies. Read our Privacy Policy for more information.

Questions?
(877) 835-4635