- Auth API for developers · v1 live on zeroauth.dev
+ Built on Pramaan™ · Indian Patent IN202311041001 (Granted)
Authentication where a breach exposes nothing.
- Drop-in API. Zero-knowledge proofs.
+ Drop-in API. Zero-knowledge biometric proofs.
- ZeroAuth is an auth API that replaces stored credentials with zero-knowledge proofs.
- Ship signup, login, and device attestation in minutes — with no passwords in your database and no secrets on the wire.
+ ZeroAuth is the developer-facing auth API for Pramaan — the patented zero-knowledge biometric identity protocol from Yushu Excellence Technologies.
+ Raw biometrics never leave the device. Commitments & Groth16 proofs are all the server ever sees.
+ Ship signup, login, and device attestation in minutes.
Start building free
@@ -974,7 +1017,7 @@
1. Get an API key
2. Register a user
- POST a commitment from the client SDK. ZeroAuth stores the commitment — never the underlying secret.
+ POST a Poseidon commitment from the client SDK. ZeroAuth stores the commitment — never the underlying biometric.
3. Verify the proof
@@ -1110,10 +1153,10 @@
Open source
-
How It Works
+
How Pramaan Works
Three steps. Zero secrets exposed.
- ZeroAuth uses zero-knowledge proofs to let users prove their identity without ever revealing credentials — not to your servers, not to anyone.
+ ZeroAuth implements the Pramaan protocol: the user proves they hold a biometric on their device, and only a Poseidon hash commitment + a Groth16 proof ever cross the network. Raw embeddings stay in browser/app memory and are GC’d after hashing.
@@ -1162,9 +1205,9 @@
Verify On-Chain or Off
Live Demo
-
See it in action — 60 seconds, zero secrets.
+
See Pramaan in action — 60 seconds, zero secrets.
- Watch a complete authentication flow: biometric scan, ZK proof generation, SSO access, and a simulated breach that exposes nothing.
+ Watch a complete Pramaan flow through the ZeroAuth API: biometric capture, Poseidon commitment, Groth16 proof generation on-device, server-side verification, and a simulated breach that exposes nothing.
@@ -1181,7 +1224,7 @@
See it in action — 60 seconds, zero secrets.<
The Math
What a breach actually costs.
- In 2023, Okta's breach exposed every support customer's data. Here is the same scenario with ZeroAuth.
+ In 2023, Okta’s breach exposed every support customer’s data. In May 2024 an Indian Army contractor leaked 496 GB of biometric data. Here is the same scenario with Pramaan.
@@ -1226,7 +1269,7 @@
What a breach actually costs.
-
ZeroAuth
+
Pramaan + ZeroAuth
Same breach scenario
@@ -1262,20 +1305,30 @@
What a breach actually costs.
-
Intellectual Property
-
Patent-Protected Technology
+
Pramaan™ — The Underlying IP
+
ZeroAuth is the API. Pramaan is the patent.
- ZeroAuth's core cryptographic protocol is protected by granted and pending patents across multiple jurisdictions.
+ Pramaan is the zero-knowledge biometric identity protocol behind every ZeroAuth verification — commitment hashing, Groth16 proof, on-chain anchoring on Base L2, and DDIL-grade offline verification. Granted to Yushu Excellence Technologies Pvt. Ltd. Read the full technical whitepaper →
-
+
Granted
-
Indian Patent
-
202311041001
+
Pramaan™ Protocol
+
IN202311041001 · India
+
+
+
+
+
+
Owned by
+
Yushu Excellence Technologies Pvt. Ltd.
+
Inventors: Amit Dua, Pulkit Pareek
@@ -1377,23 +1430,28 @@
Request received
Technical Deep Dive
-
White Paper
+
Pramaan™ Whitepaper
- The cryptographic foundations, architecture, and security proofs behind ZeroAuth.
+ 25 pages on the protocol that ZeroAuth implements: architecture, cryptographic design, security analysis against 9 attack vectors, performance benchmarks, and regulatory compliance posture.
ZK-SNARKs
Groth16
- Poseidon Hash
- Enterprise Auth
+ Poseidon
+ Base L2
+ DPDP 2023
+ DDIL
-
ZeroAuth: Zero-Knowledge Authentication for the Enterprise
-
Covers threat model analysis, protocol design, circuit architecture, on-chain and off-chain verification, and deployment strategies.
+
Pramaan: Zero-Knowledge Biometric Authentication
+
+ Technical architecture & security analysis. Covers system design, registration + authentication + offline flows, Sybil/identity-binding model with LSH deduplication, Poseidon hash construction, Circom 2.1.9 circuit details, Groth16 proof system, on-chain anchoring on Base L2, threat analysis (server DB breach, device capture, MITM, replay, …), and a regulatory annex covering DPDP 2023, RBI Video-KYC, UIDAI independence, and GDPR.
+
@@ -1421,7 +1479,7 @@
ZeroAuth: Zero-Knowledge Authentication for the Enterprise
ZeroAuth
-
+