Interviews
Nate Soffio: Reusable Identity in Financial Services

Zack Jones
·
·
2 min read

In this episode, we sit down with Nate Soffio, Co-founder and & CEO of Portabl. Nate is applying decentralized identity to fintech and open banking, which is such an important but also challenging use case.
We discuss the ins and outs of Portabl’s user experience and how it differs from other reusable KYC products. Nate also provides insight into lessons learned, deliberate product decisions Portable has made, and common mistakes he has seen IDtech founders make.
This episode should be useful for anyone interested in fintech or adding SSI to their identity stack.
To contact Nate or to learn more about Portabl, reach out to hello@getportabl.com.
Reach out to Riley (@rileyphughes) and Trinsic (@trinsic_id) on Twitter. We’d love to hear from you.
Full Transcript
Transcript lightly edited for clarity.
Riley Hughes: Welcome to the Future of Identity podcast, where we talk to the people building the ID tech products of tomorrow. I’m Riley Hughes, co-founder of Trinsic, and we build infrastructure for launching awesome identity products. In this episode, I sit down with Nate Sofio, co-founder and CEO of Portabl. Nate is applying decentralized identity to fintech and open banking, which is such an important but also challenging and nuanced use case. We discuss the ins and outs of Portabl’s user experience and how it differs from other reusable KYC products. Nate also provides insights into the lessons learned, deliberate product decisions that Portabl has made, including how they’re tackling the chicken-and-egg problem, and common mistakes that he has seen ID tech founders make. This episode should be useful for anyone interested in fintech or adding SSI to their identity stack. Now, onto the episode with Nate. Nate, how are you doing?
Nate Soffio: Doing all right. Thanks for having me on. Really thrilled to be here and be part of that roster of awesome guests you’ve had over the past, howdy year now, is it?
Riley Hughes: Yeah, it’s getting close. So yeah, glad to have you as well. I kind of want to start off this conversation by, like, stating an opinion of mine, and then if you disagree, I would like to ask you to refute it. You’re focused on the financial services vertical, which I’ve thought for the last five years or something like that is, well, if I was to hone in on the reusable KYC use case, it feels like it’s simultaneously the single most brain-dead obvious use case for verifiable credentials, but it’s also the most, like, mind-bendingly challenging one to actually pull off. I feel like it’s consistently been a go-to example that people have used, and yet… I haven’t seen it in the real world very much. So, curious if you would agree with that framing, or a few things I’m missing something there.
Nate Soffio: Yeah, I think you’re spot on. I guess first things first, reusable KYC in financial services is actually kind of a misnomer, at least in our opinion. KYC is just one component of the broader reusable identity approach for financial services that encompasses identity, account information, transactional behavior, and card information. So if you look at it from our perspective, all of those things taken as a whole are more comprehensive of who you are, what you are, what you do, what you know, and what you have, to borrow a phrase from the authentication universe. And starting with verifiable credentials as a core and building out the data and authentication frameworks around it is what allows us to have this holistic sort of passport approach to financial access. It is in some ways similar to what we’re seeing in Canada and the EU regarding this once-only verification regime. It’s playing SSI in hard mode in financial services.
Nate Soffio: And there’s a bunch of reasons why we can talk about why it’s hard, but I’m wondering if we can more talk about the many different reasons why it’s super obvious why this needs to exist in financial services, because some of those reasons actually may not be super obvious to some of the audience out there.
Riley Hughes: Yeah, let’s do that. I think just to frame it, what I have in my head when I say this is a super obvious use case is just financial institutions are mandated to know who their customers are. So first of all, you’ve got somebody who needs to do this and is already doing it. And if somebody comes along with a better mousetrap, seems like logically they might be interested in that. And then the other reason is that financial access is such a fundamental part of our lives, both in person and online. You know, as we go about our lives, we’re constantly paying for things. We’re constantly using different fintech apps or banks or credit cards or what have you to get about our lives. And so we end up constantly having to re-verify ourselves over and over. You probably know better than me, but it seems like the average consumer has something like, you know, two, three, four credit cards and a number of other financial products. So it feels like those two things combined make it, like, obvious in my head. What else is there?
Riley Hughes: What are some of the kind of non-obvious reasons why this is such an obvious use case?
Nate Soffio: Yeah, so this is kind of key to how we view the problem, and it’s kind of a turtles-all-the-way-down sort of mindset about the problem. So it’s a combination of the traditional gripes that kind of everyone has with identity verification, as well as gripes with open banking connectivity and aggregators.
Riley Hughes: Could you take just a minute to explain what open banking is? So I’ve realized that sometimes when I talk about this, I take that for granted, that it’s just something that I talk about a lot, and I think there are a number of folks maybe it would be helpful to explain that further.
Nate Soffio: Definitely. So I’ll talk about it in context of, like, part B of the gripes. But part A of the gripes is, like you said, doing KYC, IDV over and over and over again is just a terrible experience for consumers and businesses alike. It’s expensive, it’s high friction. We colloquially call this the from-scratch problem at Portabl. And the 50% drop-off rate in the financial services industry is one of the many telling proofs that there’s a ton of money left on the table because identity is still not really solved. And somewhat obviously, that trust doesn’t travel with the user, and it leads to things like data fragmentation and stuff I’ll get back to in a second. But the second set of gripes around open banking, there’s a couple things there. So to level set with folks out in the audience, open banking effectively is sets of technology, whether it’s screen scraping, and much less so these days, and more so API connectivity that allows certain relying parties like fintech apps to make specific permissioned requests of underlying bank account data or identity data or other kinds of bank.
Nate Soffio: bank-verified data. So the classic examples of this would be any time you’ve, say, connected an investment app like a Robinhood or a Public or a Titan to your bank. You probably used Plaid or MX or Teller or a couple of the others in order to supply information from the underlying bank to the app. It could be information around transactions. It could be around balances, debts. It could be around things like account validation that says, I’m the correct owner of this routing number and this account number, so I’m authorized to use this DDA account or demand deposit account over in this bank to go fund my Robinhood activity over here. So that’s kind of the very, very super high-level summary of what open banking intends to do. And it’s all geared around consumer providing permission for those data sharing events.
Nate Soffio: But if we set that as the stage for kind of what open banking is designed to do, which is facilitated interoperable flow of data from point A to point B with the user’s thumbs up, there’s still a lot of friction there, even though it’s sounding like a pretty big advancement, and it is. But open banking connections still, for instance, force re-authentication. So if I’m connecting my Chase account to my Betterment account, if I’m signing up for Betterment, I’m still going to have to go log into Chase, do an OTP, do that rigmarole to say that this account is authorized to communicate with this other account. Those connections also sometimes break. So if you’ve ever had a longstanding relationship with some other fintech app and you may have gotten an email saying, Hey, can you please reconnect your bank? And despite other parts of the onboarding processes or authentication processes moving more and more towards passwordless and MFA, auth for banks governed by aggregators is still kind of passwordful. And so true passwordless financial access is a bit of a misnomer.
Nate Soffio: Beyond that, there’s basically only a handful of aggregators. So there’s a concentration of connectivity among a few providers, which kind of creates other types of ecosystem risk. This is where we get really into something that feels more self-sovereignty oriented, is that despite the consumer permissioning baked into those open banking interactions, there’s a lot that’s still kind of sort of hidden from the user: revoking authorizations, how is my data stored, are the connections persisted after I’ve closed the account on the other end, what’s going on there? I don’t have as much visibility into this data in the plumbing as I probably would like. And the kind of end state of this, if you will, is where open banking and identity reintersect. And that is where user data fragmentation is rampant.
Nate Soffio: So users, you, me, folks watching this podcast or listening to this podcast, are burdened with managing the connected accounts, the permissions, the privacy settings across every downstream app and provider they use without having any sort of, like, headquarters for where all this data is going. And certainly no one yet has solved for having that headquarters having both read and write. capabilities. So you have stuff spread hither and yon through open banking connectivity. You’re also repeatedly KYCing yourself to join different stuff. So you’re fragmented every which way. And so this is why it’s kind of two dovetailing sets of frustrations. One kind of pure identity discussion. The second is the open banking connectivity sprawl, and where they re-intersect is the fact that our data and information is kind of a little bit everywhere, with not enough, you know, user-friendly management of it yet in the marketplace. So it’s kind of logistically hard for that reason.
Nate Soffio: And I’ll pause there even before I get into, you know, the regs and kind of other pieces of the market that make it particularly difficult.
Riley Hughes: Yeah, I see the problem. I’ve experienced the problem, the fricking authorizing my bank account over and over to these fintech apps, etc. If we were to come full circle, you know, you mentioned playing SSI on hard mode, which is a little bit of a funny statement because SSI is really hard to begin with. How does this stuff play into why it’s so challenging to bring a product to market here?
Nate Soffio: I think one, it’s because of the complexity of the claims involved. I think there’s some easy stuff like, say, an address, or where you might have to do name, address, some other claims, and it’s bound by an evidence object that’s a driver’s license. This stuff on the books for how that’s done, ditto with email or phone or other core claims. But what makes it particularly difficult is that we have to answer to the OMB, the CFPB, all of these other regulatory bodies. As a result, we have to reconcile things like W3C standards and DIF recommendations. With the shifting expectations around KYC and AML laws, the Bank Secrecy Act, and stuff like that. Because there’s a very, very fine line between where SSI starts and stops being compatible with how anti-money laundering regulations and rules work.
Nate Soffio: And so you have to be very, very mindful of if you’re now putting everything much more transparently into consumer control, you also need to make sure how you implement standards literally doesn’t accidentally break the law or make an implementing party noncompliant, because that’s the last thing that you want to do. That’s a challenge. Some of it is just working backwards. So, like, okay, if I’m building verifiable credentials and DIDs, that it give you the enhanced privacy and security that everyone wants, how do you prove that it’s backwards compatible with, say… NIST? So those are the regulatory kind of red tape sorts of challenges that make it hard. But the real practical day-to-day running a company challenges really comes down to market momentum and incumbents. You have the aggregators, you have traditional KYC providers and identity orchestration platforms doing huge volumes in the United States and now globally. Cutting through all of the market incumbency is pretty tough.
Riley Hughes: Well, I wonder if we could get a little bit to your solution now. Is it like I get KYC’d with you and I can reuse it elsewhere, or is that too simplistic?
Nate Soffio: So that’s certainly part of it. You know, the traditional SSI model has a verifier, a holder, and an issuer. And you can also assume that issuers and verifiers can freely verify an issue, so swap those roles. We now have this kind of four-body problem because Portabl is built in a way where we empower holders, but we can also do our own verifications. And so it ends up being sort of an SSI-powered version of, you know, a Remember Me, but not something that’s just geared toward verify once and verify everywhere. But now we have these kind of additional capabilities around update once and update everywhere. So for us, Portabl stands as kind of this fabric through which verifiers and issuers can do their thing, kind of according to spec and according to— What we’d expect out of an SSI transaction. But we also kind of this souped-up intermediary for consumers. I can see my connected accounts. I understand what data is being shared where. I understand what’s been validated and verified by what parties.
Nate Soffio: If I need to update something on file, I can do it once in Portabl and push it to wherever it needs to go. So for us, it’s a bit of a mix of, say, single sign-on with all of the hard data coming along for the ride in ways that are selectively disclosable. But it’s also a little bit Venmo-flavored or PayPal-flavored. But instead of having cards on file and cards being pointed at specific merchants, you have claims and credentials on file that you can share with different reliant parties and update those claims and keep things ironed out dynamically. Our tech lead, Ben, once had—was speaking off the cuff in a decom session when we were talking about how we build the infrastructure to allow people to kind of self-manage and propagate data where they need. And he just off the cuff said, We want to allow people to get to identity inbox zero.
Nate Soffio: That brought the entire call to like a screeching halt because it really honed in on what we’re trying to do for consumers at the end of the day, even though we are identity infrastructure, and that’s to stop the sprawl and make transparent identity management a lot easier. Because like you said, people have three, five, seven accounts, cards, things where their data is spread around. The easiest way to help people get to kind of a useful canonical understanding, which over 90 percent of people want. is through the use of credentials, because it has this naturally sort of forming entity resolution effect within the app or within the wallet of the user. And so that’s something we keep in mind quite a bit. And I say that’s where we’re all a little different. I could certainly get into more of our differences. At the end of the day, if you mashed up SSO and, like, PayPal, it would be kind of what we’re after. If I can use Google SSO to get into something, I can use Portabl to authenticate and consent and go join some fintech app on the other end.
Nate Soffio: We really want to get that process down to two steps. We can do some dynamic kind of fill-in-the-blank stuff as well, because data is not perfect. People might have missing claims. But really at the end of the day, it should be two clicks, basically in all circumstances. Whether you’re applying for a loan or a mortgage or a credit card, opening up a bank account, opening up a brokerage, it’s connect your Portabl account, do what we have under the hood for auth, consent to share the information that you have stored as claims, off it goes. It can be verified. The relying party can consume it as they see fit, and we can definitely debate about what consumption means. And then that’s another credential for you to manage and have transparency over going forward. So there’s a lot of abstraction that happens there. But at the end of the day, it’s not just about onboarding. Far from.
Nate Soffio: It’s the entire life cycle of verification and kind of continuous identity management, as much as it is for the businesses as it is for the individual who wants to just have a headquarters for where all their information is being shared.
Riley Hughes: Well, I love the concept of identity inbox zero. That’s fantastic. Yeah, I just moved. So I am identity inbox, like red flashing notifications everywhere right now, and I sure wish I had a way to get to Identity Inbox Zero. I think I can conceptualize your product both from why it would be beneficial at an onboarding step, as well as on a continuous basis for updating and revoking and things like that. But you mentioned this is for both the business and the consumer. And here’s the inevitable conversation of almost every single one of these podcast episodes. That sounds really useful if you’ve got a bunch of consumers there that can easily onboard into businesses or who can push new updated data to those businesses. Or if you’ve got a bunch of businesses that are there, consumers might want to do that because it’s a streamlined process. But, you know, how do you think about the chicken and egg problem at Portable before you can have the fast lane for fintech, you need the ticket holders to exist and vice versa.
Riley Hughes: Now, how are you tackling that, and what are some strategies that you’ve employed to tackle that problem?
Nate Soffio: Yeah, so this is a great question that I think I’ll probably answer in two parts, because I want to talk first about what we decided not to do and why. You’re a founder, you’re an operator. You know, like the cardinal sin is building in the wrong direction. And, you know, thankfully, we’ve largely avoided that so far. And the biggest thing that we did when Alex and I sat down in mid-late 2021 and said, Okay, what’s going on in the market? What’s going on with the standards that we think are the right choice here? The first thing we did is said, Let’s go to the startup graveyard and see who tried stuff and find the, like, common denominator of why they died, failed, became zombies, what have you.
Riley Hughes: How did you find those graveyard companies? Because there’s been times where I’ve found out about a company that existed eight years ago or something that I wish I would have known about earlier. So how did you actually do that?
Nate Soffio: We asked our investors. We asked advisors. We asked people who contribute to W3C and DIF projects. And we just kind of did a lot of Googling, to be totally honest. It was just, by whatever means necessary, find companies that have, like, tried this, worked in this space, dabbled in this, that, or the other sets of keywords. And say, whose last, you know, Crunchbase record was like over 12 months ago, something like that. And so we went to the graveyard and we saw a bunch of apps, we saw a bunch of like pure wallet plays. We were both fascinated by the number of pure-play wallets there were. Some were issuing tokens, some were issuing like SBTs or NFTs. Others were trying to do like the aggregator thing. But they all kind of died on the vine because of a very common startup misstep slash misconception, which is if, oh, if you build it, they will come, which is 110% incorrect in 99% of cases. And so we said, okay, this is obviously the wrong way to do it. Clear pattern here, clear cause of death. And so we knew from that moment on, we had to be infrastructure first.
Nate Soffio: So then really the only path-dependent question for us is, are we B2B or are we B2B2C? And then we said, we have to be B2B2C. There’s no such thing as B2B SSI. It doesn’t work that way. So long as consumers are holders of credentials and need to administer their own PII on an initialization and ongoing basis, you have to be B2B2C. So this was the commitment we made to ourselves and our team and our architecture and our product from graveyard day and plus one.
Riley Hughes: Can you clarify, when you say you had to be infrastructure first, what do you mean by that? Because presumably the infrastructure is in service of you building an app, right? And then why could you not pick up existing infrastructure or open source frameworks or something like that and build the same kind of app, assuming they had comparable functionality?
Nate Soffio: First things first, like we still use W3C conventions under the hood for DIDs and VCs. Ask me anything about DID Ion and I’ll go on a rant. And we knew like interop is critical. As well as being compatible with a bunch of the other nascent stuff that’s going on, whether it’s NIST, UDRF, something else, we knew that all of these, like, background things that govern our environment have to still be satisfied. And so we knew we couldn’t, like, way go off script. On the other hand, the team has over 50 years of experience now, and Alex and I alone have over 20 in this space. And so we knew that the current infrastructure, as it was, at least when we were getting started in 2021, parts were really smart, and parts were just simply not there yet for the kinds of things that we knew that we needed to do for identity, for account-based information sharing, for other types of ongoing identity stuff, not just verify once, verify everywhere, but update once, update everywhere.
Nate Soffio: We knew that there was stuff that we just needed to do from scratch that uses the standards in ways that haven’t really been used before. And so we said, okay, we’re going to build the infrastructure and be the, like, identity-as-a-service company that solves for SSI and finance with just a couple north stars. If you’re a consumer, if you can use Venmo or Google SSO, you should be able to use Portable. If you’re a business, if you can set up Stitch or Treasury Prime, which is a banking-as-a-service company, you can set up Portable. There’s a lot we can abstract, there’s a lot we can simplify, and we just need to build for where the pain is. Those are the north stars. That’s kind of the prime directive if you’re a Star Trek person. And in order to achieve that, we said, okay, existing solutions will get us halfway there; the other half we’re just going to have to do ourselves.
Nate Soffio: That set the stage for How we decided to build, the way we decided to see some of these problems with root of trust, information, re-verifiability, circulation, real-time updates, stuff like that, and how that’s affected how we go to market is it all comes down to going where the users are and incentivizing issuance. This means going to other types of financial services infrastructure providers where there’s large networked populations already who would love to build trusted networks that are smarter, more efficient, more cost-effective to boost deposits, improve under- underwriting, boost conversions, while driving down the cost of verification and acquisition. If I’ve seen Riley over here as a banking-as-a-service provider, it makes no sense to do re-KYC him from scratch over here in another corner of my own ecosystem. It feels really silly, and it’s not very good in terms of the balance sheet. So for us, that’s something we’ve been spotting on repeat.
Nate Soffio: That was kind of a long-winded answer of saying, okay, here’s what we didn’t do, which means here’s what informs how we’re going to build stuff, which is then informed for the early days of bringing reusability into market.
Riley Hughes: Yeah, I can see how you’ve gotten to where you are. Now, if we kind of go one layer deeper on that chicken-and-egg issue, it sounds like one lesson that I can extract here is find somebody who’s got an existing network, but that it’s not sort of a trusted network in the sense that maybe identities aren’t persistent or reusable across that network despite people being seen more than once within that network, and you can sort of drive efficiencies there. I think that’s one really solid takeaway that I think will be really helpful for the listeners. I listened to a webinar that you did for the SSI meetup, and you talked about some interesting things around incentivizing issuance without paying the issuers. I thought that was really kind of fascinating, and wonder if you think that it’s relevant to expand on that at all here.
Nate Soffio: Yeah, so I like talking about issuance because there’s a lot of non-intuitive value that comes from re-enabling a user with their own identity. And this actually is sort of derived from the parable of UK open banking. So it was maybe, I don’t know, easily over five years ago at this point. Hopefully somewhere out in your listenership, like Simon Taylor or someone can pin me down on the exact date. But the point is, when all of the open banking regs were coming to pass in the UK, all of the banks were, like, quite bristled about it because they said, Oh, by instituting data standards, all my customers are going to leave. What came to pass is that very few customers actually left their home bank. In fact, it was maybe 1%. It was, like, very, very small. It was marginal. And the UK banks that most fully embraced the open banking standards around data interoperability, reuse, stuff like that, ended up with the highest TLV and NPS, or to clarify, total lifetime value and net promoter score.
Nate Soffio: So really what we learned is those banks that leaned furthest into data sharing and reuse had kind of reaped the biggest rewards because they were the bundling accelerant that their users wanted to go do other things in their financial life that their home bank could not do. And so we take that parable and we said, Hey, this same thing applies to SSI. If you can give an identity credential back to your users, it could be in Portable, it could be Chase ID powered by Portable, what have you, say, Hey, we also now have these downstream affiliates. You can go join these affiliates with your Chase ID and get XYZ BIPs on a portfolio or premium for three months or something like that. Why? Because the cost of re-originating someone using a credential-based method from a trusted signer, it can be much, much cheaper. It creates economic surplus that you can then turn back into perks for retention, promotion, things like that. So this kind of natural path to saying, okay, what did we learn from open banking?
Nate Soffio: How do you turn the knob around to 11 and let it run, but on a verifiable credentials basis?
Riley Hughes: And how does that benefit the original issuer? I understand that there’s perks that the user could get from other sources. Presumably that builds some goodwill, I guess, with the original issuer. Is that kind of the idea, or is there more here to unpack?
Nate Soffio: It’s goodwill, but there’s also something that’s called home account advantage. It’s basically a stickiness factor. Going back to the UK example, if your users are going to churn, just because these new standards in place is not going to stop them from churning. If you’re not meeting their needs, they’re going to go elsewhere, whether it takes a lot of effort or a little effort. However, if you can now empower them to do other stuff outside of the core services that you can already provide them, you’ve suddenly gotten super extra sticky. What that means is that you’ll have less churn, and that kind of spirals out into goodwill, word of mouth, upselling and cross-selling, things like that. That’s the stuff that’s kind of the first-order effects of these identity-powered experiences. Now, there’s others, I think, in other parts of the SSID world, some of whom kind of model some of this stuff on tokenomics and some who don’t, who think that, like, the issuer should be compensated.
Nate Soffio: There are some potential ways where we can do that with, like, things like account credits, but I think it would be very difficult in the short term, at least, to try and set up infrastructure whereby Robinhood is, like, paying Chase for a credential. I think it’s tricky. It introduces a complexity that is potentially harmful to our sales cycle, and I think would raise a lot of eyebrows, to put it mildly.
Riley Hughes: Yeah, it’s like when I’ve had these conversations with issuers, a lot of times they’re like, we’re talking to the wrong person for that. We’re not talking to the person in charge of coming up with new revenue line items for the company. So it’s almost just a distraction from the job to be done for that individual. I’m not going to say that it’s always a bad idea or anything like that, but it’s often met with some kind of blank stares and some cartoonish question marks above the head sort of thing, right?
Nate Soffio: And now things may change in the medium term or the long term, like Fifth Third Bank and Newline is a really good example, where it’s a bank that started creating their own banking-as-a-service that becomes a revenue-generating stream for the bank. Cool. I think it’s quite honestly too early to say whether banks will spin up their own identity-as-a-services services, or whether instead SSI becomes sort of the next phase of what banks and fintechs have done with, say, open banking connections.
Riley Hughes: We’ve spoken a little bit about your product and some of the features that it has, including things like being able to update your information as well as receive it and as well share it, et cetera. I wonder if we could get more specific into the actual product form factor that it takes and maybe some of the trade-offs that you thought about when developing it in the way that you did. So maybe take us from a high level. What is this product like for a user? You mentioned if they can use Venmo or Google SSO, they should be able to use Portabl. Now if we go one level deeper, what is it really like for the user using it?
Nate Soffio: Yeah, sure. I’ll start off with probably the most controversial headline, and I’d love for your hot take on this. We’re actually appless by design, at least for now, or until we start operating in a geography or regime where non-custodial approaches are required. But for now, we are appless and custodial because it’s what the vast majority of people feel comfortable with and are comfortable with using. With respect to design patterns, language framing, workflows, everything else. So that’s kind of the biggest thing that I would accentuate, is that it’s appless by design. For your first time as a user, if you’re joining Riley Bank and you’re accepted to Riley Bank, you can opt in to using Portable. And sort of in the way that, like, Magic spins up Web3 wallets, we will spin up your non-wallet wallet in the background that you can get back into at any time and see your Riley Bank credential, or update it remotely and push data to Riley Bank. That’s kind of a fundamental experience that we have and we thought long and hard about.
Nate Soffio: Or if you’re a longstanding happy user of Riley Bank and Riley Bank turns on Portable, and I’m an existing customer, I can go request a credential or a reusable ID from within my own account. Same sort of thing, spins it up, send me invisibly in the background, hey, view your data at any time. And if you’re a consumer, it’s just my.getportable.com, passwordless auth into there, and it looks and feels pretty much like an identity wallet that you would expect, or at least one that’s using a lot of the common conventions. You can see your data, you can see your linked accounts, you can see other kinds of account administration-type stuff. If you want to go add or update data, there are embedded workflows to do so, stuff like that. Again—
Riley Hughes: Common conventions maybe depends on who you’re talking to. Are we talking, you know, QR codes and cameras, or are we talking OIDC and passkeys?
Nate Soffio: So fair question all around. For, like, getting in and out of your wallet, OTPs, web authn, and passkeys, kind of all of those are available. We realize that we need to be flexible for the time being, though we would love to see a world where it’s like—
Riley Hughes: Passkey is your single and only factor because it’s easy.
Nate Soffio: But, you know, consumers are not uniformly there yet. Some like OTPs, some are somewhere in between on their authentication journey. When you’re actually in the passport, which, by the way, we call it a passport, not a wallet, for updating information, yeah, it’s, hey, do you want to add a driver’s license or, like, update your address? Great. You’ll want to either switch to your mobile and do it so you can take a picture of something, your uploaded document, things like that. That’s kind of the core engine of it. It’s just like, okay, I need to update some information. And then everything else is largely read-only. We’re very, very particular about the mechanisms through which users can update their data because for us, it’s all about governance, provenance, and root of trust. Like, okay, where did this address come from? Or what is all the metadata around this driver’s license to make sure that any relying party can understand where it came from, how is it packaged, who did this, who’s signing this thing, stuff like that. So we do abstract a lot of that away for the users.
Nate Soffio: You can see, like, last updated at and things like that in details views, but generally speaking, it’s a pretty lightweight HQ for now for consumers. I would say 75% of the, like, UX work we’ve done has been on the B2B side because that’s everything from managing configuration to white-label settings to API keys, webhooks, all sorts of other implementation configuration, and then the lightweight case manager we have built in. Because at the end of the day, if you’re using Portabl for any combination of auth, KYC, and data management, that means your connected users, or effectively the users you’re now subscribing to via their wallet, you have to manage those connections. And that’s where you go for things like unsticking someone or revoking or suspending someone in the event of, like, some suspicious transaction, what have you. And that needed a lot of tender love and care because that’s where the real complexities happen. So, okay, what is the audit trail of this user? I need to see what this guy’s data looked like six months ago when he actually laundered this money.
Nate Soffio: How do I get at that? And that’s actually a very unique set of considerations we had to sit with because it’s how do you reconcile consumer-controlled data and, like, self-sovereignty to a certain degree with the fact that financial institutions have pretty stringent requirements for audit trails, record retention, and sort of, like, effectively track changes over the customer record for the life of the customer and then seven years afterwards. So how do we get that to agree with SSI, I think, was one of the hardest things we had to design for.
Riley Hughes: Yeah, I want to double-click into that, but I think you asked for my hot take on what I think about your appless design by default. And I think Trinsic is most known generally for wallets or us having a wallet, the Trinsic wallet, right, us offering wallet SDKs, et cetera. Early days, we offered a wallet SDK that was an edge wallet SDK for building apps, and then we also offered a custodian API, is what we called it, for basically building cloud wallets. And this is for, like, guardianship. This is if people don’t have a smartphone. This is for those types of use cases. And you fast forward, like, nine months or something, over 95% of the wallets that were created using Trinsic products were cloud custodial wallets. We’re like, it wasn’t how we, you know, originally intended, wasn’t what we were after, but it is what the market wanted. What you’re describing is very, very close to how I think our infrastructure is set up as well.
Riley Hughes: So it’s comforting to hear that we’re kind of seeing the same things, and I think hopefully we can save some other builders of wallets out there some pain of needing to spend months building one thing only to learn that the market actually wanted another thing. Well, I want to transition into this idea that I’ve had and tried out a few times recently, where I’ll come up with some objections, because I think identity is so easy to object to. There’s so many reasons not to move forward with a new identity product or service, and I think it’s helpful maybe to hear how you work through some of these concerns. And so I’ll just rapid-fire them at you, and you can feel free to just answer them how you please, and we’ll try to get through a few of them in a relatively short period of time. Okay, so you just mentioned one thing that I thought we could double-click on. If financial institutions have to hold this data for seven years anyway, isn’t the whole point of verifiable credentials privacy?
Riley Hughes: So are we spinning our wheels here, or is there something really beneficial about using SSI for this use case?
Nate Soffio: I can’t remember who said this originally, but privacy is obviously quite important. I take the position, though, we’re actually oversold on it. I think the thing that’s actually way more important is security. And so if you look at it from more of a security position than a privacy position, without throwing privacy away, because things like selective disclosure matter, preventing data leaks matter, but really when you get down to it, businesses will benefit from taking SSI or verifiable credential approaches because it’s just way, way, way more secure ways of sharing data, and way easier ways of providing high assurance data, because it comes with the signatures and the provenance and the governance that is incumbent in the DID model and the verifiable credentials model. It’s a huge, huge step forward in terms of solving for how to move trusted data around. And not to mention that things like DIDComm are nice security enhancements as well. And to close the loop on what I mean by this is much more of a security thing than a privacy thing, without throwing privacy away.
Nate Soffio: When you can set up DIDComm and presentation exchange in ways where the fintech app also has to prove that they’re them to you, that kind of reciprocal authentication is desperately needed when something like seven in ten or eight out of ten data breaches are caused by phishing and ATO. Now, this is not to say that protecting data at rest is super, super important, and there’s a million startups that are working on data protection at rest, vaulting tokenization, e.g., Evervault, e.g., Basis Theory, very good security, Skyflow, I could go on. Those are all still massively important for the data retention obligations that financial institutions have. However, anytime data is in motion or verifications are happening or authentications happening or KYC is happening, verifiable credentials are way, way better at moving that information from point A to point B and ensuring the data as you receive it is high assurance and believable. Like, that’s the major thing that’s going to crack this wide open.
Nate Soffio: Because if you can now say, oh wait, in two steps, authentication and disclosure, I can now onboard someone in 15 seconds, where previously it took me six and a half minutes. And you’re telling me my attrition rate will go from 50% to like 7%? That’s a no-brainer.
Riley Hughes: Yeah, it’s an absolute no-brainer. I, at some point when I was doing the fundraising thing for Trinsic, I remember telling an investor, there’s a lot of tools out there for privacy. This is for basically helping you prove something is true when you need to share it, not necessarily avoiding having to share it in the first place. It was sort of a light bulb, right? I think that makes total sense. Okay, next one is, pretend I’m the CEO of FinTech ABC, and I don’t want to give a user their data because I don’t want that user to go to FinTech XYZ. And I heard your other answer earlier, and I still have this deep-seated concern because maybe I’m insecure about the true value that I’m providing or something like that, right? But how else do you— kind of overcome that concern?
Nate Soffio: Sure. I mean, part of it is, can you tell how many of those users are already users of the other ABC anyway? So, like, do you have a reasonable expectation that you’re either losing users or having users double book in two of these places? Like, surely that’s a problem already if you’re already asking about it. That’s one thing. So two then is, do you know why they’re leaving? Because I would hazard a guess that it’s not because of necessarily what you’re doing on the KYC side, but some other product features you have or you don’t have. So that’s the next thing. The third thing is more about, like, okay, what is your cost of user acquisition today, and then what is your total cost of ownership for user records on an ongoing basis? That’s the next question. It’s like, okay, we can make that stuff cheaper for you. Subscribe your users via wallet, all of that remote proofing stuff kicks in. Cool. And then the fourth question is situational whether I’d ask this, but I would definitely ask about, like, first-party fraud, phishing, and ATOs, and, like, what’s going on there.
Nate Soffio: It’s a non-answer because I think that, oh, I’m afraid of losing customers to ABC. We can have that part of the conversation, but I would wager a guess that that’s actually not your worst problem.
Riley Hughes: Great. And then just a meta point. Now I’m the CISO of FinTech ABC, and, you know, I hear your pitch. The first thing I say is, Hell yes, no passwords. The next thought on my mind is, okay, what about data storage? You mentioned you’re the custodian. Sounds like it’s going to be a good user experience, but where’s that data live? Is there a blockchain in here? Who else has access to this data, and does this pose a risk to me and my business?
Nate Soffio: Yeah, so also killer question. This is one of those questions that’s actually two separate questions. Yes, we use blockchain. We use the DID Ion method to do specific identifier-related interactions like two-way auth, things like that. A DID is kind of a UUID of sorts, but it’s pseudonymous. It doesn’t tell you anything useful about the underlying person or issuer slash verifier in the network. So there’s no PII on chain. Rest assured, we’re not issuing NFTs, SBTs, anything like that. So there’s not sensitive information that is in a permissionless environment. That’s part A. Part B, the information we have that is actually information, you get a tenant, every user gets a tenant. All of that stuff is encrypted in transit and rest, and we have stuff on the roadmap around reverse proxying and vaulting anyway if you super really don’t want to hold on to non-obfuscated data, or if you want to hold on to different types of obfuscated data. We’re SOC 2 friendly. We’re ISO friendly.
Nate Soffio: You know, we follow all the best practices we possibly can, either from kind of existing data management practices. And I think the biggest question then for that CISO is not that, like, the data is not secure at rest. It’s what the heck is Presentation Exchange, and is that secure? And so that’s probably what I’d really focus the discussion on. Like, the storage stuff at rest, non-problematic. Key management, and you basically have to require DIDComm and PEX to access any of it anyway, at least between authenticated parties. But the actual thing that is interesting for the CISO is the fact that DIDComm and presentation exchange is a really, really secure pipe for exchanging data. Like, you can’t have fake Robinhood inject themselves into the process to steal data. It just fails. Doesn’t work. And you can do this stuff synchronously, asynchronously. It’s OS agnostic. It’s device agnostic. You can do it, set it up by a QR code. You can kick it off with other passwordless auth mechanisms.
Nate Soffio: But point is, the only information that’s moving is the information that is, like, strictly required by the relying party inside a secure channel. And so I think if that’s where most of your heebie-jeebies are, that’s the stuff where I can point you at specs. We can do run-throughs. Like, I can show you the attestations for why DIDComm and PEX are as strong as they are, stuff like that. So if you’re the CISO, I’d say, let’s talk about the new technology that you’re interested in implementing, not the stuff that’s table stakes.
Riley Hughes: Cool. I think that was good. Nice job. I’m buying it. I recall early in the days of Portabl, I remember reading quite a bit about Web3 stuff and Web 2.5. I saw it was a term that someone framed you as at one point. And recently looking at your website, I feel like I see a lot less of that. I’m curious if you expand on your journey exploring traditional fintech and finance versus emerging kind of DeFi and Web3 stuff, where did you land on that? It seems like both need reusable ID. It does seem like Web3 maybe is an earlier adopter type of a place, but also maybe a little less. Real world, a little less meat on the bones there. So curious what that calculus was like for you and what you learned that maybe could save some other listeners some time spinning their wheels in one place or the other.
Nate Soffio: This was an interesting bit in our lifecycle where you’re certainly right. Your institutional memory is correct, where we had this kind of Web 2.5 mindset. And it was happening during, like, the peak of ‘21 and into 2022, where there was a lot of conversation around how do we bridge these two universes. And in that kind of, like, bridging phase in the market, you had identity providers trying to think about stuff. You had oracles trying to think about stuff. So how do you get off-chain data into on-chain environments in real time without, like, consensus lag? And you had a bunch of other startups and non-startups trying to figure out how you do this alchemical thing of moving Web2 data into Web3. So it kind of was naturally part of the conversation. So, okay, how do we get traditional KYC or other stuff into those environments, if at all? We saw the tide turn, I think. There were a lot of different events that happened one after another that started suggesting, first quietly and then loudly and all at once, that this market was going to have a lot of contortions.
Nate Soffio: It’s going to contract before it has its phoenix moment. So we kind of sat back and said, okay, maybe the crypto-y part of the equation, the DeFi part of the equation, it may still be there, but it has to sort itself out first. There will probably be a path where we do stuff regarding stablecoins and CBDCs as they pertain to remittances and cross-border payments, and we’re starting to see that come true. But back a couple of years, and we said, okay, this reusable ID stuff, it forced us to learn a lot about Web3 really, really quickly. But we realized that the actual biggest problem space is where all the people actually are, which is still firmly planted in CeFi. And so we said, okay, we have the from-scratch problem with traditional KYC. We have the persistent friction with open banking aggregators. And we don’t have anything that is identity wallet-esque in the open banking context when that’s an extremely, extremely large market. So he said, to quote The Little Mermaid, I want to go where the people are.
Nate Soffio: And so that decision, probably around, like, early-mid 2022, to be like, okay, let’s drop the Web3 experiments and the bridging stuff and really nail this identity for open banking problem, because that’s also our sweet spot with our experience, the tools we had on hand, the pre-existing connections and support network. That was our sweet spot. So we said, okay, let’s just do more in a smaller area and play to our strengths.
Riley Hughes: Awesome. Well, there’s a takeaway for everybody, is be like the Little Mermaid and go where the people are. I love that. And by the way, I hear people say trad-fi. That sounds so bad. I think CeFi sounds so much better, so I hope everybody picks that up as well. Trad-fi just feels so clunky or something. Anyway, I like words, as you can tell. Okay, so I don’t know if I’m projecting too much here or something, but I think you could draw a parallel between the ethos and philosophy and even technology of Web3 to SSI, VCs and DIDs, etc., the same way that you can with, like, maybe DeFi versus CeFi. And I wonder as you kind of were bridging those and ended up more firmly in the traditional finance realm, whether you think that a similar move will happen in terms of the technology, or do you think you’ll ever become like a centralized identity company that throws away DIDs and VCs and DIDComm and all of that, or is there something unique about— DIDs, VCs, and the like. That is stickier than the Web3 stuff.
Nate Soffio: I think DIDs, VCs are here to stay. There’s a ton of new movement around, like the KERI spec, for instance, which is effectively like a really smart implementation of VCs without DIDs, a bunch of other stuff going on. The point is that APIs have been around for a long time. They allow for really sophisticated machine-to-machine communication. But what’s been missing from that whole, like, communicating process in the financial services industry is a standardized way of actually packaging up information. And so, from our perspective, we view verifiable credentials as sort of what the shipping container did for global trade in the 1960s. It’s a standardized way to move stuff from point A to point B. Hell, it even has a manifest to it. There’s permissions around what you can take in, take out, put in, and we think it’s here to stay. It did force us to learn a lot about Web3 stuff because that’s where decentralization was born for the most part.
Nate Soffio: But we think that there’s a huge opportunity to get away from centralized identity providers and move towards just layers or fabric, pick your metaphor, where there’s no one central authority, but instead lots of different participating institutions have certificate authority-like power to say, okay, these three things are true about Riley from over here. These four other things about Riley are true over here. Riley has perfect visibility about these seven things that are true, and now he’s going to join some other app or ecosystem but only have to share five of those seven things. It’s going to take a lot of effort to get it right in the United States, because the U.S. is big and complicated and diverse and private market-led, whereas, like, Canada is much more public-private partnership focused, or the EU is being driven towards eID standards largely by civil projects. It’s going to be shaped differently in the U.S., but I think they’re here to stay because the formats and the benefits are just so much better than the status quo. But we’re still in the infancy for this stuff.
Nate Soffio: So portable is going— to be a long-term commitment, but we’re eager to get this right.
Riley Hughes: Awesome. Well, this is a really good segue into what I love to ask to close out the episode every time, which is I want to ask you to tell me what the future of identity looks like to you in 10 years. What’s it going to look like when I onboard into a fintech app or, you know, originate an account or something like that?
Nate Soffio: I think the hallmark of it is going to be user control and composability. I think we will get to a saturation point where I no longer have to take an awkward picture of my driver’s license or take a weird selfie where I might also be holding my driver’s license, stuff like that. It’s going to be more like a, hey, thanks for signing up for Riley Bank. Which claims, which credentials do you want to share to join? You know, it’s going to be that simple. I don’t know if it’s going to be like an e-commerce checkout or the UX is going to be, like, radically different. But I think the starting from scratch or, like, verifying from scratch problem will very certainly go away. We’re starting to get glimpses of it between things like verifiable credentials, the mDL spec or the mobile driver’s license spec, things like that. I think more and more elements of identity, financial suitability, account validation, and payment capacity will take on these sorts of reusable formats.
Nate Soffio: And so I think more and more of these sorts of onboarding procedures will just get boiled down into two steps: authenticate and consent to share, because that information will just travel with us. I couldn’t tell you, and I would never claim to know, what is going to be the reusable format 10 years from now. None of us know. But I think reusability will happen. But how the form factor is, it’s a combination of anyone’s guess, and it’s our opportunity to build.
Riley Hughes: Yeah, well, that’s what we’re all trying to figure out right now, I guess, right? So that’s a great place to end. Thanks a lot, Nate. This has been an awesome conversation, and there’s like a hundred other things that I wish we could dive into. You know, suffice to say, I am definitely rooting for you and Portabl. It’s a tough nut to crack, as we’ve explored in this conversation, but I sure hope you do it. And I hope that to be a user of Portabl, to onboard into all kinds of products myself, as well as for other people out there, I think what you’re doing is really important for the world. So thanks a lot for doing it, and thanks for joining us.
Nate Soffio: Yeah, thanks so much. I had a ton of fun. Really honored to be now a part of your roster of awesome smart identity experts you’ve interviewed over the past year, and I’m looking forward to a lot of future episodes of the pod.
Riley Hughes: Well, anything to plug, or if people want to get in touch with you, how should they do it?
Nate Soffio: Great question. I think the easiest way to reach out is hello@getportabl.com. That’ll go to both me and Alex. We’d love to chat with you, whether you’re a practitioner in the space or you’re looking to implement us or something like us, or if you just want to learn more and nerd out about authentication or open source specs, give us a shout. We’re always happy to chat, and hopefully we’ll hear from some of you as soon as this episode hits the airwaves.
Riley Hughes: Thanks again, Nate, for joining, and thank you for listening. You can find us on YouTube, Apple, Spotify, and wherever else you listen to podcasts. Feel free to reach out to us on Twitter at Trinsic underscore ID and me at Riley P Hughes, and visit Trinsic if you’re interested in building the ID tech products of the future. Subscribe to get new episodes as they drop. Thanks a lot.

Zack Jones
Director of Product Partnerships @ Trinsic
Zack Jones leads the product partnerships at Trinsic that together form the connections that make up the world’s largest identity acceptance network. Zack is a published author, expert on digital IDs, and passionate about entrepreneurship.
Newsletter
Subscribe to weekly insights and updates in the digital ID ecosystem.
