Malta EU ID Wallet software
A complete European Digital Identity Wallet stack built by Aloaha Limited in Malta: a personal wallet your users carry, a Business Wallet your accounting team uses, and a Wallet Relying Party verifier registered with the EU reference registry. Ships on-premise or Malta-managed. No US-cloud dependency. Aligned with eIDAS 2 (Regulation (EU) 910/2014 as amended by 2024/1183) — which covers the full European Economic Area (30 countries: 27 EU by December 2026 + Norway, Iceland, Liechtenstein following with roughly one additional year) — and the Architecture Reference Framework 3.0.
Three products, one stack
Personal EU Wallet
A wallet your users install (web PWA + native iOS/Android). Receives PID + mDL + PhotoID + EHIC + PDA1 issuance from any European catalogue issuer. Presents credentials via OpenID for Verifiable Presentations to any WRP.
Business Wallet
A wallet your accounting / operations team uses. Signs invoices with CSC v2 to PAdES-B-LTA (GoBD-compliant), verifies incoming credentials, sits inside your existing SSO. On-premise or Malta-managed.
Wallet Relying Party verifier
An OpenID4VP verifier registered with registry.serviceproviders.eudiw.dev. Accepts credentials from any EU Reference Wallet. Publishes a WRP certificate + intended-use certificate per ARF 3.0 ยง5.
All three surfaces share one identity, one crypto module, one audit trail, and one deployment story. Buy the stack, deploy one surface, extend to the others when you're ready.
What you can issue + verify today
Issuance (as PID Provider + non-qualified EAA Provider)
- Personal Identification Data (PID) — the core eIDAS 2 credential. Issued as
urn:eudi:pid:1per ARF 3.0. Accepted by the EU Reference Wallet without additional trust anchors when consumed inside our jurisdiction. - Mobile Driving Licence (mDL) — ISO/IEC 18013-5 profile.
- PhotoID, EHIC (health insurance), PDA1 (posted-worker), Diploma, Learning Credential, Employee Attestation, MSISDN, Power of Representation, IBAN, Tax number, Loyalty, Seafarer, Reservation — the 27-credential EU reference issuer catalogue.
Verification (as Wallet Relying Party)
- OpenID for Verifiable Presentations — the ARF-mandated presentation protocol. Registered WRP entry at /eudi-registration.html with live proof surface (Wallet Provider attestation, OpenID Federation entity statement, EU Trusted List, DID document, machine-readable RP metadata).
- haip-vp:// scheme — the EU reference verifier scheme.
- DCQL queries for selective disclosure.
- Formats:
dc+sd-jwt,mso_mdoc,jwt_vc.
Signing (GoBD-compliant, eIDAS AdES)
PAdES B-B / B-T / B-LT / B-LTA via the Cloud Signature Consortium v2 API, the personal EU Wallet, or the Business Wallet. Every signature carries an RFC 3161 qualified timestamp under a QTSP on the EU LOTL — the immutability signal that lets German GoBD (BMF letter 2019) recognise the archive without a WORM appliance. See /gobd-compliant-invoice-signing.html for the practitioner guide.
PAdES-B-LTARFC 3161CSC v2eIDAS AdESGoBD
Deployment
- On-premise. Windows Server + IIS + our SIP bridge. Deploy inside your own datacentre or your own Azure/AWS EU region. You keep the keys, we ship the software.
- Malta-managed. Multi-tenant, hosted from our Malta datacentre. Per-tenant isolation (each tenant is its own IIS site, its own
App_Datadirectory, its own signing key). You get the SLA; we get the ops burden. - OEM / white-label. Embed the wallet + issuer stack in your product; see /wallet-oem.html.
Independent proof surfaces
Every claim on this page is machine-verifiable from a third party, not just our word:
- EU Reference Registry entry — live fetch from
registry.serviceproviders.eudiw.dev. - OpenID Federation entity statement at
/.well-known/openid-federation. - EU Trusted List at
/.well-known/trust-list.xml. - Wallet Provider attestation at
/.well-known/wallet-provider.jwt. - RP metadata at
/.well-known/eudi-relying-party.json.