AttaID · ATTA-KH

Keycloak,
but for Cambodia.

One identity across all our applications — and the only Cambodian identity layer that speaks to the government's own systems.

CamDX · CamDigiKey · Delivery plan

01 · Where the value actually is

A translated login page is not a business.

What anyone can copy

Keycloak already speaks Khmer. Theming and translation get a competitor a localised login screen in a week. Sign-in, sessions, password resets — all commodity.

What they cannot

Membership of CamDX and a working CamDigiKey integration. That is a door only the government opens, and a commune app or a farmer cooperative will never walk through it alone.

We integrate with the government once. We serve the long tail many times.

That sentence is the company. Everything in this deck serves it.

02 · The four government systems that matter

We integrate with them. We never impersonate them.

Transport

CamDX

The national data exchange, built on Estonia's X-Road. Every government integration travels through it. We must become a member.

Identity

CamDigiKey

National eKYC and authentication. Scan a QR, prove who you are. Our only realistic route to strong verified identity.

Documents

verify.gov.kh

Checks that a document or credential is genuine. Feeds our evidence records once membership is live.

Future

IPIS

The emerging national population register. We design the connection point now and depend on none of it yet.

03 · How CamDX works

Every member runs its own gateway. Even CamDX cannot read the traffic.

AttaID our platform Our Security Server signs · encrypts holds our member keys CamDX the payload stays sealed end to end — CamDX carries it but cannot read it Their Security Server verifies · decrypts CamDigiKey eKYC · auth

A Security Server is a dedicated, hardened machine that signs and encrypts every exchange. It is our end of the government pipe, it holds the keys that prove we are us, and operating one is a condition of membership — not an optional extra.

04 · Joining CamDX

They issue our identity. We build everything around it.

Only CamDX can give us

  • A member name, class and code — our legal identity on the network
  • Signed certificates for our Security Server
  • CamDigiKey client credentials and keystores
  • Approval to register and go live

What we control

  • Submitting the application — week one, and it needs a CamDigiKey account first
  • Standing up and rehearsing the Security Server
  • Building the whole integration against public documentation
  • Everything that does not touch government data

The one question we must ask this week

Members today are mostly ministries and banks. Which member class would we fall into? If the answer is a queue, we wait and keep building. If it is an eligibility bar, we need a government sponsor — and that changes the company's plan, not just the project's.

05 · What running the gateway means

Small machine. Serious responsibility.

Two

gateways in production, so one machine failing does not cut us off from the government entirely.

2 / 4 / 100

cores, GB memory, GB disk. Ubuntu LTS. Modest hardware, published install guides, ready-made automation scripts.

Weeks

to recover if we lose the keys — a paperwork process, not a technical one. They get escrowed on day one.

It runs on its own isolated host with no application code on it, and its admin panel never faces the internet. This is the machine that proves AttaID is AttaID to the government, so it is treated like a vault, not like a server.

06 · CamDigiKey

Someone else does the hard identity check. We carry the result.

  • Reads the national ID card and extracts the details
  • Matches the face against the document photo
  • Proves the person is live, not a photo of a photo

That process is called KYC — know your customer — and it is a legal requirement for anything touching money. It is expensive and it carries liability.

The commercial argument, in one line

Verify a person once. Every app we serve consumes the result — with proof of where it came from — instead of paying to do their own checks and storing sensitive documents they would rather not hold.

We store the outcome and never the evidence: no ID numbers, no face images, no document scans.

07 · How a CamDigiKey sign-in works

The user scans a QR code. Everything else is ours to build.

01

We request a login token

AttaID asks CamDigiKey to start a session and gets back a one-time code.

02

We show a QR code

The only part the citizen ever sees. They scan it with the government app.

03

They confirm with their face

CamDigiKey checks the person and approves the request on their phone.

04

We exchange it for a token

Proof that a verified person just authorised us — signed, and only for us.

05

We record the result

The account is marked strongly verified, with an expiry date. No documents kept.

Nine published operations in total — sign-in, token refresh, sign-out, profile lookup and organisation accounts among them. We wrap the government's own library rather than writing any of this ourselves.

08 · One architecture decision to take now

CamDigiKey does not plug into Keycloak.

What we assumed

That Keycloak — the off-the-shelf engine underneath AttaID — could talk to CamDigiKey with configuration alone, the way it talks to Google.

What is actually true

CamDigiKey uses its own security scheme, not the industry standard one. Keycloak cannot speak it. The government publishes a library that can — and it is written in the same language our platform already uses.

So we build it in our own application layer, and use the government's library.

Caught now, this is a diagram change. Caught in month seven, it is a rewrite in a language nobody on the team writes. It is the single most valuable thing this review turned up.

09 · Why we do not have to wait

The government publishes almost everything except the keys.

Public today

  • The full CamDigiKey specification and a working client library
  • Security Server install guides and automation scripts
  • The verification API documentation, including a test environment

Gated behind membership

  • Our credentials and certificates
  • Our member identity on the network
  • Permission to go live

We build and test the whole integration now, against a stand-in.

When the credentials arrive we swap them in. That turns the government integration from a three-month project that starts after approval into a two-to-four-week finish — which is the difference between an answer and an excuse when someone asks how soon we can go live.

10 · The shape of the next eight months

Two tracks. Only one of them is ours to schedule.

M1M2M3M4 M5M6M7M8M9+
Government CamDX membership — apply week 1, then pursue
Which member class? Legal basis & data agreements
Build Decide First real integration Open it to others Pilot-ready
CamDigiKey integration built & tested against a stand-in Swap in credentials

The top bar has no end because we do not control it. Everything below it is designed so that waiting costs us nothing.

11 · What could go wrong

Three risks worth your attention.

RiskWhy it mattersWhat we do about it
Membership refused No government verification, and the defensible part of the business goes with it. Ask about member class this week. If a sponsor is needed, find that out in month one, not month six.
Nobody outside integrates Farms Nexus and CashEW are ours. Proving we can connect to ourselves is not proof of a market. Name one target outside the company now — and build for them from day one: our own apps connect through the same public interface a stranger would, with no shortcuts.
Apps depend on us with no way out We ask apps to delete their own identity data. If AttaID stops, their logins stop — including ours. Write the exit terms before the first outside integration, not during the negotiation.

Ten further engineering findings — account takeover, data correlation, recovery — are documented separately and are all fixable inside the plan above.

12 · What I need from you

Four decisions. All of them yours to make.

1

Authorise the CamDX application

And name who owns chasing it. It is a relationship and a queue, not a ticket, and it is the longest lead time we have.

2

Farms Nexus drops its own farmer records

It reads them from AttaID instead. Ours to decide, and it is what makes the first milestone real rather than a demo.

3

CashEW consumes one verified detail

Rather than collecting it. Without this we are a login button, which is the outcome worth avoiding.

4

Half a day for the architecture decisions

Nine choices that are an afternoon now and months of rework later.

And one question I cannot answer for you: who is the first organisation outside this company that we want using AttaID? If we can name them, the plan has a target. If we cannot, that is the most useful thing to come out of this meeting.

The whole plan, in one line

Be holding a finished integration on the day the government opens the door.

Everything else we ship while it is opening.

Full delivery plan & engineering detail →

AttaID · CamDX & CamDigiKey