We keep no biometrics.There is nothing to steal.

JERIX proves where and how a capture happened — against a state’s own signature on a passport chip, or a capture signed on the device as it was taken — and then deletes the images. Zero retention on images and biometrics, verified on disk.

Machine-readable zone · ICAO 9303 TD3

P<UTORIVERA<<ALEX<<<<<<<<<<<<<<<<<<<<<<<<<<<
L898902C3·UTO740812·F320403·ZE184226B<<<<<··

Specimen document, state code UTO — the code ICAO reserves for specimens. The highlighted positions are check digits, computed in your browser under ICAO 9303.

Who brings us this problem.

Reading the chip is not the differentiator.

Several established vendors ship it. Reading the chip is how we earn the right to keep no images — and what is left after the check is where the vendors actually differ.

After the checkThe typical IDV vendorJERIX
What is retainedThe face image and the document imageNo image is retained — zero retention, verified on disk
How deletion worksA retention period, set in the contractThere is no retention setting to configure
Two clients, one personOften linkable across clientsA different token for each client, not relatable
A returning userCharged again on every re-verificationVerify once, then authenticate — on desktop and in our app, not yet in a mobile browser

An established vendor could copy the architecture in a quarter, and the reason they have not is commercial rather than technical. Their customers are mostly regulated entities that must retain evidence for years, so retention is the thing those customers bought — and charging again on every re-verification is a revenue line that deleting the evidence would delete too.

One case explains the whole market.

In June 2026 a 20-year-old was arrested in Israel after allegedly opening fraudulent bank accounts and drawing money from roughly 120 victims. He bought identity photographs from breached databases, animated them with AI, and passed the banks’ remote checks.

Every check he passed accepted an image handed to it. And the raw material came out of stored biometrics — which is the part that should worry anyone still keeping them.

SOURCE: CALCALIST, 21.06.2026

What the bank required, and what he supplied
live videoan AI-animated video
a selfiea synthetic face
a photo of an ID documenta forged image
a confirmation documenta forged document

Provenance, not pixels.

Two paths reach the same verdict, and both prove where and how the capture happened. The chip path also proves the document.

The chip path

A passport carries an NFC chip signed by the issuing state. We read the chip, verify the signature chain to a national root, and match the live selfie against the photograph the state itself signed.

A forged image needs a graphics model. A chip signature needs the state’s private key.

certificates
588
certificates
countries
112
countries
network calls
0
network calls

The trust chain is verified fully offline — no network, no CRL, no OCSP. A chip whose issuer is not in the store is refused.

The capture path

Where there is no chip, every frame is hashed and signed on the device with a single-use nonce, and on iOS the app itself is attested through Apple App Attest. Android hardware attestation is built but not yet configured, so an Android capture is tiered as a browser capture is.

So a live capture can be told apart from a gallery upload or a replayed frame. An injected feed from a virtual camera is foreclosed by App Attest on top of that, which holds on iOS and not yet on Android.

specimen · no portrait
Surname
RIVERA
Given names
ALEX
Document no.
L898902C3
Nationality
UTOPIAN
Date of birth
12 AUG 1974
Date of expiry
03 APR 2032
Specimen · state code UTO · synthetic, not a real holder

This is the part a breach would be after.

A face image and a document image are what an attacker animates, and what the June 2026 case was built out of. Neither survives the request that used it — zero retention on images and biometrics, verified on disk. Run the deletion and watch what is left — on this page, and on the server.

What is kept: a one-way token, the verdict, three encrypted text fields — name, national ID, date of birth — and two one-way face-derived hashes that expire at 30 and 7 days. What is never kept: face images, face embeddings or templates, document images, the chip data itself.

Two calls and one URL.

There is no SDK requirement, so the language your product is written in stops being a gating question. A client on any stack integrates server-to-server.

And you choose how little you receive. The integration running in production today takes three fields and nothing else — no name, no ID number, no date of birth, no image. It holds nothing identifying about the person, so that client has nothing to leak.

Full API reference →

What your server receives

verified
The person held a document whose issuing state signed it, and the face on that signed data matched the person in front of the camera.
meets_age
Whether they clear the gate you asked about. Not their birthday — the answer to your question.
age_gate_min
The gate that was applied, so the answer is auditable later.

Three fields, and nothing else. No name, no ID number, no date of birth, no image. Larger field sets exist and are configured per client, so you take the minimum your product can run on.

Assurance is enforced.

Each verification earns a level, frozen onto the credential. Your server declares the level it requires, and ours refuses anything weaker.

LevelEarned byTypical use
humanityselfie with a detected faceanti-bot
lowweb capturelow-risk signup
substantialnative capture attested on this request (iOS today)standard onboarding
highattested native capture + the chip verified server-sidebanking, large loans

What is not shipped.

Every vendor in this category has a list like this. Most of them do not publish it. Yours is the second meeting that does not go badly.

SOC 2, ISO 27001, penetration test
External audits. Not started, and we will not show a badge we do not hold.
Screen and print detection
Two detectors compute on every capture. Neither decides anything yet.
Liveness enforcement
Measured and recorded on every capture. It does not gate a verdict today.
SSO / OIDC for enterprise
The signing core ships. The four endpoints do not.
On-prem deployment
The core is verified offline, but there is no reference installation yet.
The full roadmap, with what each item is blocked on →

Verify every user without becoming the target.

Twenty minutes, a real passport, and the trust chain resolving in front of you. One of the two founders runs it; there is nobody else to hand you to.

Request a walkthrough
  • A real passport against a phone, with the signature chain resolving to a national root, offline
  • The capture path on a document with no readable chip, and what the attestation does and does not prove
  • Your own data path, drawn for your stack — and how few fields you can choose to receive
  • The images being gone on disk when the check completes
  • The roadmap unedited, including the compliance work that has not started
  • What it would cost at your volume, once we understand it