VettiGuard

Know when a real person is present—and when identity evidence needs a closer look.

VettiGuard protects high-value digital actions with human verification, native document screening, hosted identity capture, trusted facial/liveness checks, risk controls, and server-side decisions.

Human verification Document + face workflows Server-controlled decisions
Customer onboarding
Verification in progressDocument evidence · face · liveness · policyVettiGuard
Authoritative backend decisionControlled
3Identity assurance profiles
Short-lived capabilities
APIHosted or direct integration

Protect the person, the identity evidence, and the business action.

Use only the verification surface a workflow needs, or combine them into a stronger identity journey.

Human verification

Checkbox, invisible, score, policy, proof-of-work and visual challenges help reduce automated abuse before expensive actions run.

Human-verification use cases

Native document screening

Screen supported captures with quality, OCR, ICAO MRZ, barcode/PDF417, consistency, capture geometry and bounded tamper signals.

Document API

Identity verification journeys

Combine document evidence with trusted backend facial match and liveness for standard or high assurance, with manual-review routing when required.

Identity workflows

Hosted capture

Launch a device-adaptive VettiGuard flow for front/back document capture and face evidence without exposing the underlying identity-session capability.

Hosted integration

Risk, review & governance

Route uncertain outcomes to review, version policy decisions, apply review SLAs, and manage evidence-retention and legal-hold controls.

Identity security

API-first delivery

Use the canonical https://api.vettiguard.com/v1 API from web, backend and native application integrations.

Developer guide

Apply stronger verification where the consequence is higher.

VettiGuard can protect a lightweight form, a high-risk account action, or a document-and-face onboarding journey without moving the final decision into browser code.

Identity onboarding

Screen passports, national identity documents, driver licences and residence-permit captures, then step up to face/liveness or manual review when policy requires it.

Identity onboarding

Registration and account access

Reduce automated sign-ups, credential stuffing, password-reset abuse and repeated OTP traffic.

Account protection

High-risk account changes

Require a fresh identity journey before sensitive profile, payout, beneficiary or recovery changes.

Step-up identity

Forms and lead capture

Reduce spam enquiries, form flooding, fake leads and automated newsletter or support submissions.

Form protection

APIs and high-value operations

Require recent human or identity evidence before resource-intensive searches, exports, uploads or submissions.

API protection

Commerce and applications

Protect checkout, bookings, promotions, applications, surveys and other workflows targeted by scripted activity.

Explore use cases

Built for teams that need trustworthy digital interactions.

Use VettiGuard in customer-facing sites, mobile applications, internal portals, regulated workflows and custom APIs.

E-commerce and FinTech SaaS applications Healthcare and NDIS systems Membership organisations Education and government portals Developers and agencies

Capture evidence in the browser. Make the decision on trusted infrastructure.

The hosted experience guides the user, but browser-submitted claims never become the source of truth for identity outcomes.

1

Create a governed session

Your backend records consent, selects the action and assurance profile, and creates the identity or hosted session with a scoped server credential.

2

Capture and evaluate evidence

VettiGuard screens document quality and machine-readable data, then collects face evidence when standard/high assurance requires it.

3

Consume the final result

Your backend uses the authoritative session result or signed webhook, including review or recapture outcomes, before the protected business action continues.

Designed to keep sensitive verification state off the client.

Capabilities, evidence handling and governance are structured so the browser captures data but cannot award itself a verified identity.

HMAC-held capabilities

Identity and hosted-session capabilities are short-lived; only keyed hashes are stored where the flow permits.

Protected transient portrait

The short-lived document portrait used for face comparison is protected with AES-256-GCM and removed after comparison/finality.

Trusted facial decision

Client-supplied match, liveness, score or pass booleans are not accepted as an authoritative biometric result.

Recapture before false finality

Blur, glare, crop, distance and perspective issues can return safe capture guidance when there is no material document contradiction.

Retention lifecycle

Versioned policy can schedule evidence purge and later record minimisation, with legal holds when authorised.

Explicit assurance boundary

Native document checks are screening signals, not issuer/government database confirmation or forensic proof of genuineness.

Use hosted identity for the fastest full journey.

Create the session from your backend after explicit consent, send the user to the returned hosted URL, then consume the server-side result or signed webhook.

POST https://api.vettiguard.com/v1/identity/hosted/session

{
  "subject_id": "customer-4821",
  "action": "customer-onboarding",
  "assurance_level": "high",
  "consent_accepted": true,
  "consent_reference": "consent-event-7d1a",
  "country": "AUS",
  "document_type": "drivers_license"
}

Evidence-based verification decisions.

VettiGuard can combine document screening, data consistency, capture quality, trusted facial comparison, liveness and policy/review outcomes into a governed verification result.

Screening is not issuer confirmation.

Unless a separately governed authoritative connector is explicitly configured, VettiGuard does not claim that a government or document issuer confirmed the presented identity document.

Start with human verification—or build a complete identity journey.

Protect one workflow first, then add document, facial/liveness and governance controls only where the business consequence justifies them.