VettiGuard

Verification decisions stay enforceable on trusted infrastructure.

VettiGuard combines origin/action binding, short-lived capabilities, server-side validation, identity evidence controls, review routing and lifecycle governance without treating browser completion as authority.

Approved origin Expected action Scoped capability Server decision

Layer safeguards from challenge creation to final business action.

Client-side completion alone is never treated as permission to continue a protected action.

Origin restrictions

Site keys can be restricted to approved hostnames and supported wildcard subdomains.

Short-lived challenges

Challenge and response lifetimes are bounded and enforced by the server.

Action binding

Responses are checked against the registration, login, checkout or API action that requested them.

Single-use responses

Consumed response tokens cannot be replayed for another request or business operation.

Risk and rate controls

Per-site policy, quotas and rate limits reduce abuse and constrain expensive verification paths.

Workspace isolation

Customer resources, credentials, logs, verification state and policy are scoped to the authenticated workspace.

The browser captures evidence; it does not decide identity.

Document and biometric workflows use separate capabilities and server-side trust boundaries so client code cannot self-assert a successful identity result.

Capability hashing

Identity-session and hosted capabilities are designed for short-lived use; keyed hashes are stored instead of reusable plaintext capabilities where applicable.

Encrypted transient portrait

The short-lived portrait crop used for document-to-face comparison is protected with AES-256-GCM using session-bound associated data and removed after comparison or finality.

Trusted biometric authority

Browser fields such as matched, liveness, verified, passed or client scores are not accepted as the authoritative biometric decision.

Fail-closed availability

Standard/high assurance cannot become an automatic pass when the trusted facial/liveness subsystem is unavailable; the workflow routes according to governed policy.

Evidence minimisation

Identity APIs do not return raw document images, portrait crops, raw OCR text, raw barcode payloads, token hashes or subject hashes in the normal result contract.

Capture guidance without false rejection

Capture-only issues such as blur, glare, crop, distance or perspective can request recapture when there is no material machine-data or tamper contradiction.

Policy is captured with the verification.

Versioned identity policy can preserve the assurance, review SLA, retention, evidence-retention and validity settings that governed a session. Later policy edits do not silently rewrite an earlier verification decision.

  • Immutable policy-version history and snapshot hashes
  • Review priority, SLA and overdue escalation
  • Evidence purge followed by record minimisation
  • Authorised legal holds block scheduled purge stages

Explicit consent precedes the hosted identity journey.

Hosted identity creation requires consent_accepted: true and a non-empty consent reference. The underlying identity-session token is not returned to browser code; the browser receives a separate hosted capability.

  • Hosted capability delivered in a URL fragment
  • Fragment removed immediately by the hosted client
  • Continuation uses X-VettiGuard-Hosted-Token
  • No-store API responses and rate-limited hosted operations

Native document screening is not government or issuer confirmation.

VettiGuard analyses the evidence available to the configured engine. It does not turn optical or machine-readable checks into a claim that the issuing authority confirmed the document.

Supported

Capture quality, OCR-derived fields, ICAO MRZ checks, supported barcode/PDF417 data, consistency, geometry and bounded tamper/recapture signals.

Supported with trusted backend

Document-to-face comparison and liveness for standard/high assurance when the trusted VettiGuard facial subsystem is correctly bound.

Not implied

Issuer database lookup, government confirmation, universal country-template certification or forensic proof that a document is genuine or forged.

Operate with controlled retention and visibility.

Keep only the evidence and decision metadata that your governed workflow requires, use the lifecycle worker for scheduled minimisation, and protect private API credentials outside browser/mobile bundles.

Verification is one layer of application security.

Combine VettiGuard with secure authentication, authorization, input validation, rate limiting, fraud controls, monitoring and safe business logic. Use HTTPS in production and fail safely when required verification dependencies are unavailable.

Found a security issue?

Report suspected vulnerabilities privately through the deployment's security contact. Do not include production secrets, customer identity data or destructive proof-of-concept activity.

Acceptable use