Origin restrictions
Site keys can be restricted to approved hostnames and supported wildcard subdomains.
VettiGuard combines origin/action binding, short-lived capabilities, server-side validation, identity evidence controls, review routing and lifecycle governance without treating browser completion as authority.
Client-side completion alone is never treated as permission to continue a protected action.
Site keys can be restricted to approved hostnames and supported wildcard subdomains.
Challenge and response lifetimes are bounded and enforced by the server.
Responses are checked against the registration, login, checkout or API action that requested them.
Consumed response tokens cannot be replayed for another request or business operation.
Per-site policy, quotas and rate limits reduce abuse and constrain expensive verification paths.
Customer resources, credentials, logs, verification state and policy are scoped to the authenticated workspace.
Document and biometric workflows use separate capabilities and server-side trust boundaries so client code cannot self-assert a successful identity result.
Identity-session and hosted capabilities are designed for short-lived use; keyed hashes are stored instead of reusable plaintext capabilities where applicable.
The short-lived portrait crop used for document-to-face comparison is protected with AES-256-GCM using session-bound associated data and removed after comparison or finality.
Browser fields such as matched, liveness, verified, passed or client scores are not accepted as the authoritative biometric decision.
Standard/high assurance cannot become an automatic pass when the trusted facial/liveness subsystem is unavailable; the workflow routes according to governed policy.
Identity APIs do not return raw document images, portrait crops, raw OCR text, raw barcode payloads, token hashes or subject hashes in the normal result contract.
Capture-only issues such as blur, glare, crop, distance or perspective can request recapture when there is no material machine-data or tamper contradiction.
Versioned identity policy can preserve the assurance, review SLA, retention, evidence-retention and validity settings that governed a session. Later policy edits do not silently rewrite an earlier verification decision.
Hosted identity creation requires consent_accepted: true and a non-empty consent reference. The underlying identity-session token is not returned to browser code; the browser receives a separate hosted capability.
X-VettiGuard-Hosted-TokenVettiGuard analyses the evidence available to the configured engine. It does not turn optical or machine-readable checks into a claim that the issuing authority confirmed the document.
Capture quality, OCR-derived fields, ICAO MRZ checks, supported barcode/PDF417 data, consistency, geometry and bounded tamper/recapture signals.
Document-to-face comparison and liveness for standard/high assurance when the trusted VettiGuard facial subsystem is correctly bound.
Issuer database lookup, government confirmation, universal country-template certification or forensic proof that a document is genuine or forged.
Keep only the evidence and decision metadata that your governed workflow requires, use the lifecycle worker for scheduled minimisation, and protect private API credentials outside browser/mobile bundles.
Combine VettiGuard with secure authentication, authorization, input validation, rate limiting, fraud controls, monitoring and safe business logic. Use HTTPS in production and fail safely when required verification dependencies are unavailable.
Report suspected vulnerabilities privately through the deployment's security contact. Do not include production secrets, customer identity data or destructive proof-of-concept activity.
This action may affect your integration.