VettiGuard

Match verification strength to the action you are protecting.

Use VettiGuard for bot resistance, identity evidence, or both. High-friction identity checks belong on high-consequence actions—not every click.

Protect the consequenceHuman · Document · Face · Review · API

Customer, member, worker and high-risk account verification

Build a governed identity journey from a document capture through trusted facial/liveness evaluation and manual review when policy requires it.

  • Screen passport, national identity, driver-licence and residence-permit captures using available native signals.
  • Use document_only, standard or high assurance based on the action.
  • Require explicit consent and a consent reference before creating hosted identity sessions.
  • Use re-verification for sensitive account recovery, payout changes or periodic identity refresh rather than silently reusing an old decision.

Boundary: native document screening is not an issuer/government database confirmation unless a separately governed authoritative connector is explicitly introduced.

Registration, login, password reset and OTP requests

Reduce automated account creation, credential stuffing, recovery flooding and repeated verification requests with human-verification controls.

  • Apply stronger challenges to repeated or suspicious attempts.
  • Bind every response to the exact action being protected.
  • Escalate to an identity journey only when the business risk warrants it.

Contact forms, enquiries, newsletters and support requests

Keep automated spam and form flooding away from service teams, shared inboxes and downstream systems.

  • Keep the private site secret on your backend.
  • Use checkbox, invisible, score or policy-driven verification.
  • Inspect failure codes, request volume and site-level outcomes.

Checkout, payment initiation, reservations and limited inventory

Reduce slot hoarding, fake checkout attempts, promotion abuse, card-testing support traffic and scripted purchase activity.

  • Use human verification before high-cost or scarce-resource operations.
  • Require fresh identity verification for exceptional payout, beneficiary or account-owner changes when your policy calls for it.
  • Validate the authoritative server response before completing the transaction.

Comments, reviews, polls, voting and user submissions

Limit fake reviews, automated comments, mass voting and repetitive submissions that distort community trust.

  • Use visual or interactive challenges only where they add value.
  • Rate-limit challenge issuance and server verification.
  • Keep identity verification separate unless the community genuinely requires verified identity.

Giveaways, surveys, referrals, job applications and public programmes

Protect campaigns and application workflows from automated entries, duplicate submissions and resource exhaustion.

  • Create a dedicated site key and protected action for each campaign.
  • Use document/identity verification only for stages that genuinely require identity evidence.
  • Use quotas, rate limits and analytics to understand exceptional traffic.

Search, export, upload, generation and submission endpoints

Require recent human or identity verification before operations that consume compute, storage, messaging or third-party API capacity.

  • Use https://api.vettiguard.com/v1 as the canonical production API base for new integrations.
  • Keep private credentials out of browser and native app bundles.
  • Consume the final server-side result, not a browser success animation or client-provided biometric claim.

One trust layer across different assurance needs.

Choose lightweight bot protection for routine public interactions and stronger identity evidence only where it is proportionate.

E-commerceCheckout, stock, promotions, account recovery
FinTechOnboarding, authentication, high-risk account changes
Healthcare & NDISPortals, referrals, worker/member onboarding
SaaSTrials, accounts, privileged operations
Education & governmentApplications, forms, services and identity evidence
Agencies & developersReusable human and identity verification APIs

Protect the highest-risk action first.

Begin with the least intrusive verification that meets the risk, then step up to document, face/liveness or review when needed.