Skip to content

About

Identity verification should show its working.

KYCVerify started from a simple observation: most verification products return a verdict and keep the reasoning to themselves. For the people who must defend a decision, and the people being verified, that is the wrong trade.

Architectureone host
  • Hosted flow
  • Console
  • Your backend

KYCVerify · kycverify.me

  • Next.js appconsole, hosted flow
  • kyc-apiRust engine, workers
  • SQLitedata/kyc.db
  • UploadsAES-256-GCM
Outbound only: code emails, your webhook, the OFAC and UN list downloads
Rust crates, each with one job
5
check kinds behind one decision rule
10
MRZ layouts, every check digit recomputed
6
third-party verification APIs called
0

Why it exists

Identity verification is a narrow, well-specified problem. Passports follow ICAO 9303. Aadhaar's offline formats are signed by UIDAI with published certificates. Sanctions lists are published by their issuers. Face detection and embedding models are openly licensed. The parts exist; what was missing was a careful assembly that keeps the minimum and explains every result.

So KYCVerify is that assembly, run as a hosted service at kycverify.me: a Rust engine with its own crates for the MRZ, India's identity formats, vision and sanctions screening, an API that follows a written contract, a hosted flow that works in any browser, and a console for the people who review the hard cases.

It says what it does and what it does not. Liveness is challenge-response, not a certified PAD model. PAN is validated structurally. AML covers two lists. Those limits are on the product pages because the people choosing a verification system deserve to know them before they sign up, not after.

Principles

How decisions get made here.

  1. 01

    Our own engine

    Every check runs on KYCVerify's own code. No third-party verification or model API sees an image.

  2. 02

    Standards first

    Implement the specification, cite it, and recompute what it says can be recomputed.

  3. 03

    Evidence over verdicts

    Every decision carries the checks, scores and warnings behind it.

  4. 04

    Minimum by default

    Mask, hash and purge. Keep the last four digits, not twelve.

  5. 05

    Honest limits

    State what a check cannot prove, in the product and on this site.

Built on standards

Implement the specification, cite it, recompute it.

Each part of the engine follows a published standard or an openly licensed model, so you can check what it does against something other than our word.

  • ICAO Doc 9303

    Machine-readable zones of passports, ID cards and visas: TD1, TD2, TD3, MRV-A, MRV-B, plus the French ID.

    kyc-mrz
  • UIDAI Secure QR and Offline e-KYC

    RSA-2048 signatures over the QR payload; enveloped XML-DSig over the offline XML; iterated SHA-256 contact hashes.

    kyc-india
  • Verhoeff and PAN structure

    The checksum on Aadhaar numbers read by OCR, and the holder-type and name-initial rules of PAN.

    kyc-india
  • OFAC SDN and UN consolidated lists

    The published CSV and XML, with aliases, programmes, dates of birth and nationalities.

    kyc-aml
  • YuNet, SFace and ocrs

    Openly licensed face detection, face embedding and OCR models, run on a pure-Rust runtime.

    kyc-vision
  • AES-256-GCM, HMAC-SHA256, Argon2id

    Uploads at rest, webhook signatures and console passwords.

    kyc-api

How it is built

Small crates, each with one job.

The engine is a Rust workspace. The library crates are pure: no network, no database, documented against the standard they implement.

  • kyc-mrz

    ICAO 9303 parsing and check digits, pure Rust

  • kyc-india

    PAN, Verhoeff, Aadhaar Secure QR and Offline XML with UIDAI signatures

  • kyc-vision

    YuNet, SFace and ocrs on a pure-Rust inference runtime

  • kyc-aml

    OFAC SDN and UN parsers with a fuzzy screening index

  • kyc-api

    axum, SQLite, workers for webhooks and retention

  • frontend

    Next.js console and hosted verification flow

What it does not do

Said plainly, before you ask.

These are not on a dated roadmap. If one of them is a requirement for you, tell us: it shapes what gets built next.

Compare with other vendors
  • NFC chip reading of e-passports
  • Passive or certified (ISO/IEC 30107-3) liveness
  • PEP lists, adverse media and ongoing AML monitoring
  • Government database lookups, including PAN
  • Native iOS and Android SDKs
  • Running across several servers (SQLite and an in-process rate limiter today)

Get in touch

Questions go to people who know the code.

Read the code paths, then try it.

The documentation describes exactly what each check does. The sandbox lets you see it.