Product
From consent to a signed decision, with the evidence.
A hosted flow collects what the workflow asks for, the Rust engine runs each check, a documented rule decides, and a signed webhook tells your backend. Here is every piece.
Example decision
ses_01JD7Q8YB6N2Z3K4M5P6R7S8T9
- documentTD3 · check digits valid0.97Passed
- livenessturn_left · smile · move_closer0.91Passed
- face_matchthreshold 0.363 · reference document0.612Passed
- amlpotential_match · ofac_sdn0.86Needs review
- duplicate1 fingerprint · 1 face compared0Passed
- ipip and user agent recorded—Passed
aml_potential_match · a hit alone never fails the AML check01 · Identity
Prove the document is real and the person holding it is present.
Document verification
Passports, ID cards and residence permits through the ICAO 9303 MRZ; Indian cards through OCR.
ICAO 9303 · 7-3-1Liveness
Active challenge-response: turn left, turn right, smile, move closer, in a random order.
Active challenge-responseFace match
1:1 comparison of the selfie with the document portrait, or the Aadhaar photo.
SFace cosine · 0.363Age verification
A minimum age checked against the date of birth from a verified document.
Document date of birth
02 · India
Aadhaar and PAN, handled the way UIDAI and the Income Tax Department define them.
03 · Risk
Screen against sanctions and catch the same person coming back.
04 · Platform
Configure, review and integrate without writing a verification UI.
Workflows
Choose the steps, the thresholds, the documents and the countries, without code.
No-code builderReview console
A queue of sessions in review, with every check, image and warning beside the decision.
RBAC · audit logWebhooks and API
Signed webhooks with persisted retries, a sessions API and standalone check endpoints.
HMAC-SHA256 · v1
Try it in your browser
Eleven rules you can run before you sign up.
Every capability page has a working demo of the rule it applies, ported from the Rust engine and run locally in your tab. Nothing you type is sent anywhere.
- Document verificationRecompute a check digit yourself.
- LivenessPlay the rules, not a recording.
- Face matchMove the similarity, watch the outcome.
- AadhaarFollow an artefact from scan to stored digits.
- PANType a PAN, read it position by position.
- AML screeningSee why a name scores what it scores.
- Age verificationThree kinds of birth date, three honest answers.
- Duplicate detectionHash a document number the way the engine does.
- WorkflowsBuild a workflow and read its consequences.
- Review consoleDecide like the engine, then like a reviewer.
- Webhooks and APISign and verify a delivery in your browser.
- SandboxThen run them on real captures, with test keys.
Built on standards
Named standards, not a black box.
Each check implements something you can look up. Where a model is involved, it is an openly licensed one, run in-process on KYCVerify's own servers. No external model API sees an image.
| Standard or primitive | What it does here | Where |
|---|---|---|
| ICAO Doc 9303 | Machine-readable zones: 6 layouts, 7-3-1 check digits | Document verification |
| UIDAI Secure QR (2019) and Offline e-KYC | RSA SHA256withRSA and enveloped XML-DSig, verified with UIDAI's certificate | Aadhaar |
| Verhoeff checksum | Aadhaar numbers read from a card by OCR | Document verification |
| Income Tax Department PAN format | Structure, holder type and name initial | PAN |
| OFAC SDN and UN consolidated lists | Downloaded from the official sources into an in-memory index | AML screening |
| YuNet and SFace (OpenCV model zoo) | Face detection, landmarks and 1:1 embeddings, run on your CPU | Liveness, Face match |
| HMAC-SHA256 | Webhook signatures over timestamp and raw body | Webhooks and API |
| AES-256-GCM | Every uploaded file, encrypted at rest | Security |
| Argon2id | Console passwords | Security |
The hosted flow
Seven positions, always in the same order.
A workflow chooses which steps appear; the order never changes, so the experience is predictable for people and for your support team.
- 01ConsentThe person accepts the processing notice for your app.
- 02EmailOptional one-time code: 6 digits, valid 10 minutes.
- 03DocumentType, country, front and back, with a quality gate.
- 04AadhaarSecure QR or Offline e-KYC, signature verified.
- 05PANNumber, name and an optional card photo.
- 06LivenessRandom challenges, analysed frame by frame.
- 07SubmitBackground checks run and a decision is reached.
Checks
Ten check kinds, two moments.
Steps write their checks as the person goes. Background checks run once, at submit, from what the steps collected.
- 01
Any check failed
The session is declined, or sent to review when the workflow turns auto-decline off.
- 02
Else any check in review or error
The session goes to the review queue for a person to decide.
- 03
Else
The session is approved.
During the flow
- Document
document - Liveness
liveness - Aadhaar
aadhaar - PAN
pan - Email
email
At submit
- Face match
face_match - AML
aml - Age
age - Duplicate
duplicate - IP
ip
The checks, in depth
Know exactly what each check proves, and what it does not.
Every check writes a status, a score where one exists, and the warnings behind it. Defaults below are the shipped workflow configuration; every limit is stated next to the feature.
ICAO 9303 · 7-3-1
Read the document the way the issuer wrote it.
Passports, ID cards and residence permits through the ICAO 9303 MRZ; Indian cards through OCR.
- Check digits
- Document number, date of birth, expiry, optional data and the composite digit, each recomputed with ICAO's 7-3-1 weights. Long TD1/TD2 document numbers that continue into the optional field are handled.
- OCR correction you can see
- Common confusions (O and 0, I and 1) are corrected only in positions whose alphabet is known, and every correction is reported, so a reviewer can tell a clean read from a repaired one.
- Image quality
- Resolution, sharpness (variance of the Laplacian), exposure and glare are measured first. A blurry or glare-washed capture is sent back to the person with a reason instead of being guessed at.
- Expiry, type and country
- An expired document is declined when the workflow says so. The declared type and issuing country must match what the MRZ says, and the country must be on the workflow's allow-list.
Stated plainly: No NFC chip reading: the e-passport chip is not read, so the check relies on the printed MRZ and the image.
Workflow configuration · defaults
- allowed_types
- Which document types the person may choose.
- all 7
- allowed_countries
- ISO 3166-1 alpha-3 issuing countries, e.g. IND, GBR.
- [] (any)
- reject_expired
- Decline a document past its expiry date.
- true
- max_attempts
- Captures allowed before the step fails.
- 3
{
"kind": "document",
"status": "failed",
"score": 1.0,
"data": {
"document_type": "passport",
"country": "UTO",
"attempt": 1,
"issuing_country": "UTO",
"verification_level": "mrz_check_digits",
"mrz": {
"format": "td3", "document_code": "P", "issuing_state": "UTO", "valid": true,
"check_digits": { "document_number": true, "birth_date": true, "expiry_date": true,
"optional_data": true, "composite": true },
"corrections": 0
},
"reason": "document_expired"
},
"warnings": [
{ "code": "document_expired", "message": "The document expired on 2012-04-15", "severity": "high" }
]
}FAQ
What people ask before they integrate.
Is KYCVerify a hosted service?
Yes. KYCVerify runs at kycverify.me: your backend calls https://kycverify.me/api, people verify at kycverify.me/verify/{token}, and your team uses the console there. Every check runs on KYCVerify's own engine, uploads are encrypted at rest with AES-256-GCM, and each app's evidence is purged after its retention period.
What can it verify?
Passports, ID cards and residence permits through the ICAO 9303 MRZ; Aadhaar, PAN, voter ID and Indian driving licences by OCR; Aadhaar Secure QR and Offline e-KYC against UIDAI signatures; active liveness; face match; sanctions screening against OFAC SDN and UN lists; minimum age; duplicates; email ownership.
What does it not do?
No NFC chip reading, no certified passive liveness, no PEP or adverse-media screening, no KYB, no phone OTP, no government database lookups and no native SDKs. We would rather you know now. The comparison lists it all.
Is the liveness check certified?
No. It is active challenge-response (turn left, turn right, smile, move closer) analysed frame by frame on KYCVerify's engine, and it is labelled as such. It has not been tested by a presentation-attack-detection lab.
How does my backend get the result?
A session.status_updated webhook signed with HMAC-SHA256 for every status change, carrying the full decision when the session is final. You can also call GET /v1/sessions/{id}/decision at any time.
Do people need to install an app?
No. The hosted flow runs in the browser on any modern phone or laptop and uses the device camera.
How long is data kept?
Each app has a retention period, 90 days by default. A worker purges the files, face embeddings and identity data of older sessions automatically, and you can purge any session on demand with DELETE /v1/sessions/{id}.
Does it handle Aadhaar numbers?
The offline formats (Secure QR and Offline e-KYC XML) contain only the last four digits, so that is all they give you. If a workflow also accepts a photographed Aadhaar card, the number is read to validate it and kept only masked and as a keyed fingerprint; the card image, which shows the full number, stays encrypted until the retention purge.
Try every check in the sandbox.
Sign up for an organisation with a sandbox app, test keys and a default workflow.