
Features
Part of A working brief on identity verification
What should you demand before proving your identity to a tool?
Identity verification tools judged from the outside: what to demand of any service that asks you to prove yourself, and what no tool can settle about a stranger.
Most writing about verification tools is aimed at the buyer of the service. This page is aimed at the person being scanned.
You rarely choose the provider, but you choose whether to proceed, what to hand over, and what to ask first.
The useful list is not a ranking; it is what a service must do to deserve your document. It covers the few cases where you walk away, no matter how good the service is, and nothing is named, on purpose.
What to take away
- You are not buying the tool, so judge it by what it asks for and what it says about retention.
- No verification product can tell you who is on the other end of a conversation, which is the question most readers arrive with.
- The strongest check available to an individual is presence, and it costs nothing.
Six things to demand before you upload anything
Ask these of the service, or find the answers on its own pages. A service that will not answer has answered.
Demand before you upload
- What is retained, and for how long
- Who actually performs the check
- Whether a partial document is enough
- What the alternative route is
- What happens on a false rejection
- Whether the image is used elsewhere
Six things to demand
- What exact data will you collect from me, and will you collect only what the check needs?
- How long will you keep each item, and what is the deletion date for the document image and the face scan?
- Who else receives my data, including any subcontractor, and what do they do with it?
- Can I finish the check without giving a document image, a face video, or a bank login?
- What happens to my data if I close the account or ask for deletion?
- Will you verify me again without a fresh request, and will you tell me when that happens?
A retention answer that should satisfy: 'We delete the document image within 30 days and keep only a pass or fail flag.' A disqualifying answer: 'We retain records as long as needed for legal compliance,' with no period given.
The reason these questions matter is simple: once a document or a face scan is stored, it cannot be recalled, and the identity verification risks 2027 page has the detail.
What the different methods can actually establish
What it establishes
- Document scan
- A document was presented and appears consistent
- Document plus liveness
- Somebody was present at that moment with that document
- Knowledge questions
- The answerer knows facts about a record
- Phone number matching
- A number is associated with a name in a dataset
- Bank connection
- An account exists in a matching name
What it does not
- Document scan
- That the person presenting it is its holder
- Document plus liveness
- Who holds the account afterwards
- Knowledge questions
- Anything, once those facts have leaked, which they have
- Phone number matching
- Control of that number today
- Bank connection
- That anybody consented to more than one check
The right-hand column explains why verification badges mean less than users assume, and why re-verification exists at all.
What each method establishes
Method
- Document scan
- Document presented, looks consistent
- Document plus liveness
- Someone present with document
- Knowledge questions
- Knows facts about a record
- Phone number matching
- Number linked to a name
- Bank connection
- Account exists in matching name
Establishes
- Document scan
- Presenter is its holder
- Document plus liveness
- Who holds account later
- Knowledge questions
- Anything, once facts leak
- Phone number matching
- Control of number today
- Bank connection
- Consent beyond one check
Does not
- Document scan
- Document plus liveness
- Knowledge questions
- Phone number matching
- Bank connection
What none of them do
There is one question this whole industry cannot answer for you: is the person messaging me the person these checks were run on.
Accounts change hands. Sessions get taken over. A profile verified two years ago was verified two years ago.
A live video call at your chosen time and a payment route that supports a dispute both survive the gap. The stranger-facing version sits in catfishing.
Services that are sold to you rather than to a platform
Three consumer categories are worth sorting out.
Identity monitoring. Tells you an address of yours appeared somewhere. Useful after a known exposure, weak as a general purchase, and it cannot prevent anything.
Document vaults. Convenient, and they create another copy of exactly what you are trying to protect. Judge them on retention and on what happens when you close the account.
Verification as a service for private deals. Marketed for renting, selling, and dating. It confirms that a document was presented to it, which is not the thing you wanted to know, and it puts your details into another system to say so.
Where a service reaches you during or after an incident, treat the approach itself as the signal. Nobody legitimate contacts you first offering to restore, clear, or verify anything for a fee, and the routes that work are in reporting and recovery.
Judging a flow while you are inside it
Four quick observations tell you more than any review.
Judging a flow from inside
Did you arrive by your own route?
continue checking the rest
stop regardless of the rest
Whether you arrived by your own route or by a link that came to you. Whether the address in the browser belongs to the organization or to something adjacent. Whether it asks for anything that is not identity, such as a payment, a code, or a login. And whether it is willing to say what it keeps.
If the first is wrong, stop regardless of the rest. The full walkthrough for completing a genuine check safely, including how to spot a fake handoff, is in identity verification guide 2027.
For anyone choosing a provider rather than facing one
The same list works, read from the other side, plus one addition: prefer the smallest check that answers your question. Collecting a full document image and a face video for a decision that needed a name and a date creates a liability for you and a permanent exposure for the person you are checking.
The published standards for what different assurance levels are for are at the NIST digital identity guidelines, and the ordinary consumer view of privacy and data collection online is set out by the FTC.
Common questions
Is one verification method clearly safer for me than another?
Less is safer. A check that needs a name and a date beats one that needs a full document, and one that needs a full document beats one that also needs your face.
What if the automated check keeps failing?
Ask for the manual route. Rejections are common and are frequently about lighting and image quality rather than about you.
Should I pay for a service that verifies other people for me?
For a private deal, no. It answers a question about a document, not about the person you are talking to.
Are these tools regulated?
It depends where you and the provider are, and it changes. The bodies to ask, and how to find them, are covered on the identity verification overview.
What is the cheapest thing that improves my position?
Asking what is retained, before you upload. It costs one email, it changes what you agree to, and the answer tells you what kind of company you are dealing with.







