Age verification, for a duty that is already in force.

If your platform is in scope and the gate is still a self-declared checkbox, you are not working towards a deadline. The deadline passed, and the exposure is open now. That is a stronger reason to act than any date on a slide, which is why this page leads with it rather than with a calendar.

UK Online Safety Act age assurance: in force, present tense.

Procurement in this segment is usually driven by a calendar, and the calendar has already turned. Both duties below are live today.

The Online Safety Act's age duty took effect in February 2026

Platforms in scope must verify or estimate a user’s age, and have had to since February. An in-scope service still gating with a checkbox has been out of step with the duty for months, not preparing for it. The question in front of you is no longer whether to put a check in place; it is which kind of answer you want to be holding when somebody asks how the gate works.

PEGI 16 for paid loot boxes in the UK applies from June 2026

A UK title with paid loot boxes has carried a PEGI 16 minimum since June 2026, which turned an age signal into a purchase precondition rather than a sign-up formality. If your check sits beside checkout rather than inside it, that gap is open now.

None of this is legal advice

We are not your counsel, and whether a given title or service is in scope is a question for your own lawyers rather than for a vendor’s marketing page. What we can tell you is exactly what each capture path establishes, so your counsel is reasoning about a mechanism rather than about an adjective.

The position, in one line

An estimate is a judgement you may be asked to defend. A date of birth read from a signed chip is not.

That difference does not matter on a quiet day. It matters on the day somebody asks how a specific fourteen-year-old got through, because at that point the only useful thing to own is a record of what was checked.

Verified, not estimated — and no age estimation from a face.

This is a product decision, not a gap in the roadmap. We do not offer an estimator and are not building one.

The date of birth is read from a document

Not inferred from a face, not modelled from behaviour, not bought from a data broker. It is read from the document the person presents, and the verification is tied to the live selfie taken at the same moment.

On the passport chip path, the state signed it

A passport carries a chip the issuing state signed. JERIX reads it over NFC and verifies the signature chain to that state’s national root — offline, against 588 certificates from 112 countries, with no network call, no CRL and no OCSP. On that path the date of birth is not our reading of a printed page; it is data a government signed.

Why we refuse to ship an estimator

An estimate is a probability presented as a decision. It will be right most of the time, and the cases it is wrong about are exactly the cases that end up in front of a regulator — a young face refused, or a sixteen-year-old waved through. A document check can be wrong too, but it is wrong in a way you can reconstruct, because there is a document and a signature behind it rather than a model output.
What each path establishes about age
PathWhere the date of birth comes from
passport chipData signed by the issuing state, verified to its national root offline. The strongest answer available here.
document pageRead from the printed document. No state signature is verified — an Israeli ID card is always this path, because that chip is government-locked and cannot be read.
age estimationNot offered. Deliberately. There is no estimator in the product and none planned.

Your server declares the assurance level it requires and ours refuses anything weaker rather than returning a pass with a caveat attached. How the chip path works, in full →

Age verification for gaming and digital goods, without holding the identity.

The gate and the dossier are two different decisions, and most vendors bundle them. A platform can prove the gate without becoming the custodian of who was behind it.

Three fields, and nothing else

A client can be configured to receive only verified, meets_age and age_gate_min — no name, no ID number, no date of birth, no image. You can demonstrate that the gate ran and that the person met it, while holding nothing identifying about them. The integration running in production in this segment takes exactly that.

Inside your own flow, at the moment that matters

Your server asks for a session and receives a URL, which you open where the player is already standing — at the age gate, at checkout, at the first withdrawal. Two server-to-server calls close the loop and there is no SDK requirement, so the language your platform is written in is not a gating question.

And the images are not kept

The document image, the chip data and the face image are used inside the request and are not retained. The correct claim is zero retention on images and biometrics, verified on disk — not that we keep nothing, which would be false. Name, national ID and date of birth are retained encrypted, and two face-derived hashes live 30 and 7 days.

The asymmetry worth noticing

A compliance programme that works by accumulating identity documents makes the platform a better target every month it runs. A three-field answer does the opposite: the gate gets stronger and the thing an attacker would want is not there.

Larger field sets exist and are configured per client, so your security review covers what you chose to take rather than everything a vendor decided to send.

What this page is not claiming.

An age-assurance page is exactly the kind of page that gets handed to a lawyer and a security officer in the same week. Here is what they would otherwise have to extract by asking.

This is not legal advice, and we are not certifying your compliance

Whether a given title or service falls in scope, and what a particular duty requires of it, is a question for your own counsel. We describe a mechanism. We do not tell you that running it makes you compliant, and a vendor who does is selling you a sentence rather than a check.

An Israeli ID card cannot reach the chip-backed level

That chip is government-locked and cannot be read — by us or by anyone outside the state’s own systems. Every Israeli ID card is therefore a photo-only verification, and the date of birth on that path comes from the printed page rather than from signed data. If your duty needs the chip-backed level, the document that gets you there is a passport.

A mobile browser cannot read a chip or attest a device

The hosted page works, and it tops out below the attested levels. The chip path needs a native capture — the JERIX app, or your own app through the React Native or Flutter SDK. A returning person in a mobile browser is sent through full verification rather than a quick re-recognition, so verify once and log in anywhere is not a claim we make.

Spoof detection does not decide anything

Liveness and the movement ceremony are measured and recorded on every capture and gate nothing. We do not claim the system blocks a spoofed selfie or detects a printed or on-screen copy. What rejects a swapped or replayed frame is the capture manifest, hashed and signed on the device against a single-use nonce; on iOS, Apple App Attest proves a genuine unmodified app on real Apple hardware. Android carries no hardware attestation.

Not shippedScreen and print detection as an enforcing control; liveness enforcement; Android hardware attestation. The first is blocked on a false-reject rate we are willing to publish, the last on provisioning.

No certification stands behind this

No SOC 2, no ISO 27001, no third-party penetration test and no iBeta presentation-attack evaluation. Two founders, pre-certification, with one live third-party integration in this segment since 30 August 2026 — a gaming ticket platform, which we will not name.

Not shippedSOC 2, ISO 27001, penetration test, iBeta ISO 30107-3. Published data-retention policy — blocked on drafting, not on behaviour.

The full architecture, and the full list of what is missing →

Bring the titles you think are in scope.

Twenty minutes, a real passport chip read with the network interface down, and a straight answer about which of your flows the gate belongs inside.

Request a walkthrough