Ten questions,answered the way procurement needs them.

This page is written to be forwarded. Each answer is the one we would give your security officer and your procurement lead in writing, with the limit stated beside the claim and a link to the page that carries the long version. Four of the ten answers are partly or wholly “no”.

Commercial and contractual

The four questions that decide whether a conversation is worth either side's time. They are first because they are the ones most often left until a vendor has already consumed a procurement cycle.

What does it cost?

Priced per verification, by monthly volume and by the assurance level the flow requires, with no per-seat licence, no platform fee, no minimum commitment and no charge for re-verifying someone already verified. There is no published rate card, because with one third-party integration live a table would be an extrapolation from one observation, and a number invented now is a number to walk back in the contract. Send monthly volume and the assurance level needed and the figure comes back by email, without a discovery call in front of it.

The shape of the price, and why the rate is missing →

Is a data processing agreement available?

Yes. A DPA is available and is signed per client, negotiated against your paper rather than ours. The unusual part is how little it has to cover: the personal data a JERIX deployment actually processes and retains is three encrypted text fields — name, national ID number and date of birth — because no face image, no biometric template, no document image and no chip data is retained to be transferred, sub-processed or disclosed.

Not shippedThere is no published DPA template to download before a conversation, and the privacy notice on this site has not been reviewed by counsel. Both are being drafted; neither should be treated as a finished legal instrument until it is signed.

What is processed, field by field →

Where is the data held?

What exists to hold anywhere is small: the three encrypted identity fields, two face-derived hashes that expire at thirty days and seven days, and the tamper-evident audit chain. There are no images, no embeddings or templates and no chip data at rest — zero retention on images and biometrics, verified on disk — so the residency question is a question about encrypted text and a log, not about a face gallery. Hosting region is settled per deployment and written into the contract; we will not assert a legal conclusion about transfers on a marketing page, because that is counsel's call and not ours.

Not shippedThere is no data-retention policy published yet: the encrypted identity fields are retained indefinitely today, with no per-field lifetime and no deletion job enforcing one. On-prem packaging, which would answer residency by removing us from it, has zero reference installations.

Zero retention, and how to verify it yourself →

What happens if you stop existing?

A fair question to ask two founders, and the architecture answers the worst part of it: because no image and no biometric template of your users is ever retained, insolvency puts no face gallery into an administrator's hands. What an administrator would find is three encrypted text fields per verified person and an audit chain — and your key material is generated by you, so the ciphertext does not travel with the means to open it. The data-protection exposure of a JERIX failure is therefore structurally smaller than the exposure of a retention-based vendor's failure, which is the part of this question that normally has no good answer.

Not shippedService continuity is the part with no answer yet: there is no source-code escrow arrangement and no written continuity undertaking. Both are a negotiation we expect to have with you, not a surprise to discover afterwards — raise it in the term sheet and it gets drafted.

Who the company is, in full →

Technical and assurance

Six questions a security officer asks, including the three where the honest answer is a limit. The limit is the proof of the claim — an answer that never says no is an answer nobody should accept.

How long does the integration take?

The integration surface is two server-to-server calls and one URL, with no SDK requirement and no constraint on your backend language. Your server starts a verification, you send the person to a URL, and a signed webhook returns the result — which can be narrowed to verified, meets_age and age_gate_min alone, with no name, no ID number, no date of birth and no image crossing into your systems. React Native and Flutter SDKs exist if you want the capture inside your own app instead, and the first third-party integration has been live since 30 August 2026.

Real request and response shapes →

Do you have SOC 2?

No. JERIX holds no SOC 2 Type I or Type II, no ISO 27001, no third-party penetration test and no iBeta ISO 30107-3 result, and there is no badge row on this site because there is nothing to put in it. If a certification is a hard gate in your procurement, this is the answer that disqualifies us, and it is better read now than in week six.

Not shippedAll four are unstarted or blocked, each for a named reason: written policies and an engaged auditor for SOC 2, the management system for ISO 27001, cost and scope for a credible penetration test, and gating detectors for iBeta. What exists instead is architecture you can inspect in a walkthrough, which is evidence rather than attestation and not a substitute for one.

Every unshipped item, and what it is blocked on →

Can you read an Israeli ID card?

No. The chip in an Israeli ID card is government-locked and cannot be read by anyone outside the state's own systems, so no vendor — us included — is reading it, whatever a competing deck says. An Israeli ID card is therefore a photo-only verification in JERIX: the document is captured, read and matched, and it does not earn the chip-backed assurance level, because nothing cryptographic was proved. The chip-backed path is the passport: an NFC read whose signature chain resolves to a national root offline, against 588 certificates across 112 countries, with no network call, no CRL and no OCSP.

What the chip read actually proves →

Do you block deepfakes?

Not by detection, and we will not claim otherwise. Liveness and the movement ceremony are measured and recorded with every capture, and they decide nothing — no verification is refused because a detector disliked it. What actually resists a synthetic face is provenance: a state's signature on the passport chip, from which the reference face is taken server-side; a capture manifest hashed and signed on the device with a single-use nonce, so frames cannot be swapped or replayed; and Apple App Attest, proving a genuine unmodified app on real Apple hardware.

Not shippedAndroid hardware attestation is not configured, so an Android capture carries the signed manifest and the nonce but no device attestation. Screen and print detection computes on every capture and gates nothing, blocked on a threshold defensible to a security officer, which needs labelled attack data rather than an opinion.

Provenance, mechanism by mechanism →

What happens when a user changes phone?

They verify again from the beginning. The wallet is encrypted on the device and unlocks only with the holder's own biometric, which is the point of it and also the reason a replaced, lost or wiped phone cannot be recovered into. Note the related limit while you are modelling this: in a mobile browser, the hosted login page sends the person to full verification rather than recognising them, so “verify once” holds inside the app and not in every browser.

Not shippedThere is no account recovery on a new phone. Blocked on a recovery design that does not reintroduce what was removed — every quick version works by keeping a biometric centrally or escrowing a key that opens a holder's wallet without the holder, and either one would make the architecture argument false.

The recovery problem, stated in full →

Who runs the demo?

One of the two founders — Michael Livshitz or Ron Hillel. There is no sales engineer between you and the system, which means the person answering your security officer's questions is the person who built the thing being questioned, and can be wrong in writing rather than vague in person. A walkthrough covers what works and then the unshipped list, because a gap that blocks your procurement is cheaper for both of us in the first meeting.

Request a walkthrough →

What a procurement pack can contain today.

The same list a vendor normally sends as a folder of PDFs, printed here with the empty slots left empty. Nothing in the right-hand column is a plan with a date on it.

Procurement documents — what exists, in full
ItemStatus
DPAAvailable. Signed per client, negotiated against your paper.
security questionnaireAnswered in writing, by a founder, with the gaps marked rather than smoothed.
architecture walkthroughAvailable. The trust store, the offline chain resolution and the signed capture manifest, inspected live.
DPA template

Not shippedNo published template to download before a conversation.

privacy notice

Not shippedPublished, but not reviewed by counsel. Treat it as a description of the architecture rather than a legal instrument.

retention policy

Not shippedNo per-field lifetime and no deletion job. The encrypted identity fields are retained indefinitely today.

SOC 2 report

Not shippedNeither Type I nor Type II. Unstarted; blocked on written policies and an engaged auditor.

penetration test report

Not shippedNone. Blocked on scope and on the cost of a credible engagement; a cheap test would be worse than none.

source-code escrow

Not shippedNo escrow arrangement and no written continuity undertaking. A negotiation, not a surprise.

If a missing row above is a hard gate for you, say so in the first email and we will tell you plainly whether it can be met on your timetable. Several of them can be negotiated into a contract rather than waited for, and the ones that cannot — the audits — are better known early than discovered late.

Every unshipped item, and what each is blocked on →

A question that is not on this page.

Send it. It is answered in writing by one of the two founders, and if the answer is a limit you will get the limit.