What is not shipped,and what each item is blocked on.

Everything below is unfinished. Nothing on this page is a commitment to a date, and nothing on it is described as working when it is not.

Why a vendor publishes this.

A mock-up presented as a product does not end a deal in the first meeting. It ends it in the second one, when the security officer asks the question the demo cannot survive — and by then you have spent a procurement cycle on us.

So we publish the list instead. The second reader on your side is the one this page is written for: the person whose job is to find the overclaim. If they find the limits already written down, in our own words, with the blocker named, then the rest of the site becomes testable rather than promotional.

The limit is the proof of the claim. Read this page first, then go back and argue with the ones that say something works.

Near term

Three gaps a buyer will hit in the first weeks of a real deployment. These are ours to fix, and none of them is waiting on anybody else.

Account recovery on a new phone

The wallet is encrypted on the device and unlocks with the holder's own biometric. That is the point of it — and it is also the reason a replaced, lost or wiped phone means verifying again from the beginning. There is no recovery path today.

Not shippedBlocked on a recovery design that does not reintroduce the thing we removed. Every quick version of this works by keeping a biometric somewhere central, or by holding an escrowed key that can open a holder's wallet without the holder. Either one would make the architecture argument false, so neither ships.

Off-site encrypted backup

Server-side state today is the encrypted identity fields and the audit chain. There is no off-site encrypted copy of it.

Not shippedBlocked on key custody. A second copy is only worth having if restoring it is possible, and only safe if restoring it is hard — and we are not willing to describe a backup as encrypted while holding the key beside it. The design has to settle who holds what before anything is copied anywhere.

A data-retention policy

Zero retention on images and biometrics is already true and verified on disk: no face images, no document images, no embeddings or templates, no chip data. Two face-derived hashes expire at 30 days and 7 days. What is missing is the text: name, national ID and date of birth are retained encrypted, and today that retention is indefinite. That is the honest answer, not a placeholder for a shorter one.

Not shippedBlocked on the policy itself — a defined lifetime per field, a deletion job that enforces it, and counsel review of what a regulated client's own retention duty will require of us. Writing a number on this page before the job exists would be the kind of claim this page is here to prevent.

Next

Work where a real part already ships and the part you would actually buy does not. The distinction matters, so each entry states which half exists.

SSO / OIDC, including Entra

The signing core ships — tokens are issued and signed today. The four endpoints an identity provider needs in order to talk to us do not exist, so no enterprise can point Entra at JERIX and have it work.

Not shippedBlocked on building and conformance-testing those endpoints. Until they answer, there is no SSO, and nobody should plan a procurement around one.

Screen and print detection

Two detectors compute on every single capture, and their output is recorded with the capture manifest. Neither of them decides anything. A verification is not refused because a detector disliked it.

Not shippedBlocked on a threshold we could defend to a security officer, which needs labelled attack data rather than an opinion. Until a detector gates a verdict, this site will not say that JERIX detects printed or on-screen copies — because it does not.

On-prem packaging

The core already runs fully offline once provisioned — chip verification, trust chain, face matching and OCR need no network. So the hard part is done, and the deployable package is not. There are zero reference installations.

Not shippedBlocked on a first installation to learn from. An on-prem claim without one is a claim about an untested build, and we would rather say the number is zero.

External

Audits, certifications and independent testing. JERIX holds none of these. There is no badge row on this site because there is nothing to put in it, and a badge we do not hold is the one lie that would cost us the whole category.

External attestations — status, in full
ItemWhat it would beStatus
SOC 2 Type IAudited controls report, first point-in-time stage.

Not shippedBlocked on written policies — the retention policy above is one of them — and on engaging an auditor. Not started.

SOC 2 Type IIThe same controls, observed operating over a period.

Not shippedBlocked on Type I, and then on the observation window itself, which is time nobody can compress. Not started.

ISO 27001Certified information-security management system.

Not shippedBlocked on standing up the management system the certificate attests to, which overlaps heavily with the SOC 2 work. Not started.

Third-party penetration testAn external team attacking the production system.

Not shippedBlocked on scope and on the cost of a credible engagement. The company is two people and pre-funding, and a cheap test would be worse than none, because it would come with a report we would be tempted to cite.

iBeta ISO 30107-3Independent presentation-attack detection testing.

Not shippedBlocked on screen and print detection above. Submitting a system whose detectors decide nothing would certify nothing — there is no attack to resist yet, only one to measure.

What exists today instead is architecture you can inspect for yourself in a walkthrough: 588 certificates and 112 countries in the trust store, the chain resolving with no network call, and every capture hashed and signed on the device with a single-use nonce. That is evidence rather than attestation. It is not a substitute for an audit, and we are not going to pretend it is one.

Ask us about the items on this page.

A walkthrough covers what works, and then this list. If one of these gaps blocks your procurement, it is better for both of us that you learn it in the first meeting.

Request a walkthrough