One human, one account.

A ban that a player can walk around by signing up again is not a ban, and an age gate a fourteen-year-old answers with a checkbox is not a gate. JERIX ties an account to a person who was identified against a government document — and then keeps no image of either.

The bill is already being paid.

These are other people's numbers, not ours. We have no published benchmark of our own and will not invent one.

Roblox reported chargebacks at roughly 3.41% of bookings in its 2024 SEC filing. The disputed amount is never the whole bill — scheme fees, the representment window and the manual review behind each case are charged on top, and none of them appear in the chargeback line itself.

The dispute is only the first invoice. The second is the account opened an hour later, by the same person, with a different email. Fraud that is cheap to repeat is not a fraud problem. It is an identity problem that has been priced as a fraud problem.

SOURCE: ROBLOX 2024 SEC FILING

Attributed, third-party, and not about us
19%median share of all login attempts that are credential stuffingVerizon DBIR
8,065AI-deepfake injection attempts against one financial institution's KYC flow in eight monthsGroup-IB

Inside the flow you already have.

The check happens where the player already is. No app download, no third-party-branded redirect, and no interstitial that reads as somebody else's product bolted onto yours.

One URL, opened in your own purchase flow

Your server asks for a session and receives a URL. You open it where the player is standing — at checkout, at the age gate, at the first withdrawal. Two server-to-server calls close the loop. There is no SDK requirement, so the language your platform is written in is not a gating question.

The verdict is a token, not a dossier

What comes back is the smallest answer that settles the question. A client can receive only verified, meets_age and age_gate_min — no name, no ID number, no date of birth, no image. A platform holding nothing identifying has nothing identifying to leak.

The same person, recognised again, without a database of faces

Re-identification runs against a one-way token. Two platforms receive different tokens for the same person and cannot cross-reference their user bases, so the ban you issue is yours and stays yours.

The whole of the integration

Two calls, one URL, three fields back.

A three-field answer is not a stripped-down trial tier. It is a legitimate configuration, and it is the one running in production in this segment today. Larger field sets exist and are configured per client, so your security review covers what you chose to take rather than everything a vendor decided to send.

The scoping question stops being “how long is the build” and becomes “which of our flows do we put it in”.

What the two calls look like →

Where the browser stops, and what that costs you.

A hosted page in a mobile browser cannot attest the device and cannot read an NFC chip. That is a real ceiling, and it is better read here than discovered in week three.

Assurance level by capture path
LevelEarned byWhat it is honestly good for
humanityA selfie with a detected face.Keeping bots out of a free tier.
lowA web capture in the hosted page.Low-risk signup. No device attestation.
substantialAn attested native capture in the JERIX app or your own app via the SDK.Standard onboarding, purchase gating, bans that hold.
highAn attested native capture plus an NFC passport chip read.Withdrawals, high-value accounts, regulated age duties.

Your server declares the level it requires and ours refuses anything weaker. The limit on the other side of this: a returning player in a mobile browser is sent through full verification again rather than a quick re-recognition, because a browser session cannot prove the device. Verify once, log in anywhere is not a claim we make.

Two duties that are already in force.

Procurement in this segment is usually driven by a calendar, and that calendar has already turned. Both duties below are live today, so an in-scope platform that is not verifying is not working towards a deadline — it is exposed now.

In force since February 2026 — the UK Online Safety Act's age duty

Platforms in scope must verify or estimate a user’s age, and have had to since February. JERIX verifies: the date of birth is read from a document, and on the chip path it is read from data the issuing state signed. We do not estimate age from a face, and we do not offer an estimator, because an estimator is a guess that a regulator can later ask you to defend.

In force since June 2026 — PEGI 16 for paid loot boxes in the UK

A UK game with paid loot boxes has required a PEGI 16 rating minimum since June 2026, which has already turned an age signal into a purchase precondition rather than a sign-up formality. If your check still sits beside checkout rather than inside it, that gap is open now.

Neither of these is legal advice, and whether a given title is in scope is a question for your counsel. What we can tell you is which of the two capture paths produces an answer you can stand behind afterwards.

Running in production in this segment.

One live third-party integration, in gaming, since 30 August 2026. We will not name it and we will not show its deployment domain, for the same reason we will not show yours.

It is a gaming ticket platform. It takes three fields and nothing else. It holds no name, no ID number, no date of birth and no image, which is why the integration review was short: there was very little to review on their side of the line.

The live integration, described as far as we are willing to describe it
FactDetail
segmentGaming — ticketing and digital goods.
live since30 August 2026.
integrationTwo server-to-server calls and one URL. No SDK.
fields returnedThree. No name, no ID number, no image.
named on this siteNo. Not now and not after a logo request.

What this page is not claiming.

The gaming buyer hands this page to a security officer. Here is what that officer would otherwise have to find out by asking.

Spoof detection does not decide anything

Liveness and the movement ceremony are measured and recorded on every capture. They do not gate a verdict. What rejects a swapped or replayed frame is the capture manifest — every frame hashed and signed on the device with a single-use nonce — and, on iOS, Apple App Attest proving a genuine unmodified app on real Apple hardware.

Not shippedScreen and print detection. Two detectors compute on every capture and neither decides anything yet. Blocked on a measured false-reject rate we are willing to publish.

Android captures carry no hardware attestation

The Android app ships and the capture manifest signs on it. Hardware attestation is not configured, so an Android capture is not the equal of an App Attest capture. For a gaming platform with an Android-heavy base this is the number to put in front of us.

Not shippedAndroid hardware attestation. Blocked on provisioning, not on architecture.

A player who changes phone

The wallet is encrypted on the device and unlocks with biometrics only. There is no escrow, which is the point — and it means a new phone is a new verification today.

Not shippedAccount recovery on a new phone. Blocked on designing a recovery path that does not become the weakest way in.

The full architecture, and the full list of what is missing →

Verify every player without becoming the target.

Bring your Android share, your chargeback rate and your in-scope titles. Twenty minutes with a real passport and the trust chain resolving offline.

Request a walkthrough