The courier at the door has to be the courier you cleared.
Onboarding is the half of the problem every platform has already solved. The unsolved half is the pickup eleven weeks later, when the account is the account you approved and the person holding the phone is not. JERIX identifies the human at that moment, inside your own app, without keeping a face to compare against.
Per-pickup identification, with nothing stored to match on.
A re-check that depends on a stored face image or a stored template is a re-check that builds the breach. Ours resolves against a one-way token instead.
Zero retention on images and biometrics, verified on disk
Your brand, your app, your flow
What lands on your server
One call to one endpoint you own
The result is delivered to an address you nominate, signed, so your server can prove the message came from us before it acts on it. There is nothing to poll and no console for your ops team to sit in.
A delivery cannot be replayed
Each one carries a single-use nonce. A second copy of the same message is rejected rather than processed again, so a captured delivery is not a way to clear a pickup twice.
Four answers, not a file on the person
What happened, whether it verified, the assurance level the capture earned, and the token for this courier that is scoped to you alone. No image, and no face to compare against. Field sets are configured per client.
Three moments, one mechanism.
Marketplaces tend to buy for the first row and get burned on the second. The third is the one nobody budgets for.
| Moment | What the person does | What comes back |
|---|---|---|
| onboarding | Verifies against a passport chip, or a signed native capture where there is no chip. | A verdict, an assurance level, and a token scoped to you alone. |
| pickup | A capture in your app, signed on the device with a single-use nonce. | Recognition against the same token. No document, no upload, no stored image touched. |
| a banned account returning | Nothing voluntary. The identity is already locked out across operators. | A refusal, without disclosing which operator issued it. |
Cross-operator lockout operates inside JERIX against the identity. It does not hand you another operator’s user base and does not hand them yours — per-client token isolation means the two tokens for the same person are different values and cannot be joined by either side.
What a courier operations lead actually asks.
Three questions, every time, and the second one is where most vendors go quiet.
How long does the check add to a pickup?
What happens on a bad phone, in a stairwell, with no signal?
What does integration cost my team?
The two gaps that matter most here.
Both of them cost a courier a shift, which in this segment is the only unit of harm that counts.
A courier who replaced their phone
The wallet is encrypted on the device and unlocks with biometrics only, with a screen-capture guard. There is no escrow and no copy held anywhere else. The consequence is plain: a new phone means a new verification, mid-shift, today.
Not shippedAccount recovery on a new phone. Blocked on a recovery path that does not become the cheapest way to impersonate a cleared courier.
Nothing here blocks a spoof on its own
Liveness and the movement ceremony are measured and recorded on every capture and decide nothing. What makes a swapped frame or a virtual camera hard is the manifest signed on the device with a single-use nonce, and on iOS Apple App Attest. On Android, hardware attestation is not configured.
Not shippedScreen and print detection; Android hardware attestation. Both compute or ship partially; neither is load-bearing today.
Put the eleventh-week pickup in front of us.
Bring your worst case: a shared account, a replaced phone, a courier with no passport. We will tell you which of those we solve and which we do not.
Request a walkthrough