The courier at the door has to be the courier you cleared.

Onboarding is the half of the problem every platform has already solved. The unsolved half is the pickup eleven weeks later, when the account is the account you approved and the person holding the phone is not. JERIX identifies the human at that moment, inside your own app, without keeping a face to compare against.

Per-pickup identification, with nothing stored to match on.

A re-check that depends on a stored face image or a stored template is a re-check that builds the breach. Ours resolves against a one-way token instead.

Cleared once, recognised many times

The courier verifies against a government document once: NFC passport chip where there is one, a signed native capture where there is not. After that, each pickup is a recognition against the token that verification produced — not a document re-upload, and not a photo compared to an archived photo.

Zero retention on images and biometrics, verified on disk

No face images, no face embeddings or templates, no document images, no chip data. There is no retention window to configure and no dashboard toggle to get wrong, because there is nothing to configure. Two face-derived hashes are kept for 30 and 7 days; name, national ID and date of birth are retained encrypted. We say zero retention on images and biometrics, and never “we keep nothing”.

Your brand, your app, your flow

The capture runs inside your application through the React Native or Flutter SDK. The courier does not leave your app, does not install a second one, and does not land on somebody else’s branded page in the middle of a shift.

What lands on your server

One call to one endpoint you own

The result is delivered to an address you nominate, signed, so your server can prove the message came from us before it acts on it. There is nothing to poll and no console for your ops team to sit in.

A delivery cannot be replayed

Each one carries a single-use nonce. A second copy of the same message is rejected rather than processed again, so a captured delivery is not a way to clear a pickup twice.

Four answers, not a file on the person

What happened, whether it verified, the assurance level the capture earned, and the token for this courier that is scoped to you alone. No image, and no face to compare against. Field sets are configured per client.

Three moments, one mechanism.

Marketplaces tend to buy for the first row and get burned on the second. The third is the one nobody budgets for.

What each moment requires, and what your server receives
MomentWhat the person doesWhat comes back
onboardingVerifies against a passport chip, or a signed native capture where there is no chip.A verdict, an assurance level, and a token scoped to you alone.
pickupA capture in your app, signed on the device with a single-use nonce.Recognition against the same token. No document, no upload, no stored image touched.
a banned account returningNothing voluntary. The identity is already locked out across operators.A refusal, without disclosing which operator issued it.

Cross-operator lockout operates inside JERIX against the identity. It does not hand you another operator’s user base and does not hand them yours — per-client token isolation means the two tokens for the same person are different values and cannot be joined by either side.

What a courier operations lead actually asks.

Three questions, every time, and the second one is where most vendors go quiet.

How long does the check add to a pickup?

The native capture is the capture, and the verification runs on the device: chip verification, trust chain, face matching and OCR all run with no network call. We will not quote you a figure in milliseconds on a marketing page, because yours will depend on your phone fleet and we have no published benchmark to point at. Measure it on your own handsets during the walkthrough.

What happens on a bad phone, in a stairwell, with no signal?

The verification itself does not need the network. The trust chain is verified fully offline — no network, no CRL, no OCSP — against a store of 588 certificates covering 112 countries. A chip whose issuer is not in that store is refused rather than accepted on the benefit of the doubt.

What does integration cost my team?

Two server-to-server calls and one URL if you want the hosted path, or the SDK plus a webhook endpoint if you want it native. No SDK is required, so your backend language is not a gating question — the SDK exists for the cases where the capture has to be inside your app, which in this segment is most of them.
Real request and response shapes →

The two gaps that matter most here.

Both of them cost a courier a shift, which in this segment is the only unit of harm that counts.

A courier who replaced their phone

The wallet is encrypted on the device and unlocks with biometrics only, with a screen-capture guard. There is no escrow and no copy held anywhere else. The consequence is plain: a new phone means a new verification, mid-shift, today.

Not shippedAccount recovery on a new phone. Blocked on a recovery path that does not become the cheapest way to impersonate a cleared courier.

Nothing here blocks a spoof on its own

Liveness and the movement ceremony are measured and recorded on every capture and decide nothing. What makes a swapped frame or a virtual camera hard is the manifest signed on the device with a single-use nonce, and on iOS Apple App Attest. On Android, hardware attestation is not configured.

Not shippedScreen and print detection; Android hardware attestation. Both compute or ship partially; neither is load-bearing today.

Put the eleventh-week pickup in front of us.

Bring your worst case: a shared account, a replaced phone, a courier with no passport. We will tell you which of those we solve and which we do not.

Request a walkthrough