Interactive demonstration

What a compliant onboardingactually has to prove.

Four steps, each answering a different question a regulator will ask. Run it end to end — the audit trail at the end is built from what the earlier steps emit, not written in advance.

Onboarding console · KYC-2026-0417-UTOSynthetic data
Synthetic demonstration subject in the capture frame
Camera ready

The challenge sequence is randomised per session, so a recording of one session cannot be replayed into the next.

Step 1 — prove a live human is present

Passive checks alone are trivial to defeat with a printed photo or a looped video. An active challenge forces a response the attacker cannot pre-record, and the capture engine measures whether the response came from a face or a surface.

01Center your face in the frameFace bounding box · distance estimate
02Blink slowlyEye-aspect-ratio delta over 14 frames
03Turn your head slowly to the leftYaw sweep · motion parallax
04Hold stillDepth consistency · micro-texture

Four randomised challenges. Nothing is uploaded — the sequence runs entirely in your browser.

Demonstration only. Synthetic subject, AI-generated portrait, specimen document, invented list records. No client data appears on this page.

Demonstration only. Synthetic subject, AI-generated portrait, specimen document, invented list records. No client data appears on this page.

What each step proves

Four questions, four pieces of evidence that survive review.

Onboarding fails audit in predictable places: a liveness check that a printed photo defeats, a document read that never verifies the chip, a screening pass with no recorded reason, and a log that cannot prove it was not edited afterwards.

Step 01

Is a live human present?

Passive liveness is defeated by a printed photo or a looped video. Active challenges force a response that cannot be pre-recorded, and the engine scores whether it came from a face or a surface — depth, texture, blink, specular response.

Step 02

Is the document genuine, and is it theirs?

Three separate questions. The MRZ proves internal consistency, the chip signature proves the issuing authority stands behind it, and the biometric match binds the document to the person who just passed step one.

Step 03

Why did you clear the name that scored 87?

Fuzzy matching is mandatory — names transliterate and reorder — so it returns people who are not your customer. The regulator does not ask whether you screened. They ask what discriminated the near-match, and whether you wrote it down.

Step 04

Can you prove none of it changed?

A log that can be edited after the fact proves nothing. Chaining each entry to the hash of its predecessor makes tampering detectable: alter one field and every hash downstream stops matching.

How this was built

What is real here, and what is not.

A demo of a compliance system that plays fast and loose with its own provenance would be a strange thing to trust. So, precisely:

Nobody real appears on this page

The subject is invented. Her portrait is AI-generated rather than a licensed stock photo — rendering an identity dossier around a real photographed person is a likeness problem no licence resolves. The issuing state is Utopia (UTO), the ICAO specimen code used on example travel documents worldwide.

The lists are real, the records are not

Naming the UN, EU, OFAC and OFSI list groups is accurate — they are public. Every candidate record shown against them is fabricated. Putting a genuinely designated person beside a fictional customer would create a defamation risk, so we did not.

The MRZ actually validates

The machine-readable zone is a real ICAO 9303 TD3 string. All five check digits are computed with the 7-3-1 weighting and verify correctly. The step claims the checksum is valid, so the checksum had better be valid.

No client system was screenshotted

This is a purpose-built demonstration, not a capture of anything we operate. No production interface, no client data, and no regulated system belonging to anyone else appears here.

The engineering behind the real thing is described on regulated systems and fintech engineering.

One next step

Need this built against a real regulator?

Tell us the jurisdiction you answer to and where your current onboarding flow loses evidence. Senior engineer on the first call — no sales layer.

Chat on WhatsApp