Trust Center · know who you are dealing with

Nine signals. One answer.
Is this person real?

Trust Center is Xuda's own verification engine. It makes independent channels agree, phone, email, domain, photo ID, live face capture, payment record, public registers, web footprint and a cross-account link graph, and then a versioned scorer, not a model, resolves a level from 1 to 4.

Deterministic scorer, versioned policy
Document images never stored
Liveness by active challenge
Unlimited free sandbox
Your verification levelpolicy 1.6.0
Level 2 · Identity
Levels are cumulative
58
Trust score
Contact
≥ 10
Identity
≥ 45
Financial
≥ 60
Networks
≥ 75
What we have confirmed
Email Phone, not a virtual line Photo ID Face match Live capture
Still needed for Level 3: a payment record
Independent channels that have to agree:Phone line typeEmailDomain controlPhoto IDLive capturePayment recordPublic registersWeb footprintLink graph
4

Cumulative levels: Contact, Identity, Financial, Networks

0

Identity document images kept after the read

3

Images bound to each other, not two

Free

Verification on your own account, never tiered by plan

A verdict you can re-run

The models read. The policy decides.

Vision and search models do one job here: turn a photo or a page into typed fields. They never issue a verdict. The score, the claims and the level come from a deterministic scorer running over a policy file, and every stored decision records the policy version it was computed under. Change a threshold and the next call uses it, with no restart and no retraining. That is why the same evidence produces the same answer twice.

How a level is reached

Four steps, each one an independent channel.

Nothing here rests on a single document or a single selfie. Each step adds evidence from a source the others cannot fake, and the scorer only grants a level when the required claims are all present and the score clears the floor.

  1. 01

    Confirm the channels you already own

    Type your number in international format and enter the six digits we send. A line-type lookup runs first, so a code delivered to an internet or throwaway number still arrives but does not count. A business proves its website with a TXT record, and the registration age and mail records are read alongside it.

  2. 02

    Photograph a photo ID

    Upload the file, use your camera, or scan a QR code and take the photos on your phone with no sign-in there. The check digits are recomputed, the printed side is compared with the machine-readable one and the front with the back, and a North American licence has its barcode decoded and matched field by field.

  3. 03

    Prove you are live

    The camera takes bursts while you follow prompts: look straight at the camera, turn your head, lean in a little closer. The order is drawn server side after you ask for the capture, and every movement is measured against your own neutral frame. You get back a green and red list of exactly which steps landed.

  4. 04

    The scorer resolves the level

    Typed signals go into a deterministic scorer over the versioned policy file, and out comes a score, a claim set and a level. The page shows what has been confirmed, what is still missing for the next level, and why the score stopped where it did.

What the engine checks

Nine channels that have to agree.

Every one of these produces typed signals that feed the same scorer. No single check can grant a level on its own, and several of them are flagged so they can only ever help an applicant.

A scorer, not a model

Extractors produce typed fields. A deterministic scorer over a versioned policy file produces the score, the claims and the level. Every stored decision records the policy version it ran under, and a threshold change takes effect on the very next call.

A phone that is really a phone

A line-type lookup runs before the code goes out, so a virtual number never earns the claim. Codes live 10 minutes, allow 5 attempts, and are capped at 5 sends an hour per account.

Documents checked, not just read

Full ICAO 9303 MRZ parsing and check digits for TD1, TD2 and TD3, printed against machine-readable and front against back consistency, AAMVA barcode decoding on North American licences, and image provenance with editor detection.

Liveness by active challenge

The order of head movements is chosen server side after the capture is requested, with a cryptographic shuffle, then measured against your own neutral frame. A printed photo, a screenshot, a saved selfie, the same frame sent twice, a second face in shot and a person swapping mid-sequence are all refused.

Three images bound together

The document portrait, the profile picture and the live capture are each matched against the other two at a calibrated threshold, so the avatar on the platform traces back to a face that was checked against an identity document.

The payment record as identity

Card fingerprint, funding type, issuing country, address and security-code checks, wallet, verified tax IDs and charge history. An account that has never been charged can place a small authorization that is released immediately and never captured.

Business domain and register

A DNS TXT record proves the company controls its website, with the registration age and mail records read alongside it, and it feeds the score without being required at any level. A company registration is cross-checked against Companies House for the United Kingdom, New York for itself and an aggregator elsewhere, including whether the account holder is a current officer.

A cross-account link graph

Accounts are joined on hashed card fingerprint, document hash, phone, company registration and network prefix, so an applicant sharing a card or a document with a suspended account is visible. Raw identifiers are never stored and an IP is reduced to a network prefix.

A person, when the machine keeps refusing

After two failures at the same step the retry stops and the case goes to a human, with a stated wait of up to 3 days. Exactly one ticket is opened, the reviewer sees the held images, and the decision overrides the scorer.

Level 2 · Identity

Photograph the ID. Then prove you are the one holding it.

The Level 2 window opens from the ladder and tells you exactly what is still needed. Photograph the front and the back, or scan the QR code and use your phone with no sign-in there. The document is read in seconds, and the live capture starts on its own.

  • Full ICAO 9303 MRZ parsing and check digits for TD1, TD2 and TD3, plus printed against MRZ and front against back consistency.
  • A one-time link in the QR code, valid 15 minutes, so the phone never signs in.
  • The order of head movements is picked by the server after you ask for the capture, and each one is measured against your own neutral frame.
  • A 15 minute window from reading the document to finishing the rest, stated on screen with a countdown.
Level 2 · Identity
Levels are cumulative
Still needed
Photo ID
Profile picture
Face match
Live capture
Photo IDpassport · driving licence · national ID
1. Front
2. Back
File
Camera
Phone
Submit documentMy document has no back
Finish the rest of Level 2 within 15 minutes of reading the document.
Live captureorder randomized server side
  • Looked straight at the camera
  • Turned to your left
  • Leaned in closer
  • Matched the photo on your document
What we keep

Your ID photo is read, then it is gone.

The image arrives in the request, is read, and is dropped when that request returns. There is no bucket of passport photos behind this product, because there is no place the image is written to.

  • The photo of your ID is read inside the request and dropped when it returns, so there is no image sitting somewhere to leak later.
  • The document number is reduced to its last four before anything is written down.
  • A one-way hash of country plus document number catches the same document used on two accounts, without keeping the number itself.
  • The only images that persist are the ones a human reviewer needs, held at most 7 days and deleted the moment the decision is made.
After the document is read
Kept
  • Document type and issuing country
  • Name and date of birth
  • Document number, last four only
  • Expiry date
  • Check-digit and consistency results
  • Barcode decode result and field match
  • A portrait vector used for matching
  • A one-way duplicate hash
Dropped when the request returns
  • The photo of the front
  • The photo of the back
  • The full document number
  • Every frame of the live capture
  • The photos sent from the phone
  • The profile picture copy used for the match
One exception: a case a person has to look at. Those images are held for the review only, at most 7 days, and are deleted the moment the decision is made.
Trust Center as a service

Verify your own users
with the engine that verifies ours.

Switch the service on, create a session, send the person the hosted link, and get a signed webhook when it resolves. The verification endpoints use your existing Xuda API keys, so there is no second key system to manage.

  • Signed webhooks on Starter and up, with replay protection, up to 5 delivery attempts and a log of every one.
  • Your own verification domain on Grow and up, so the person stays on a hostname they recognize.
  • Unlimited sandbox verifications that are never counted and never charged, so you can build the whole loop first.
  • Live capture for external users opens as the rollout finishes. Until then a live link is created and valid, and both the dashboard and the API tell you so before you send it.
Verification serviceTest mode
Starter · this month's allowance37 / 100
Max level a session may ask for
2 · Identity
API rate ceiling
60 / min
Webhook endpoint
api.acme.com/hooks/…
Signing secret
whsec_•••• shown once
Verification domain
Grow and up
History kept
365 days
webhook delivery
POST https://api.acme.com/hooks/xuda-verify
Xuda-Event: verification.approved
Xuda-Signature: t=1754899200,v1=9f2c4b…
// v1 is HMAC-SHA256 of t + "." + body, keyed with your signing secret

{ "event": "verification.approved",
  "sent_at": "2026-08-11T09:14:22Z",
  "data": { "session_id": "vs_8Qk2…", "external_ref": "user_4417",
            "sandbox": true,
            "result": { "outcome": "approved", "level": 2 } } }
The tier ladder

Four tiers, and what each one unlocks.

Every flag below is enforced in code, not in a brochure: the level a session may ask for, the monthly allowance, the request ceiling, webhooks, your own domain and how long a result stays readable.

Free

Start here
No card needed

Run the whole flow before you pay for any of it.

10
verifications included each month
  • Unlimited sandbox verifications, never counted, never charged
Max level a session may ask for
1 · Contact
Past the allowance
Stops for the month
API rate ceiling
10 / min
Signed webhooks
Your own verification domain
History kept
30 days

Starter

Pricing to be confirmed

Check a real person, and hear about it on your own server.

100
verifications included each month
Everything in Free, plus
  • Signed webhooks on every session outcome
Max level a session may ask for
2 · Identity
Past the allowance
Metered
API rate ceiling
60 / min
Signed webhooks
Your own verification domain
History kept
365 days

Grow

Most complete
Pricing to be confirmed

Ask for a payment record, and host the flow on your own domain.

500
verifications included each month
Everything in Starter, plus
  • Your own verification domain on the hosted flow
Max level a session may ask for
3 · Financial
Past the allowance
Metered
API rate ceiling
300 / min
Signed webhooks
Your own verification domain
History kept
3 years

Scale

Pricing to be confirmed

Every level, the highest ceiling, and the longest memory.

2,500
verifications included each month
Everything in Grow, plus
  • The full ladder, up to an established business
Max level a session may ask for
4 · Networks
Past the allowance
Metered
API rate ceiling
1000 / min
Signed webhooks
Your own verification domain
History kept
5 years

Sandbox verifications are unlimited on every tier, are never counted against the allowance and are never charged. Free stops when its allowance runs out. Paid tiers meter each verification past the allowance, and a business registry lookup is charged as used on top of the plan.

Said plainly

What this does not do yet.

A verification product that oversells itself is worse than no verification product. Here is what is still in rollout, where we will not operate, and what the checks cannot catch.

Still in rollout

Levels are being calibrated across the platform before anything is enforced. Today the product gates report what they would have blocked instead of blocking it, and the verification page says exactly that to the user. Nothing on your account is held back while that finishes.

Three countries we will not process

Verification above Level 1 is refused in Canada, China and Russia. That refusal is deliberately exempt from the rollout, because calibrating a score is not permission to process biometric data somewhere Xuda is not cleared to operate.

What liveness cannot catch

The challenge stops a printed photo, a screenshot, a saved selfie and the same frame sent twice. A video of the subject re-cut into the requested order, and a live deepfake driven by the same prompts, both still pass. We would rather write that here than let you find out.

Trust Center vs the alternatives

Buy a verdict, or buy the evidence.

Most verification is a black box that answers pass or fail. Trust Center gives you a level, the claims behind it, the reasons it stopped where it did, and a policy file you can read. Here is how that compares to a hosted vendor and to building it yourself.

Xuda Trust Center You
A hosted KYC vendor
Build it in-house
What you get backLevel 1 to 4, claims and reasonsPass or failWhatever you build
Decision rule you can read and versionNot exposedYou build it
Identity document images never storedVaries by vendorYour problem
Liveness order randomized per attemptVaries by vendorYou build it
Document, profile picture and live capture bound togetherYou build it
Payment record used as an identity signalNot their dataYou build it
Cross-account link graph on hashed identifiersNot their dataYou build it
Signals flagged so they can only help the applicantNot exposedYou build it
Human review route built inVaries by vendorHire a team
Unlimited sandbox that is never countedVaries by vendorNot applicable
Reuses API keys you already haveNot applicable
Time to a first integrationSwitch the service onContract, then onboardingMonths
Common questions

The questions a careful buyer asks.

Find out who is on the other side.

Four cumulative levels, nine independent channels and a deterministic scorer over a versioned policy file. Verification on your own Xuda account is free and never tiered by plan, and the sandbox for verifying your users is unlimited.

Models read the evidence. The policy makes the call.