Nine signals. One answer.
Is this person real?
Trust Center is Xuda's own verification engine. It makes independent channels agree, phone, email, domain, photo ID, live face capture, payment record, public registers, web footprint and a cross-account link graph, and then a versioned scorer, not a model, resolves a level from 1 to 4.
Cumulative levels: Contact, Identity, Financial, Networks
Identity document images kept after the read
Images bound to each other, not two
Verification on your own account, never tiered by plan
The models read. The policy decides.
Vision and search models do one job here: turn a photo or a page into typed fields. They never issue a verdict. The score, the claims and the level come from a deterministic scorer running over a policy file, and every stored decision records the policy version it was computed under. Change a threshold and the next call uses it, with no restart and no retraining. That is why the same evidence produces the same answer twice.
Four steps, each one an independent channel.
Nothing here rests on a single document or a single selfie. Each step adds evidence from a source the others cannot fake, and the scorer only grants a level when the required claims are all present and the score clears the floor.
- 01
Confirm the channels you already own
Type your number in international format and enter the six digits we send. A line-type lookup runs first, so a code delivered to an internet or throwaway number still arrives but does not count. A business proves its website with a TXT record, and the registration age and mail records are read alongside it.
- 02
Photograph a photo ID
Upload the file, use your camera, or scan a QR code and take the photos on your phone with no sign-in there. The check digits are recomputed, the printed side is compared with the machine-readable one and the front with the back, and a North American licence has its barcode decoded and matched field by field.
- 03
Prove you are live
The camera takes bursts while you follow prompts: look straight at the camera, turn your head, lean in a little closer. The order is drawn server side after you ask for the capture, and every movement is measured against your own neutral frame. You get back a green and red list of exactly which steps landed.
- 04
The scorer resolves the level
Typed signals go into a deterministic scorer over the versioned policy file, and out comes a score, a claim set and a level. The page shows what has been confirmed, what is still missing for the next level, and why the score stopped where it did.
Nine channels that have to agree.
Every one of these produces typed signals that feed the same scorer. No single check can grant a level on its own, and several of them are flagged so they can only ever help an applicant.
A scorer, not a model
Extractors produce typed fields. A deterministic scorer over a versioned policy file produces the score, the claims and the level. Every stored decision records the policy version it ran under, and a threshold change takes effect on the very next call.
A phone that is really a phone
A line-type lookup runs before the code goes out, so a virtual number never earns the claim. Codes live 10 minutes, allow 5 attempts, and are capped at 5 sends an hour per account.
Documents checked, not just read
Full ICAO 9303 MRZ parsing and check digits for TD1, TD2 and TD3, printed against machine-readable and front against back consistency, AAMVA barcode decoding on North American licences, and image provenance with editor detection.
Liveness by active challenge
The order of head movements is chosen server side after the capture is requested, with a cryptographic shuffle, then measured against your own neutral frame. A printed photo, a screenshot, a saved selfie, the same frame sent twice, a second face in shot and a person swapping mid-sequence are all refused.
Three images bound together
The document portrait, the profile picture and the live capture are each matched against the other two at a calibrated threshold, so the avatar on the platform traces back to a face that was checked against an identity document.
The payment record as identity
Card fingerprint, funding type, issuing country, address and security-code checks, wallet, verified tax IDs and charge history. An account that has never been charged can place a small authorization that is released immediately and never captured.
Business domain and register
A DNS TXT record proves the company controls its website, with the registration age and mail records read alongside it, and it feeds the score without being required at any level. A company registration is cross-checked against Companies House for the United Kingdom, New York for itself and an aggregator elsewhere, including whether the account holder is a current officer.
A cross-account link graph
Accounts are joined on hashed card fingerprint, document hash, phone, company registration and network prefix, so an applicant sharing a card or a document with a suspended account is visible. Raw identifiers are never stored and an IP is reduced to a network prefix.
A person, when the machine keeps refusing
After two failures at the same step the retry stops and the case goes to a human, with a stated wait of up to 3 days. Exactly one ticket is opened, the reviewer sees the held images, and the decision overrides the scorer.
Photograph the ID. Then prove you are the one holding it.
The Level 2 window opens from the ladder and tells you exactly what is still needed. Photograph the front and the back, or scan the QR code and use your phone with no sign-in there. The document is read in seconds, and the live capture starts on its own.
- Full ICAO 9303 MRZ parsing and check digits for TD1, TD2 and TD3, plus printed against MRZ and front against back consistency.
- A one-time link in the QR code, valid 15 minutes, so the phone never signs in.
- The order of head movements is picked by the server after you ask for the capture, and each one is measured against your own neutral frame.
- A 15 minute window from reading the document to finishing the rest, stated on screen with a countdown.
- Looked straight at the camera
- Turned to your left
- Leaned in closer
- Matched the photo on your document
Your ID photo is read, then it is gone.
The image arrives in the request, is read, and is dropped when that request returns. There is no bucket of passport photos behind this product, because there is no place the image is written to.
- The photo of your ID is read inside the request and dropped when it returns, so there is no image sitting somewhere to leak later.
- The document number is reduced to its last four before anything is written down.
- A one-way hash of country plus document number catches the same document used on two accounts, without keeping the number itself.
- The only images that persist are the ones a human reviewer needs, held at most 7 days and deleted the moment the decision is made.
- Document type and issuing country
- Name and date of birth
- Document number, last four only
- Expiry date
- Check-digit and consistency results
- Barcode decode result and field match
- A portrait vector used for matching
- A one-way duplicate hash
- The photo of the front
- The photo of the back
- The full document number
- Every frame of the live capture
- The photos sent from the phone
- The profile picture copy used for the match
Verify your own users
with the engine that verifies ours.
Switch the service on, create a session, send the person the hosted link, and get a signed webhook when it resolves. The verification endpoints use your existing Xuda API keys, so there is no second key system to manage.
- Signed webhooks on Starter and up, with replay protection, up to 5 delivery attempts and a log of every one.
- Your own verification domain on Grow and up, so the person stays on a hostname they recognize.
- Unlimited sandbox verifications that are never counted and never charged, so you can build the whole loop first.
- Live capture for external users opens as the rollout finishes. Until then a live link is created and valid, and both the dashboard and the API tell you so before you send it.
- Max level a session may ask for
- 2 · Identity
- API rate ceiling
- 60 / min
- Webhook endpoint
- api.acme.com/hooks/…
- Signing secret
- whsec_•••• shown once
- Verification domain
- Grow and up
- History kept
- 365 days
POST https://api.acme.com/hooks/xuda-verify
Xuda-Event: verification.approved
Xuda-Signature: t=1754899200,v1=9f2c4b…
// v1 is HMAC-SHA256 of t + "." + body, keyed with your signing secret
{ "event": "verification.approved",
"sent_at": "2026-08-11T09:14:22Z",
"data": { "session_id": "vs_8Qk2…", "external_ref": "user_4417",
"sandbox": true,
"result": { "outcome": "approved", "level": 2 } } }Four tiers, and what each one unlocks.
Every flag below is enforced in code, not in a brochure: the level a session may ask for, the monthly allowance, the request ceiling, webhooks, your own domain and how long a result stays readable.
Free
Start hereRun the whole flow before you pay for any of it.
- Unlimited sandbox verifications, never counted, never charged
- Max level a session may ask for
- 1 · Contact
- Past the allowance
- Stops for the month
- API rate ceiling
- 10 / min
- Signed webhooks
- Your own verification domain
- History kept
- 30 days
Starter
Check a real person, and hear about it on your own server.
- Signed webhooks on every session outcome
- Max level a session may ask for
- 2 · Identity
- Past the allowance
- Metered
- API rate ceiling
- 60 / min
- Signed webhooks
- Your own verification domain
- History kept
- 365 days
Grow
Most completeAsk for a payment record, and host the flow on your own domain.
- Your own verification domain on the hosted flow
- Max level a session may ask for
- 3 · Financial
- Past the allowance
- Metered
- API rate ceiling
- 300 / min
- Signed webhooks
- Your own verification domain
- History kept
- 3 years
Scale
Every level, the highest ceiling, and the longest memory.
- The full ladder, up to an established business
- Max level a session may ask for
- 4 · Networks
- Past the allowance
- Metered
- API rate ceiling
- 1000 / min
- Signed webhooks
- Your own verification domain
- History kept
- 5 years
Sandbox verifications are unlimited on every tier, are never counted against the allowance and are never charged. Free stops when its allowance runs out. Paid tiers meter each verification past the allowance, and a business registry lookup is charged as used on top of the plan.
What this does not do yet.
A verification product that oversells itself is worse than no verification product. Here is what is still in rollout, where we will not operate, and what the checks cannot catch.
Still in rollout
Levels are being calibrated across the platform before anything is enforced. Today the product gates report what they would have blocked instead of blocking it, and the verification page says exactly that to the user. Nothing on your account is held back while that finishes.
Three countries we will not process
Verification above Level 1 is refused in Canada, China and Russia. That refusal is deliberately exempt from the rollout, because calibrating a score is not permission to process biometric data somewhere Xuda is not cleared to operate.
What liveness cannot catch
The challenge stops a printed photo, a screenshot, a saved selfie and the same frame sent twice. A video of the subject re-cut into the requested order, and a live deepfake driven by the same prompts, both still pass. We would rather write that here than let you find out.
Buy a verdict, or buy the evidence.
Most verification is a black box that answers pass or fail. Trust Center gives you a level, the claims behind it, the reasons it stopped where it did, and a policy file you can read. Here is how that compares to a hosted vendor and to building it yourself.
Xuda Trust Center You | A hosted KYC vendor | Build it in-house | |
|---|---|---|---|
| What you get back | Level 1 to 4, claims and reasons | Pass or fail | Whatever you build |
| Decision rule you can read and version | Not exposed | You build it | |
| Identity document images never stored | Varies by vendor | Your problem | |
| Liveness order randomized per attempt | Varies by vendor | You build it | |
| Document, profile picture and live capture bound together | You build it | ||
| Payment record used as an identity signal | Not their data | You build it | |
| Cross-account link graph on hashed identifiers | Not their data | You build it | |
| Signals flagged so they can only help the applicant | Not exposed | You build it | |
| Human review route built in | Varies by vendor | Hire a team | |
| Unlimited sandbox that is never counted | Varies by vendor | Not applicable | |
| Reuses API keys you already have | Not applicable | ||
| Time to a first integration | Switch the service on | Contract, then onboarding | Months |
The questions a careful buyer asks.
Find out who is on the other side.
Four cumulative levels, nine independent channels and a deterministic scorer over a versioned policy file. Verification on your own Xuda account is free and never tiered by plan, and the sandbox for verifying your users is unlimited.