Case Study · Marketplace × Identity

How MiAuto.ec eliminates fake listings with identity verification

Listing a car costs something a fraudster cannot pay: proven identity. This is how MiAuto.ec and Verify with ISM fit together.

The problem: fake listings and anonymous sellers

A vehicle marketplace lives or dies on trust.

A vehicle marketplace lives or dies on trust. If listing is free and anonymous, the marginal cost of a fake advert is also zero, and the market fills with them faster than human moderation can empty it. In Ecuador that isn't hypothetical: a single ring defrauded around eighty people with fake luxury-car sales before eleven of its members were arrested in Guayaquil and Quito.

The industry's usual answer is to ask for a photo of an ID. We happened to have a team building chip-based identity verification at the same time — and the evidence that a photo no longer proves anything, because 14.8 million Ecuadorian identity records, more than 10 million high-resolution ID images and even fingerprints surfaced on dark forums in May 2026.

So we didn't buy a vendor. We used our own, and forced ourselves to live with the result.


The solution: verified identity before listing

The whole architecture rests on one rule: identity is proven before a listing exists, and long before a charge exists.

Where the identity gate sits in the listing flow A five-step flow. Identity verification sits between account creation and listing creation, and the payment gate sits after moderation. Account email + phone Identity chip · liveness · 1:1 match Listing photos captured in-app Moderation human review Payment invoice issued No listing can exist before this step passes No charge before identity is proven

The order matters for a very concrete reason, and it isn't philosophical. When someone pays to feature a listing, an SRI-authorized electronic invoice is issued. An authorized invoice cannot be deleted: if the listing later had to be rejected for fraud, removing it isn't enough — it needs a refund and a formal cancellation, which is a legal process rather than a button.

That is why the gate lives in a single backend file and not in the interface. A rule spread across screens breaks the first time somebody adds a new screen; a rule that lives at one point on the server only breaks if somebody deletes it deliberately.


The seller journey, step by step

Forty seconds on their own phone, without emailing a photo of anything.

Open the app

iOS or Android. Verification isn't a web page inside the app: it's native code, because it needs the NFC radio and the depth sensor.

Hold the ID to the phone

Read the printed code, then rest the document against the back of the handset. The chip opens with keys derived from the document itself.

The state's signature is checked

Passive Authentication against the trust anchor. If the document was altered, verification fails and there is no seller.

Liveness and a 1:1 match

A depth-sensed selfie is compared against the portrait the state put in the chip. The comparison happens on the phone.

Nothing is uploaded

The portrait and the selfie produce a verdict and are discarded. MiAuto never receives anyone's face — only whether it matched.

What remains is an identity, not a file

The listing binds to a proven person. MiAuto keeps the verdict and the consent receipt — not the document.


What the implementation taught us

A product that is only ever demonstrated in meetings never finds this out.

What the design got right:

  • On-device biometrics isn't only privacy, it's cost. With no server GPU, verifying one more seller costs essentially nothing — which is what makes free listing possible
  • Failing closed is sellable. A seller whose verification fails is not lost revenue: they are precisely the one we didn't want
  • The chip carries more than you ask it for. Name and document number come from the signed chip, so the seller doesn't type their details — and can neither mistype nor lie about them
  • Two separate consents — sharing facts, and processing a face — was legally right and turned out to be the better experience: people understand what they are agreeing to

What forced us to change:

  • NFC isn't where you think it is. The antenna moves between handset models, so “hold the document to the phone” had to become an animation rather than a sentence
  • A missing portrait is a failed verification, not a finished one. We had to fix that explicitly: a chip with no readable portrait cannot produce a 1:1 match, and letting it through would have been worse than not verifying at all
  • Identity has to be changeable. People renew their documents. Binding an account to a document number forever was a mistake, and we corrected it on both platforms
  • We verify the seller, not the car. Saying that out loud on the page, rather than letting a buyer assume otherwise, was a product decision as much as an honesty one

Where the project stands today

With the same candour we ask for everywhere else on this site.

The full journey runs end to end against real infrastructure: a seller is provisioned, verifies with their national ID, builds a listing from photos captured in the app, passes moderation and reaches the payment gate. What it does not yet do is take money or publish to the public: payments are deliberately parked and the buyer site is not open. There are no real users yet, and therefore this case study reports no business results — it describes an architecture and the decisions behind it. When there are numbers, we'll publish them with the same signature.


Apply the same verification to your platform

If fake accounts, anonymous sellers or onboarding fraud are costing you, the same gate can be built on what you already run.

🍪 We value your privacy

We use cookies and analytics to understand how you use our site and improve your experience. This includes Google Analytics for tracking site usage.

By clicking "Accept", you consent to analytics tracking. Learn more in our Cookie Policy and Privacy Policy.

Decline Accept