Digital Identity · KYC · Age Verification

Identity verification with the chip in the ID

Prove who someone is by reading the secure chip in their national ID or passport, on their own phone. You receive only the fact you need, and biometrics never leave the device.

Why a photo of an ID is no longer enough

Because Ecuadorians' identity data is already public. This is not a risk projection. It is documented.

Ecuador's identity data, as a matter of public record A timeline of publicly reported exposures of Ecuadorian identity data between 2019 and 2026. 2019 Novaestrat
~20M records exposed — 17M Ecuadorians, 6.7M of them children. Cédulas, family records, tax and bank balances.
2024–25 Registro Civil
More than 3.5 million attempted cyberattacks reported against the Civil Registry.
May 2026 Dark forums
14.8M identity records and over 10M high-resolution ID images — with fingerprints and signatures.

A photograph of a document proves nothing once the contents of every document are already published.

What already circulates in Ecuador:

  • 2019 — Novaestrat: roughly 20 million records exposed on an unsecured server, including 17 million Ecuadorians and 6.7 million children, with ID numbers, family records, tax data and bank balances [1]
  • May 2026 — dark forums: 14.8 million identity records and over 10 million high-resolution ID images, together with signatures and fingerprints. Ecuador's data-protection regulator opened an investigation [2]
  • 2024–2025: more than 3.5 million attempted cyberattacks against the Civil Registry [3]

What it costs your business:

  • 4,784 identity-impersonation complaints filed with the Attorney General between January and October 2025 — Guayas 1,755, Pichincha 1,525 [4]
  • Identity fraud in Ecuador rose 26% year over year, with the report attributing it directly to weak verification processes [5]
  • Video-injection attacks against face verification on iOS rose 1,151% in the second half of 2025; native virtual-camera attacks, 2,665% [6]
  • Under the LOPDP, a serious breach carries a fine of up to 1% of annual turnover — and administrative sanctions have been live since May 2023 [7]

If someone's ID number, their document photograph and even their fingerprint are already circulating, then asking for those same details proves nothing. It only shows that whoever is on the other end knows how to search. The one thing an attacker cannot reproduce is the state's signature inside the chip.


How NFC identity verification works

Ecuadorian IDs and every ICAO passport carry a contactless chip — the same one used at automated border gates. Verify with ISM reads it and checks the state's digital signature.

1. One tap on a link

The customer opens a Verify with ISM link — over WhatsApp, in an app, or from a QR code. Confirming the holder with biometrics (level L4) uses the ID Protekt app, on iPhone or Android; checks without biometrics launch on iPhone as an App Clip, with nothing to download.

2. Scan and tap the ID

They point the camera at the printed code, then hold the document to the back of the phone. The chip is opened over NFC using keys derived from the document itself.

3. Authenticate on device

The chip's data is checked against the issuing country's digital signature (Passive Authentication). If it doesn't verify, the check fails and nothing is released.

4. The right person

Liveness plus a 1:1 match against the portrait the state put in the chip — not against a selfie somebody once uploaded.

5. Consent in plain language

The customer sees exactly which facts are requested, who is asking and why, before anything is shared. Declining is a first-class outcome, never a dead end.

6. Only the facts you need

Your system receives the claims you asked for — a name, an age check, a holder match — and nothing else. What you don't ask for is never collected.


Protect your users' data and comply with the LOPDP

Data minimization is not a setting you can switch off. It is how the verification works.

Collect only what you need:

  • If you only need to know someone is over 18, the flow computes a yes/no from the chip and the date of birth is never released
  • Biometrics are compared on the phone: the chip portrait and the selfie produce a verdict and are discarded, never uploaded
  • Sharing facts and allowing face processing are two separate consents, never bundled and never pre-ticked
  • It fails closed: if the document cannot be cryptographically authenticated the verification fails — unproven data is never handed on as fact

And evidence lawful processing:

  • Every verification leaves a receipt with its own identifier: what was asked, at which assurance level, when, and with what result
  • A negative answer is recorded too: if the person does not hold the declared document, the receipt says so and no authorization is registered
  • ISM acts as the data processor; your business is the controller deciding what is asked and why
  • The data-processing agreement and the impact assessment are prepared with each client, under the LOPDP and the GDPR where EU residents are involved

Levels of assurance

Not every check needs the same strength of proof. Verify with ISM is a ladder — each level adds an independent proof on top of the one below, so you buy exactly the assurance the use case requires.

Level What it proves Status
L1 · Document authentic The document is genuine and unaltered, issued by a state we trust — and what it says about the holder. Built
L2 · Chip bound The physical chip is present and has not been cloned, closing document-data replay. No biometrics, no new consent category. It depends on the document: the Ecuadorian cédula and passport do not support it, so in Ecuador the step is from L1 to L4. Document-dependent
L3 · Live presence A live human is present right now — not a photo, a screen, or a mask. Delivered today as part of L4. Within L4
L4 · Holder bound This person is the document holder — a 1:1 face match against the chip portrait, computed on the device. Built
L5 · Assisted A trained human adjudicates the case over a live video call, for the highest-stakes decisions. Roadmap

A level describes what was proved; the claim set describes what is released — they are independent. A high-assurance check that returns only “over 18” is normal, and good.


Which sectors is Verify with ISM for?

Anywhere you need to trust who is on the other end of a phone.

Insurance, banking and regulated sectors:

  • Data authorization and consent: anyone who knows an ID number can tick an “I agree” box. This confirms the person authorizing is the holder of the declared cédula — and if they are not, nothing is registered
  • A company's legal representative: from the RUC, the SRI's public register names the legal representative, and the verification confirms that person is the one signing. Neither fact comes from the applicant
  • Proof of life: pensions and insurers, every year, matched against the state's own portrait rather than a selfie enrolled years ago
  • Banking and fintech: remote onboarding against a state-signed identity, instead of an agent squinting at a scan
  • Telco: line and eSIM activation with a compliant identity capture, without a store visit
  • Betting and gaming: prove age by returning only over 18: yes — no birth date, no stored ID
  • Government: a trustworthy way for a citizen to prove who they are to a digital service

And where fraud lands directly:

  • Call centers: confirm the caller is the account holder before a sensitive change
  • Marketplaces: verify the seller at the moment they list — the problem we solved in MiAuto.ec
  • Contracts and signatures: bind the person to the document at the instant of signing
  • Only need to send a copy without exposing everything? That is ID Protekt, and it is free

Built on the ICAO 9303 standard, not on an AI model

The attacker improves with every generation of models. A state signature does not.

ICAO 9303 eMRTD is the same chip standard used in e-passports and modern national IDs at border control. Passive Authentication verifies the issuing state's signature and that no data group was altered. The NFC session is established from keys read off the document, not guessable over the air. An attacker who perfectly synthesises a face still cannot make a chip produce a valid signature over a document that does not exist: their attack improves with time; our defence does not degrade.


What works today, and what doesn't yet

Everything below is checkable. Ask us for the evidence on any line.

Built and proven

  • ICAO 9303 chip reads over NFC on iOS and Android, proven on real Ecuadorian and German documents
  • Passive Authentication against a CSCA trust anchor, on the device
  • Liveness and a 1:1 match against the chip portrait — assurance level L4, working
  • A complete verification runs end to end on an iPhone or a Pixel against the live backend

By invitation, for now

  • No relying parties are in production yet — we are looking for the first regulated pilot
  • Server-side verification is deliberately switched off: today every receipt declares the verdict was computed on the device
  • The server-issued consent receipt, carrying a fingerprint of the exact wording the person accepted, is under construction
  • It is not a billable product yet, and the readiness gate refuses production on purpose
  • If your case needs L5 with human adjudication, we scope it as a dedicated engagement

Verify your customers' identity

Tell us where fraud is hitting you — consent, onboarding, proof of life or the call center — and we'll scope a pilot.

🍪 We value your privacy

We use cookies and analytics to understand how you use our site and improve your experience. This includes Google Analytics for tracking site usage.

By clicking "Accept", you consent to analytics tracking. Learn more in our Cookie Policy and Privacy Policy.

Decline Accept