The session
-
Scan the data page
A guided camera sweep captures the passport's printed page and reads the machine-readable zone.
-
Tap to read the chip
The document's NFC chip is read directly — the same signed data the issuing state placed there.
-
Selfie and liveness
A short guided capture confirms a live person, compared against the portrait stored in the chip.
-
Proof of address
Photographed and read automatically, including Swiss QR-bills, with the name checked against the document.
Interrupted? The session resumes where it left off — nothing already captured is asked for twice.
Verified server-side, not asserted by the phone
IDsig is built on one principle: the phone is never trusted to vouch for anything it could fake. Every claim in the result is established by the backend, from evidence the phone could not have fabricated.
-
Document authenticity
The chip's signature is verified against the issuing country's national trust anchors — the full chain, checked on the server.
-
Live chip, this session
The chip proves it is present and live through a challenge the backend runs itself, with the phone acting only as a relay.
-
Face comparison
The selfie and the printed page are both compared against the portrait signed into the chip — recorded as evidence for review.
-
Sealed evidence
Every artefact is encrypted on capture to the requesting intermediary's session — modern public-key encryption, one session, one destination.
The record is the product
The outcome is not a green tick. It is a structured, auditable file: every check named, with its own individual result — including the difference between a check that failed, one the document cannot support, and one the deployment chose not to run. A consent receipt and a human-readable report travel with it.
For Swiss financial intermediaries, results are reported item by item against the due-diligence requirements of FINMA Circular 2016/7. For organisations outside that framework, a narrower technical assessment covers document authenticity, chip verification, face match and liveness — scoped honestly to what was actually checked.
Built to operate
-
Per-intermediary flows
Seven onboarding modules, each mandatory, optional or disabled per intermediary — full KYC for one, passport-and-selfie for another, from the same deployment.
-
API and webhooks
Create sessions, list onboardings and fetch results over a simple API; signed webhooks notify your backend the moment a verdict lands.
-
Self-hosted, if you want it
Run the whole system on your own infrastructure. Evidence stays where you put it — data residency as a deployment fact, not a promise.
Talk to us
Piloting IDsig, evaluating it for your onboarding, or just curious how the evidence holds up under scrutiny — we're happy to walk through it.
contact@idsig.app