UbID Proof
UbID Proof is the product domain for identity proofing and assurance. It helps an institution evaluate whether the evidence presented for an identity, document, or eligibility claim is sufficient for a defined purpose.
Proofing is different from authentication. Authentication asks whether the current user controls an approved authenticator or session. Proofing asks what evidence supports the claimed identity or attribute and how much confidence an institution should place in that evidence.
What it addresses
Remote identity processes face risks that do not exist in a direct inspection of an original document. Images may be altered, documents may be expired or inconsistent, biometric media may be replayed or synthetically generated, and source data may be incomplete or unrelated to the person presenting it.
UbID Proof organizes these checks into a governed evidence process rather than treating one successful check as sufficient for every use case.
Evidence sources
Depending on the approved use case, proofing may combine:
- document capture and quality assessment;
- structured extraction from document zones or machine-readable data;
- consistency checks across names, dates, identifiers, and document attributes;
- validation of QR codes, digital signatures, issuer domains, or recognized sources;
- biometric comparison or liveness controls where legally permitted and proportionate;
- existing trusted credentials or institutional attestations;
- human review when automated evidence is incomplete, ambiguous, or high risk.
Not every deployment uses every evidence source. The institution selects the methods appropriate to the transaction, jurisdiction, risk, and available alternatives.
Assurance, not a universal score
UbID Proof does not reduce identity trust to one permanent score. Assurance depends on context:
- what fact is being established;
- which evidence source produced it;
- how current and complete the evidence is;
- whether the source is authoritative or independently verifiable;
- whether the subject is appropriately linked to the evidence;
- which policy and risk threshold apply to the transaction.
The same person may require different proofing for opening an account, entering a building, receiving an educational credential, or recovering a protected identity.
Governed outcome
A proofing result should include enough evidence for an authorized downstream service to understand the outcome without receiving unnecessary raw data.
The result may describe:
- checks performed;
- evidence quality and limitations;
- policy applied;
- review or exception state;
- time and transaction context;
- authorization for the next step.
This outcome may support credential issuance, account enrollment, step-up authentication, document verification, or recovery. It should not automatically trigger a high-impact operation unless policy explicitly authorizes that transition.
Biometric governance
Biometric processing requires special care. Where used, it should be:
- necessary or supported by a valid legal basis;
- purpose-bound and proportionate;
- separated from unrelated profile data;
- protected against replay and misuse;
- retained only as long as approved;
- accompanied by an alternative where law, accessibility, or policy requires one;
- subject to clear human review and challenge procedures.
UbID Proof is therefore not positioned as "biometrics first." It is an assurance framework that may include biometric evidence under controlled conditions.
Relationship with other products
- UbID Credential Cloud consumes approved proofing evidence before issuance.
- UbID Access may use proofing for enrollment or step-up decisions.
- UbID Recover uses guarded identity assurance before recovery stages advance.
- UbID Trust API exposes approved proofing interactions to partners.
- UbID Pulse records health and evidence for proofing operations.
What this product does not decide
A successful proofing check does not automatically prove that a source document is lawful, that a claim remains current forever, or that every verifier must accept it. Those decisions depend on issuer governance, credential status, verifier policy, and transaction context.
Public documentation boundary
Public documentation explains evidence categories, assurance concepts, privacy controls, and human review. Vendor-specific configuration, fraud signatures, anti-abuse thresholds, model internals, customer decision rules, and operational endpoints remain controlled.
See also Identity Proofing and Biometrics, Verification and Policy, and UbID Credential Cloud.