Why it works this way

There are other ways to prove a human is behind an account. Most of them ask for more than IRLProof does. This page is about what we gave up to ask for less, and what that costs you.

The bouncer standard

A bouncer checks your ID at the door. A clerk checks it at the register. Everyone involved knows this is imperfect: a younger sibling borrows an older one's license, a passable fake gets through, someone is waved past on a busy night. We know, and we keep doing it anyway, in every state, for decades.

That is not carelessness. It is a judgement that the check is good enough for what is at stake, and that the alternatives cost more than they are worth. Nobody proposes an iris scan to buy a beer. If they did, most people would object, and they would be right to: the intrusion would be wildly out of proportion to the problem.

IRLProof is built to the bouncer standard, deliberately. We check that a real, government-issued credential was presented by the phone it lives on. We do not check that the person holding the phone is the person on the license. That is the same gap the bouncer has, and we are making the same trade for the same reason.

What that means we cannot catch

Stated plainly, because you should not have to work it out:

What it does do is make operating at scale expensive. Every account needs a distinct, real, government-issued credential behind it, and any one credential can only make a limited number of proofs. A script can invent a million usernames. It cannot invent a million driver's licenses.

That is the actual claim: not "this specific person is who they say", but "this is not a bot farm". Those are different, and conflating them would be dishonest.

How this compares

Approach What it asks of you What you end up with
Iris or face scanning A biometric scan, sometimes at dedicated hardware you travel to Strong uniqueness. A permanent biometric record held by someone.
Document upload Photos of your ID and usually your face A company holding images of your identity documents, indefinitely.
Device attestation Nothing, it is invisible A signal the site sees. Nothing you hold, control, or can show elsewhere.
Behaviour analysis Nothing, it watches how you move and type A probability score about you, computed without your knowledge.
IRLProof One tap in your phone's wallet. No photos, no scans, no documents. A link you own, publish where you choose, and revoke whenever you want.

Three things that make this different

1. You hold the proof, not the platform

Every other approach answers a question a website asked about you, and hands the answer to that website. You never see it, cannot show it to anyone else, and cannot take it back.

A proof here is yours. You decide whether to make one, where to publish it, and when to revoke it. Nobody has to ask us anything about you for it to work, and you can walk away with it still standing.

2. We keep essentially nothing

We do not store your name, date of birth, address, license number, or photo. What we keep is a one-way fingerprint of your license that cannot be reversed, so that we recognise you when you come back and know nothing else about you.

The consequence is worth being blunt about: we cannot tell anyone which license belongs to which account, because we do not know. Not for a court, not for ourselves. There is nothing to hand over, sell, or lose in a breach. The full detail is in the privacy policy.

3. Two of your proofs cannot be connected to each other

If you make a proof for one account and another for a second, nothing in either one links them. No shared identifier, no matching timestamps, nothing. Somebody who finds both learns only that two accounts each have a verified person behind them, not that it is the same person.

This is why the dates on a proof are rounded to the day, and why proofs renew on a schedule that has nothing to do with when you made them. Those are not details, they are the feature.

Where this does not fit

If you need certainty that a specific individual is present, this is the wrong tool and you should use something stronger. Banks and border control should not be using the bouncer standard, and we are not suggesting they do.

IRLProof is for the enormous middle ground where a site wants to know it is dealing with people rather than automation, and where demanding biometrics from everybody would be a cure worse than the disease.

How this works · Is my state supported? · Privacy policy