Why it works this way
There are other ways to prove a human is behind an account. Most of them ask for more than IRLProof does. This page is about what we gave up to ask for less, and what that costs you.
The bouncer standard
A bouncer checks your ID at the door. A clerk checks it at the register. Everyone involved knows this is imperfect: a younger sibling borrows an older one's license, a passable fake gets through, someone is waved past on a busy night. We know, and we keep doing it anyway, in every state, for decades.
That is not carelessness. It is a judgement that the check is good enough for what is at stake, and that the alternatives cost more than they are worth. Nobody proposes an iris scan to buy a beer. If they did, most people would object, and they would be right to: the intrusion would be wildly out of proportion to the problem.
IRLProof is built to the bouncer standard, deliberately. We check that a real, government-issued credential was presented by the phone it lives on. We do not check that the person holding the phone is the person on the license. That is the same gap the bouncer has, and we are making the same trade for the same reason.
What that means we cannot catch
Stated plainly, because you should not have to work it out:
- Someone using a license that is not theirs.
- Someone who handed their account to another person after making a proof.
- Someone acting on instructions from somebody else.
What it does do is make operating at scale expensive. Every account needs a distinct, real, government-issued credential behind it, and any one credential can only make a limited number of proofs. A script can invent a million usernames. It cannot invent a million driver's licenses.
That is the actual claim: not "this specific person is who they say", but "this is not a bot farm". Those are different, and conflating them would be dishonest.
How this compares
| Approach | What it asks of you | What you end up with |
|---|---|---|
| Iris or face scanning | A biometric scan, sometimes at dedicated hardware you travel to | Strong uniqueness. A permanent biometric record held by someone. |
| Document upload | Photos of your ID and usually your face | A company holding images of your identity documents, indefinitely. |
| Device attestation | Nothing, it is invisible | A signal the site sees. Nothing you hold, control, or can show elsewhere. |
| Behaviour analysis | Nothing, it watches how you move and type | A probability score about you, computed without your knowledge. |
| IRLProof | One tap in your phone's wallet. No photos, no scans, no documents. | A link you own, publish where you choose, and revoke whenever you want. |
Three things that make this different
1. You hold the proof, not the platform
Every other approach answers a question a website asked about you, and hands the answer to that website. You never see it, cannot show it to anyone else, and cannot take it back.
A proof here is yours. You decide whether to make one, where to publish it, and when to revoke it. Nobody has to ask us anything about you for it to work, and you can walk away with it still standing.
2. We keep essentially nothing
We do not store your name, date of birth, address, license number, or photo. What we keep is a one-way fingerprint of your license that cannot be reversed, so that we recognise you when you come back and know nothing else about you.
The consequence is worth being blunt about: we cannot tell anyone which license belongs to which account, because we do not know. Not for a court, not for ourselves. There is nothing to hand over, sell, or lose in a breach. The full detail is in the privacy policy.
3. Two of your proofs cannot be connected to each other
If you make a proof for one account and another for a second, nothing in either one links them. No shared identifier, no matching timestamps, nothing. Somebody who finds both learns only that two accounts each have a verified person behind them, not that it is the same person.
This is why the dates on a proof are rounded to the day, and why proofs renew on a schedule that has nothing to do with when you made them. Those are not details, they are the feature.
Where this does not fit
If you need certainty that a specific individual is present, this is the wrong tool and you should use something stronger. Banks and border control should not be using the bouncer standard, and we are not suggesting they do.
IRLProof is for the enormous middle ground where a site wants to know it is dealing with people rather than automation, and where demanding biometrics from everybody would be a cure worse than the disease.