Video customer identification

Video KYC that produces evidence, not just a decision.

A live V-CIP session between your official and your customer — and a record that carries how every fact came to be known. Identity is read from signed payloads and verified, never guessed from a photograph.

Verification record PROVENANCE, PER FIELD
AADHAAR SECURE QR Cryptographically verified
PAN Structurally valid
LIVENESS CHALLENGE Challenge completed
PASSPORT MRZ Not required by this journey
media path: relayed via kyc.contetial.com
recording: sealed with a SHA-256 chain
RBI V-CIP process PMLA digital KYC Data stays in India On-premises or your cloud
Three

flows run with no UIDAI licence

Every field

carries its own provenance

Isolated

runs with the network interface disabled

The problem

Most video KYC shows you a tick.

A tick tells you a check passed. It does not tell you whether the field was proven by a signature the issuing authority put there, or merely found to be well-formed. Those are different facts, and only one of them survives being questioned. A well-formed identifier belonging to nobody passes a format check every time.

When an auditor asks, three years later, how a particular customer came to be identified, the record has to answer on its own. Ours carries the provenance of every field, the journey it followed, the stages that journey required — and, by name, the stages it deliberately did not.

How a session runs

Six stages, each one recorded.

Your official opens the session and admits the customer, who joins from a single-use link and signs in to nothing.

01Consent

Captured against a one-time code, read aloud on the call.

02Identity

Signed payload decoded, signature checked against a named anchor.

03Photograph

Live capture and face match — value, scale and threshold together.

04Liveness

An active challenge the customer performs on camera.

05Question

Drawn at random, asked on the call, judged by the official.

06Record

Recording sealed with a SHA-256 chain; evidence pack exported.

Flow coverage

Every KYC flow, and how each one is delivered.

“Online KYC” is not one flow. Some run in the product, some run on a licence you already hold and no vendor can hold for you, and some are delivered with a specialist. The table says which, per flow, so a deployment can be planned rather than discovered.

IncludedIncluded in the product
Your licenceRuns on your licence
PartnerDelivered with a partner
RoadmapOn the roadmap
FlowHow it is deliveredWhat it is
V-CIP (video-based customer identification) Included A live video session between your official and your customer: consent against a one-time code, identity payload, live photograph and face match, liveness challenge, randomised question, and a retained recording with a hash chain. Runs end to end and produces the verification record. Your trained official, operating from your premises under your audit, is what makes a deployment compliant — the product carries the process and the evidence.
Offline Aadhaar — Secure QR Included The signed QR on an eAadhaar printout or PVC card. Decoded, decompressed, and the RSA signature checked against a named anchor before any field is read. Needs no UIDAI licence, which is why it is the primary identity path here. A signed field cannot be misread the way an extracted one can. Verified against the issuing authority's key in your own deployment.
Offline Aadhaar — paperless e-KYC XML Included The share-code protected archive your customer downloads from UIDAI, holding an XML document signed by the issuer. The share code gates access; the signature gates extraction. Also licence-free, and the second of the two routes that let you read Aadhaar data without holding an AUA/KUA agreement.
Digital KYC — officer captured Included The PMLA-defined flow: your officer captures a live photograph of the customer, geo-tagged and timestamped, with the officer's own identity on the record. Photograph, coordinates and attribution are captured and carried. Coordinates are recorded as the browser reported them; enforcing a boundary is a deployment decision we wire to your rules rather than assume.
Passport (machine-readable zone) Included A TD3 zone validated in full against its own check digits, so a misread fails loudly instead of becoming a permanent customer record. The zone is entered rather than read optically, which is the deliberate choice: check digits make a typing error visible, where an optical misread would be silent.
Indian identifier validation (PAN, GSTIN, CIN, LLPIN, DIN) Included Format and checksum validation, including the Aadhaar Verhoeff check digit, with every result carrying what it proves. Structural validity, reported as structural validity. Confirming an identifier against its registry is the row below, and the record never lets one be read as the other.
Re-KYC / periodic updation Included Risk-based re-verification — two, eight or ten years by customer risk category — run over the same V-CIP journey. The verification runs today. Scheduling and campaign management are driven from your own customer master, which is where the risk category and the due date already live.
Aadhaar OTP e-KYC Your licence An OTP to the Aadhaar-registered mobile; UIDAI returns demographics and photograph. Runs through your AUA/KUA licence — the credential is yours and could not be ours. Worth knowing before it is chosen as the default: for banks it yields limited KYC, with balance and annual-credit ceilings and conversion within a year, which is why the two offline routes above are the primary path here.
Aadhaar biometric e-KYC Your licence Fingerprint or iris capture on a UIDAI-registered device. Your AUA/KUA licence and your certified capture hardware. Yields full KYC where OTP e-KYC does not.
DigiLocker issued documents Your licence Issuer-signed documents fetched with the customer's consent, satisfying the officially-valid-document requirement. Your DigiLocker partner agreement. The trust model is the one this product is built on — an issuer signs, we verify, fields are read only if the signature holds — so the verification side needs no new machinery.
CKYC / CERSAI registry Your licence Search and download an existing KYC record by CKYC identifier, and upload newly created records. Your CERSAI registration, which every regulated entity holds and no vendor can hold on your behalf. We integrate to it and put the download on the record with its provenance.
PAN verification against the registry Your licence Confirming a PAN and its name match against a permitted channel, and PAN–Aadhaar linkage status. Your agreement with the permitted channel. The identifier's checksum is validated here today; the registry confirmation is carried onto the record as a separate, stronger state.
Presentation-attack and deepfake detection Partner Detecting a replayed video, a mask or a synthesised face, beyond the active challenge the journey already runs. Delivered with a specialist engine, integrated behind an interface so it can be replaced, and reported with its version and its threshold on its own scale. On-premises capable engines exist and licensing one for your estate is part of the deployment conversation.
AML / CFT screening Partner Sanctions and PEP screening, adverse media, and ongoing monitoring. Screening is a licensed-data business rather than a software one, and most regulated entities already run a system for it. We call yours at the right point in the journey and carry the result onto the record with its provenance — rather than asking you to buy a second one.
KYB / legal-entity onboarding Roadmap Company, LLP and partnership onboarding: registry data, beneficial-ownership identification, and KYC of the authorised signatory. The signatory's KYC runs on the V-CIP journey today, and CIN, LLPIN, DIN and GSTIN are validated. The entity flow around them, and beneficial ownership in particular, is committed work rather than a shipped feature.

Every limit named on a row is also carried on the verification record itself, and the full scope statement is published in one place for your evaluation team.

Why it holds up

Three things that survive a technical evaluation.

01 — Signed, not guessed

A signed field cannot be misread.

Offline Aadhaar — the Secure QR and the paperless XML — is verified against a named anchor before a single field is read. Extraction can misread a character and write it permanently into a customer record. A signature check either holds or it does not.

02 — Provenance

A record that states its own limits.

Three states, kept permanently apart: cryptographically verified, structurally valid, and not looked for. They are never collapsed into a tick, and no route in this application can set an absence to a passing outcome.

03 — Your estate

Nothing leaves without being named.

Deploy on-premises or in your own India-region cloud. Any relay is named in advance for that deployment, and every session's record states which media path that session actually took.

Deployment

It runs where your data is allowed to be.

Option A

On-premises, in your data centre

  • Containerised — Docker or Kubernetes
  • No outbound call of any kind by default
  • Demonstrable with the network interface disabled
Option B

Your cloud, India region

  • Same image, your tenancy and your keys
  • Personal data stored and processed in India
  • Relay inside your own estate, named in advance

This deployment has a relay configured: media may be carried through kyc.contetial.com, named in advance and reachable by both parties. Every session's record states which path it actually took.

How the rest is delivered

The parts that are yours stay yours.

A V-CIP deployment is not one vendor's product. Your AUA/KUA licence, your CERSAI registration, your DigiLocker agreement and your screening system are assets you already hold, and a vendor who offered to hold them for you would be describing something that cannot exist. We integrate to them and put the result on the record with its provenance.

Where the capability is a data or research business rather than a software one — sanctions screening, deepfake detection — we deliver it with a specialist, behind an interface, reported with its version and its threshold on its own scale. You are not asked to buy a second system you already run.

And every limit the product has is written down: on the record, inside the evidence pack, and on one published page your evaluation team can read before they meet us. A record read three years from now states its own limits without needing us to still exist.

Read the scope statement
Next step

See a real session, and read the record it produces.

Cases on this instance: 1