This page is the one to read before an evaluation, and the one to argue with. Everything on it is carried onto every verification record as well, so a record read three years from now states its own limits without needing this page to still exist.
It is not a compliant V-CIP deployment, and does not claim to be. RBI's process requires a trained official of the regulated entity, operating from its premises, under concurrent audit. None of those hold here. What this shows is the mechanism and the evidence it produces — and the mechanism is the part that is hard to build.
A capability this build does not have is named here rather than approximated. The credibility of everything above rests more on this list being complete than on anything it does provide.
| Capability | Why it is absent |
|---|---|
| RBI-compliant V-CIP | This is a demonstration of the mechanism, not a compliant V-CIP deployment. RBI's process requires a trained official of the regulated entity, operating from its premises, under concurrent audit. None of those hold here. Every other absence below is a consequence of this one. |
| Presentation-attack and deepfake detection | Not implemented. The liveness challenge is an active challenge-response: it defeats a held-up photograph, because a photograph cannot turn its head. A replayed or synthesised video of the right person would pass. Declared rather than approximated -- this is the single most over-claimed control in video KYC. |
| Tamper-proof recording storage | The recording is retained with a SHA-256 hash chain, so alteration after the fact is detectable and the build will name the altered chunk. That is tamper-EVIDENCE. It is not WORM storage, and this build does not itself enforce a retention period; both are deployment concerns this build does not provide. |
| OTP delivery to the customer's mobile | There is no SMS gateway, because a gateway is an outbound call and this build makes none. The one-time code is generated on the server and shown on the official's console to be read out. In production it goes through the bank's own gateway; the consent mechanism is otherwise identical. |
| Geo-fencing to India | The customer's coordinates are captured and put on the record. They are NOT checked against an authoritative boundary, and a browser-supplied coordinate is a claim by the client rather than a measurement. Recording a location is not establishing one. |
| Relay (TURN) bundled with this build | A relay is supported but not supplied and not configured by default. Unconfigured — which is how this build ships — the video leg gathers host ICE candidates only, contacts no STUN or TURN server, and makes no outbound call of any kind; the cost is that both participants must be on the same network. Configured, media is relayed through a host named in advance for that deployment, which on-premises is the operator's own relay inside its own estate. This build does not ship, operate or host that relay. Every session's record states which of the two applied to it. |
| AML/CFT screening and regulatory reporting | A V-CIP deployment is expected to integrate with AML screening and evidence-pack workflows. No screening is performed here and none is simulated. |
| Directory-based authentication (AD/LDAP) | Operator accounts are local to this deployment. Integration with an enterprise directory is designed for and stubbed, but it cannot be tested without a directory to test against, so it is declared rather than presented as working. |
| Password recovery | There is no mail path, and adding one would be an outbound call. An administrator resets a password directly. |
| OCR extraction | Not provided by this build. A defensible extraction accuracy figure requires a purpose-built synthetic corpus, because production data cannot lawfully be used to build one. That corpus does not exist yet. |
| Government-source verification | No government registry is connected, and none is simulated. Every lookup is reported as not connected. |
| CKYCRR / CERSAI | Outside the scope of this component. |
| AUA / KUA operation | Real UIDAI authentication runs through a licensed agency. This build performs none. |
| Aadhaar masking on a document image | Masking is a detection task requiring per-field bounding boxes from the corpus described above. Not provided. |
| Optical capture of a passport machine-readable zone | The zone is entered rather than read from an image. Its check digits are validated in full. |
A declared absence is not a failure and is not a pass. It is a statement that we did not look, and it cannot be set to a passing outcome by any route in this application — the server refuses, rather than the interface hiding a button.
Every field on a record carries how it came to be known, and the three states are never collapsed into a tick. A cryptographically verified field was signed by an issuer and the signature held. A structurally valid field passed a format or checksum test and nothing more — an identifier belonging to nobody passes those. An absent field was not looked for. Reading the second as the first is the single most common misreading in this market, so the record refuses to make it available.
Every payload in this deployment is synthetic and generated on the server. No real identity document has been processed, in this or any environment. No extraction accuracy, confidence score or match probability is reported as a headline figure; where a comparison is made, its value, its scale and its threshold are carried together, because a number without its scale is not a measurement.