VeraVault™ · For card issuers & program managers

The card ships to the fraudster.
Stop it before issuance.

In prepaid, payroll, and tax-refund card programs, impersonation happens on both channels: remotely, where an attacker who controls a phone number passes every check the program runs, and in person, where someone stands at the counter with stolen PII and a manipulated ID. VeraVault sits in front of card issuance and refuses to treat a delivered passcode — or a plausible-looking walk-in — as proof of a person.

Attack timeline

Every control reports success while the fraud completes.

T-0

Number takeover

An attacker SIM-swaps or ports the taxpayer's line. From this moment every SMS code the program sends lands on the attacker's device.

T+2m

Enrollment

They enroll in the card program with real, stolen PII. Name, SSN, and DOB all check out against the bureaus, because the data is genuine.

T+5m

OTP passes

The one-time passcode is delivered and entered correctly. Every automated control the program runs reports success.

T+1d

Card ships

Funds load to a card in the victim's name, controlled by someone else. The first signal anyone gets is the dispute.

What VeraVault does

Identity proven at issuance, not inferred from a passcode.

Carrier attestation

Direct network operator signals on SIM swap recency, port history, line tenure, and subscriber-name match — not a delivery receipt.

Possession vs. presence

Possession of a number is treated as a weak signal. Presence is proven with a live capture bound to an authentic document.

Document authenticity

Security-feature, MRZ, and tamper analysis on the government ID presented at enrollment.

Bound identity record

Device, line, document, and biometric are bound into one sealed record at issuance time and re-checked on high-risk events.

Issuance decision API

A single call returns approve, step-up, or refuse with the underlying signals, so your issuing flow keeps its own policy control.

Evidence trail

Every decision is written immutably for dispute defense, network audits, and regulator inquiry.

Why programs adopt it

The economics of refusing before the card ships.

Pre-issuance

Loss avoided, not recovered

Refusing a bad issuance costs a decision call. Clawing back a loaded card costs the program the funds, the dispute, and the network scrutiny.

One call

No KYC rip-and-replace

VeraVault layers in front of the stack you already run. Keep your bureau checks, your onboarding UX, and your policy engine.

Signal-level

Explainable refusals

Every decision returns the reasons behind it, so risk teams can tune thresholds instead of arguing with a black-box score.

Step-up

Friction only where it pays

Clean applicants pass untouched. Presence proof is requested only when carrier or document signals warrant it, protecting approval rates.

Immutable

Dispute-ready evidence

A sealed record of line, device, document, and biometric at issuance time stands up in chargeback defense and regulator inquiry.

Portfolio-wide

Ring detection across programs

Repeated device, line, and document patterns surface across enrollments, catching organized rings that spread thin across many applications.

Both channels

Remote and in-office coverage

The same proof standard applies whether the applicant is a web session behind a swapped SIM or a walk-in presenting a manipulated ID at the counter.

Remote and in-office

An imposter can be a session or a person at the counter.

Remote intake hides the applicant behind a device and a phone number. In-office intake puts a face in the room — but a face is not an identity until it is bound to an authentic document. VeraVault applies the same proof standard to both channels.

Remote intake

SIM-swapped applicant, never seen

An application arrives online at 2 a.m. with genuine stolen PII. The OTP is delivered and entered in nine seconds. No human ever sees the applicant, and the device is new to the program.

What VeraVault blocksCarrier attestation returns a SIM swap one day old and a subscriber-name mismatch. VeraVault steps the applicant up to presence proof; no live capture is ever completed, and issuance is refused.

Remote intake

Injected selfie from a stolen ID photo

A ring uploads a crisp document image and a face capture generated from the victim's driver's license photo, replayed through a virtual camera on an emulator.

What VeraVault blocksLiveness and injection detection flag a non-camera capture path. The document passes, the person does not — the record is held for review instead of shipping a card.

Integration

One call before issuance.

VeraVault returns a decision and the signals behind it. Your program keeps policy control: approve outright, step up to presence proof, or refuse issuance. Integration is API-first and does not require replacing your KYC vendor.

See Verafile for tax preparers

Issuance decision · illustrative

POST /v1/issuance/decision

{
  "decision": "refuse",
  "reasons": ["sim_swap_recent", "no_presence_proof"],
  "signals": {
    "carrier.sim_swap_days": 1,
    "carrier.line_tenure_days": 1462,
    "carrier.name_match": "mismatch",
    "document.authentic": null,
    "biometric.liveness": null
  }
}

Request the API contract

Talk to us about your issuance flow.

Send your details and we'll share the issuance decision contract — endpoints, signal definitions, and response codes — plus where VeraVault fits in your program.

We use your details only to reply to this request.