Skip to main content

Requests you send

  • Every API request carries your workspace’s public key and an HMAC-SHA256 signature made with a secret key, over the method, the path, the query and the exact body. A request whose body was changed in transit fails the check. See API authentication.
  • The secret key never travels: it only keys the signature. Keep it on your backend.
  • A workspace holds up to five secret keys, so you can rotate without downtime and delete a key the moment it may have leaked.
  • Fields that tie a verification to your user, external_id and callback_url, are accepted only on a signed request. A page holding only your public key cannot create a verification in your user’s name.

Webhooks you receive

  • Every webhook is signed with HMAC-SHA256 over a timestamp and the exact body, with the workspace’s active secret key.
  • The timestamp lets your handler refuse an old request replayed later; the official SDKs reject anything older than five minutes. See Webhooks.
  • Webhooks go only to public addresses, checked when the URL is saved and again before each delivery, and redirects are not followed. See the webhook URL.

The person’s capture

  • Selfies are taken from the live camera; the widget offers no file upload.
  • The widget’s messages to your page are accepted only from the widget’s own origin, and the verification runs only on HTTPS pages.
  • Selfies and documents are checked for presentation attacks and tampering; see Liveness and anti-spoofing and Identity (KYC).

Personal data

  • Retention: images are deleted after 60 days, capture recordings after 30. See Data retention and erasure.
  • Erasure on request: your administrators and support specialists can erase a person’s personal data from the console or through the MCP server. The erasure is recorded with its reason, and the API tells your integration that the data was erased rather than never captured.
  • Access: your team sees only your account’s data, with roles limiting who can change the integration or erase data.

Data Processing Agreement

ProofAge processes personal data on your behalf as a processor. The terms are in our Data Processing Agreement.

Reporting a vulnerability

Write to [email protected].