Identity verification without identity disclosure

Prove your authority. Not your identity.

Your people often need to prove they are authorised to someone outside the organisation. VeilOne proves it, and keeps their identity behind the veil.

  • No name
  • No service number
  • No photograph
  • No biometric data shared
The problem

The third party needs the answer. Not the identity.

Today they get both, because there has never been a way to give them one without the other.

A defence officer arrives at a contractor's facility.

The security desk needs to know the person is authorised, the credential is valid, and this is its legitimate holder.

To get those answers, the officer hands over:

  • Full name
  • Photograph
  • Service number
  • Personal details
  • Often a biometric

None of it was needed. All of it is now held on a system your agency does not control.

Exposure comes from admin, not operations

Visitor books, lanyard photographs, names on meeting invites. Routine paperwork discloses more over a year than any operation does.

The badge cannot be checked

An unverifiable credential is accepted because it looks right. The next person with a plausible card gets the same welcome.

A stored face is permanent

A password can be reissued after a breach. A face cannot, and the person carries that for the rest of their career.

The answer

Separate authority from identity.

One question in. One answer out, backed by the issuing agency.

What the contractor asks

“Is this person authorised to enter this facility?”

Chosen from the assertions the agency has authorised. Anything else returns nothing.

What they receive
  • Authorised personnel
  • Cleared for this site
  • Credential valid, not revoked
  • The legitimate holder
What they never receive
  • Name
  • Photograph
  • Service number
  • Biometric data
  • Anything to store or leak

They get the answer. They do not get the identity.

How it works

Three parties. One direction of travel.

1. The agency issues

A credential goes to someone your organisation has already vetted. It carries what they may assert. It carries no name.

2. The person proves

A live check on their own device confirms they are the legitimate holder. The biometric stays with the person, and is never sent to the third party.

3. The counterparty checks

They receive the verification they asked for. Nothing identifying moves between the two sides at any point.

Where it is used

Anywhere your people must be believed by someone outside.

Contractor facilities

Prove authority without exposing identity.

Verify visiting personnel at the gate without collecting anything about them.

Partner agencies

Prove authorised representation.

Establish standing with a coalition partner without exchanging personnel records.

External meetings

Meet the outside world without revealing who you are.

Suppliers, local officials, community representatives and the public.

Protected roles

When the identity itself must stay protected.

Sensitive investigations and personnel whose names must not circulate.

Incident response

Prove the team on arrival.

A bank, a utility or a hospital confirms the responders on the spot, in minutes.

Contractor assurance

The same check, pointed the other way.

Confirm the person on your site is the vetted individual the contract names.

Deployment

Inside your boundary, on your terms.

Issued from the directory you already run, to the people you already vet.

  • Sovereign deployment

    Runs in your own environment, including isolated networks.

  • Issues from your directory

    Change a role and what that person may assert changes with it.

  • Works without connectivity

    Verification holds up in a basement, a plant room or a remote site.

  • Revocation in seconds

    Withdraw centrally and the next check fails everywhere.

Assurance

Protect the identity of your personnel without weakening the verification.

The guarantee is the architecture, not the undertaking.

Nothing central to breach

No register of officers and no store of face templates. An attacker who takes the system still cannot name anyone.

No privileged view

Nobody, at your organisation or ours, can silently unmask an officer. The capability does not exist.

Defensible after the fact

Each check records what was asserted, when, and by whose authority. Anonymity in front, accountability behind.

Evaluating against a programme, standard or threat model? Bring it to the briefing.

Request a briefing

Bring us your hardest engagement.

A focused 30-minute session against a scenario you actually face. No commitment.

  • Worked through against your own operating environment
  • Straight answers on assurance, deployment and what we cannot do
  • Confirmed people only, because we verify before we schedule

Request your demo

We'll confirm your details and get back within one business day.

Please enter your name.
Please enter your organisation.
Please enter a valid email address.
Please enter a valid phone number, including country code.

We verify your email and phone before scheduling, so we know we're talking to the right people. We never share your details.

Confirm it's you

Enter the codes we just sent.

Didn't get them?

You're confirmed

Thank you. Your email and phone are verified, and we will be in touch within one business day to arrange the briefing.