Anti-fraud
We are not anti-fraud.
We do not compute scores, risk or fraud probability, anywhere in the product. The receipt records what happened, verifiably; the business decision is the client's.
Hummand presents
Hummand answers who it is, is present, authorized what.
Everything outside that is here, with the reason.
We are not anti-fraud.
We do not compute scores, risk or fraud probability, anywhere in the product. The receipt records what happened, verifiably; the business decision is the client's.
We are not an audit firm.
The receipt is verifiable by an auditor, the client's, a regulator's or an expert's, without trusting Hummand. We audit no one; we hand the proof to whoever audits.
See ReceiptWe are not login.
We do not manage the client's user identities, sessions or third-party passwords. An act happens inside the client's process, when there is a consequence; the session remains theirs.
We do not sell KYC.
Civil identity is a plugged source, labelled in the receipt and in accreditation. The lead offer is recurring presence with proof: a living person, the same one as the reference, authorizing something, with a receipt.
See SourcesWe estimate nothing.
No score, risk, probability or age estimation from a face. It is a written rule of the restructuring plan, not a preference of the moment.
We keep none of it.
In no table and in no receipt. Image and template are discarded at the end of the step; the act context stays encrypted and only the hash leaves. Biometrics retained equals false is a product invariant.
See LGPDBureaus, fingerprinting, lists, geolocation and behaviour stay out.
Credit bureaus, anti-fraud scores, commercial device fingerprinting, PEP and sanctions lists, geolocation as proof, behaviour as proof, age estimation from a face and third-party biometrics are not in the catalogue. SMS is only the delivery channel for the link, never proof of possession.
No SLA, no guaranteed accuracy, no certification of our own.
The live-presence component is AWS-certified; Hummand is not certified. There is no SLA before a contract defines one, nor "post-quantum" in the vocabulary. Every capability carries one of three labels: available, in accreditation, target architecture.
See StatusAlerts are computed on read; nothing runs in the background.
There is no monitored population and no background sweep of sources before there are real acts in the register. A vital-status source only triggers an exception proof at the client's request; the proof is still the presence.
See AlertsPaste the JSON and the public key. No account, nothing sent: it runs in your browser.
Open the verifier