For National ID · Border Authorities · Field Operations · Regulated Benefits

Verify the right citizen. Where connectivity does not reach.

Execution Authority Infrastructure for the public sector. A benefit does not disburse, a border record does not commit, and a registration does not stand unless a named officer signed for it, or signed the boundary it falls inside. Once a device is enrolled that check runs fully offline at the field point of service and reconciles when connectivity returns. No biometric leaves the handset. Dedicated and on-premise deployment are available on request.

The Problem

Legacy identity programs assume connectivity. They fail at exactly the points where identity assurance matters most. Border posts with intermittent links. Field health and humanitarian operations. Remote benefit disbursement. Disaster zones. Rural customs. Conditional cash-transfer program delivery.

Cloud-only authentication is not a technical preference. It is a capability gap that forces offline workflows to fall back on manual processes, paper receipts, and post-hoc reconciliation that no regulator would accept for sensitive actions in a connected context.

The political and regulatory surface is also moving. European eIDAS 2.0 and national wallet programs are pushing toward citizen-held cryptographic identity. The question for a national authority is no longer whether citizen-side hardware-bound identity is coming. The question is whether the authority produces the infrastructure or inherits an imposed one.

What Yuthent Provides

Identity proved in the field. Verifiable anywhere. Portable to the central system.

Yuthent verifies the right citizen end-to-end on the device held by the field officer or by the citizen. The result is a cryptographically non-repudiable proof, signed by a hardware-bound key, that can be verified against a published public key by the central authority, by a regulator, or by a court, regardless of whether the verifier is online at the moment of verification.

No biometric material leaves the device. Matching, liveness, and signing all execute locally in the device secure element. The proof carries a hash of the biometric binding, never the biometric itself. The authority receives evidence, not raw citizen data.

In-person and remote link-enrollment flows enable supervised device issuance, family re-linking, humanitarian registration, and the full range of workflows where a trusted operator must co-sign the citizen's initial enrollment. Every grant is time-boxed, scoped, signed, and revocable from the control plane.

Capability Surface

Field capabilities shipped in the SDK today.

Offline verification and signing in the field

Losing the network does not lower the bar. Once a device is enrolled, an action still does not proceed without the officer's press, and the proof it produces holds in a durable, encrypted on-device queue that reconciles on sync, never in the critical path. Enrollment itself is a supervised, connected step, and the highest-assurance tier is refused rather than queued when the device is offline, because it co-signs online by design.

In-person link enrollment

A citizen device does not enrol itself. A supervised operator issues a time-boxed, signed grant from a provisioning tablet, carrying the operator's identity and the issuance moment. Past its window the grant enrols nobody.

Remote video link enrollment

Where in-person is impractical, enrolment still does not happen unsupervised. A video-remote grant flow carries the same time-boxed bounds, with the operator's video identity verification step signed into the grant.

Portable, verifier-agnostic proofs

Verification does not depend on Yuthent being reachable. A regulator, auditor, or partnering ministry checks an Explicit or Authoritative action against the authority's own published public key, on the canonical bytes of the original signing, with no call to us in the path.

Privacy-preserving biometric binding

No biometric leaves the handset, so there is no central store to breach, to leak, or to subpoena. Face, liveness, and identity-document extraction execute on-device, and what travels is a hash anchored to the citizen's enrollment, never the raw biometric.

Control plane and audit export

Yuthent runs today as a hosted multi-tenant service with a scheduled audit-export pipeline. Dedicated cloud and on-premise deployment are available on request and scoped during a first deployment.

Regulatory Alignment

What each framework will not let you run without.

Border and customs

A post with no connectivity is still a post where the record does not commit without the officer's signature. The bar offline is the bar online, and the evidence travels back to central on reconnection.

Humanitarian and field operations

A registration in a disaster zone, a remote clinic, or a refugee camp does not stand on an unaccountable operator. Supervised link-enrollment grants carry the issuing operator's identity, so field onboarding names who did it.

Regulated benefit disbursement

A disbursement does not close without a signed receipt from the person who received it, taken at the point of delivery. A conditional cash transfer nobody signed for does not reconcile, and the receipt is portable back to the central system.

National ID re-verification and wallet alignment

Re-verification in a low-connectivity region does not wait for the network and does not proceed without the citizen's own device. Architecture aligned with the direction of citizen-held hardware-bound identity under eIDAS 2.0 and comparable national frameworks, with central reconciliation on sync.

Data residency and deployment

Biometric data never leaves the citizen device, and once a device is enrolled, field verification and signing carry no cloud dependency. Yuthent runs today as a hosted multi-tenant service. Dedicated cloud and on-premise deployment are available on request and scoped during a first deployment.

Audit, retention, and non-repudiation

An officer cannot later deny an action tiered Explicit or Authoritative, and the record cannot be quietly edited. The signature is made on the officer's own device and chained into a tamper-evident ledger with daily anchors, so altering one entry breaks every entry after it. An auditor or a court verifies offline against a published public key, with multi-year retention configurable per program.

Standards and assurance posture

Standards-based cryptography: ECDSA P-256 signatures and JOSE/JWS proof formats. Control mappings to SOC 2, ISO/IEC 27001, and NIST SP 800-53 are maintained and shared under NDA. No external certification is claimed at this stage, and assurance evidence is delivered through the first deployment.

Alongside Your Stack

Yuthent does not replace a national ID registry. It is the field-edge authorization and evidence layer that the registry does not produce today. Integration is a signed service contract with the central system, with BigQuery export for audit.

Deployment Readiness

A first engagement typically scopes one field workflow: border verification, benefit disbursement, or humanitarian registration. Android is the primary deployment target given the field handheld fleet. iOS parity available.

Questions

Answered plainly.

Does Yuthent see citizen data?

No. Biometric matching, liveness, and identity-document extraction execute on the citizen's or officer's device. The authority receives a signed proof anchored to the enrollment, never the raw biometric, a template, or citizen records. Yuthent handles evidence, not data.

Does it work fully offline?

In the field, yes. Once a device is enrolled, biometric verification and action signing require no network; proofs hold in a durable on-device queue and reconcile to the central system on sync. Enrollment is a supervised, connected step, and the highest-assurance tier requires a synchronous server co-signature by design. Every proof verifies offline against the authority's published public key, by a regulator or a court, without a live connection to Yuthent.

Can we run it on-premise?

Field operation does not depend on it. Once a device is enrolled, verification and signing run on-device and carry no cloud dependency, and proofs reconcile to the central system when connectivity returns. Yuthent runs today as a hosted multi-tenant service. Dedicated cloud and on-premise deployment are available on request and scoped during a first deployment.

Can an automated or AI system authorize a regulated citizen action?

No. A regulated action requires the accountable official's or the citizen's fresh hardware-bound biometric proof at the moment of the act. An automated or AI system cannot produce that proof, it can request, but only the enrolled human can authorize.

Are you SOC 2 or ISO certified?

No external certification is claimed at this stage. Control mappings to SOC 2, ISO/IEC 27001, and NIST SP 800-53 are maintained and shared under NDA, and assurance evidence is delivered through the first deployment. We will not present certifications as complete before they are.

Start a first deployment.

Tell us the flow you want to protect. We will come back with a working integration proposal. First call within five business days.