Verify · Research
Checking that a person is present — without overclaiming
A research design for voluntary, consented, one-to-one check-in. It combines cardiac and optical pulse measurements with document, credential and session checks — and keeps every result honest about what it cannot know.
Research only. Nothing here identifies anyone. The demonstration uses synthetic signals, its matcher returns not_evaluated, and every receipt states valid_for_authentication: false. No accuracy figures exist and none are claimed. This must never become a condition for voting.
The core idea
Four decisions, kept separate
None of these establishes the others. A real, living person can still present someone else's identity, and a correct identity match does not establish eligibility for anything.
Walkthrough video
See the synthetic session
A silent recording of the browser walkthrough: consent, synthetic enrolment, five capture windows (one fails its quality check and is retried), an honest “inconclusive” comparison, and a test receipt that cannot authorise anything.
- Consent, with the non-biometric alternative offered first.
- Five capture windows: quiet baseline, two neutral prompts, a quiet pause and a final confirmation.
- Comparison over all usable windows by a fixed rule — never the best single match.
- A minimal test receipt, marked simulated and not valid for authentication.
Silent screen recording with captions.
Read the transcript
- 00:00 This is the synthetic verification walkthrough. It uses no camera, microphone or sensor, and nothing is saved.
- 00:03 Consent comes first, and the non-biometric alternative is offered before anything else.
- 00:07 Synthetic enrolment: a service-specific pseudonym, a synthetic identity review and a test-only credential.
- 00:11 Five capture windows follow. Each is checked for quality before anything else.
- 00:15 Window two asks the participant to read a fresh number. Typing it is an accessible alternative.
- 00:19 That attempt failed its quality check because of motion. A capture problem is not a judgement about the person.
- 00:22 A bounded retry succeeds. The flow channel stays “unavailable”: there is no qualified hardware.
- 00:27 All usable windows are combined by a fixed rule. The matcher returns “not evaluated”, so the result is honestly inconclusive.
- 00:32 The person approves exactly one synthetic action. It cannot register, verify or authorise anything.
- 00:36 The test receipt holds no biometrics and no ballot choice, and says valid for authentication: false.
- 00:41 Redeeming it twice is rejected as a replay.
- 00:44 A production verifier rejects it outright: test issuer, simulated evidence.
Commitments
What the research will not do
- No public-camera identification, covert location searches or global tracking index.
- No lie detection: a physiological reaction is not evidence of dishonesty.
- No automatic fraud labels, roll removals or denials from a failed sensor or an unanswered message.
- No biometric data in ballots, receipts or audit exports, and no link between identity and ballot choices.
- No treating five windows of one session as five independent proofs.
Before any real use
Gates that must be passed first
- Qualified hardware with raw-data access and safety documentation.
- A reviewed adult volunteer study with repeat visits, designed with a statistician.
- Predefined error, capture-failure and attack-acceptance measures, reported with uncertainty.
- For any election pilot: approval by the responsible authority, jurisdiction-specific legal review and an accessible non-biometric route.
Next step: read the 21 checks or see the election evidence programme.
Behind this page
A fuller research prototype runs privately
Private · local only The BB2G Verification Lab (version 0.1.0) is a synthetic-only working prototype on the BB2G Probox. It includes the enrollment simulator, five-window capture, the 21-check registry, test-only signed receipts, a review queue and an audit room. It is not published and has no public address; this page is its public explanation.
Its own tests run on synthetic data only. Passing them does not validate any biometric method, sensor or election use.