Screening operations and risk
A name and an SSN on an application do not tell you who showed up to the tour
Identity verification pairs a government ID with a live selfie matched against it. Without that pairing, a credit report describes a person who may not be your applicant.
Every screening product downstream of the application assumes the application is about the person filling it out.
A credit report pulled on a name and an SSN describes whoever that name and SSN belong to. If the applicant is using someone else's, the report is accurate and about a different person, and every decision you make on it is sound reasoning from a false premise.
Three distinct fraud patterns, one countermeasure
Borrowed identity. An applicant with poor credit uses a relative's or friend's information, with or without permission. The report comes back clean because it is a clean person's report. This is the highest-volume version.
Synthetic identity. A fabricated identity assembled from a real SSN and an unrelated name, built up over time until it has a credit file. Harder to construct and effective, because there is no victim to notice.
Occupancy substitution. The person who applies and qualifies is not the person who moves in. The application was legitimate about someone who was never going to live there.
All three fail against the same check: does the person completing this application physically match a government-issued ID bearing the name on it.
The two halves have to be paired
Either half alone is close to worthless, which is why the pairing is the product.
Document authentication examines the ID itself. Whether the security features expected for that issuing state and issue year are present, whether the data encoded in the barcode matches the printed data, whether fonts and layout match the known template, and whether the photo area shows signs of substitution.
Biometric match with liveness captures a live selfie and compares it to the ID photo, while confirming that the selfie is a live person rather than a photograph, a screen, or a video.
A verified authentic ID with no selfie tells you a real ID exists. It does not tell you the holder is the applicant, and an ID borrowed from someone who looks vaguely similar defeats a visual check by a leasing agent at a desk.
A selfie matched against an ID photo with no document authentication tells you the person matches the picture on a card that may be entirely fabricated.
ProofUp does both: front and back of a government-issued ID, then a live selfie matched in real time by facial recognition, in a browser with no app and no account.
The barcode is the cheapest strong check available
Worth calling out because it is a lot of signal for very little work.
US driver licenses carry a PDF417 barcode on the back encoding the holder's data in a standardized format: name, address, date of birth, license number, issue and expiration dates, and physical descriptors.
Someone altering the printed front of a license almost never re-encodes the barcode, because that requires different tooling and knowledge of the encoding standard.
So parsing the barcode and comparing every field to the printed front catches a large share of altered IDs immediately. It also catches a mismatch between the ID and the application, which is a separate and useful finding.
This is why the back of the ID is required rather than optional. An ID verification flow asking only for the front has discarded the strongest check on the document.
Where this connects to income verification
The two checks reinforce each other in a way that is easy to miss.
An applicant whose identity is verified and whose income comes from a connected bank or payroll account has demonstrated control of both a government ID and a financial account in the same name. Those are two independent institutions that both believe this person is who they say they are.
An applicant who submits an uploaded document and an unverified identity has demonstrated control of a file.
That is a substantial difference in what you know, and it is available in the same two-to-three-minute flow.
The consistency requirement is a compliance requirement
Identity verification has to run on every applicant, in the same way, at the same point in the process.
Running it selectively on applicants who seem questionable is discretionary screening applied by appearance, name, or accent, which is a fair housing problem whether or not anyone intends it that way. It is also the version most likely to be applied by a leasing agent's instinct.
The operational answer is to make it a gated step every application passes, with the same verdict logic and a per-attempt audit trail. Every attempt, including retries, recorded with what happened. That record is what makes the process defensible later and it is also what tells you whether a failure was fraud or a bad camera.
What we do not do
Stated plainly, because identity verification is a category where overclaiming is common.
We do not detect every injection attack, and we do not claim to. See the callout.
We do not verify identity for someone with no government-issued photo ID. That is a real accessibility gap affecting a real population, and if it applies to your applicant base you need a documented manual alternative rather than a rejection.
We do not perform criminal or credit checks as part of identity verification. Those are separate products and separate legal frameworks with their own notice requirements.
We do not confirm that the verified applicant is the person who eventually moves in. Verification happens at application. Occupancy is a lease enforcement matter and no screening product covers it.
Check one thing on your current process
Look at your application flow and answer one question: do you capture the back of the ID.
If not, you are skipping the barcode comparison, which is the single strongest check available on the document and costs the applicant one extra photograph.
Do you capture it?
Keep reading
Screening operations and risk
What a screening override really costs, and how to measure your exception rate
An override is not automatically wrong. Some are legitimate cash-income applicants. Measuring which is which is the difference between a policy and a habit.
Document fraud forensics
An edited PDF usually still contains the number it used to say
Annotations, hidden text layers, and incremental saves leave the original values inside the file. The rendered page hides them. A parser does not.
Screening operations and risk
Physical vs economic occupancy: why your occupancy looks fine and NOI does not
A delinquent tenant is 100% physically occupied and contributing nothing. The weekly report can read 94% while the number owners underwrite against slides.