Built for Jordan

Verify identities remotely, with evidence you can defend

A customer opens a link on their phone, photographs their Jordanian national ID and completes a short liveness check. Perspicax reads the card in Arabic and English, matches the face, screens the name against your blocked-persons list and — when connected — continuously updated international sanctions and PEP lists, then returns a decision you can explain line by line.

Built in from the first release

  • Versioned consent recorded at Start
  • Hash-chained audit log
  • Photos purged after 72 h by default
Approved
  • Document read · AR + ENSecond read agrees
  • MRZ check digitsValid
  • Face matchMatch
  • LivenessPassed
  • Watchlist screeningClear
Sample sessionRiskLow · policy v1
Illustration with fictional data; the national number is masked.
The pipeline

Seven steps, one auditable trail

From consent to decision, every stage is timed, stored and explainable from the evidence Perspicax keeps.

  1. Step 1: Consent

    The Terms and Privacy Policy are shown in the applicant's language, Arabic or English. Tapping Start records consent to that versioned text, before any camera opens.

  2. Step 2: ID front & back

    Guided capture of both sides of the Jordanian national ID. Size, brightness and blur are checked before a photo is accepted, and a quick check confirms the right side was photographed.

  3. Step 3: Selfie

    The front camera frames the face in an oval guide; a straight-on frame becomes the selfie compared with the ID portrait.

  4. Step 4: Liveness

    A short randomised challenge — look straight, blink, turn left, turn right — verified on the phone and re-checked on the server.

  5. Step 5: Verify

    The card is read in Arabic and English, a second read confirms the critical fields, the MRZ check digits are recomputed and the ID portrait is matched to the selfie.

  6. Step 6: Screen

    The Arabic name and its Latin forms are screened against your blocked-persons list and, when connected, OpenSanctions sanctions and PEP data.

  7. Step 7: Decide

    A versioned rule set turns the evidence into approve, decline or review — and records every rule that fired and why.

Watchlist screening

Your own list, always. Global watchlists, when connected.

At onboarding, every name is checked against your internal blocked-persons list and, when connected, the OpenSanctions consolidated sanctions and PEP data — the UN, OFAC, the EU, the UK and hundreds of other sources, refreshed several times a day.

  • Your list, and the world's when connected

    Your compliance team maintains the internal blocked-persons list, entry by entry or by CSV import. When connected, OpenSanctions adds consolidated sanctions and politically exposed persons data from hundreds of official sources, screened in the same pass.

  • Always the latest designations

    OpenSanctions republishes its consolidated data several times a day, so screening runs against current lists rather than a quarterly download.

  • Arabic-aware matching

    The Arabic name and its Latin transliterations are normalised — spelling variants, the definite article, compound names — then fuzzy-matched; date of birth and national number sharpen the score.

  • Every result kept as evidence

    Names are screened at onboarding, and every result — the names queried, any hits with their scores and the final outcome — is kept in the session evidence, so a reviewer or auditor can see exactly what was screened.

How a name is screened

Applicant name

محمد أحمد خالد الحسن

MOHAMMAD AHMAD KHALED ALHASAN

Arabic + Latin variants

Blocked-persons list

Internal · maintained by your team

OpenSanctions

Consolidated sanctions + PEP data

  • UN
  • OFAC
  • EU
  • UK
  • + hundreds of sources

Refreshed several times a day

Result

Clear

Result stored in the session evidence

A match or potential match routes the session to compliance review; a clear result lets the pipeline continue.

OpenSanctions data is queried through an OpenSanctions yente service you connect; without it, names are screened against the internal list only.

Features

Everything an onboarding team needs, in one verified pipeline

Each layer contributes evidence. Nothing in a decision is a black box you cannot open six months later.

  • Arabic-first document reading

    Google Gemini transcribes both sides of the card in Arabic and Latin script and keeps the four-part name chain intact. An independent second read of the critical fields must agree, or the difference is flagged.

  • Field checks & forensics

    National number format, date logic and the ICAO 9303 TD1 check digits are recomputed, front and back must agree, and a forensic check looks for signs of tampering.

  • Face match

    The ID portrait is matched to a selfie frame, and every liveness frame must show the same person. The similarity score and its band are stored with the decision.

  • Active + passive liveness

    A randomised head-turn and blink challenge proves a live person is present, while passive checks look for screens, print-outs and other presentation attacks.

  • Versioned risk policy

    Rules and thresholds live in a versioned policy. Every decision records the policy version and each rule that fired, so a later change never rewrites history.

  • Four-eyes review

    Grey-zone sessions land in a compliance queue with a 24-hour SLA; approving a high-risk case needs a second approval from a different reviewer.

  • Hash-chained audit log

    Every admin action and key session event is appended to a hash-chained log, with a one-click integrity check that shows where a chain was broken.

  • Short media retention

    ID photos and liveness frames are purged automatically after the decision, while the fields, hashes and evidence behind it are kept.

Perspicax in numbers

Pipeline stages, each timed and stored
10
Rules in the default risk policy, all editable
22
Default window before photos are purged
72 h
Languages — Arabic and English, full RTL
2
Compliance

Written around Jordan's own obligations

Perspicax is a verification platform, not legal advice — but its defaults are chosen so your compliance team starts from the right place.

  • Personal Data Protection Law No. 24 of 2023

    Terms and Privacy Policy shown in the applicant's language, with a versioned consent recorded when they tap Start, before the camera opens; photo metadata stripped on upload; national numbers masked in lists and logs; a scheduled purge that enforces your retention window.

  • AML/CFT Law No. 20 of 2021

    Customer due diligence evidence — verified identity, screening results against your own lists and, when connected, sanctions and PEP data, the risk score and the reason for every outcome — kept with the session for reviewers and auditors.

  • Central Bank of Jordan e-KYC expectations

    Designed to sit alongside national digital identity, including Sanad-based verification, as a complementary document and biometric check rather than a replacement for it.

  • Data residency

    The API, the web apps, the face and liveness service, the database and object storage run on infrastructure you choose — in Jordan or on-premise. Only the Google Gemini calls leave it, and OpenSanctions screening can run on a self-hosted service inside it.

Regulatory references are provided for orientation. Confirm your own obligations with your compliance counsel and supervisor.

FAQ

Questions we get before the first pilot

Does the customer have to install an app?

No. The flow runs in the phone's web browser, from a single link you generate for that customer — or from its QR code on a desktop screen.

Which documents are supported?

The Jordanian national ID card, front and back, including the ICAO 9303 TD1 machine-readable zone printed on the back. Any other document is declined as unsupported rather than guessed at.

What happens when the system is not sure?

It says so. Grey-zone sessions go to a compliance review queue with the full evidence attached instead of being forced into approve or decline, and approving a high-risk case needs a second reviewer.

Which watchlists are names screened against?

Your internal blocked-persons list and, when connected, OpenSanctions consolidated sanctions and PEP data covering the UN, OFAC, the EU, the UK and hundreds of other sources, refreshed several times a day. Names are screened at onboarding, and every screening result is kept in the session evidence.

How long are the photos kept?

72 hours after the decision by default, and you can change the window. An hourly job deletes the ID photos and liveness frames and marks the session, so reviewers can see the media was purged on purpose; the extracted fields, hashes and evidence stay.

Can we run it on our own infrastructure?

Yes. Perspicax ships as two container images — the API, which also serves the web apps, and the face and liveness service — alongside MongoDB and S3-compatible object storage that you run, in your own cloud tenancy or data centre.

Does the applicant see their score?

No. Applicants never see scores, evidence or internal reasons. A decline shows a neutral message, and the full picture stays with your compliance team.

See a verification end to end

Run the demo on your phone and watch the whole pipeline work on a real capture, or sign in to the compliance panel to see how a reviewer reads the evidence.