Developer preview

Prove your age.
Never your identity.

IDoro is age assurance built the other way round. A person verifies once with a government document and a liveness check — then that raw evidence is destroyed. Every service they visit afterwards receives one boolean and a pseudonym that belongs to that service alone.

Regulatory-grade age assurance for platforms under the EU Digital Services Act and the UK Online Safety Act.

Zero

Documents or biometrics retained after a check completes

Once

One verification, reusable across every participating service

Boolean

The entirety of what a relying party learns about a person

Pairwise

A different pseudonym per service, so nobody can correlate users

The problem

Age checks and privacy are being treated as a trade-off. They aren't one.

Regulation now requires the check

The EU Digital Services Act, the UK Online Safety Act and national implementations oblige platforms to enforce age assurance. The obligation is no longer optional and no longer limited to adult content — social, gaming, streaming, gambling and regulated e-commerce are all in scope.

The usual answer creates a new liability

Most providers satisfy the age requirement by collecting and retaining identity documents and biometrics. That converts a compliance obligation into a permanent breach surface and a data-minimisation problem under GDPR — trading one regulator's approval for another's exposure.

IDoro removes the trade-off. The evidence needed to establish age exists only for the seconds it takes to evaluate it. What persists is an assertion — not a person.

How it works

Four steps. Nothing sensitive survives step two.

  1. 01

    Verify once

    The user presents a government-issued document together with a biometric liveness check, through a certified verification provider.

  2. 02

    Destroy immediately

    As soon as the age bands are established, the document imagery and biometric capture are discarded. They are never written to durable storage.

  3. 03

    Issue an age assertion

    The user receives a non-identifying, cryptographically signed age assertion. It carries an age band — never a birth date, a name or a document number.

  4. 04

    Record the audit trail

    Issuance, revocation and every age check are written to a permissioned enterprise ledger, giving auditors and regulators a tamper-evident record that no single party can quietly rewrite.

Relying parties integrate over a REST API. A check is one request and one response: meets_required_age: true, plus the pseudonym for that relying party.

Privacy architecture

Unlinkability that holds up mathematically, not just contractually.

Pairwise pseudonyms

Each relying party receives a pseudonym derived specifically for that user-and-service pair. Two services holding records for the same person hold two unrelated identifiers.

No shared identifier to leak

There is no wallet ID, account number or national identifier travelling between services, so there is nothing for a data broker to join on — even after a breach at a relying party.

One-way biometric matching

Duplicate enrolment is prevented by comparing non-invertible feature hashes. The original face image is never stored and cannot be reconstructed from what we hold.

Additive revocation

Revoking an assertion appends a revocation record rather than editing history. The audit trail stays complete and internally consistent.

No dependence on a national scheme

IDoro does not require a state identity wallet to function, so availability is not tied to any one government's rollout, policy change or outage.

Breach containment by design

There is no central store of documents or biometrics to exfiltrate. The worst case is bounded to isolated assertion revocations, not a population-scale identity leak.

Pairwise identifier derivation follows the pattern described in OpenID Connect Core §8.1. The permissioned ledger is a private enterprise audit ledger — there is no cryptocurrency, no public chain and no tradeable asset anywhere in the system.

Who it's for

Built for the parties who carry the compliance risk.

Digital platforms

Social, gaming, streaming and user-generated-content services obliged to enforce age assurance under the DSA and the Online Safety Act.

Regulated commerce

Online gambling, alcohol, tobacco and pharmacy operators with cross-border age obligations across the EU and UK.

Identity providers

KYC and AML vendors who want to offer a zero-retention age layer on top of the document verification they already run.

Governments & regulators

Digital ministries and regulators seeking enforceable age assurance that does not require building a population identity database.

Enterprise & public sector

Organisations that need assured age signals without taking on biometric retention liability in-house.

Developers

Teams who want to integrate an age check in an afternoon, test against a sandbox ledger, and ship without a procurement cycle.

Pricing

Priced per check. No platform fee to start.

Developer

Free

  • Up to 500 verifications per month
  • Full REST API access
  • Sandbox audit ledger
  • Community support
Start building

Most popular

Platform

€0.12 / verification

  • Volume pricing from 1,000 checks per month
  • Production audit ledger
  • Pairwise pseudonym engine
  • 99.9% uptime SLA
  • Email and ticket support
Talk to us

Enterprise

Custom

  • Unlimited verifications
  • Dedicated ledger nodes
  • White-label API branding
  • Public tender support
  • 24/7 SLA and named contact
Contact sales

Add-ons: compliance audit reports · data-destruction certificates · integration services. Pricing shown is our planned commercial pricing at general availability.

Standards & compliance

Designed against the frameworks regulators actually cite.

  • EU Digital Services ActAge assurance obligations for online platforms
  • UK Online Safety ActHighly effective age assurance duties
  • GDPR Art. 5(1)(c)Data minimisation, by architecture rather than policy
  • OpenID Connect Core §8.1Pairwise subject identifiers
  • ISO/IEC 29115 LoA 2/3Target assurance level — certification in progress

Where we are

From working MVP to certified platform.

  1. Working MVP

    Verification flow, pairwise pseudonym engine, permissioned audit ledger and REST API, running end to end.

  2. Developer preview

    Sandbox environment and self-service developer tier. We are here.

  3. Pilot partners

    First platform integrations in regulated sectors, with compliance feedback feeding the certification audit.

  4. Certification

    ISO/IEC 29115 LoA 2/3 and formal GDPR assessment, as required for EU and UK platform procurement.

  5. General availability

    Production platform with a 99.9% SLA and white-label enterprise tier. Targeting Q1 2027.

Get in touch

Tell us what you need to comply with, and we'll show you the integration.

Whether you're a platform facing an age assurance deadline, an identity provider looking for a zero-retention layer, or a regulator assessing the approach — we'd like to hear from you.

contact@idoro.net