For IDV Providers
Enforcement after
identity verification.
Your verification happens once. Lemma.id makes it worth something on every site the user visits afterward.
Here's the shape of it: an upstream IDV provider runs the live document and liveness check. Lemma.id derives a privacy-preserving person root from the result and issues site-private credentials, which relying sites verify locally from then on.
Lemma.id currently uses Didit as its upstream IDV provider.
You handle the check.
We handle what happens after.
The division of labor is clean. The IDV provider runs the identity check. Lemma.id handles everything downstream of it: credential issuance, site-scoped PPIDs, local verification, and the abuse enforcement that relying sites actually buy this for.
To be blunt about it: Lemma.id is not a replacement for IDV and doesn't want to be. It's the layer that sits after IDV.
We want to work with providers whose verification events could power enforcement in fraud-heavy consumer flows. Ticketing, marketplaces, rewards, gaming, account abuse. Places where the customer would never buy full IDV directly, but will pay for the signal.
Why this matters for IDV providers
Demand you can't reach today
Most websites never buy IDV. A waitlist, a free-trial SaaS, a comments section: none of them can justify $1–2 per signup. Lemma pools that demand, so one issuance gets amortized across every site in the network, and the long tail becomes a market.
Net-new verification volume
Sites that won't pay $1–2 per user will pay a few cents per check when the cost is pooled. They adopt because they get a verified-human signal without ever touching ID documents or running a KYC stack. That volume doesn't exist for you today; this is how it starts existing.
You keep the upsell
When a relying site outgrows the basic signal and needs full IDV, age checks, KYB, AML, monitoring, or manual review, that conversation is yours. Sold direct, at full margin. Lemma takes no cut of expansion revenue.
One onboarding, recurring checks
Sites can challenge a credential whenever they want, and refresh and step-up checks keep generating issuance events long after the first onboarding. One-shot KYC turns into a trust signal that gets re-priced over time.
Built so we can't cut you out
The local-first architecture means lemma.id doesn't need cross-site behavioral data to deliver its value, so there's no data position for us to leverage against you later. The verification relationship, the pricing power, and the upsell path stay with the provider.
How it works
Verify once. Carry the credential. Enforce locally.
A user completes live IDV through Lemma.id's hosted flow, and a signed human proof lands in their lemma.id. From then on, relying sites verify it locally. Routine access decisions never round-trip to the IDV provider or to Lemma.
Site triggers verify
Relying site embeds the SDK; user has no credential yet.
Live IDV runs
Lemma.id hosts wallet unlock and upstream document + liveness checks.
Lemma.id issues credential
Ed25519-signed credential with site-scoped PPIDs derived from a privacy-preserving person root.
lemma.id stores it locally
Credential lives in the user's lemma.id, not on Lemma servers.
Sites verify locally
Future sites validate signature + freshness in-browser, no round-trip required.
It works like a driver's license. The DMV signs once, the bar checks it on the spot, and the DMV never hears about it. Same model here: you issue after IDV, sites verify locally, and the user carries the credential around.
Architecture
Designed not to disintermediate IDV providers
A fair question from any provider is: what stops Lemma from accumulating a data position and squeezing us later? The architecture is the answer. Credentials live in the user's browser, verification happens in-browser, and routine access decisions never call back to anyone. lemma.id doesn't observe cross-site usage because it doesn't need to, which means there's nothing to build a competing position from.
The design complements provider distribution. It can't replace it, and that's on purpose.
Issuer program
Where we are with providers
Full disclosure: what follows is who we're talking to and who we'd like to talk to, not a list of signed partners. If your name is on it and shouldn't be, or isn't and should, email us.
Exploring
Persona
Mapped to Persona Connect. Strong fit for consumer-web distribution.
Exploring
Veriff
Net-new anti-bot tier as a product line for long-tail sites.
Open
Yoti, Sumsub, iProov
Adjacent providers with reusable-credential strategies. Open to conversation.
Issue once. Distribute everywhere.
Keep the customer.
If the consumer-web distribution thesis sounds interesting, send a note. We'll reply with a one-pager and find 20 minutes for a call. No pitch deck marathon, promise.