Skip to Content
Australian support
1300 195 055 support@truevault.com.au Mon–Fri · 9am–5pm AEST
Checks and credentials · checked at the source

Prove a lot. Reveal almost nothing.

Identity, criminal history, right to work, sanctions, court records, student enrolment, phone ownership. Each one is a signed statement about a person - and you can ask for a single data point instead of the whole thing. The documents behind the check are deleted. What you did not ask for never becomes yours to protect.

01
Compliant credentials
Tamper-evident, secure
02
Ask claim by claim
Not the whole record
03
No document photos
No images, just digital proof
The request userinfo
{
  "trueidentity.valid": true,
  "acicncchc.result": "NDCO",
  "vevortw.work_entitlements": "UNLIMITED"
}
Three questions answered.
No name. No date of birth. No document number.
Nothing to store, nothing to lose.
01 / Two words

A credential, and a claim.

One is a complete result, the other is a single compenent - Selectively Disclosed.

Credential

A signed statement about a person: that their identity was verified, a criminal history check result, or their right to work check. Secure, revocable, tamper-evident.

Claim

One field out of a credential: a family name, an expiry date, a yes or no. You ask for claims, not for credentials, and you get back exactly the fields you named, with no extra personal data to manage.

Same question, two safe answers

Both of these answer "has this person verified their identity". Neither one hands you a document. The whole credential lists what was checked and when it expires, with document numbers masked to their first and last character. The single claim gives you the answer and stops there.

The safe version trueidentity.credential
{
  "given_name": "Jane Alice",
  "family_name": "Smith",
  "birth_date": "1988-04-11",
  "evidence": [
    {
      "type": "Passport",
      "number": "N••••••7",
      "expires": "2031-07-02"
    },
    {
      "type": "Driving licence",
      "number": "S••••••4",
      "expires": "2028-03-19"
    }
  ]
}
What was checked, and when it runs out. Document numbers keep their first and last character so you can cross-check one you already hold - the middle never leaves us, and the documents themselves were deleted. No images, no certificates.
The safer version trueidentity.valid
{
  "trueidentity.valid": true
}
The question is answered and nothing else needs to be disclosed. This can be tailored to your specific needs.

Either one is safe to hold. Ask for the narrowest thing that answers your question anyway - what you never receive is one less thing to look after.

Credentials and claims, in the docs
02 / The credentials

Secure checks & credentials. A single flow to verify ID with all your checks.

Which of them you can ask for depends on your needs, compliance requirements, or internal ruleset. If you need something we don't offer yet, or something custom - just ask us.

Credential Attests Valid for Note
TrueIdentity The person is who they say they are, verified against the issuing authority Earliest expiry of its documents; one year if none expire Our keystone offering. Biometrically backed identity, with no document storage
Australian Criminal History Check A nationally coordinated criminal history check, via ACIC Three months by default, as per ACIC guidelines Provided by trusted third parties - ACIC accredited bodies
Australian Right To Work Check Work entitlements, checked against Home Affairs VEVO The passport or visa's own expiry, fallback to 90 days Handles Australian citizens automatically
PEPs & Sanctions Check A PEP and international sanctions screening One day - ensures a fresh check next time Ranks matches on name and birth date above others. Links to the listing, and to a public image where one exists
Court Records Check A court records search by name Fourteen days Match on name only. A risk indicator, simple data
Student Status Check A current enrolment End of next term, approximately Checks for a currently enrolled student. It will not verify staff or other .edu email types
Verified Phone Number The person answered on that number Fourteen days Prevents SIM swaps and simple SMS fraud
Enrolled Customer or Employee Is this person enrolled with your organisation, as a customer or a client Custom expiry, or until you un-enrol them Ideal for gating access to resources automatically

Credential by credential.

Open any row for what it says, when to use it, and exactly what comes back.

TrueIdentity Valid for earliest document expiry
What it says

This person is who they say they are. Their documents were checked against the authority that issued them - the Australian DVS, Home Affairs, Indian Aadhaar system, etc - and their face was matched to the document. It is the foundation the other credentials sit on.

Valid for

The earliest expiry among the documents it was built from. One year if none of them expire.

Use it for
  • Onboarding a customer without ever touching their documents.
  • Verification of identity for conveyancing, built to the ARNECC standard.
  • Customer due diligence for the businesses coming into the AML/CTF regime.
  • Proving there is a real human behind a signup, not a bot.
  • Re-using an identity the person already holds, so a returning customer is a click rather than a form.
The least you can ask for
{
  "trueidentity.valid": true
}
A few useful claims
{
  "trueidentity.reference": "9f2c1d4e-7a63-5b28-9e14-3c8d5f0a7b61",
  "trueidentity.given_name": "Jane Alice",
  "trueidentity.family_name": "Smith",
  "trueidentity.birth_date": "1988-04-11"
}

Illustration only. Jane Alice Smith is not a real person.

There are more: full name, email, phone, verification status, the selfie, and every name verified across all documents. The whole credential shows names, document types and expiry dates only. Document numbers come through masked to their first and last character - enough to cross-check one you already hold, never the whole number.
Every claim, in the reference Full credential bodies
Australian Criminal History Check Valid for three months
What it says

An Australian Nationally Coordinated Criminal History Check, run through ACIC. The result is NDCO (no disclosable court outcomes) or DCO (disclosable court outcomes). Where there are outcomes, each one comes through with its court, date, offence and result.

Valid for

Three months from the date of the check, which is the ACIC convention.

Use it for
  • Pre-employment screening where a police check is part of the role.
  • Volunteers and contractors.
  • Licensing and accreditation renewals, where the check has to be re-run on a cycle.
  • Anywhere you currently collect a PDF certificate by email and then have to store it.
A clear check - the credential body
{ "type": ["VerifiableCredential", "OpenBadgeCredential"], "name": "Australian Nationally Coordinated Criminal History Check", "issuer": { "name": "TrueVault Credential Issuer", "url": "https://app.truevault.com.au/" }, "validFrom": "2026-09-08T14:00:00Z", "validUntil": "2026-12-07T14:00:00Z", "credentialStatus": { "type": "BitstringStatusListEntry", "statusPurpose": "revocation" }, "evidence": [ { "name": "NCCHC Result", "dateIssued": "2026-09-08T14:00:00Z", "tv:dataObject": { "result": "NDCO" } } ] }
Disclosable outcomes - the evidence array
"evidence": [ { "name": "NCCHC Result", "tv:dataObject": { "result": "DCO" } }, { "name": "Disclosable Court Outcome", "tv:dataObject": { "court": "Melbourne Magistrates Court", "source": "VIC", "date": "2019-06-15", "offence": "Exceed speed limit by 25 km/h or more", "result": "Convicted, fined $500, licence suspended 1 month" } } ]

Abridged for readability, with illustrative values. The full body is in the docs.

The full body also carries its contexts, schema, issuer keys and badge image. The shape is the point: one evidence entry holds the overall result, and where there are disclosable outcomes, each one arrives as its own entry with its court, date, offence and result. Signed, and revocable through the status list.
Full credential bodies Every claim, in the reference
Australian Right To Work Check Valid for visa expiry, or 90 days
What it says

What this person is entitled to do for work in Australia. For a visa holder it is checked live against Home Affairs VEVO and carries the visa's own conditions. For a citizen or permanent resident there is no visa to check, so the entitlement comes from the identity documents already verified, and the answer is UNLIMITED.

Valid for

Ninety days, or the visa's own expiry if that comes first. A right-to-work credential can never outlive the visa behind it.

Use it for
  • Onboarding staff and contractors.
  • Labour hire and high-turnover workforces, where the check has to happen at speed.
  • Watching for visa expiry, so the compliance date arrives before the problem does.
  • Re-checking an existing worker without asking them for their passport again.
A student visa
{
  "vevortw.work_entitlements": "Work limited to 48 hours per fortnight while course is in session",
  "vevortw.date_expires": "2027-02-28"
}
A citizen
{
  "vevortw.work_entitlements": "UNLIMITED"
}

Illustration only - these values are made up.

work_entitlements is the claim most integrations want. On a visa check the wording is VEVO's own.
Every claim, in the reference Full credential bodies
PEPs & Sanctions Check Valid for one day
What it says

Whether the person's name and date of birth match a politically exposed person or an international sanctions listing. You get a yes or no on each, a result summary, and the matches themselves if you ask for them.

Valid for

One day. This is the shortest of any credential, deliberately. Sanctions lists change daily, and a screening that was clean last week is not evidence of anything today.

Use it for
  • Customer due diligence at onboarding, for the businesses in and entering the AML/CTF regime.
  • Deciding whether to escalate a customer to a human, which is usually the only decision that matters.
  • High-value transactions, where the check belongs at the point of the deal.
A clear check
{
  "sanctionscheck.is_pep": "No",
  "sanctionscheck.is_sanctioned": "No",
  "sanctionscheck.result": "No PEP or sanctions matches found",
  "sanctionscheck.date_expires": "2026-09-22"
}
A match - the flags
{
  "sanctionscheck.is_pep": "Yes",
  "sanctionscheck.is_sanctioned": "No",
  "sanctionscheck.result": "1 PEP match found"
}

Illustration only - these values are made up.

The match behind the flag
{ "name": "Jane A. Smithson", "similarity": 78, "is_pep": true, "is_sanctioned": false, "country": "NZ", "birth_date": "1974-11-02", "record_updated": "2026-08-14", "classification": "Regional government", "positions": [ "Deputy Mayor, Example District Council" ], "pep_sources": [ "Example National PEP Register" ], "profile_url": "https://screening.example/profile/8812", "source_urls": [ "https://register.example.govt.nz/declarations/8812" ], "wikipedia_url": "https://en.wikipedia.org/wiki/Example_article", "image_url": "https://commons.wikimedia.org/wiki/File:Example_portrait.jpg" }

Illustrative values. The link fields are absent unless the source record carries one, which for a lesser-known listing is most of the time - never build a screen that assumes a link is there.

That photo is the person on the listing, not your customer. It is there so a reviewer can see at a glance that a 78% name match is somebody else - and it is a Commons page rather than a file, so nothing is transferred until something renders it.
A match is a name similarity, not a determination about your customer. If all you need is whether to escalate, ask for the two flags. If a human is going to review it, the link fields let them check the listing for themselves rather than take the match on faith. Sanctions matches carry sanction_sources and sanction_programs instead of the PEP fields, each programme with its authority, summary, status, dates and provisions.
Every claim, in the reference Full credential bodies
Court Records Check Valid for fourteen days
What it says

Whether the person's name appears in public court records across the Australian states and territories. It is a search by name and nothing else - no date of birth, no address.

Valid for

Fourteen days. Longer than sanctions, because court records are added far more slowly.

Use it for
  • Extra due diligence alongside a criminal history check.
  • Enhanced due diligence on a higher-risk customer.
  • Anywhere a fuller picture is wanted and the reader understands what a name match is worth.
Nothing found
{
  "courtcheck.person_name": "Jane Alice Smith",
  "courtcheck.result": "No court records found",
  "courtcheck.date_expires": "2026-09-22"
}

Illustration only - these values are made up.

Records found - the evidence array
"evidence": [ { "name": "Court Check Result Summary", "description": "The records below are included based on the name 'Jane Alice Smith' appearing in public court records ... and must not be taken to directly represent the Jane Alice Smith from this credential.", "tv:dataObject": { "result": "2 court records found" } }, { "name": "Court Record", "tv:dataObject": { "case_no": "2023-01234", "date": "2023-04-19", "court": "District Court of South Australia", "type": "civil", "case_title": "Smith v Alderton Property Group Pty Ltd", "listing_type": "Directions hearing" } }, { "name": "Court Record", "tv:dataObject": { "name": "Court Record (disputed, hidden)", "court": "Magistrates Court of Tasmania", "date": "2021-08-03", "type": "criminal" } } ]

Abridged for readability, with illustrative values. The full body is in the docs.

The credential carries that warning itself. The records are there because the name appeared, not because they are the person holding it - and deciding what a name match means is yours to do.
Where records are found, the result becomes a count and each record arrives with its case number, court, date and type. Before the credential is issued, the person is shown every record the search returned and can mark any of them as somebody else. A disputed record is not deleted - it still counts, as in the third entry above - but it is redacted down to court, date and type, and it says so. The person gets to answer for themselves.
Full credential bodies Every claim, in the reference
Student Status Check Valid for end of next term
What it says

This person is currently enrolled, with their unique student identifier, verified through the AAF student verification service.

Valid for

The enrolment's own end date, as the institution gives it. No rounding and no minimum - an enrolment ending next week gives you a credential that expires next week.

Use it for
  • Student pricing and concessions, without collecting a photo of a student card.
  • Campus and member services that are only for current students.
  • Anything where "were enrolled once" is not the same as "is enrolled now".
A current enrolment
{
  "student.identifier": "A5C7K2M9P3",
  "student.date_expires": "2026-12-13"
}

Illustration only - these values are made up.

Every claim, in the reference Full credential bodies
Verified Phone Number Valid for fourteen days
What it says

The person answered on that number, verified by SMS one-time code.

Valid for

Fourteen days from the moment the number was verified.

Use it for
  • Knowing a number is reachable at the moment you are relying on it.
  • Cutting fake and duplicate accounts at signup.
  • Giving a counterparty a contactable number they can trust without you vouching for it.
A verified number
{
  "phonenumber.phone_number": "+61400000089",
  "phonenumber.date_expires": "2026-09-22"
}

Illustration only - these values are made up.

Every claim, in the reference Full credential bodies
Enrolled Customer or Employee Valid for an expiry you choose
What it says

This person is enrolled with your organisation, as a customer or a client. It is the one credential you set yourself, and you can withdraw it the moment the relationship ends.

Valid for

An expiry you choose, or until you un-enrol them.

Use it for
  • Gating access to resources automatically.
Enrolled with you
{
  "enrolled.is_enrolled": true
}

Illustration only - these values are made up.

Every claim, in the reference Full credential bodies
03 / Document claims

When you need the number itself.

Some fields can be read from a single verified document rather than from a credential. They are named document.{type}.{field}. We don't store these, but can re-request them when essential. Useful when your own system keys off a licence number and nothing else will do.

Other document types are used to establish identity but we don't make fields available for request: identity cards, birth, marriage, change of name and citizenship certificates, bank accounts, the electoral roll, Medicare and ASIC/MSIC cards.

The full claim reference
Driving licence
Licence number, state, expiry, date of birth
Passport
Travel document number, expiry, country
Visa
Passport number, expiry, country
ImmiCard
Card number, expiry
Student
Identifier, expiry
Centrelink
CRN
04 / Rulesets

Identity Rulesets. Complete verification flexibility.

A ruleset is the recipe: how strong the identity check has to be, and which other checks come with it. The person completes it once, in one sitting, and you receive separate credentials - each with its own expiry.

Bronze
One biometric document
Bronze, Australian documents
One biometric document, Australian documents only
Silver
One biometric document plus one supporting document
Gold
One biometric document plus two supporting documents
Conveyancing
The ARNECC verification of identity standard
Conveyancing with ConnectID
ARNECC, with ConnectID as an option
AML Customer due diligence
For general use, under the AML/CTF regime
AML Enhanced due diligence
The same, at a higher standard, for a higher-risk customer
ACIC Checks
Identity plus a criminal history check
ACIC Checks plus Right to work
Identity, criminal history and right to work, together
Right to work
Work entitlements, checked against Home Affairs VEVO
Build your own
No-code ruleset builder. Rulesets usable with APIs and OIDC
Plan around this

The expiries differ.

One journey does not mean one clock. On Criminal history and right to work, the sanctions credential will expire long before the rest of them. Student verification is available too, and custom rulesets can be built for obligations that do not fit the list.

Setting up rulesets, in the docs
PEPs & sanctions One day
Court records Fourteen days
Criminal history Three months
TrueIdentity Document expiry
Relative lifespans, not to scale.
05 / Custom credentials

Not on the list? Ask us to build it.

A credential is just a signed statement about a person. There is nothing special about the eight we happen to offer today - they are the ones customers asked for first.

If the statement your industry runs on is not here, tell us what it needs to say. We will work out who confirms it and how long it stays true, and put it on the road map. Custom rulesets work the same way, for obligations that do not fit the standard recipes.

01

Tell us the statement

In one sentence, what does it have to say about the person? "Holds a current trade licence." "Completed the induction." "Is on the approved supplier register." If you can say it plainly, it can be a credential.

02

We agree the source

Who confirms it - an issuing authority, a register, a third party we already talk to, or you. A credential is only worth what stands behind it, so we settle that before we build anything.

03

We set the expiry

How long the statement stays true. A day for something that moves daily, a term, a year, or until you withdraw it. The expiry is part of the design, not an afterthought.

04

It arrives as claims

Signed, selectively disclosed, revocable, and read exactly like the eight above - same request, same shape, same narrow asks. Nothing new to learn.

The road map is a conversation

If we don't have it, just ask.

Send us the statement you need attested and we will tell you straight away whether it is a configuration, a road-map item, or something we cannot stand behind. No sales dance either way.

06 / Getting them

Four ways. Same credentials.

Only the delivery differs. Pick the one that matches how the person reaches you - sitting in front of you, waiting on a webhook, checking their inbox, or scanning a code on a form.

integration
When they are with you

Sign in with TrueVault

OpenID Connect. The person signs in and consents to share the claims you asked for. Best when they are in front of you and you want an answer in the same session.

OIDC quick start
integration
When they are not

The REST API

You ask for an identity, the person completes it in their own time, and a webhook tells you when it is done. Best for batches, back-office work and anything that runs overnight.

Identity API reference
no-code
When you have their email

A direct invite

Ask for the identity and let us send the email. The person gets a link to complete their TrueIdentity, finishes whenever suits them, and you are told the moment it lands. Nothing to build beyond the request itself.

Request a new TrueIdentity
no-code
When you do not know who is coming

A static verification link

One link that is not tied to a person. Print it as a QR code on a form or a poster, drop it in an email footer, put it at the end of a job ad. Everyone who opens it starts their own journey, and the credentials arrive the same way they always do.

Talk to us about setting one up
Read a check, or run one

Asking for a check to be run, rather than merely read, is one flag on the request. If the person does not already hold the credential, they are taken through getting one and come back with it.

Requesting claims
07 / What stands behind it

Proof you can check for yourself.

A credential is only useful if the person reading it can be sure of it without trusting us twice.

Signed by us, checked by you

Credentials are signed by us and can be checked by anyone holding our public keys. You do not have to call us to know a credential is genuine.

You only see what you asked for

Selective disclosure means the credential carries a hash of each value rather than the value. The person sends you what you asked for, and you check it. Anything they did not send, you cannot see and cannot reconstruct.

Revoked is not the same as expired

A credential can be revoked before it expires, and that is published in a status list attached to the credential. An expired credential is not revoked and not false - it says what it said, on the day it said it.

The documents are gone

No identity document images. The documents behind a True Identity are deleted once the check is done. This is our breakthrough technologies to protect data providers and receivers alike.

Built on W3C Verifiable Credentials 2.0 Open Badges 3.0 SD-JWT for selective disclosure How it all fits together

Ask for less.Know more.

Tell us the checks your obligations call for and we'll map them to credentials, claims and a ruleset that runs in one journey. If the one you need doesn't exist yet, we'll road-map it.