secure.prontoid.com

The secure operations
host for ProntoID

Tokenized verification flows, biometric file delivery, and signed-release uploads. This subdomain is reached by invitation from partner platforms — not by typing the address into a browser.

Looking for your secure link?
Access here is granted by single-use tokens issued by the partner platform that sent you. If your link has expired, return to that platform and request a fresh one.
What happens here

Three flows. One secure surface.

Everything on this subdomain is short-lived, scoped to one user, and gated by a token issued elsewhere in the ProntoID stack.

Release-form uploads
Photographers and studios upload signed model releases plus the model’s ID, linked to a piece of content on the partner platform. Files land in encrypted storage.
Biometric file delivery
ProntoDeliver claim links resolve here. The recipient verifies their identity and passes a liveness check before the file’s decryption key is ever released.
Tokenized verifications
Partner platforms hand off to secure.prontoid.com with a single-use JWT. We exchange it for a session, run the flow, and redirect back with a signed result.
Why this surface is safe to use

Built for short-lived,
scoped, auditable access.

No long-lived sessions, no shared accounts, no plaintext at rest. Every action here is bound to the original token that opened it.

Encrypted at rest, per-file KMS keys
Uploaded documents are stored as ciphertext in S3 with SSE-KMS. Decryption keys are released only on a successful verification.
Single-use, short-lived tokens
Platform JWTs are exchanged for a first-party session locked to this domain with SameSite=Strict.
No human review by default
Documents are processed by automated pipelines. People only see your data if a dispute is opened — and every such access is logged.
Full audit trail, every action
Token exchanges, uploads, claim attempts, and key releases are all recorded against the originating partner platform for accountability.
Locked to one domain, one cookie
Sessions live in a secure.prontoid.com-only cookie that doesn’t cross subdomains and can’t be replayed elsewhere.
Hosted in EU AWS regions
Operated by Brooks & Keitt Sàrl in Switzerland. Infrastructure runs on AWS with automatic backups, snapshots, and disaster recovery.
Need a hand?

Reached this page by mistake?

If a partner platform sent you here but the link no longer works, or if you’re a partner looking to integrate ProntoID’s secure flows, the support and main marketing sites are the place to start.