Position
Hummand stands in the path of every human act with consequences: policy per act, source orchestration, a receipt for the act.
What we don't doWho it is, is present, authorized what.
- 0.1Policy per act
The client declares the guarantee level; the policy turns it into steps.
- 0.2Source orchestration
Native live presence and match; civil identity and signature as plugged sources.
- 0.3Receipt for the act
Signed, chained per client, verifiable without Hummand.
- Sectors
- Regulated: financial, pensions, public sector
- Offer
- Presence, identity and mandate, with a receipt
- Guarantee
- Signed receipt, verifiable without Hummand
How we speak
- [ Act 1 ]
- Everything
the client asks,
with type and level - [ Policy 2 ]
- Type and level
become steps;
version in the receipt - [ Receipt 3 ]
- Signed,
chained,
hashes only
Meet the
Human guarantee
Illustrative demonstration. Live presence available; civil identity in accreditation.
- tipo
- presenca.recorrente
- consentimento_geral
- v1 · accepted
- consentimento_biometrico
- v1 · accepted
- ts_criado
- 2026-09-07T14:31:40Z
- ref_cliente_hash
- sha256:8a1e…f07c
- contexto_hash
- sha256:c4d2…91ab
- etapa presenca
- ok
- etapa match
- ok
- fonte
- hummand.presenca
- fonte
- hummand.match
- humano_vivo
- true
- mesma_pessoa_da_referencia
- true
- imagem
- discarded
- template
- discarded
- biometria_retida
- false
- imagem_referencia_hash
- sha256:2b7f…44e0
- retencao
- by policy · crypto-shred
- formato
- humanproof/1
- nivel
- 2
- resultado
- positivo
- ts_concluido
- 2026-09-07T14:32:07Z
- kid
- hp-2026-09
- alg
- ES256
- prev_hash
- sha256:3f9a…c21e
The receipt the act leaves: humanproof/1 format, real fields, fictitious values.
Live presence and civil identity in a policy per act, with a receipt that
any auditor verifies.
Where the proof is a receipt.
- 0.5Chained receipt
Every finished act generates a signed receipt, chained to the same client's previous one.
- 0.6Hashes only
No receipt contains an image, a template or client content.
- 0.7Active challenge
A passive signal collapses against a competent replay; what resists is the live response.
* Honest labels on every capability: available · in accreditation · target architecture. A step that does not execute yet responds as unavailable; nothing is simulated.
Go to Labs- 2.0 Verify a receipt
- Paste the JSON and the public key. No account, nothing sent: it runs in your browser.
- Open the verifier
- 3.0 Talk to us
- A technical conversation, straight with the people who build it, no sales script.
- Contact
Security by design
Centralized custody, declared: KMS envelope per record, per-client isolation in the database, erasure by crypto-shred.
See SecurityData and LGPD
Consent per step, with versioned text recorded in the receipt. No image or template persists after the act; erasure on request, on record.
See LGPDIntegration
An acts API with a TypeScript client generated from the contract, signed webhooks, and the dashboard that generates the journey by link, with no code.
See Docs