All Products
Search
Document Center

ID Verification:Security operations agent

Last Updated:Sep 16, 2026

Powered by the advanced reasoning of the Qwen large model, ID Verification offers offline in-depth risk analysis and high-risk device handling for face presentation attack scenarios. This enhances your risk identification and security posture.

  • group risk: Identifies potential group risk during face authentication.

  • device risk: Identifies potentially high-risk devices during face authentication.

Applicability

  • The security operations agent applies to the following product solutions for scenarios involving face presentation attacks. Only app (SDK) integration is supported, and the Device Guard module must be fully integrated.

    Product code

    Description

    Integration method

    eKYC_PRO

    A complete eKYC workflow that includes OCR for global identity documents, liveness capture, and face-ID comparison to verify the end user's identity.

    Note
    • Supports document types from multiple countries.

    • Due to regional model differences, supported document types vary by region.

      • Singapore region: Supports documents listed in the Table of Document Types.

      • Indonesia region: Only supports recognition of Indonesian ID cards and global passports (document type codes IDN01001 and GLB03002).

      • Malaysia region: Supports recognition of only Malaysian ID cards and global passports (document type codes MYS01001 and GLB03002).

    App (SDK) + server-side

    eKYC

    A complete eKYC workflow that includes identity document OCR, liveness capture, and face-ID comparison to verify the end user's identity.

    Note

    Supports various document types in China (including China (Hong Kong), China (Macao), and the Taiwan region).

    App (SDK) + server-side

    eKYC_NDI (No Document Image)

    An eKYC workflow for document types verifiable against authoritative sources, eliminating the need for users to capture a document image. Users complete a face scan to verify their identity.

    Note

    Available for users in the Chinese mainland.

    App (SDK) + server-side

    FACE_LIVENESS_PRO

    Captures and analyzes the user's face and interactive movements in real time. It uses Qwen-VL to perform in-depth analysis of spoofing risks and verify the user's liveness.

    App (SDK) + server-side

    FACE_IDU (Identity Unique)

    Verifies liveness by capturing and analyzing the user's face and interactive movements in real time. It supports comparison against stored faces to confirm the user's identity, or searching a face gallery to prevent duplicate registrations. After successful verification, the service automatically adds the face to a specified face gallery.

    App (SDK) + server-side

    FACE_VERIFY

    Verifies user liveness and compares the face with a stored image to confirm the user's identity. Ideal for secondary verification scenarios.

    App (SDK) + server-side

    FACE_GUARD

    Collects device features and reports them to the server for risk analysis.

    App (SDK) + server-side

    FACE_GUARD_PRO

    Collects features of the device used for the face scan and uses the Tongyi large text model for in-depth analysis to detect device risks.

    App (SDK) + server-side

  • The security operations agent is available only in the Singapore region. You can enable this feature by authorizing data synchronization to the Singapore region.

Procedure

Note

Before you begin, ensure you have activated the ID Verification service and have completed authentication records from the supported product solutions.

  1. Go to the ID Verification console. In the left-side navigation pane, choose Security Operations Agent > Detection and Response.

  2. Turn on the Auto Detection feature. You can then filter records by criteria such as Scene ID or Verification Status.

  3. Due to the model's processing time, we recommend checking the Detailed Records on the following day to identify potential risks. Cross-reference these risks with your business data to confirm them. If a risk is confirmed, click Add to Blacklist in the Operating column for the corresponding record to block the associated device.