Toni Security Center

Your identity. Your permission.

Reusing your verification should not mean sending your ID photo to every website. You review what a participating site requests. Toni shares the results you approve, not your raw ID photos or biometric images.

Consent

You approve sharing

Scoped results

Limited partner access

Signed tokens

Verifiable results

Account controls

Manage connections

How can you trust us?

Understand what Toni checks, what a partner receives, and how you control your connections.

Scoped Verification Results

Partner applications receive signed results for their approved scopes. Requested email or profile information is shown during consent. ID photos and biometric images are not included in partner assertions.

Data Minimization

Toni keeps account information, verification decisions, provider references, consent, and audit records to operate the service. Didit processes verification evidence. Provider retention is separate; returning from verification does not mean evidence has been deleted.

Connection Controls

New live integrations require representative verification, website-control proof, and registered callback URLs. Users approve requested access and can revoke connections in their dashboard.

Verification Boundaries

A verified result reflects specific checks at a point in time, not a guarantee of future conduct. Additional or recent checks may be needed for another platform. Businesses remain responsible for their eligibility and compliance decisions.

Questions about security?

Contact support about integration security, data handling, or a suspected vulnerability. Review our Privacy and Data Policies for further information.

Contact Security Team
toni