Proof of verification

A verification should leave evidence.

Vericode's authorised-contact register records who requested a check, the masked target, what happened and when. Ordered, hash-linked events help show whether that history remains intact.

What the schema records

The fields behind the evidence

The current authorised-contact schema is mobile-number based. It does not describe an email target, so this page does not claim one.

Contact
Full name and optional external reference
Target
Masked mobile number and last four digits
Request
Who requested it and when
Verification
Method, linked verification ID and relevant timestamps
Outcome
Pending, authorised or other recorded event state
Integrity
Sequence, previous hash, event hash and chain-valid result
Illustrative field map

What an audit record contains

Placeholder — annotated from API response fields. This is not a screenshot of production data or current product UI.

Illustrative record · placeholder Chain valid
mobile_masked
•••• ••• 4821
requested_by
workspace actor
requested_at
UTC timestamp
verification_method
recorded method
event_type
authorisation outcome
verification_id
linked identifier
previous_hash
prior event digest
event_hash
current event digest
Why the record matters

Reasonable steps are easier to defend when they are documented.

A manual callback may be sensible but still leave the firm reconstructing evidence later. A contemporaneous record gives compliance teams, insurers and dispute reviewers a concrete artefact to examine. The source guidance below defines the obligation; Vericode does not claim that a record alone guarantees compliance.

LPLC — Call first to avoid cyber fraud

LPLC tells firms to call a known number, verify instructions and make a file note of the conversation.

Official source

AFCA — Published decisions

AFCA's published-decision search lets firms review how evidence and reasonable verification steps are assessed in actual disputes.

Official source

TPB(PN) 5/2022 — Proof of identity

The Tax Practitioners Board practice note addresses proof-of-identity requirements and keeping evidence of checks.

Official source

AUSTRAC — Customer identification and verification

AUSTRAC guidance explains customer due diligence, identification, verification and the associated record-keeping obligation.

Official source

Export

Compliance-authorised users can export an authorised contact's audit in PDF or CSV. The CSV includes sequence, UTC event time, event type, actor, verification ID, hashes and details.

Visibility

Reads are scoped to the current workspace. The export endpoint checks for a compliance-level permission before returning a file.

Retention and residency

Authorised-contact audit events carry a seven-year retain-until value. Customer and verification data is hosted in Australia; staff sign-in is handled by WorkOS in the United States.

See the verification flow

Understand how a request moves from selected number to recorded outcome, or review the controls around the service.