Why identity verification is the foundation of trust on Refonte Learning
On a learning platform, the person on the other side of a lesson is the product. If a learner books a mentoring session on adversarial machine learning, they are not paying for a chat window, they are paying for the specific human whose credentials, experience, and reputation justified the price. That is why identity verification is the load-bearing wall of the entire Refonte Learning marketplace. Without a reliable answer to the question of who is actually delivering the work, every other trust signal, from reviews to certificates to payout guarantees, becomes theatre.
This article is a child piece under our broader guide on how Refonte vets everyone who earns on the platform. The parent article covers the whole vetting funnel: identity, credentials, employment history, skills assessment, references, and ongoing monitoring. This child piece zooms into one stage: how we confirm that a person applying to teach, mentor, tutor, or advise on Refonte is genuinely who they claim to be. If you are considering an application to become an instructor on Refonte Learning, this is the process you will move through in the first 48 to 72 hours of onboarding.
We are writing this in early 2026, and identity verification for online marketplaces has changed sharply in the last 18 months. Generative AI has made synthetic identities cheap, deepfake video calls now defeat naive liveness checks, and regulators in the EU, UK, and several US states have tightened rules on how platforms handle biometric data. A verification process designed in 2022 is no longer fit for purpose. Refonte rebuilt its stack over 2024 and 2025 to reflect the new threat model, and the sections below explain how it now works, what it is designed to catch, and where the tradeoffs sit.
A fair warning before we go deeper: this piece is dense. Identity verification is not a five-step listicle, and pretending otherwise would be dishonest. If you are an applicant, read the sections on document capture, liveness, and reverification carefully, because those are the ones that most often cause avoidable rejections. If you are a learner or an employer partner, focus on the sections about what the checks actually prove and where the residual risk sits, because that is where you make sound decisions about who to trust.
The threat model: what identity verification on an EdTech platform must defeat
Before describing controls, it helps to be explicit about the threats. Identity verification is not a general-purpose good, it is a specific defence against specific attacks. On Refonte Learning, we design against seven categories.
First, straightforward impersonation. Someone applies using another person's real name, LinkedIn profile, and CV, hoping to inherit that person's reputation. This is the oldest attack and the easiest to catch, because the impersonator cannot produce the real person's government-issued documents on demand.
Second, synthetic identity. The applicant fabricates a coherent-looking persona: a plausible name, a fake LinkedIn built over months, a stitched-together portfolio, and forged or AI-generated documents. Synthetic identities have exploded since 2023 because large models can now produce convincing headshots, CVs, and even reference letters.
Third, credential borrowing. The applicant is a real person with real ID, but they intend to hand the actual teaching work to someone else, often a cheaper subcontractor in another country, while collecting the money and the reviews. This is not strictly an identity failure at signup, it is an identity failure at delivery, and it is why we reverify at intervals.
Fourth, deepfake video interviews. A candidate passes document checks with genuine stolen ID, then joins the live interview with a real-time face-swap tool. This attack was rare in 2023 and common by 2025.
Fifth, jurisdictional laundering. The applicant is real and identifiable, but they are on a sanctions list, banned from working with minors, or subject to a professional debarment that they have concealed. Identity verification is the enabler for the sanctions and background checks that catch this.
Sixth, session hijack after onboarding. The account is genuinely created by a verified person, then sold or handed off to a third party who uses the good standing to run scams, phishing, or low-quality delivery. This is why device binding and periodic reverification exist.
Seventh, coerced or trafficked identity use. A real person's documents are used with their nominal consent but under duress or exploitation. This is the hardest category to detect, and it is why we combine document checks with independent behavioural signals and human review.
Every control described below maps to one or more of these threats. If a control does not defeat a specific threat, it is theatre and we do not run it.
Stage one: account creation and initial signal collection
The verification funnel begins the moment a prospective instructor creates an account. At this stage we are not yet asking for a passport, we are collecting the signals that will let us decide how aggressively to scrutinise the application later.
We capture the email address and verify it with a one-time code, but the email itself is analysed. Disposable-domain services, freshly registered domains, and addresses that match known fraud patterns are flagged. We check whether the address has appeared in credential-stuffing dumps, not to reject it, but to force stronger downstream authentication if it has.
We capture the device fingerprint using standard browser and mobile SDK signals: user agent, screen dimensions, timezone, language, installed fonts on desktop, sensor data on mobile. We are not trying to uniquely identify the device forever, we are looking for two things. One, whether the device has been used to create other accounts on Refonte recently, which suggests a fraud ring. Two, whether the device's declared timezone and language are consistent with the country the applicant claims to be applying from.
We capture the IP address and enrich it with geolocation, ASN, and known-proxy or known-VPN flags. VPN use is not disqualifying, many legitimate instructors use them, but a VPN combined with other risk signals raises the risk score.
At this stage the applicant provides a stated legal name, a country of residence, a country of citizenship, and a preferred payout jurisdiction. These three geographies must be consistent with each other or the applicant must be able to explain the inconsistency later. A person residing in Germany, holding Indian citizenship, and requesting payout to a Cayman Islands account is not automatically fraudulent, but the combination triggers manual review.
No one is approved or rejected at this stage. The output is a risk score and a routing decision: standard track, enhanced track, or manual-review track. Approximately 78 percent of applicants in 2025 went through standard track. The other 22 percent hit enhanced or manual, most often because of VPN use, mismatched geography, or a device fingerprint already seen on another application.
Stage two: government-issued document capture
The first hard identity check is a government-issued document. We accept passports, national identity cards from countries that issue them, and, in a narrower list of jurisdictions, driving licences. We do not accept utility bills, student cards, or employer badges as primary identity documents, because they are trivially forgeable and not tied to a national identity register.
The capture happens in the browser or mobile app using a guided workflow. The applicant is prompted to photograph the front of the document, then the back if applicable, then, for passports, the machine-readable zone specifically. The workflow enforces framing, focus, and glare checks in real time, so a blurry or partial image is rejected before it is even submitted.
Once the images are captured, they run through several parallel checks. Optical character recognition extracts the name, date of birth, document number, expiry, and issuing authority. The machine-readable zone, if present, is parsed independently and cross-checked against the OCR of the visual zone. A mismatch between MRZ and visual zone is a strong forgery signal, because most forgers update one and forget the other.
Document-specific security features are inspected. Modern passports include holograms, microtext, ultraviolet-reactive inks, and specific font metrics that change between issue years. Our provider maintains a template library covering thousands of document variants, and each captured document is matched against its expected template. A Spanish DNI issued in 2019 has different features from one issued in 2023, and both must match their respective templates, not just any Spanish DNI template.
AI-generated documents are the fastest-growing forgery category. We run a separate model that looks for the artefacts characteristic of generative image models: over-smoothed skin in the portrait, physically implausible lighting, and pixel-level statistical patterns that differ from real camera output. This model is retrained quarterly because generative tools improve constantly.
A document that passes all checks is not yet proof of identity, it is proof that a real document exists. The next stage ties that document to the actual applicant.
Stage three: liveness and biometric binding
A valid document proves a document exists somewhere. It does not prove the person submitting it is the person on it. Binding the two requires a liveness check, and this is where the biggest changes of the last two years have landed.
The applicant records a short video selfie following prompts on screen: turn head left, turn head right, blink, sometimes read a phrase aloud. The video is analysed for three things simultaneously. One, is the face in the video the same face as on the document, measured by standard face-embedding similarity above a calibrated threshold. Two, is the face a live human, not a photograph, screen, mask, or video replay. Three, and this is the newer test, is the face a live human whose video signal is not being intercepted and replaced by a deepfake pipeline.
The third check is the hard one. Naive deepfake detection looks at the pixels of the incoming video and asks whether they show artefacts of face-swap software. Modern face-swap tools are good enough that pixel-level detection alone fails against motivated attackers. The current state of the art, and what Refonte uses, combines several signals: challenge-response prompts that are randomised per session and hard to lip-sync in real time, sensor-level attestation on mobile devices confirming the camera feed came from the actual hardware camera and not a virtual camera driver, and micro-motion analysis of features like pupil dilation and skin blood-flow patterns that current face-swap tools do not yet reproduce reliably.
We combine these signals into a liveness confidence score, and the threshold for passing depends on the risk track from stage one. A standard-track applicant needs a moderately high score. An enhanced-track applicant needs a higher score plus a second liveness check taken at least 24 hours later from a different network. A manual-review applicant is routed to a live human interview in addition to the automated checks.
Biometric data handling is a legal minefield in 2026. Under GDPR, biometric data used for identification is a special category of personal data. Under the EU AI Act, biometric identification systems are high-risk. Illinois BIPA and several other state laws impose their own consent and retention rules. Our policy is that the face template derived from the liveness video is stored only as a one-way embedding, is used only to match against the document photo and against future reverification attempts, is never sold or shared with third parties, and is deleted on request when an account is closed. The raw video is retained for a shorter window for fraud investigation and then destroyed.
Stage four: cross-checks against external identity registers
A document that passes forensic checks and matches a live face is strong evidence, but it is not the end. We then cross-check the identity against external registers.
For sanctions and politically-exposed-person screening, we run the extracted name and date of birth against consolidated lists including the OFAC SDN list, the EU consolidated sanctions list, the UK OFSI list, and UN sanctions. A hit does not automatically disqualify, because common names produce false positives, but a hit routes the application to specialist review. Since Refonte handles payouts across many jurisdictions, sanctions screening is not optional, it is a condition of maintaining our payment processor relationships.
For jurisdictions where they are available, we check government identity registers directly. Some countries expose an API where a document number and holder details can be validated against the issuing authority's database. Where these exist and are legally accessible, we use them, because they defeat forged documents that pass forensic checks by simply not existing in the real register.
For applicants who will work with learners under 18, or who apply to teach in categories where safeguarding matters, we run additional checks against professional debarment registers where applicable. This is a small subset of applicants but a critical one, and it sits alongside our broader policy on what gets you removed from the platform.
Corporate applicants, meaning course providers who apply as a business rather than as an individual, go through a parallel process. The business itself is verified against the relevant company register, the beneficial owners are identified per anti-money-laundering rules, and each beneficial owner above the 25 percent threshold goes through individual identity verification. The company register we cite in our own corporate footprint is the French INPI, where Refonte Infini Infiniment Grand is registered under SIREN 949 841 605, viewable at https://data.inpi.fr/entreprises/949841605, and we expect provider entities to be verifiable to a comparable standard in their own jurisdiction.
Stage five: the human review layer
Automation handles the volume, but every meaningful platform trust decision has a human in the loop somewhere. On Refonte, the human review layer sits at three points in the identity funnel.
The first point is triage of edge cases. Applications that hit enhanced or manual-review tracks in stage one, or that fail any single automated check in stages two through four, are routed to a trust-and-safety reviewer. The reviewer sees the risk signals, the document images, the liveness video, and the external check results, and decides whether to approve, reject, or request additional information. Reviewers work from written criteria, not gut feel, and their decisions are sampled for quality control.
The second point is high-value or high-sensitivity applications. Someone applying to teach in a category with regulatory exposure, such as anything involving healthcare data, financial advice, or minors, gets a video interview with a Refonte staff member regardless of automated scores. The interview is not primarily an identity check, it is a professional-competence check, but it doubles as a final identity confirmation because a deepfake that survives 30 minutes of unstructured conversation with a domain expert is still, as of early 2026, very hard to sustain.
The third point is post-approval monitoring. When a learner or another instructor files a report suggesting that the person delivering work is not the person on the account, the case is reviewed by a human even if all automated signals still look green. The mechanism for these reports is documented in our guide to reporting a concern about a course provider, and it is deliberately low-friction because we want the signal.
Human review is expensive, which is why we do not run it on every applicant. But it is also the layer that catches novel attacks the automated pipeline was not designed for, and it is the layer that lets us apply judgement in the messy cases where the rules do not give a clean answer.
Reverification: identity is not a one-time event
A verification passed in January 2024 does not prove the same person is delivering work in November 2026. Accounts get sold, credentials get borrowed, and people's circumstances change. Refonte therefore treats identity as a continuous state, not a one-time gate.
Routine reverification is triggered on a schedule. Every active instructor completes a lightweight reverification annually: a fresh liveness check matched against the original enrollment biometric, plus confirmation of key profile facts. This catches accounts that have been sold or handed off to a different person, because the new holder will fail the biometric match.
Event-driven reverification is triggered by specific signals. Sudden large increases in earnings, changes to payout details, logins from a country the account has never used before, a spike in negative reviews suggesting delivery quality has dropped, or a report from a learner alleging the person on the call is different from the profile photo. Any of these prompts an immediate reverification challenge, which the account must complete within a set window or lose the ability to accept new bookings.
The key point is that reverification is designed to be low-friction for legitimate holders and expensive for attackers. A legitimate instructor takes 90 seconds to open the app, run a liveness check, and confirm their details. An attacker who has bought the account cannot pass the biometric match at all. This asymmetry is what makes reverification worth running.
Reverification also connects to our employment history verification process, because employment claims that were true at signup may need refreshing as instructors move between roles. Someone who joined Refonte in 2023 as a senior engineer at a major cloud provider and left that role in 2025 needs to update their profile, and we prompt for that update as part of the annual cycle.
What identity verification does not prove
A robust identity check tells you the person on the other end of the account is who they say they are. It does not tell you they are good at the work. It does not tell you they will show up on time. It does not tell you they will not be rude to a learner. It does not tell you their advertised experience is accurate.
Those things are the job of other stages in the vetting funnel: credential verification, skills assessment, references, trial deliveries, and ongoing reputation signals. Identity verification is the necessary foundation for all of them, because none of those signals are meaningful if attached to the wrong person, but it is only the foundation, not the building.
This is worth stating clearly because a common failure mode in trust design is to over-index on identity checks and under-invest in the checks that follow. A platform that verifies passports rigorously but never checks whether the instructor can actually teach is not safer, it just has a more expensive-looking illusion of safety. Refonte's approach is deliberately layered: strong identity verification, then strong credential and skills checks, then strong ongoing monitoring, then strong response when things go wrong.
The mentor informed consent explained piece covers a related layer: even after a mentor is verified and vetted, learners should understand what mentoring is, what it is not, and what the mentor is and is not agreeing to deliver. Consent and verification together, not verification alone, are what make a mentoring relationship safe.
Failure modes and how we handle them
No verification system is perfect. It is worth being explicit about the ways ours can fail and what we do when it does.
False rejections are the most common visible failure. A legitimate applicant fails a check, most often the liveness step, because of poor lighting, an unusual camera, a facial injury, a religious head covering that confuses face detection, or simply a document type the template library does not recognise well. Our policy is that a false rejection must have a human appeal route within 48 hours, and appeal decisions must be documented. False rejection rates are tracked by country, document type, and demographic factors, and we audit for disparate impact.
False acceptances are the more dangerous failure, because they are invisible until something goes wrong downstream. We catch them through several mechanisms: sampled quality control on automated approvals, learner reports, and behavioural anomalies in post-approval monitoring. When we detect a false acceptance, we do not just remove the account, we run a retrospective on how it passed and update the pipeline accordingly.
Deepfake-driven attacks against liveness are the fastest-evolving threat. Our defence is a combination of the technical measures described earlier and a policy of escalating to human video interview whenever automated confidence drops below a moving threshold. As generative tools improve, the threshold moves.
Coerced identity use is the hardest case. A person whose documents are used under duress will often pass every technical check, because the checks are all satisfied by their real presence. Our defences here are indirect: unusual behavioural patterns, payout addresses that do not match the verified identity's known residency, and, most importantly, welfare-focused messaging in the onboarding flow that gives coerced applicants a low-friction way to signal distress. This is imperfect and we do not claim otherwise.
Systemic failures, meaning the verification provider itself has an outage or a bug, are handled by refusing to approve new accounts during the incident rather than falling back to weaker checks. A delay in onboarding is a much smaller harm than admitting an unverified earner to the platform.
Data protection, retention, and applicant rights
Identity verification involves collecting some of the most sensitive personal data a platform ever handles: government documents, biometric templates, sanctions-screening results. How that data is stored, used, and eventually deleted matters as much as how it is collected.
Our policy is built around data minimisation. We collect only what is needed for verification and for the ongoing legal obligations of running the platform. Document images are stored encrypted, accessed only by trust-and-safety staff on a strict need-to-know basis, and retained for the period required by anti-money-laundering rules in the relevant payout jurisdiction, typically five years after the last transaction. Biometric templates are stored separately from documents, in a form from which the original image cannot be reconstructed, and are used only for match operations.
Applicants have specific rights that we surface in the onboarding flow rather than burying in a privacy policy. They can request a copy of their verification file. They can request correction of inaccurate data. They can request deletion of biometric templates on account closure, subject to legal retention requirements on the document data. They can appeal an automated decision to a human reviewer. Under the EU AI Act's transparency requirements, they are told when a decision is made or supported by an automated system.
We do not sell verification data. We do not use it to train models that will be sold or shared outside Refonte. We do share it, under strict contract, with the specialist verification providers whose tools we use, because it is impossible to run OCR or liveness detection without doing so, but those providers are contractually barred from using the data for their own purposes and are audited.
The balance we try to hold is between rigorous verification, which requires collecting sensitive data, and rigorous data protection, which requires collecting as little as possible and holding it as briefly as possible. There is no clean resolution to that tension, only a set of tradeoffs we make explicit and revisit annually.
What this means if you are applying to teach on Refonte
If you are reading this because you want to apply to teach, mentor, tutor, or advise on Refonte, here is the practical summary.
The verification process will take between two hours and three days, depending on which track your application lands in. Most applicants clear it in under 24 hours. Prepare by having a valid, unexpired passport or national identity card ready, and by planning to do the liveness step in good lighting on a device with a working front camera. Do not use a VPN during verification unless you have a specific reason, because it will slow things down without helping you. Answer the geography questions honestly, because inconsistencies are common and forgivable, but concealment is not.
If you are rejected, you have a right to appeal. Read the reason carefully before appealing, because most rejections are for fixable reasons like image quality or document expiry, not for anything sinister. If you are accepted, you will be prompted to complete related steps: credential submission, skills assessment, profile setup, and the various policy acknowledgements including our terms on delivery, on non-circumvention, and on what will get you removed.
Once you are active on the platform, keep your profile current. Update your employment history when it changes. Complete the annual reverification promptly when it is prompted. If your circumstances change in a way that affects your ability to deliver committed work, tell us early rather than late, because the platform is much better at accommodating early notice than at cleaning up after silent failures.
And if you have not yet applied but are considering it, the starting point is the application flow to become an instructor on Refonte Learning. The verification steps described above begin the moment you complete that form. We are, as of 2026, one of the more rigorously vetted teaching marketplaces operating internationally, and that rigour is a feature, not a bureaucratic burden, because it is what makes the reviews, the earnings, and the reputation you build on the platform actually mean something.
About Refonte Learning
Refonte Learning is an EdTech platform offering professional training in AI, data engineering, cloud, DevOps, and software engineering. We operate a marketplace where verified instructors, mentors, and course providers deliver work to learners and to employer partners around the world. Refonte Learning is operated by Refonte Infini Infiniment Grand, a French SAS registered under SIREN 949 841 605, with an operational office at 1 Poulton Close, Dover, Kent, United Kingdom, CT17 0HL. Our approach to trust and safety is built on the principle that a marketplace is only as valuable as the people on it, and that verifying those people properly, then keeping the verification current, is the single most important thing we do.
