Security & Compliance

How AsliVerify authenticates a returned product.

The AsliVerify methodology pairs a brand-issued Reference Library of product fingerprints with a four-frame counter capture and an AI-assisted similarity score — and keeps a human-review fallback on every low-confidence verdict. The output is a tamper-evident audit record that closes the authentication gap most beauty and luxury retailers carry into the counter, and the credibility framework enterprise buyers and brand partners can audit on every return.

The methodology

Three pieces, each one a credibility lever.

The Reference Library is the source of truth — the four-frame capture is the input — and the AI matcher plus the manager-review fallback are the loop that resolves every low-confidence verdict before it lands. Each piece is auditable in its own right.

A stored Reference Library of brand-issued fingerprints.

Every enrolled SKU has a brand-side fingerprint published at intake, anchored to the SKU code, a baseline photo, and a metadata hash. The fingerprint stays put — counter capture is compared against it; the Reference Library never leaves the tenant.

Multi-photo customer submissions at the counter.

The shopper contributes a four-frame capture at the return desk on the associate’s rescan device. Front, side, batch code, and tamper seal are all in the submission, so the matching logic has independent angles to score against — not just the single shot most retailers stop at.

AI-assisted matching with human-review fallback.

A similarity score runs the four frames through the Reference Library and emits one of three verdicts — auto-pass, auto-flag, or escalate to the on-shift manager. The manager queue catches the cases the model is uncertain on, so a low-confidence score becomes a review, not a wrongful pass or a wrongful return refusal.

Authentication loop

The six steps, every return.

Each return submission moves through the same six steps — capture, brand lookup, similarity scoring, verdict, manager review where needed, and the audit-record close. The loop is small on purpose, and the audit record is the only output that survives.

01

Four-frame capture

Front + side + batch code + seal — every return submission lands as a four-shot set, taken on the rescan device before the counter decision.

02

Brand lookup

The Reference Library resolves the SKU to its brand-issued fingerprint and rule set. Resolver is per-tenant; cross-tenant lookup is impossible by construction.

03

Similarity scoring

Each of the four frames is scored against the fingerprint, and the per-frame confidences are combined into one verdict. The threshold is set per brand, per SKU cohort.

04

Verdict — pass, flag, or escalate

A clean score passes, a failing score flags, and a borderline score escalates. Manager review is the fallback, never bypassed.

05

Manager review on the off-ramp

Escalated verdicts land in the manager queue with the four frames, the per-frame confidence, and the reasons flagged. Reviewers decide pass / decline / escalate-to-finance.

06

Audit record closes the loop

The verdict, the manager ID, the timestamp, and the geo are sealed into the audit record before the next return enters the pipeline — chargeback-defense ready on day one.

What this means in practice

For enterprise buyers evaluating the platform.

The Reference Library is the credibility lever LP and finance teams care about most — the same fingerprint can be re-queried on every return and on every chargeback representment, anywhere in the world. Brand partners get a methodology they can audit on day one of the pilot, and an audit record they can defend on day ninety.

Compliance posture

The compliance & audit-trail shape.

The audit record on every verified return is the spine that the compliance posture sits on — independent of whether the team is on the PIPEDA, GDPR, or SOC 2 line.

PIPEDA-aligned data handling

Canadian-founded; data lives in tenant-isolated stores, retention is rule-based per brand and per SKU cohort, and every access is logged. The full posture is in the Privacy Policy.

GDPR-ready for European brand partners

Sub-processor list and Standard Contractual Clauses available on request; data-residency configuration is a per-tenant setting audited at provisioning time.

SOC 2 Type II audit scheduled Q4 2026

Trust Services Criteria selection is locked; the report will be released under NDA to enterprise customers once finalized. The architecture, access-control, and logging controls are already in place at the level the audit verifies.

Enterprise buyers and brand partners — talk to the team about the Reference Library, the audit record, and how a 6-week pilot plugs into the compliance posture your security review needs.

Or read the methodology end-to-end on /how-it-works.