ProntoDeliver wraps every file in a biometric gate. The recipient passes a live ID check and liveness scan before the download key is ever generated — encrypted at rest, decrypted by identity.
Sensitive files are still being delivered like brochures. A forwarded link, a leaked password, a shared inbox — and the chain of custody is gone.
A magic link, signed URL, or password-protected ZIP is a bearer token. Whoever holds it gets the file. Forwarded once, screenshotted once, intercepted once — and your sensitive document is in the wrong hands with no audit trail.
You can prove the link was clicked. You cannot prove the right human clicked it. For contracts, medical records, financial statements, or age-restricted content, that gap is the whole problem.
GDPR Article 32, HIPAA, bar association rules, 18 U.S.C. § 2257 — every framework now expects more than a password. When the file is sensitive, the sender carries the burden of proving the right person received it.
Send a file, define who can open it, and let ProntoDeliver handle everything in between — from encryption to identity verification to the final decrypted byte.
create-delivery. ProntoDeliver generates a per-file encryption key via KMS, encrypts the payload, and stores the ciphertext in S3 with SSE-KMS.prontoid-deliver-rules as data — no code changes to add a new constraint.secure.prontoid.com. The link reveals the filename, size, and what verification is required — never the file contents.RecipientToken, and the rules engine confirms every condition. Fail = audit log + rejection. Pass = decryption key released.Every delivery is identity-gated. The difference is how tightly you bind the file to a specific person.
Bind the file to a named recipient. The sender provides the recipient's legal name and optionally email; the rules engine confirms the verified ID matches before the decryption key is released. Forwarding the link to someone else doesn't work — their face doesn't open it.
Anyone can claim the file — if they prove who they are and meet the attribute thresholds. Perfect for age-gated digital goods, age-restricted research data, or public bounty distributions where you don't know recipients up front but still need a real identity attestation.
Every component of ProntoDeliver is designed so that a compromised link, a stolen account, or a forwarded email is not enough to access the file.
Each file is encrypted with its own KMS-generated data encryption key. The DEK is wrapped under your tenant master key and stored in DynamoDB — never in the URL, never in a cookie, never reusable across files.
The recipient’s verification session is bound to the FileID at completion. The same attestation cannot unlock a different file, and the download Lambda re-validates the binding on every request.
When the gate opens, the download Lambda issues a single-use, 60-second pre-signed S3 URL. Even if it leaks, it’s dead by the time anyone else sees it — and the DownloadCount has already incremented.
For PDFs and images, the recipient’s verified legal name and timestamp can be burned into the file at decryption time — a permanent, per-recipient watermark that survives screenshots, prints, and re-encoding.
Set expires_at per file. S3 lifecycle rules permanently delete the ciphertext on expiry — the file ceases to exist on disk, not just behind a closed link.
Every claim attempt, verification result, rule evaluation, and download is written to prontoid-deliver-audit with timestamp, IP, user agent, and the SHA-256 attestation hash. Auditable end-to-end.
Any document where “the right person got it” is more important than “the link was clicked”.
Deliver privileged documents, settlement drafts, and confidential briefs to verified clients. Bar association rules in many jurisdictions require identity confirmation for privileged material.
Send offer letters, contracts, and onboarding documents to verified candidates. Eliminate the risk of leaked compensation data or accepted offers from imposters.
Deliver test results, claim documents, and policy paperwork with HIPAA-aligned recipient verification. The patient or policyholder is who they say they are, every time.
Deliver downloadable digital goods only to recipients who have passed age verification + liveness. Built-in support for the UK Online Safety Act, EU age assurance, and US state laws.
Send financial statements, term sheets, and data room documents to identity-verified counterparties. Replace bespoke virtual data rooms for single-file delivery use cases.
Invert the model: the journalist publishes a claim link, sources verify their identity before submitting documents back. A verified channel for sensitive uploads, not just downloads.
"We used to send NDAs over email and pray. With ProntoDeliver, the recipient’s face is the key — we can prove who opened the document, when, and from where. It changed how our compliance team thinks about delivery."
"For age-gated content, ‘click here to confirm you are 18’ isn’t compliance — it’s theatre. ProntoDeliver bolted real biometric age assurance onto our delivery pipeline in a week."
"The single-use 60-second signed URL was the convincer. Even if a sophisticated attacker intercepts the link, the file is already on disk for the verified recipient and the URL is dead."
Everything you need to know about ProntoDeliver. Can't find the answer? Contact us.
prontoid-deliver-audit with the failure reason (document rejected, liveness failed, name mismatch, age below threshold, etc.). The decryption key is never released. The recipient can retry with a new verification session, but the failed attempt is permanently auditable.max_recipients cap, each producing their own attestation record. Single-use mode locks the file to the first successful claimant.expires_at via S3 lifecycle rules — the file ceases to exist, not just becomes inaccessible.revoke-delivery at any time before the recipient has downloaded. This sets the file status to revoked and the next claim attempt is rejected at the rules-engine layer. Already-completed downloads cannot be unsent — once the bytes are on the recipient’s device, they’re out of our reach. Watermarking is the recommended deterrent for post-delivery leaks.The identity verification layer that powers ProntoDeliver. Document capture, biometric liveness, and age verification in a single API call.
Learn MoreCryptographic document delivery for certified ledger use cases. Where ProntoDeliver gates the recipient, ProntoVault anchors the document itself.
Learn MoreIdentity-verified digital contracts for any document type — NDAs, service agreements, partnership deeds — with the same KYC anchor as ProntoDeliver.
Learn MoreProntoDeliver is available to platforms on the ProntoID enterprise plan. Contact us to discuss your use case and onboard your first verified delivery.
Brooks & Keitt Sàrl · Place du Midi 30, 1950 Sion, Switzerland · Data Processor