Frequently Asked Questions for Businesses
Understanding Humanmark
What does Humanmark do?
Humanmark provides cryptographic verification of human intent. We use hardware security mechanisms to confirm that a request comes from a human. Not identity, not behavior, just human presence.
How is this different from existing solutions?
CAPTCHAs are IQ tests that sophisticated automation passes better than humans. Behavioral analysis can be tricked by AI. Risk scoring creates false positives that frustrate real users. These tools now measure automation quality, not humanity. Humanmark measures human presence through hardware attestation of user presence.
Why do we need this?
Because existing verification is failing. AI solves puzzles faster than humans. Behavioral patterns can be perfectly mimicked. Every defensive measure becomes training data for better automation. You need infrastructure that actually differentiates humans from automation.
Technical Architecture
How does it work?
Three layers of proven security:
1. **Platform Attestation** - Verifies genuine devices
2. **Hardware Security** - Enforces user-present authentication
3. **Cryptographic Verification** - Unique proofs that can't be replayed
Result: Verification of human presence, delivered as a simple API response.
What makes this reliable?
- Secure processing that can't be simulated
- OS-level integrity checks reject compromised devices
- Hardware-enforced user-presence requirements
- Cryptographic proofs, not patterns to mimic
Automation fails at the hardware layer: the one thing that can't be faked in software.
How do you ensure privacy?
Stateless architecture. Nothing persists between verifications. Each request is processed in isolation and all data is immediately discarded. No databases, no logs, no correlation possible.
What's the false positive rate?
Hardware security is binary. The signature is either valid or not. No probabilistic scoring that degrades over time. No machine learning that can be gamed. Just cryptographic certainty.
Implementation
What about user experience?
Users verify with the same gesture they use dozens of times daily when unlocking their phone. Faster than CAPTCHAs, less frustrating than behavioral tracking, more intuitive than SMS codes.
Do users need an app?
Yes, the free Humanmark app. It's a lightweight bridge to their device's security hardware. No accounts, no sign-up, no data collection. Once installed, verification is seamless across all sites using Humanmark.
What about users without smartphones?
Humanmark requires modern devices with security hardware. This covers 95%+ of users in most markets. You'll need alternative flows for the remainder, but you'll know with certainty which users are verified humans.
Privacy & Compliance
What data do you see about our users?
We process cryptographic proofs, not personal data. Our stateless system discards everything immediately after verification. No profiles, no history, no possibility of correlation. Your users remain anonymous to us.
How does this help with compliance?
No data retention means no compliance burden. Nothing to delete under GDPR, no profiles to export under CCPA, no data subject requests to handle. Privacy through architecture.
Business Value
What's the ROI?
**E-commerce**: Happy (actually human) customers, reduced fraud
**Content**: Protection from AI scrapers
**Social**: Authentic human-generated content
**Marketplaces**: Verified humanity behind every listing
The value compounds: less fraud, lower moderation costs, higher user trust.
How does pricing work?
Free tier up to 2,000 successful verifications per month. Paid tiers above that each come with an increasing monthly allotment of verifications and a lower per-verification overage price.
What about global users?
Humanmark works wherever smartphones exist. No geographic restrictions. Same verification quality worldwide.
How do you handle support?
24/7 system monitoring, technical integration support, and user resources. Most users never need help because the experience is intuitive.
Strategic Considerations
Why trust a new solution?
We're not inventing new primitives, we're applying proven hardware security in a focused way. The same mechanisms that banks trust for payments, we use for human verification. Novel application, proven foundation.
What if platforms change?
We use standard APIs that underpin critical features across millions of app installations. These APIs are designed for stability. We monitor changes and adapt as needed.
How does this fit our security stack?
Humanmark complements existing solutions. Use it when human intent matters:
- High-value transactions
- Content creation
- Account creation
- Rate limiting
It's a new signal: confirmed human presence, to enhance your decision-making.
What's your long-term vision?
Human verification as internet infrastructure. As fundamental as SSL for encryption or DNS for routing. In a world where AI is indistinguishable from humans online, knowing what's human becomes essential infrastructure.
Technical Deep Dive
How do you prevent replay attacks?
Each verification includes a unique challenge. Timestamps embedded in hardware-signed data. Old proofs are cryptographically invalid.
What about emulators?
Platform attestation specifically detects and rejects emulated environments. Virtual devices fail at the first check.
How is this different from WebAuthn?
WebAuthn verifies identity (who you are). Humanmark verifies humanity (what you are). Similar hardware, different purpose. Use both: WebAuthn for login, Humanmark for human verification.
What cryptographic standards?
Industry standards throughout: ECDSA signatures, SHA-256 hashing, platform-native attestation. Proven primitives, novel application.
Ready to Start?
Join forward-thinking companies building for a human-first future.
Humanmark is currently in beta.
To get started, email us at sales@humanmark.io and we'll help you integrate Humanmark into your application.