How it works

Enroll once. Prove every transaction.

Nulliti binds a cardholder's biometric identity to their payment card at the moment of enrollment. Every transaction that follows carries irrefutable, timestamped proof that the actual cardholder authorized it - by the right person, on the right device, at the right moment.

A checkout completing after a biometric confirmation Enroll, Bind, Prove

The flow

Enroll, Bind, Prove

A thin proof layer that sits on top of the payment you already run - recording provable, biometric-bound consent for every transaction.

  1. The first time a cardholder checks out at a Nulliti-connected merchant, they enter their card details and confirm their identity with a single biometric - a glance at their phone or a fingerprint. That one action creates a device-bound passkey. Nothing biometric ever leaves the device.

  2. Nulliti cryptographically binds that passkey to the card, establishing a permanent, portable identity anchor. From that point forward, no card entry is required at any Nulliti merchant - the credential travels with the cardholder across the entire network.

  3. At checkout, one tap generates a signed proof of intent - a timestamped, biometrically validated cryptogram bound to the cardholder, the registered device, and the exact transaction scope. It is attached to the transaction and available if a dispute is ever raised.

Step 1 - Enrollment

A device-bound passkey, one biometric confirmation

Enrollment is simple and happens once. A single biometric confirmation creates a permanent, cryptographically secured link between the cardholder and their card. The passkey lives in the device's secure hardware - and nothing biometric ever leaves the device.

Nulliti's architecture also supports an optional issuer-side identity check at enrollment. Where an issuer participates, that check is invisible to the consumer and adds a bank-validated identity link that strengthens every subsequent authorization record.

  • One biometric - a glance or a fingerprint - creates the passkey.
  • Nothing biometric ever leaves the device.
  • Card details are entered once; the credential then travels automatically.
  • Optional issuer identity challenge adds a bank-validated identity link.

Step 2 - Binding

The passkey becomes a portable identity anchor

Nulliti cryptographically binds the passkey to the card. That binding is the difference between a wallet that merely unlocks a phone and a credential that ties the card and the person together. Once bound, the identity anchor is portable: a single enrollment covers every merchant in the Nulliti network, and every purchase re-proves the binding upstream to the issuer and the network.

  • Card and person are cryptographically tied - not just co-located on a device.
  • One enrollment covers every Nulliti merchant.
  • Works online exactly as it does in-store.
  • Any card, any device, any OS, with any token provider.

Step 3 - Per-transaction proof

One tap - a signed proof of intent

At checkout, a single tap generates a signed cryptogram: timestamped, biometrically validated, and bound to the cardholder, the registered device, and the exact transaction or authorization scope. The proof is attached to the transaction and available if a dispute is ever raised. When a customer says "wasn't me," the merchant holds cryptographic evidence that the real, bound cardholder authorized it.

For recurring billing, a single enrollment at signup produces an authorization record that covers every future renewal - no re-authentication per cycle, no added friction, and one record that defeats disputes across months of charges.

  • Timestamped, biometrically validated cryptogram per transaction.
  • Bound to cardholder, device, and exact transaction scope.
  • Attached to the transaction and available for representment.
  • Covers recurring renewals from a single enrollment.

Privacy by design

The biometric never leaves the device

Nulliti proves who authorized a payment without ever moving a biometric off the cardholder's phone. The biometric confirmation happens on-device and stays there; what travels is a cryptographic proof, not a fingerprint or a face. Actual card data is handled exclusively by the token provider and never stored in the merchant's environment - so there is nothing to steal and PCI DSS scope is substantially reduced.

The technology

A patented biometric security engine

Nulliti's biometric security engine is covered by U.S. Patent No. 12,499,444 B1, granted December 2025. It makes every card transaction provably authorized - by the right person, on the right device, at the right moment - and that single capability flows into lower fraud losses, fewer chargebacks, better approval rates, and a smoother cardholder experience across the entire payments ecosystem.

The same portable proof extends naturally to AI and agentic commerce, where a signed record ties an agent-initiated purchase back to a real, enrolled human who consented.

  • U.S. Patent No. 12,499,444 B1 - granted December 2025.
  • Additive to the existing payment stack - not a wallet, not tokenization.
  • Consumer-to-environment binding at the core.
  • Provable human consent for agent-initiated purchases.

See the AI / agentic commerce use case →