Technical Documentation

System Architecture & Platform Documentation

Last updated October 2026

Dokimos ID is an enterprise B2B identity verification platform engineered specifically for remote recruitment and hiring workflows. The platform enforces cryptographic meeting gating by withholding video conference join links until candidates verify their government-issued identity, complemented by automated in-meeting live identity verification and audit trail reporting.

1. System Architecture & Cloud Stack

Dokimos ID is architected as a distributed, high-security monorepo pairing a modern Next.js edge-ready frontend with an event-driven Convex reactive backend and enterprise third-party infrastructure:

  • Next.js 15: Next.js 15 (App Router on Vercel): Hosts the marketing surfaces, multi-language internationalization (English and Spanish), recruiter web dashboard, candidate verification portals, and secure API webhook ingress handlers.
  • Convex Cloud: Convex Reactive Cloud: Manages application state, document relational modeling, tenant isolation, ACID mutations, real-time subscriptions, and background cron schedules with zero operational overhead.
  • Clerk B2B: Clerk B2B Authentication: Provides enterprise authentication, multi-tenant organization membership synchronization, session management, and role mapping, synchronized with Convex via webhook events.
  • Veriff: Veriff Identity Verification: Performs automated global government ID validation (passports, driver licenses, national IDs from 190+ countries) and AI-driven facial liveness checks.
  • Recall.ai & AWS Rekognition: Recall.ai & AWS Rekognition: Orchestrates video meeting bots that join scheduled interviews, captures meeting frames via dedicated AWS Lambda functions, and performs facial comparison against the verified identity reference.
  • AWS Key Management Service (KMS): AWS Key Management Service (KMS): Direct symmetric encryption in eu-north-1 for all meeting join links and platform OAuth tokens, binding each secret to organization- and interview-specific encryption contexts.
  • Resend: Resend: Transactional candidate invitation delivery, reminder notifications, and delivery lifecycle tracking via webhook telemetry.
  • Stripe Billing: Stripe Billing: Multi-tier subscription billing (Starter, Growth, Pro) combined with metered usage billing per verified interview.

2. End-to-End Verification Lifecycle

The core verification flow protects hiring teams against candidate impersonation through a rigorous five-stage pipeline:

  1. Stage 1 — Scheduling & Gating: The recruiter schedules an interview via Zoom, Microsoft Teams, or custom URL. Dokimos ID encrypts the actual meeting join link with AWS KMS and withholds it from all public queries.
  2. Stage 2 — Invitation & Verification Token: Dokimos ID generates a secure, one-time candidate verification token and dispatches an invitation email via Resend containing the verification portal link.
  3. Stage 3 — Government ID & Liveness Check: The candidate opens the mobile-responsive verification portal, grants consent, and completes automated photo ID capture and biometric liveness verification powered by Veriff.
  4. Stage 4 — Just-in-Time Join Link Release: Upon receiving an approved verification webhook from Veriff, Dokimos ID unlocks the interview. The candidate accesses the waiting room and the AWS KMS-encrypted join link is decrypted just-in-time for the candidate to enter the call.
  5. Stage 5 — In-Meeting Live Check & Audit Trail: If configured, a Recall.ai bot enters the meeting room, captures candidate video frames via AWS Lambda, and AWS Rekognition compares facial vectors against the verified ID. A tamper-evident PDF audit report is generated and archived for recruiter review.

3. Video Platform Integrations

Dokimos ID integrates seamlessly with major enterprise video platforms through standardized adapter interfaces:

  • Zoom Integration: Connects via Zoom OAuth 2.0 with per-tenant token encryption. Automatically creates meetings via Zoom API, extracts and withholds join URLs, and enables automated bot entry.
  • Microsoft Teams Integration: Authenticates via Microsoft Entra ID with Microsoft Graph online meeting provisioning. Includes a native Microsoft Teams app manifest for in-meeting panel and tab access.
  • Custom Video Links: Supports Google Meet, Cisco Webex, and custom interview URLs, applying the identical KMS join-link withholding and verification gating mechanism.

4. Multi-Tenancy & Access Control

Multi-tenancy is enforced at the database layer in Convex. Every data operation requires verified tenant context, preventing cross-tenant leakage. Roles are mapped across three tiers:

  • Admin: Organization Admin: Full administrative privileges, including member invites, role updates, billing and Stripe customer portal management, retention policy adjustments, and Data Subject Access Request (DSAR) compliance tools.
  • Recruiter: Recruiter: Standard operational privileges, including scheduling interviews, sending candidate verification requests, reviewing verification statuses, and downloading live-check audit reports.
  • Viewer: Viewer: Read-only access to view scheduled interviews, verification outcomes, and audit histories without modification rights.

5. Cryptography, Biometrics & Security Posture

Dokimos ID adheres to strict security, privacy, and data protection standards designed for enterprise compliance:

  • KMS Cryptography: Direct AWS KMS Cryptography: Meeting join URLs and OAuth tokens are protected using direct AWS KMS Encrypt and Decrypt calls with tenant-specific encryption contexts. Plaintext secrets are never stored in the database or server memory.
  • Biometric Privacy: Zero Biometric Persistence: Dokimos ID never retains raw biometric templates. Recall video recordings and extracted frames are purged immediately post-comparison using the Recall media deletion API.
  • Automated Retention: Automated Retention Sweeps: Scheduled daily maintenance crons systematically purge expired verification artifacts, webhook logs, and audit reports according to organization retention policies.
  • DSAR & Compliance: GDPR & CCPA Compliance: Built-in Data Subject Request (DSR) workflows allow organization administrators to execute immediate candidate data exports or cryptographic erasures.

6. Inbound Webhook Infrastructure

Dokimos ID processes inbound events through dedicated webhook ingress endpoints, each authenticated with independent cryptographic signatures and recorded in an idempotent event registry:

  • Clerk Ingress (/api/webhooks/clerk): Verified via Svix HMAC signatures; synchronizes user profiles, organizations, and team memberships.
  • Veriff Ingress (/api/webhooks/veriff): Authenticated via Veriff HMAC SHA-256 signatures; receives real-time identity session status and decision payloads.
  • Stripe Ingress (/api/webhooks/stripe): Authenticated via Stripe webhook signatures; tracks subscription upgrades, downgrades, renewals, and invoice payments.
  • Recall Ingress (/api/webhooks/recall): Verified via Svix HMAC signatures; triggers frame extraction and face matching upon bot meeting ingress.
  • Resend Ingress (/api/webhooks/resend): Verified via Svix HMAC signatures; monitors email delivery confirmations, bounces, and recipient complaints.

7. Automated Background Jobs & Maintenance

A scheduled suite of automated cron jobs runs continuously in Convex to ensure high availability, regulatory compliance, and system integrity:

  • Artifact & Data Purge (Daily 03:00 UTC): Systematically sweeps and purges expired Veriff and Recall media artifacts based on configured retention schedules.
  • Report Retention Sweep (Daily 04:30 UTC): Deletes live-check audit reports and stored PDFs that exceed the 90-day retention window.
  • Hourly Reconciliations: Automatically reconciles pending live-checks, dispatches scheduled candidate verification reminders, auto-completes concluded interviews, and reconciles Stripe metered usage.

8. Enterprise Support & Contact

For enterprise technical inquiries, security whitepapers, custom integrations, or compliance audits, contact our engineering and support team at: support@dokimosid.com

System Architecture & Platform Documentation | Dokimos ID