Back to case studies // authentication

Maison Loyalty Verification

A luxury maison protected its high-tier loyalty program with biometric identity verification at enrollment and step-up at redemption, stopping account takeover of accounts holding significant stored value.

April 8, 2025 · Veripass
Maison Loyalty Verification

The maison’s invitation-only loyalty program was a genuine asset: top-tier members accrued substantial stored value, exclusive allocations, and private-event access. That value made the accounts a target. Fraudsters attempted takeovers to drain points and hijack allocations, and weak enrollment let bad actors register under stolen identities to claim member benefits they were never entitled to.

The maison wanted to be certain that a member is who they claim to be — at enrollment and again at the moments that matter — without burdening genuine members at every interaction.

The challenge

Loyalty accounts sit in an awkward middle ground: they hold real value like a financial account, but members expect them to feel effortless like a brand experience. Lock them down with constant friction and members disengage; leave them open and they get drained.

Password-only protection was failing on both fronts. It let imposters enroll under unverified identities, and it gave members no real defense against takeover when credentials leaked. The maison needed assurance proportional to the stakes — strong where value moved, invisible everywhere else.

What Veripass deployed

Veripass anchored the program in verified identity. At enrollment, prospective members completed biometric verification — face matched against an ID document — so each account was bound to a real, proven identity rather than a self-asserted one. That single check closed off enrollment under stolen or fabricated identities.

At runtime, access stayed frictionless for routine activity but escalated by context. Browsing benefits proceeded on a standard session; redeeming significant stored value, changing payout details, or claiming a high-value allocation triggered a step-up — adaptive MFA over phone TOTP, or a biometric re-check — before the action completed.

  • Biometric identity verification (face and ID document) at enrollment
  • Context-aware, policy-based step-up at redemption and high-value actions
  • Adaptive MFA over email and phone TOTP
  • RBAC via claims, capabilities, roles, and access profiles for member tiers
  • Immutable audit trail over enrollment and every redemption

Member tiers and entitlements were modeled through layered claims, capabilities, roles, and access profiles, so benefits resolved automatically from a member’s verified standing. Every enrollment and every redemption was written to an immutable audit trail, giving the maison a defensible record when a member or investigator questioned an action.

Outcome

Enrollment fraud collapsed once identity had to be proven biometrically rather than asserted. Account-takeover attempts that previously drained points hit a step-up wall at the redemption stage and failed. Genuine members felt almost none of it — verification concentrated at enrollment and high-value moments, leaving everyday browsing untouched.

The maison protected the stored value and exclusivity that made the program worth belonging to, turning loyalty from a soft target into a verified, audit-backed membership.

More deployments

Campus-Wide Student SSO

Campus-Wide Student SSO

A university gave every student one login for the entire campus stack by federating Google Workspace and the student directory through Veripass, ending the credential sprawl across portals and services.

Clinician EHR Single Sign-On

Clinician EHR Single Sign-On

A hospital network gave clinicians one federated sign-on across the EHR and clinical applications, cutting repeated logins at the bedside while keeping every access policy-governed and audited.

Fingerprint Turnstile Entry

Fingerprint Turnstile Entry

A manufacturing site replaced badge tailgating at its turnstiles with fingerprint biometric verification bound to identity, so every entry proved the person was physically present and authorized.