Security Features Check (SSF)

A security features check examines the physical and optical protections built into an identity document to establish that the document is genuine. Sometimes abbreviated SSF, it is the difference between reading a document and authenticating one — and it is the check that a well-made counterfeit is designed to defeat.

Purpose Establish that the document itself is genuine, not merely legible
Level 1 features Visible to the unaided eye — holograms, guilloche patterns, color-shifting ink, tactile printing
Level 2 features Require a tool — UV fluorescence, infrared response, microprinting
Level 3 features Forensic — verifiable only in a laboratory, and deliberately undocumented
Remote capture limit A phone camera sees Level 1 only; there is no UV or IR source
The substitute at distance Reading and validating the document’s chip, where one exists
Complementary check Cross-referencing printed fields against encoded data
What it does not establish Who is holding the document

The three levels, and what a phone can actually see

Document security is conventionally organized into three levels by the inspection each requires. The distinction is not academic — it determines what is verifiable in a given setting.

Level Examples Inspectable by
Level 1 — overt Holograms and kinegrams, guilloche line work, color-shifting ink, tactile embossing, laser-engraved portraits The unaided eye, and a camera
Level 2 — covert UV fluorescent inks, infrared-responsive elements, microprinting, retroreflective overlays A device with a UV or IR source and magnification
Level 3 — forensic Chemical taggants and features known only to the issuer and specialist labs A laboratory

Here is the constraint that shapes every remote verification product, stated plainly: a consumer phone has no ultraviolet source and no infrared source. It can observe Level 1 features, sometimes well, and Level 2 features not at all. Border control desks and bank branches use purpose-built readers precisely because those sources are needed.

The honest consequence is that remote document checks are working with a subset of the available evidence — and that the subset is the one counterfeiters concentrate on defeating, because it is the one most often inspected.

What remote checks do instead

Two things compensate, and they are stronger than they first appear.

Level 1 analysis is harder to fake than it looks. Optically variable features behave differently across frames as the document moves under a camera — a hologram shifts, a kinegram animates, laser engraving catches light at particular angles. A printed or screen-displayed copy does not reproduce that behavior, so capturing motion rather than a still image recovers real signal.

Cross-referencing encoded data catches the common attacks. A document encodes the same information in several places: printed fields, the machine-readable zone, a barcode, and on modern documents a chip. Altering printed text without regenerating every encoding produces a contradiction, and that check needs no special hardware.

Where a chip is present it changes the picture entirely. The data on a passport chip is signed by the issuing authority, and a signature cannot be forged without the issuer’s private key. That is stronger evidence than any optical inspection, and it is why chip reading matters more than any incremental improvement in image analysis. See digital certificates for how that chain is verified.

Why this matters for identity verification

The distinction this page turns on is the one most verification processes blur: extracting a document’s data and establishing that the document is real are different operations. A system that reads a name, number and date of birth from an image has performed data extraction. It has not checked anything.

That gap is exactly where digital tampering lives. An edited image of a genuine document extracts perfectly — the fields are legible and internally plausible — and fails a security features check, because the alteration disturbs the printing it sits on and leaves the encoded data unchanged.

The limit worth keeping in view is that a genuine, fully authenticated document proves a document exists and is real. It proves nothing about who is holding it, which is why identity document verification pairs this check with a biometric comparison and identity verification treats the two as one step rather than two.

What a security features check can’t do

It cannot see Level 2 features remotely. No consumer device emits ultraviolet or infrared, so those features are unavailable outside a controlled setting with a purpose-built reader.

It cannot establish the holder. A genuine document in the wrong hands passes every document check there is.

Coverage is per document type. Features differ by country, document class and issuance year, and a system can only check features it has been built to know about.

It is adversarial. Counterfeiters concentrate on the features most commonly inspected, so the gap between a check’s coverage and an attacker’s effort narrows continuously.

Frequently asked questions

What is an SSF or security features check?

An examination of the physical and optical protections built into an identity document — holograms, guilloche patterns, color-shifting ink, microprinting, ultraviolet elements — to establish that the document is genuine rather than merely readable.

Can security features be checked from a phone photo?

Level 1 features can, since they are visible to the unaided eye, and capturing motion rather than a single frame reveals how optically variable elements behave. Level 2 features cannot, because no consumer phone emits ultraviolet or infrared light. Remote checks compensate by cross-referencing the printed fields against encoded data and, where present, reading the document’s chip.

What is the difference between a security features check and data extraction?

Data extraction reads the information from a document. A security features check establishes that the document is genuine. A tampered image of a real document extracts perfectly and fails the security check, which is why a process performing only extraction has verified nothing about the document.

Is reading the chip better than checking security features?

Where a chip exists, yes. Chip data is signed by the issuing authority and the signature cannot be forged without the issuer’s private key, which is stronger evidence than any optical inspection. Security features remain essential for the large population of documents that carry no chip.

Related reading

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data