Why Can’t Escort Directories Age Verify via Third Party Double Blind ID check?

two-guards-riddle
Author:
theoz
Published:
July 25, 2026
Categories

I made a post on the /r/sexworkers subreddit asking this question “Why Can’t Escort Directories Age Verify via Third Party Double Blind ID check?” and tagged the representatives of Tryst, Megapersonals, Skip the Games, Ivy Societe and Ur Little Secret, 5 of the biggest escort directories, and they all responded.

Here is our conversation.

Dear u/Tryst_Support, u/MacyWeir, u/TrystMaya, u/ChrisAtTryst, u/MegaPersonals_REAL, u/elsa_at_stg, u/BlaireHunter_ , u/Riley_Ivy_Societe and u/urlittlesecret_com,

Can you please let me know whether it would be possible for you to age verify sex workers verifying for your platforms via some kind of double blind third party ID check?

I’m trying to think of an alternative to us needing to give you our identity documents since as we all know, escort directories have a history of getting hacked and raided.

Also, no offense, but the escort directory business model shall we say “operates in a legally precarious environment” . If you are listing sex workers on your platform in jurisdictions where sex work is illegal, then you are a target for law enforcement. Escort directories have gotten raided before and it will happen again.

The real ownership of escort directories tends to be highly secretive eg real owners hidden behind shell companies, offshore banking and company registration in countries well known for facilitating illegal businesses to operate anonymously.

If we don’t know who really owns your platform, it does not inspire a lot of confidence that you will protect our identities if you do get raided, or sent a subpoena, or offered a deal involving doxxing us to protect yourself.

I would feel a lot more comfortable showing my identity documents and selfies to a legit, out in the open, legal company that exists for the purpose of age checks. They just send you an encrypted token saying “yes, this person is over 18.” Done. That way you don’t need to see, or store my ID or face pictures. Just keep the encrypted token as a record to say you’ve age verified me.

for example=

Third-party age-check providers

Sites can use services like Yoti, AgeGO, Veriff, Persona, etc. The site gets a result like “over 18: yes/no” rather than the ID itself. UK government guidance explicitly says many third-party tools can answer whether someone is over 18 without sharing extra identity data. https://www.gov.uk/government/news/keeping-children-safe-online-changes-to-the-online-safety-act-explained

Digital wallet / verified credential model

The EU Digital Identity Wallet age-verification model is very close to my idea: prove “over 18” without revealing full DOB or identity, using selective disclosure.

Anonymous/interoperable age tokens

The Age Verification Providers Association describes systems where a site requests proof, the wallet/user shares an anonymous signed token, and the site verifies it came from a trusted issuer.

Zero-knowledge proof versions

Newer EU-style designs use cryptography to prove one fact, like “this user is over 18”, without revealing name, DOB, ID number, or issuer reference.

the ideal version would be:

Escort Directory → sends user a one-time random token tied to their profile internally.

Me → takes token to approved age-verification platform.

Age-verification platform → checks ID/age and returns signed “over 18” proof for that token. Doesn’t even need to know what I’m verifying for.

Escort Directory → verifies receipt of token and marks profile age-verified, without seeing ID.

With facial recognition tech being the way it is now and considering what it might be like in years to come, being face out as a sex worker is going to be like walking around with a neon sign on our head saying “sex worker”.

Everyone within camera zoom range with a handheld device, or ring doorbell, or drone, or access to cctv, or wearing meta glasses or with a lens built into our optic nerve feeding data directly into our brain, can match our face with every face pic we’ve ever uploaded.

Face in is the future of sex worker advertising. If an escort directory is the first one to find a way to age verify us and verify we’re using our own face in body pics in the ad without needing to view or store face out selfies or ID docs (ie using one of the methods above maybe plus a face in video selfie to verify body pics), that directory will become the go to that everyone uses.

Megapersonals

Hi this is Titania in the management team at MegaP. MegaPersonals has always used a dedicated third-party age verification platform. Initially we worked with BlueCheck.me and now we work with AgeSmart.eu. Having read this thread, we agree with the statements and arguments put forth by BlaireHunter_ , urlittlesecret_com , TrystMaya , and elsa_at_stg . Furthermore, for those of us platforms that are still free to publish, it’s even more challenging to run age verification and fraud prevention economically. With the stigma that this community faces constantly we certainly recognise the importance of privacy and ensure that our verification partners have state of art encryption and data isolation practices.

Me

Hi Titiana,

Thanks for replying.

Is AgeSmart double blind?

If not, would you consider using an age verifier that is?

Do you require biometric selfies?

Or do you accept some other form of verification for face in providers eg a video clip without face showing to show that the body of the advertiser matches the faceless body pics they’re using in their ad.

If not, why not?

It’s interesting that Megapersonals is using third party age verification.

Blaire from Ivy Societe mentioned “there is currently no government requirement for platforms like ours to collect government-issued identification from advertisers”.

Apparently Eros uses third party age verification.

Tryst is planning to.

Ur Little Secret say they delete ID documents after verification.

u/elsa_at_stg says they need to retain identity documents but that does seem to be incorrect given that Mega, Ivy, Tryst and Eros are all able to verify without retaining ID.

Double blind third party age check whereby the escort directory itself doesn’t need to see ID and the age verifier doesn’t need to know the ID is being used to verify for an escort directory plus offering alternatives to verification via biometric selfies for face in providers does seem to be the only sensible way to operate in 2026.

Otherwise it’s inevitable that more of us will end up irretrievably doxxed when more hacks and raids happen.

Ivy Societe

Thanks for raising these concerns. From Ivy Societe’s perspective, what we’ve experienced has been very similar to what happened with Skip the Games. The pressure has generally centred around issues such as preventing minors from accessing platforms, combating sex trafficking, concerns around hosting providers, payment processors, and other third-party service providers becoming increasingly risk-averse.

We’ve always taken these responsibilities seriously. For example, all verification images uploaded to our platform are encrypted. Even in the highly unlikely event that someone gained unauthorised access to the underlying files, they would not be viewable without the appropriate encryption keys.

Regarding age verification, the Australian regulatory landscape is a little different. In most Australian jurisdictions, there is currently no government requirement for platforms like ours to collect government-issued identification from advertisers. Instead, we’ve developed alternative verification processes designed to confirm that advertisers are adults while avoiding the unnecessary collection of highly sensitive identity documents.

We’re continually reviewing our systems and adapting as the regulatory and technology landscape evolves.

UrLittleSecret

Thanks for raising this. We think it is a fair concern, and we agree that privacy and security should be taken seriously when people are asked to provide ID, selfies, or other sensitive information.

In our view, verification is about more than simply confirming that someone is over 18. Platforms also need to consider whether the person controls the account, whether the photos belong to them, whether the advert was posted with their consent, and whether the account has later been sold, stolen, shared, or taken over.

As part of our current verification process, we ask for a government issued photo ID and a verification selfie. These are used to confirm the person’s identity and that the person verifying is the person shown on the account.
Once verification has been completed, we delete the ID document.
We do keep the verification selfie securely. This gives us something to compare against if there are suspicious changes to the account or concerns that it may have been taken over. It helps us check that the account is still being used by the same person and is not being used to post someone else’s photos.

The selfie is not accessed casually. If it needs to be checked for any reason, that access is logged so there is a record of when and why it was viewed.

We understand that keeping any personal information comes with serious responsibility. Access should be restricted, data should be handled correctly, and information should only be kept where there is a genuine reason for it.

Privacy is a must for us.

We are also currently looking into third party verification services that could be added to our platform. However, not every age or identity verification provider is willing to work with sex work, escort, or adult service platforms. Some providers have terms, risk policies, or restrictions that make this more difficult.

Using a third party provider would also not automatically remove every privacy concern. We would still need to understand what information they collect, where it is processed, how long it is retained, who can access it, how deletion works, and what happens if they suffer a breach or receive a legal request.

We also do not think a simple “over 18 verified” result solves every problem. It may confirm that someone passed an age check at a particular point, but it does not necessarily prove that the same person still controls the account months later.

Platforms still need processes for suspicious changes, stolen content, impersonation, account recovery, non consensual listings, and suspected account takeovers.

We are always looking for ways to improve our service and make verification as secure and privacy focused as possible. We are open to third party, token based, or other privacy preserving verification methods where they genuinely protect people’s data while still helping us prevent fake profiles, stolen content, scams, impersonation, and account misuse.

Me

Thank you for taking the time to reply. I really appreciate the detailed explanation.

That’s brilliant that ULS is also looking into third-party verification services. Definitely the way to go. Anything that reduces the amount of highly sensitive personal data escort directories need to collect and retain is a good thing imo.

If you delete government-issued IDs after verification, that’s great but the problem is with an anonymously owned, legal grey area operating business like an escort directory, it’s hard to trust that the deletions are really happening. No offence. It’s just I’d prefer to only give my ID to legit, out in the open businesses with their ownership on public record.

Re facial biometrics, I get why you want to verify that the account is controlled by the same person over time and to help prevent impersonation, account takeovers and stolen content.

But, I’m not convinced that permanent facial biometrics are always necessary to achieve those goals.

What about providers who deliberately never show their face in any advertising?

Could there be an alternative verification path for those providers that doesn’t require permanent retention of a facial biometric?

For example, a verification video cropped at neck level could still show the same body, tattoos, scars, clothing, room, furnishings and a handwritten verification code. Combined with third-party age verification, that seems like it could provide a reasonable level of assurance that the person controlling the account is the same person depicted in the advert, without you permanently retaining facial biometrics.

I don’t question ULS’s intentions. My concern is based on the principle of data minimisation. Every organisation that stores facial biometrics creates another potential point of compromise, whether that’s through hacking, insider access, legal demands or simply changes in ownership many years from now.

Even if ULS has excellent security and the very best intentions, risks that don’t exist can’t materialise. That’s why I think collecting and retaining the minimum amount of personal data possible should always be the goal.

If ULS introduces third-party age verification in the future, would you consider making facial biometric retention optional for providers who never publicly show their face? Or will permanent facial biometrics will always be required regardless?

Tryst

Hi Oz! Thanks for raising this.

Verification laws around the world are constantly changing, and platforms like Tryst.link have to respond to them. As you probably know, in some jurisdictions, it has become a legal requirement for adult platforms to use third-party age verification.

Tryst.link has been working in the background to ensure we meet the latest verification requirements. This includes working to introduce third-party age verification in jurisdictions as required. We’ll keep you updated as that gets closer to launch.

To make the rest of this reply clearer, I’m going to use specific phrases to describe the two types of verification we do on Tryst.link.

Age verification using your ID. This is what a third-party provider like the ones you’ve mentioned offer.

Photo verification that you are the person in your ad and running your account. This is a photo of you holding up a hand-written sign. This is something a third-party can’t help with.

How Tryst.link handles verification

Like you, we’re very privacy-conscious. We believe that the best way to keep sex workers safe is to hold as little of their data as we possibly can.

In our current verification process, we delete all photos of your ID after we confirm your age.

We do however keep the photo verification selfie we request. We do this for two reasons:

It helps us establish your identity in case you lose access to your account. This way, we can verify that you own the account without us needing to keep your ID on file.

It helps us establish that you are in control of your account, and the photos on your profile are of you.

For these reasons, photo verification will still be required even in the jurisdictions where we bring in a third-party age verification partner.

Trusting Tryst.link

I understand that it can be hard to trust a company. It’s hard to trust anyone in our industry, when stigma and criminalisation lead to sex workers being targeted by everyone from scammers through to law enforcement.

We’re not anonymous. Our owners and members of our team have been face-out across the Internet, including on our AMA post. Nico and myself are sex workers who have been active in our local sex worker communities for quite some time, and we’re here to listen to our community’s concerns.

We understand that our platform doesn’t suit every sex worker’s business model and risk tolerance. We’ve made choices that allow us to serve as many sex workers as possible, and we’re committed to continually reviewing them whenever we can.

As always, I encourage every sex worker to consider what risk management looks like in your personal context. If there’s anything else I can answer to help you make informed decisions, please let me know.

Me

Thank you for replying.

That’s awesome that you’re going to start using third-party age verification instead of asking us to directly send you our ID.

My remaining concern is the permanent retention of biometric selfies.

I understand if someone advertises with their face visible. In that situation, keeping a facial verification image for account recovery makes more sense.

But what about providers who deliberately never show their face in any advertising? Could there be an alternative verification path that doesn’t require permanent retention of a facial biometric?

What about a video selfie cropped at neck level?

You could look at tattoos or scars.

Matching outfits between the ad pics and faceless selfie video?

Matching room and furniture etc?

Ultimately, clients just want confidence that they’ll meet the person depicted in the advert. If a trusted third party has already verified age and identity, I’m not convinced a directory needs to retain a permanent facial biometric for providers who never publicly show their face.

I don’t question Tryst’s intentions. My concern is that data minimisation is generally the safest approach. Every organisation that stores facial biometrics creates another potential point of compromise, regardless of how trustworthy it is.

Even assuming Tryst does have the very best intentions, permanent retention of facial biometrics creates risks that don’t exist if those biometrics are never collected in the first place.

I genuinely appreciate that Tryst is moving towards third-party age verification and deleting IDs after verification. That’s a really positive step for keeping our identities secure and, hopefully, it will result in faster response times since professionals will be handling the age checks leaving Tryst staff more time to handle customer service.

6 month long wait times for an email reply is not great but I’m optimistic third-party age verification will be a step towards fixing whatever is broken at Tryst that’s resulting in the glacial response times.

I can see Tryst Labs and Assembly Four on the ASIC register and ABN Lookup, so it’s great that at least there’s some accountability, unlike the other big escort directories that all seem to be registered anonymously in data haven countries.

Can you please clarify who ultimately owns Assembly Four? Is the beneficial ownership public, or is it held through trusts or holding companies? Since Tryst is asking providers to trust it with biometric data, I think transparency about who ultimately controls that data is important.

I don’t mind my bank, doctor or accountant holding records that identify me because they’re heavily regulated professions with well-understood legal obligations and identifiable organisations behind them. Escort directories are a very different category of business. They operate in a legally and politically sensitive environment, making them attractive targets for hackers and potentially for legal demands. That’s why I think collecting and retaining the minimum amount of personal data possible is the safest approach for everyone.

Nothing I’ve said is intended as a criticism of Tryst specifically. In fact, based on your reply, I think Tryst is moving in a positive direction. I’m simply arguing that data minimisation should be the long-term goal for the industry.

If Tryst adopts third-party age verification, would you consider making facial biometric retention optional for providers who never publicly show their face? Or do you think permanent facial biometrics will always be required regardless of how a provider advertises?

Skip The Games

You bring up some good points, and I personally am very privacy conscious.

I am of the belief that the move towards a widespread implementation is not about “protecting the children” but removing anonymity from the Internet. I think it is a very bad thing.

Having said that, I also believe that we need to accept the world we live in and deal with it.

A few minor points, and then I will get to the meat of the matter below.

Many third party age verification services will not deal with escort sites due to legal concerns.

In terms of the security of your ID documentation and images, I would argue that third party ID verification services are far less secure places to upload your ID to than any escort site that has been around for a while and has some basic security in place. A search for “hack third party identity verification service” will show many many hacks and breaches that have taken place. The simple reason is that these services are big targets. Think of it this way, are you going to spend a lot of time and effort to try and steal tens of thousands of identify documents, or would you do it to steal millions?

In our case (and we’re finishing off re-doing our verification process right now), we have three main concerns.

To maintain our business in a legally ambiguous situation, to maintain our hosting, to maintain our DDOS protection (distributed denial of service attacks are a real issue), to maintain our domain, we must be able to show all these parties that we go to great lengths to make sure minors are not being posted on our site and that people that are posting on our site are doing so of their own free will.

I can assure you that saying, “oh we outsource our verification to this company at xxxxxx” and we get back a token that says they’re 19 or over, will NOT be enough to pass muster. It will sound like we are absconding from our responsibility. We would be shut down.

2. The amount of fraud and scammers that we deal with is a huge issue. If you do a search for ‘buy skipthegames accounts” “buy tryst accounts” etc etc, you will find both tutorials on how to setup accounts on our sites and sell them, prices for them, how to buy them, and even tutorials on how to rip off people.

A real concern all our sites face is the phenomena of “paid signups”. That is, ordinary people are being paid to sign up, and then hand over their account to a fraudster / scammer, who then rips off other people for deposits. Sometimes they use that initial person’s photos, sometimes a mix and match of that initial person’s photos and then other photos, it varies.

Another issue is the constant hacking of accounts on our site and taking them over. The main route for this right now is the generic hacking of gmail accounts. There are many fraudulent sites out there, malware apps, bad browsers plugins, etc etc and hackers that are using these tools and others to try to break into people’s gmail accounts. Once they get in, they’ll have tools that automatically go through the account and go “oh look an stg account” and then sell the account details at an automated online auction to the people that run scams on our site. (they don’t just look for our accounts, they look for bank, brokererage, crypto exchange accounts, etc etc etc) 2FA by google authenticator on our site won’t help this, as if you take over someone’s google account, you get all their 2fa codes as well.

We need to be able to stop people who are paid signups from repeatedly signing up, we need to be able to stop people who violently assault clients from repeatedly signing up.

The verification process (selfies, videos, etc etc) are a key part in our arsenal of making sure the person posting is who they say they are.

We spend more than 50% of our time dealing with this. It is both incredibly frustrating and annoying for us. And I know it becomes very annoying for providers signing up to our site that have to go through extensive verification protocols, or when their account gets taken over and they’re trying to get it back and they get frustrated by the constant questions from support.

And yes, i know at least on our end, our staff do get it wrong sometimes, but it is something we always try to get better at.

I hope that sheds a little more light on what we are dealing with on our side, and why we have the protocols in place that we do.

I’ll look again tomorrow if anyone has any follow up questions and I will answer those then.

Me

Thank you very much for replying.

You bring up some good points, and I personally am very privacy conscious.

That’s great that you’re privacy conscious but by maintaining your own anonymity via hiding the ownership of stg in shell companies and offshore registration in Malta or wherever makes you less / completely non accountable for our privacy.

I am of the belief that the move towards a widespread implementation is not about “protecting the children” but removing anonymity from the Internet. I think it is a very bad thing.

I agree.

Having said that, I also believe that we need to accept the world we live in and deal with it.

Does that really mean we have to entrust you with our ID and biometrics?

Many third party age verification services will not deal with escort sites due to legal concerns.

Some will.

In terms of the security of your ID documentation and images, I would argue that third party ID verification services are far less secure places to upload your ID to than any escort site that has been around for a while and has some basic security in place. A search for “hack third party identity verification service” will show many many hacks and breaches that have taken place.

(I did that search. Discord’s 3d party age verifier got hacked last year and hackers got 70k ID photos. that’s pretty minor considering)

The simple reason is that these services are big targets. Think of it this way, are you going to spend a lot of time and effort to try and steal tens of thousands of identify documents, or would you do it to steal millions?

3d party age verifiers are bigger targets but they’re better equipped than any escort directory to protect themselves and better motivated since that is literally their reason for existing= to age verify in a way that is less likely to expose our private data than giving our ID directly to some shady, anonymous, borderline criminal little business nominally operating out of a data haven. A bank is a bigger target than stashing cash under my mattress but my money is safer in a bank.

In our case (and we’re finishing off re-doing our verification process right now), we have three main concerns.

To maintain our business in a legally ambiguous situation, to maintain our hosting, to maintain our DDOS protection (distributed denial of service attacks are a real issue), to maintain our domain, we must be able to show all these parties that we go to great lengths to make sure minors are not being posted on our site and that people that are posting on our site are doing so of their own free will.

I can assure you that saying, “oh we outsource our verification to this company at xxxxxx” and we get back a token that says they’re 19 or over, will NOT be enough to pass muster. It will sound like we are absconding from our responsibility. We would be shut down.

Really? I have hosting, domain registration and DDOS protection and I can’t find any mention of this requirement in the terms of anything I use. 3d party age verification would be assurance enough that you’re not advertising minors. It’s enough assurance for all the other platforms that are using 3d party age verification. Why isn’t it enough in your case? How does direct ownership of ID and biometrics, as opposed to 3d party verification, tell you the person is posting of their own free will?

The amount of fraud and scammers that we deal with is a huge issue. If you do a search for ‘buy skipthegames accounts” “buy tryst accounts” etc etc, you will find both tutorials on how to setup accounts on our sites and sell them, prices for them, how to buy them, and even tutorials on how to rip off people.

Yes but why do you need to own our identities to protect against that? You have a report button don’t you? As soon as a scammer pops up, they’re going to get reported. Then investigate. If they’re a scammer, ban their IP address and payment method. Educate users to look for ads that have a personal website and socials with a long history of engagement. Very low effort ads with no website and no socials are likely to be scammers. Higher effort web presence means they almost certainly aren’t scammers. Allow people to filter stg ads to only see ads with a personal website link and links to socials.

Another issue is the constant hacking of accounts on our site and taking them over. The main route for this right now is the generic hacking of gmail accounts. There are many fraudulent sites out there, malware apps, bad browsers plugins, etc etc and hackers that are using these tools and others to try to break into people’s gmail accounts. Once they get in, they’ll have tools that automatically go through the account and go “oh look an stg account” and then sell the account details at an automated online auction to the people that run scams on our site. (they don’t just look for our accounts, they look for bank, brokererage, crypto exchange accounts, etc etc etc) 2FA by google authenticator on our site won’t help this, as if you take over someone’s google account, you get all their 2fa codes as well.

So get everyone to set up 2FA and encourage them not to use google authenticator but rather use something like Authy.

we need to be able to stop people who violently assault clients from repeatedly signing up.

Do you? How would you even know who assaults clients and how often does that happen? Why is that your responsibility?

The verification process (selfies, videos, etc etc) are a key part in our arsenal of making sure the person posting is who they say they are.

I still don’t see why you need to hold our ID. Clients want to know the person they meet will resemble the person in the pics. ok. So if the person in the pics isn’t showing their face, all the client needs to know is if our body looks the same. So a video selfie without showing our face plus 3d party age verification should be fine.

We spend more than 50% of our time dealing with this. It is both incredibly frustrating and annoying for us.

You’ll spend a lot less time if you outsource age verification to a trustworthy 3d party.

And I know it becomes very annoying for providers signing up to our site that have to go through extensive verification protocols,

It’s not just annoying, it’s terrifying to think we could be doxxed at any moment and spend the rest of our lives exposed and dealing with the consequences of that exposure with our families, friends, acquaintances, everyone who ever thinks to run a biometric scan on us, every time we try to go through passport control at an airport etc

or when their account gets taken over and they’re trying to get it back and they get frustrated by the constant questions from support. And yes, i know at least on our end, our staff do get it wrong sometimes, but it is something we always try to get better at.

If you’re doing 3d party age verification, you can spend the time you spent doing it yourself on other things like this.

I hope that sheds a little more light on what we are dealing with on our side, and why we have the protocols in place that we do.

Thanks for trying but to be honest I worry the real reason you want our ID and biometrics is either to sell them to the highest bidder, to use in legal negotiations when you’re threatened with prosecution, or because you’ve already been prosecuted and are only allowed to operate on condition that you continue handing our ID over to the feds. I know this is harsh to say but I have no idea who owns STG, where in the world they are and no recourse even if I did find out for a fact you were selling my ID.

If verification consumes over half of your operational effort, wouldn’t outsourcing the document verification component to a specialist identity provider allow your staff to focus on fraud detection, account recovery, customer support and moderation instead?

If an established 3d party identity provider verified that (1) I’m over 18, (2) the ID is genuine, (3) the person presenting it matches the ID, and (4) cryptographically attested to that fact, what specific requirement would still force SkipTheGames itself to collect and retain my passport and biometric selfies? Can you please point me to somewhere in the terms of a specific platform like your hosting, domain reg or DDOS protection where it says that you personally need to hold onto my ID and 3d party age verification is insufficient?

I don’t think many sex workers are thinking about the likes of Palantir and Clearview right now but we should be. What they’re doing now is scary. What they might be doing in another 5 years could be apocalyptic for us.

Skip The Games

First, I understand your passion, and your concerns are reasonable. If I was in your position, I would have many of the same concerns.

As a website, we try to balance the needs/wants of our business, the providers that post on our website, and the potential clients that come to our website to contact the providers that post.

Inevitably, these wants/needs clash or diverge in regards to certain points.

So we have to walk a line and try to find what will work the best, to give us the best long term chances of success.

I will address your points.

> That’s great that you’re privacy conscious but by maintaining your own anonymity via hiding the ownership of stg in shell companies and offshore registration in Malta or wherever makes you less / completely non accountable for our privacy.

I would point out that the fact that we have a private structure makes us more legally resilient (especially in terms of illegitimate shakedowns), and in my mind the fact that we are concerned about our own privacy, can also show the average person, that yes, we take privacy seriously, both our own and therefore yours.

Think of it this way. If we stated, “here our our officers, here are our addresses, here our are photos” on our about us page, would you be more or less likely to think that we are the type of people that would respect a person’s anonymity?

I, however, cannot prove a negative to you.

All I can say is that it is in the long term interest of our business to keep people’s information private. I think the length of time our website has been operative should demonstrate that we are not a ‘fly by night’ operation, and that we are here for the long term.

>> Many third party age verification services will not deal with escort sites due to legal concerns.

>Some will.

Some say they will, then we would go through a range of contract negotiations, and at the end of the negotiation phase, compliance on their side says no.
Some will even start doing business with us, then they get a few court orders, and they then go, ‘ok we don’t want to do business with you anymore, this is too much of a hassle’.

This is a real issue and it is a reality we face. We simply cannot spend the time and money to deal with the switching and negotiation costs that would happen if we took that route.

>> A search for “hack third party identity verification service” will show many many hacks and breaches that have taken place.

> (I did that search. Discord’s 3d party age verifier got hacked last year and hackers got 70k ID photos. that’s pretty minor considering)

please see some more links
https://theconversation.com/online-age-checking-is-creating-a-treasure-trove-of-data-for-hackers-268586

https://www.reddit.com/r/technology/comments/1rrc1ny/1_billion_identity_records_exposed_in_id/

https://www.brightdefense.com/news/idmerit-data-breach/

https://www.malwarebytes.com/blog/news/2026/02/age-verification-vendor-persona-left-frontend-exposed

From the above article: “To demonstrate the privacy implications, researchers took a closer look and found a publicly exposed Persona frontend on a US government–authorized server, with 2,456 accessible files.”

https://regulaforensics.com/blog/identity-verification-incidents-2025/

https://www.reddit.com/r/transferwiser/comments/1dqydvv/wise_data_breach/

Something I was not aware of until i did those searches, is how many third party verification services pass your Identity information to various different places

https://shuftipro.com/blog/kyc-data-breach-third-party-vendors/

It seems that many of these companies also sell your data to third parties as well (something that I was also not aware of).

> So get everyone to set up 2FA and encourage them not to use google authenticator but rather use something like Authy.

The average level of technological ability of the people who post on our site precludes that. It also precludes the use of enforced 2fa via app. Look at all the issues Tryst had when they started enforcing that on their site (seen on reddit discussions), and I would think that people who participate on reddit are more technically inclined than the average person.

> > we need to be able to stop people who violently assault clients from repeatedly signing up.

>Do you? How would you even know who assaults clients and how often does that happen? Why is that your responsibility?

It does not happen that often (thankfully), but it has happened. We know as we get evidence provided to us. In the case of violent assaults, it typically comes from the person who has been assaulted, and then we tell them to go to their local law enforcement and make a report and we then deal with law enforcement. In some cases people don’t want to go to law enforcement, but they may have evidence like screen shots of threatening messages back and forth etc etc.

Aside from the morality of not helping a thief (we ban non violent thieves as well) or violent person, do you think our site will do better for the 99.9% of people who are honest and hardworking if clients know we try to keep bad elements off our site, or if clients think we don’t care at all about it?

As noted at the start, this is about trying to balance the needs of different parties.

> If verification consumes over half of your operational effort, wouldn’t outsourcing the document verification component to a specialist identity provider allow your staff to focus on fraud detection, account recovery, customer support and moderation instead?

Sorry I wasn’t clear. The verification of a person is a big part of fraud control, and it is fraud control that takes up more than half of our operational effort. Fraud control is integral to verifying who owns the account.

> If you’re doing 3d party age verification, you can spend the time you spent doing it yourself on other things like this.

As above, I think that is a big part of my point. We CANNOT do this. Proving that you are who you say you are, and who is posting on our site, is a huge aspect of our business. We need to control this in order to have good results. We take a lot more time than any third party verification service would on trying to verify people correctly, trying to make sure the person who is posting is the person who verified, etc etc. We simply would not be able to do that with a third party verification service.

> Thanks for trying but to be honest I worry the real reason you want our ID and biometrics is either to sell them to the highest bidder, to use in legal negotiations when you’re threatened with prosecution, or because you’ve already been prosecuted and are only allowed to operate on condition that you continue handing our ID over to the feds.

You may not believe me, but I can assure you that “the feds” are not interested in day to day escorts. They are interested in the forced trafficking by gangs of unwilling victims, and of minors being trafficked.

There are local law enforcement operations in various cities all over the world that *would* be interested in this, but do you really think we could make money selling the IDs and personal data to local law enforcement over the long term?

A fact in favor of my point, would be that in all the cases of site shutdowns in the United States (which I think is your main concern here because of your use of the term ‘feds’), though that data was seized by the feds, *none* of the actual normal users on the sites were prosecuted. And the federal government had a trove of data from the seizing of those servers (ip address, payment etc etc information).

> Can you please point me to somewhere in the terms of a specific platform like your hosting, domain reg or DDOS protection where it says that you personally need to hold onto my ID and 3d party age verification is insufficient?

I am quite sure that that specific sentence does that exist. However, I can also assure you that all those services do not want to deal with problem customers. Every service has the right to terminate their contract with another business. As stated, we HAVE to show our service providers that we are doing everything we can to prevent minors (and instances of people being trafficked) from being on our site. Saying “we outsource that” is NOT ENOUGH. And we have had to do this in the past.

Take a look for instance at what switter went through.

> I don’t think many sex workers are thinking about the likes of Palantir and Clearview right now but we should be. What they’re doing now is scary. What they might be doing in another 5 years could be apocalyptic for us.

And this may sound a little snarky, so forgive me. But do you think a company like Palantir is more likely to have its hooks into a large third party ID verification site, or someone like us?

I also cannot prove a negative to you. How can I prove that we’re not ‘in cahoots’ with Interpol/europol/fbi/palantir etc etc. There is no way for me to do that. The only thing I can do, and I hope I have to a reasonable extent, is show you that we do care, (hopefully we do have that reputation). and that it does not make business sense for us to do what you are fearing that we will do.

Hope that answer helps.

Me

I really appreciate you taking the time to talk to me about this.

I get it that as a business decision it wouldn’t make much sense in the short term to switch to any of the third party age verification options I recommended.

It would cost money.

It probably wouldn’t result in immediate financial reward for stg in terms of people paying for upgrades.

And your paying customers, sex workers, will advertise with you no matter how disagreeable your verification process is, no mater how slow, no matter how poorly you secure your site from hackers and regardless of your willingness to hand over our identities to law enforcement, homeland security, FBI or whoever asks. Provided you have a large enough user base that advertising on your site brings in paying clients, Sws will use your platform.

Even if it takes you 6 months to reply to an email like Tryst, or you have no customer service at all like PD, or your customer service is like the gestapo like adultwork, or your likely to be doxxing us all to the feds like Eros and adultwork, we’ll give you money if you give us clients.

I hope I’m wrong, but I think that will change when a few more platforms do get hacked, or a few more raids do happen and we reach a tipping point eg where being unable to cross borders due to directories doxxing our biometrics all over the place outweighs the profit of using your site.

>I would point out that the fact that we have a private structure makes us more legally resilient (especially in terms of illegitimate shakedowns), and in my mind the fact that we are concerned about our own privacy, can also show the average person, that yes, we take privacy seriously, both our own and therefore yours.

Not really. I’d rather buy medicine from a registered and licensed pharmacist than from a guy in an ally in a trenchcoat.

>Think of it this way. If we stated, “here our our officers, here are our addresses, here our are photos” on our about us page, would you be more or less likely to think that we are the type of people that would respect a person’s anonymity?

Yes. The alternative is that you’re anonymous and I’m not and I have to give you my ID and just hope that you’ll look after it when you have zero incentive to do so and are completely unaccountable with no consequences whatsoever if you fail to do so. I know you can’t identify your real ownership or register your business anywhere that makes public your ownership like company house in UK. You’d get arrested. That’s why I suggest third party age verification.

>Some say they will, then we would go through a range of contract negotiations, and at the end of the negotiation phase, compliance on their side says no. Some will even start doing business with us, then they get a few court orders, and they then go, ‘ok we don’t want to do business with you anymore, this is too much of a hassle’.

How do you know? Have you tried? It seems to be working fine for all the adult sites that do use it.

>It does not happen that often (thankfully), but it has happened. We know as we get evidence provided to us. In the case of violent assaults, it typically comes from the person who has been assaulted, and then we tell them to go to their local law enforcement and make a report and we then deal with law enforcement. In some cases people don’t want to go to law enforcement, but they may have evidence like screen shots of threatening messages back and forth etc etc.

This does all seem very unlikely. Local law enforcement are really making that much of an effort to investigate an assault that they’re subpoenaing escort directories? Local law enforcement here don’t bother to investigate assaults, or robberies, or really investigate anything unless it’s a crime in progress and even then it’s usually all over by the time they get there.

>The verification of a person is a big part of fraud control, and it is fraud control that takes up more than half of our operational effort. Fraud control is integral to verifying who owns the account.

But “fraud” in this context means people giving you fake ID and fake selfies? Wouldn’t a third party age verifier be better qualified to detect this than you? Staying ahead of the tech people are using to circumvent your verification is surely an arms race? A consumer grade gen AI will say no if someone asks it to generate fake ID and matching fake selfies for stg, but someone who has their own LLM installed could do it. Or anyone can find someone on the dark web, or a hacker forum, or even on fiverr or upwork to do it. You might be able to detect that kind of fraud today but what about in a few months time when their tech has improved beyond your current image forensics? Better left to the professionals surely?

>Proving that you are who you say you are, and who is posting on our site, is a huge aspect of our business. We need to control this in order to have good results. We take a lot more time than any third party verification service would on trying to verify people correctly, trying to make sure the person who is posting is the person who verified, etc etc. We simply would not be able to do that with a third party verification service.

I disagree. I think using a third party age verifier plus asking people to send in video selfies of their bodies where they don’t need to show their face is enough.

>”the feds” are not interested in day to day escorts. They are interested in the forced trafficking by gangs of unwilling victims, and of minors being trafficked.

It’s true, afaik, prostitution arrests are mostly made by state and local police. But federal agencies that say they’re going after “traffickers” (usually using a vague definition of trafficker along the lines of anyone who profits from sex work that enables them to target whomever) inevitably just end up making life more difficult and dangerous for consenting adult independent providers. Ps again, third party age verifiers keep minors off your site and faceless video selfies of our bodies are enough to assure you that the person registering is the person in the ad.

>A fact in favor of my point, would be that in all the cases of site shutdowns in the United States (which I think is your main concern here because of your use of the term ‘feds’), though that data was seized by the feds, *none* of the actual normal users on the sites were prosecuted. And the federal government had a trove of data from the seizing of those servers (ip address, payment etc etc information).

Border control is the problem. I keep hearing from providers who are face in everywhere except directory verification, eg for Eros or Adultwork, who get deported, or have their esta cancelled for prostitution.

>we HAVE to show our service providers that we are doing everything we can to prevent minors (and instances of people being trafficked) from being on our site. Saying “we outsource that” is NOT ENOUGH. And we have had to do this in the past.

Does that mean you’ve already handed over all our ID and biometric selfies to various platforms to prove that you have them?

Have you ever handed over your entire database of ID and selfies to law enforcement?

Fansly uses 3d party. Crypto exchanges, gambling sites and even banks use 3d party. I think onlyfans does? And all the big porn streaming sites. If they can, why can’t you?

Good privacy practice based on data minimisation = don’t collect or retain highly sensitive data unless you genuinely need to.

Every organisation that stores passports and biometric selfies creates another potential point of compromise, whether that’s through a breach, a subpoena, an insider, a future change in ownership, or simply changes in technology that nobody can predict today.

Like you say, you can’t prove that you’re not doxxing us to Interpol/europol/fbi/palantir and I don’t expect you to.

I just don’t think escort directories are reliable custodians of one of the most sensitive categories of personal data in the first place.

We’re all better off if a specialist identity check platform can perform the verification and attest to the result without directories seeing, or holding onto, our ID or biometric selfies.

Skip The Games

> I get it that as a business decision it wouldn’t make much sense in the short term to switch to any of the third party age verification options I recommended.

>It would cost money.

I would just like to note here, that money is not the only reason, as per my previous replies.

> Even if it takes you 6 months to reply to an email like Tryst, or you have no customer service at all like PD, or your customer service is like the gestapo like adultwork, or your likely to be doxxing us all to the feds like Eros and adultwork, we’ll give you money if you give us clients.

I like to think our customer service is better than that, I’m sure some people do fall through the cracks, but we are working on it, as well as trying to increase our presence here.

>Border control is the problem. I keep hearing from providers who are face in everywhere except directory verification, eg for Eros or Adultwork, who get deported, or have their esta cancelled for prostitution.

When you say “get deported”, do you mean that ICE actually goes and searches them out and then deports them? Or that they have overstayed their tourist visas, and then run into an issue (traffic ticket, some interaction with law enforcement etc) and their immigration status is looked up?

I know some providers have issues with border control, but many do not. I think in large part this is not to do with facial recognition, but has to do with how they approach entering the United States (or other countries). Do you think it would be useful to create a helpful guide for avoiding problems when trying to enter a country? I wouldn’t want it posted here, but in the private sexworkersonly reddit I think would be more acceptable.

>> Some say they will, then we would go through a range of contract negotiations, and at the end of the negotiation phase, compliance on their side says no. Some will even start doing business with us, then they get a few court orders, and they then go, ‘ok we don’t want to do business with you anymore, this is too much of a hassle’.

> How do you know? Have you tried? It seems to be working fine for all the adult sites that do use it.

I cannot prove this to you without discussing sensitive business information. I would say however, that anyone who works on the corporate side of the adult business would agree with the gist of my statement.

In addition, I can also say that without a doubt we know more about how third party providers deal with escort sites from the business end vs anyone who has not dealt with these issues.

>> It does not happen that often (thankfully), but it has happened. We know as we get evidence provided to us. In the case of violent assaults, it typically comes from the person who has been assaulted, and then we tell them to go to their local law enforcement and make a report and we then deal with law enforcement. In some cases people don’t want to go to law enforcement, but they may have evidence like screen shots of threatening messages back and forth etc etc.

> This does all seem very unlikely. Local law enforcement are really making that much of an effort to investigate an assault that they’re subpoenaing escort directories? Local law enforcement here don’t bother to investigate assaults, or robberies, or really investigate anything unless it’s a crime in progress and even then it’s usually all over by the time they get there.

I cannot speak to your experience, but in our experience LE officers (just like people) cover the whole range, from very good to very bad. We absolutely get inquiries about this on a semi-regular basis.

I would also note, that we’ve had several instances where someone from LE will reach out to us, and ask us to post a warning about a rapist or someone who assaults sex workers on our site in a certain area. “They look like, this they have this pattern of texting and use this verbiage, may text from these numbers, etc etc”. If you have been approached by this person, please contact a LE person at lalala. In cases like this, for people in the industry that are afraid of identifying themselves as being in this line of work, we also offer to anonymously forward information to the officer.

We have helped stop violent serial rapists by doing this, so yes, there are some good LE people out there. I would clarify that I know also that there are some very bad ones out there too, and I fully understand why many people in our industry want nothing to do with LE.

>> The verification of a person is a big part of fraud control, and it is fraud control that takes up more than half of our operational effort. Fraud control is integral to verifying who owns the account.

> But “fraud” in this context means people giving you fake ID and fake selfies? Wouldn’t a third party age verifier be better qualified to detect this than you? Staying ahead of the tech people are using to circumvent your verification is surely an arms race? A consumer grade gen AI will say no if someone asks it to generate fake ID and matching fake selfies for stg, but someone who has their own LLM installed could do it. Or anyone can find someone on the dark web, or a hacker forum, or even on fiverr or upwork to do it. You might be able to detect that kind of fraud today but what about in a few months time when their tech has improved beyond your current image forensics? Better left to the professionals surely?

Fraud takes many forms, but generally speaking the fraud I am talking about is when someone signs up with the intent to commit a crime against someone looking to meet them (or is paid to sign up on our site, by someone looking to commit a crime) The most common crime is deposit theft.

I do not know what people are using to create AI generated verification photos and videos, but I can tell you that they are doing it with ID right now and also doing videos right now, and they are getting better and better at it.

I would say that

  1. the process of onboarding people is a key part of any business, and that if you want to be successful as a business, you need to control as much of the key parts of your business as possible.
  2. I think one thing that you fail to realize, is that third party Identify verification providers have a different incentive vs ourselves.

Their incentive is to process each query as fast with as minimal cost as possible, with a low degree of fraud (they will have an expected % of fraud built into their business model).

Our incentive is to make sure that the person signing up is who they say they are, and we can spend much more time on that.

Those incentives are in conflict, and both people and businesses respond to incentives.

> Does that mean you’ve already handed over all our ID and biometric selfies to various platforms to prove that you have them?

> Have you ever handed over your entire database of ID and selfies to law enforcement?

No and No.

> Fansly uses 3d party. Crypto exchanges, gambling sites and even banks use 3d party. I think onlyfans does? And all the big porn streaming sites. If they can, why can’t you?

I feel have already answered your question most thoroughly. I understand you may not like our reasoning, but I have given it.

> I just don’t think escort directories are reliable custodians of one of the most sensitive categories of personal data in the first place. We’re all better off if a specialist identity check platform can perform the verification and attest to the result without directories seeing, or holding onto, our ID or biometric selfies.

I would like to point out that a third party identify verification business is much more likely to get a court order saying “turn over all your records that you have in terms of your dealings with this illegal site” and comply with that, vs a court order of the same nature asking for all our user information that is directed towards us. That third party is going to look at that court order and calculate the cost of fighting it vs the cost of compliance. For most businesses, that decision is an easy one.

When all is said and done, I guess this is just a difference of opinion.

I have explained our reasoning behind our policies. I would hope that most people understand where we are coming from. If a person still does not want to share their face or their ID with us, I do understand that, but at least now you have a better understanding of why we are asking for it.

As I’ve mentioned before, we are trying to strike a balance between competing needs to try and make our site as successful as possible.

thank you.

In Conclusion

They all responded!

I’m very happy and grateful that all the directories I tagged responded.

It’s not often (if ever?) that representatives from multiple directories come together to have a conversation anywhere.

Getting everyone to share their point of view on this reddit post is invaluable I think.

It means the directories actually care what we, their paying customers, think about their business.

If you have an opinion, speak up and tag the reps.

Let’s get these platforms to function in a way that actually suits us.

We’re paying for them.

Let’s insist that they provide customer service, do their best to not get us doxxed, reply to all emails and process all verifications within a day or two at the most.

If you tag them and they ignore you, or they reply and they’re unreasonable, if at all possible stop using their platform.

I know the amount of clients who contact us through each ad is important, but if a platform gets us clients so we ignore all of that platform’s failings and shortcomings and tolerate them being lazy and incompetent in every possible way apart from generating client contacts for us and showing no concern at all for our privacy and data security, then they have no incentive to improve.

If one of those directories is better than the others in ways that matter to you, if possible pay for that one and not the other ones.