← back to blog

When a platform asks for your identity

The request that changes everything

You’re running a handful of accounts on a platform. Payments have gone through fine, posts are live, ads are spending. Then one day, out of nowhere, a screen appears asking for a government ID, a selfie, or a video verification. Nothing about your recent activity looks different to you. But something in the platform’s model flagged you.

This piece is about what’s actually happening when that request shows up, and what a real infrastructure stack can and can’t do about it. We run proxy and cloud-phone farms out of Singapore and manage account fleets for a living, so this isn’t theoretical. It’s also not a guide to beating verification with fake documents. Submitting a doctored ID or someone else’s identity to a platform is fraud, and we don’t cover it here or anywhere else. What we do cover is how to run multiple legitimate accounts (agency clients, multiple brands, regional storefronts, test and production environments) without the infrastructure itself being the thing that trips the alarm.

What the verification screen is actually checking

ID verification requests rarely come out of nowhere. Platforms run a scoring model in the background, and the document request is usually the visible output of a threshold being crossed, not a random check. Common triggers include:

  • Payout or spend thresholds. Ad platforms and marketplaces are required by their own payment processors and by regulation in many countries to verify identity once money moving through an account passes a certain size. This is often the least sinister trigger and has nothing to do with suspicion.
  • Device and network overlap. If several accounts share a device fingerprint, a browser fingerprint, or an IP address that’s already tied to a flagged account, the platform’s fraud model treats that overlap as a strong signal, even if every account is doing something legitimate.
  • Behavioral anomalies. Logins from a new country within minutes of a login from another, typing and click patterns that look automated, or account creation velocity that’s higher than a normal user’s, all feed into the same score.
  • Payment instrument reuse. The same card or wallet attached to accounts that otherwise look unrelated is one of the strongest correlation signals platforms have, because it’s expensive for a real user to fake.

None of these are checking “is this a real person” in isolation. They’re checking whether the pattern of signals around the account matches what the platform expects from one person running one account, or a legitimate business running a known set of accounts through a known agency relationship.

Why this hits multi-account operators harder

If you manage five accounts from the same laptop, same browser profile, same home IP, and same card, you’ve created five data points that all correlate back to a single fingerprint. That’s not a security flaw in your setup, it’s exactly how these platforms are designed to work. The correlation isn’t a bug they’re chasing, it’s the primary defense against the kind of abuse that costs them money: fake engagement, ad fraud, marketplace scams, and coordinated manipulation.

The problem is that the same correlation net catches an agency running ten client ad accounts, a seller with regional storefronts, or a creator managing brand and personal channels separately. The platform can’t always tell the difference between someone gaming the system and someone with a legitimate reason to keep accounts distinct. That’s the gap the infrastructure side of this business exists to close, not by hiding from verification, but by making sure the signals around a legitimate account actually match the story that account is supposed to tell.

What separation actually does at the technical level

An antidetect browser doesn’t fake an identity. What it does is give each account its own isolated browser profile: its own cookie jar, its own canvas and WebGL fingerprint, its own font list, timezone, and hardware-reported values, all consistent with each other rather than picked at random. A profile that claims to be a Windows machine in Jakarta but reports a timezone from Toronto and a screen resolution nobody sells is worse than no spoofing at all, because internal inconsistency is its own fingerprint. The goal of a well-built profile isn’t to look like nobody. It’s to look like one specific, coherent, ordinary device, and to look like the same one every time that account logs in.

Residential and mobile proxies do the network-layer version of the same job. A datacenter IP is trivially flagged by most fraud models because real consumer traffic almost never originates from cloud hosting ranges. A residential IP routes traffic through an actual consumer ISP connection, and a mobile IP routes it through a carrier’s cellular network, both of which are shared by thousands of real subscribers, which is exactly what makes them look ordinary. The IP has to match the geography the account claims and the account’s history. An account with a two-year history in Manila that suddenly logs in from a Frankfurt IP is a red flag regardless of what browser profile sits on top of it.

Cloud phones exist because a growing number of platforms weight mobile signals (device attestation, SIM presence, carrier metadata, app-level sensors) more heavily than anything a browser can produce. A real Android device, physically present in a datacenter, running one account with its own IMEI and its own mobile data connection, produces signals a browser fingerprint can’t replicate. This matters most for platforms built mobile-first, where a desktop-only presence already looks unusual.

None of this changes who you are to the platform. It changes whether the account’s network and device fingerprint stays internally consistent and separate from every other account you run, which is what most fraud models are actually scoring.

What a clean stack doesn’t solve

Isolation buys consistency, not immunity, and it’s worth being direct about where it stops working.

If an account genuinely crosses a payout or spend threshold that triggers mandatory KYC, no proxy or browser profile changes that requirement. The verification exists because the platform’s payment processor needs it, often for regulatory reasons that have nothing to do with fraud scoring. At that point the honest options are to complete verification with real information if the account is legitimately yours or your client’s, or to accept that the account can’t proceed further without it.

If behavior on the account itself looks automated (unnaturally fast actions, identical timing patterns across “different” accounts, engagement that doesn’t match any plausible real audience) no amount of infrastructure hygiene fixes that, because the model isn’t looking at the network layer anymore, it’s looking at what the account actually does. Warm-up matters here: an account that ramps up activity gradually, engages the way a real user would, and rests when a real user would rest, generates a behavioral history that supports the identity it’s claiming to have. An account thrown straight into high-volume activity on day one doesn’t, no matter how clean its IP is.

Where the line is

We build and sell tools that keep legitimate, separately-owned or separately-managed accounts from bleeding fingerprint data into each other. We don’t build or endorse anything designed to get a fraudulent document past a human reviewer, impersonate a real person who isn’t you or your client, or route around a verification requirement that exists for regulatory reasons. If a platform’s compliance team asks for proof of who you are because the law requires it, that request isn’t the enemy. The infrastructure question is narrower and more useful: does everything around your account, network, device, and behavior, actually match the story you’re telling, consistently, over time. That’s the part we can help with.

If you want to see how the proxy, browser, and cloud-phone side of that stack actually works before you build your own fleet on top of it, take a look at what we run day to day here.

Get new guides and videos first — join the Telegram channel.

need infra for this today?