Digital verification is constantly evolving across the market. That pace is driven both by the need to close the gaps fraudsters exploit and by ongoing investment in new validation technologies. It was against this backdrop that FGV Direito Rio carried out an in-depth study, presenting data that points the market toward what it calls the “Nuclear Convergence Bundle”: the combination of facial biometrics, geolocation metadata, and IP address as a standard for authenticating digital contracts.
This shift is already visible in practice, and in how Brazil’s judiciary understands what constitutes reliable digital authentication. A study presented at the Digital Identity, Biometrics, and Cybersecurity Forum found that 49.7% of the electronic contracts analyzed across 21 state courts were invalidated, even when some authentication method was present.
The research, conducted by FGV Direito Rio’s E-Commerce Studies Center, analyzed 2,083 appellate rulings collected between January 2023 and September 2025. Over 33 months of real decisions, Brazil’s judiciary has been consolidating its own criteria for validating digital authorship, criteria much of the market is still working to understand.
Facial Biometrics: The Most Used and Most Challenged Method in Court
Facial biometrics is the most widely used authentication method in 19 of the 21 courts analyzed. In the courts with the largest sample sizes, the numbers are substantial: 124 occurrences at TJRN, 115 at TJCE, 108 at TJGO, and 67 at TJSP.
It’s also the method with the most volatile outcomes in the dataset, with a co-validation rate of 100% at TJAM and TJPI, 86.4% at TJMG, 80.6% at TJSP, 66.1% at TJRN, 33.3% at TJAC, and 7.4% at TJGO. The data suggests that the same method, argued with the same weight, is tied to opposite outcomes depending on the court and the factual circumstances judges weigh in each case.
In these cases, a standalone selfie shows up repeatedly among invalidated contracts. What the data shows, in practice, is that a static photo captured at sign-up doesn’t prove authorship, it only proves that someone with access to the device carried out the action. The research confirms that the judiciary reached the same conclusion.

Multifocal Convergence: The Pattern Courts Recognize
The qualitative analysis of the case set identified four lines of argument used to validate contracts. The most widespread, present in 16 of the 21 courts, is what the research calls multifocal convergence: the combination of multiple, heterogeneous authentication and traceability elements that together form a coherent chain of contextual evidence.
The concept matters because it inverts the logic most operations apply to authentication, which tends to treat each method as an independent layer: biometrics validates identity, geolocation provides context, and the IP address helps identify the device.
The judiciary, however, doesn’t see authentication that way. Its evaluation looks at the body of evidence as a whole. A single method, no matter how technically robust, generally isn’t enough to prove authorship, because it doesn’t rule out alternative explanations for who actually performed the action.
It’s precisely multifocal convergence that closes that reasoning loop: when biometrics, geolocation, IP address, and registration data all line up coherently, courts tend to conclude that only the account holder could have performed that act, at that location, with that device, at that moment.
The other three lines of argument the research identified, financial proof that credit was made available, continued use of the service, and the validity of a non-qualified electronic signature, function as reinforcing or complementary arguments.
The Nuclear Bundle: Biometrics, Geolocation, and IP
The so-called “nuclear convergence bundle” identified in validated electronic contracts follows a consistent pattern across Brazilian courts: facial biometrics or a document paired with a selfie, device geolocation, and IP address. When these three elements line up coherently, digital authentication tends to be recognized as valid in most of the judicial decisions analyzed.
In many cases, this set is further reinforced by a non-technological but factual element: proof that the contracted amount was deposited into an account belonging to the contracting party, the consumer’s silence or delay in disputing that deposit, and continued use of the service.
The logic the judiciary applies is multifactorial. Each layer of digital verification accounts for a different dimension of authorship. Facial biometrics or a document paired with a selfie help prove who carried out the action. Geolocation shows where it happened. The IP address indicates which device was used during the transaction.

The inverse pattern also shows up consistently across the decisions analyzed: breaking this “convergence bundle” is, itself, one of the reasons contracts get invalidated. Facial biometrics without geolocation. A selfie without an IP address. A cryptographic hash without identification of the device used. For the courts, a lack of correlation between elements weakens the proof of digital authorship.
In some cases, geographic mismatches serve as a standalone basis for voiding a contract. At TJSP and TJSE, for example, decisions covered by the research invalidated transactions that included biometrics, a photo, and an IP address, but whose geolocation showed the transaction happening thousands of kilometers from the address the contracting party had declared.
The TJGO case is one of the study’s most striking examples. In contracts deemed valid, researchers found only 23 instances of authentication methods and 25 evidentiary elements. In invalidated contracts, those numbers climbed to 288 authentication methods and 141 evidentiary elements. In practice, the sheer volume of authentication layers didn’t make up for the lack of coherence between the signals presented.
For the courts, what determines the validity of a contract is the evidentiary convergence between the elements presented, not simply the number of technological mechanisms used.
Diligence and Chargebacks: Who Bears the Risk When Proof Falls Short
During the debate on the research, held in May 2026 under Chatham House rules, a representative from the payments industry summed up the issue from a financial standpoint: the judiciary doesn’t just evaluate the technology used in a transaction, it evaluates, above all, the level of diligence a company demonstrated in verifying digital identity.
This logic shows up repeatedly in chargeback and digital fraud disputes. When an operation can demonstrate a consistent body of evidence about the contracting party’s authorship and intent, the transaction’s risk tends to shift away from it. When that evidence is fragmented or insufficient, the loss stays with the institution responsible for validation.
According to the forum’s discussions, the sophistication of any single tool matters less than the coherence between the signals presented. In other words, multiple disconnected authentication layers don’t necessarily add up to greater legal security.
That same view was echoed by Roberto Ferlis, VP of Legal at Certta, the verification intelligence hub, while discussing the challenges of antifraud infrastructure. “If fraud is complex enough to get past three defenses, we’ll catch it on the fourth. That’s exactly why fragmentation is so dangerous,” he said during the event.
That conclusion lines up with the research findings! While fraudsters operate in an integrated way, many companies still structure their defenses in isolated layers.
“In an environment where fraud operates continuously and automatically, the discussion shifts to infrastructure, traceability, and efficiency,” Ferlis adds.
Verification Intelligence Hub as an Answer to What Case Law Now Requires
FGV Direito Rio’s research recommends that companies reassess how they choose digital authentication methods, since it’s a strategic legal and financial decision, not just a technical one. The study advocates adopting structured digital evidentiary governance policies, with organized record preservation, auditability, and the ability to turn technical data into evidence the judiciary can actually understand.
This is exactly the logic behind how Certta supports businesses with its digital trust infrastructure. Every signal captured during the journey lets the hub produce and preserve, from the outset, the body of evidence courts have come to recognize as robust proof of digital authorship. In this model, evidence doesn’t need to be reconstructed after fraud occurs or a legal dispute arises, it’s already built into the verification process from the start.
The full study, including methodology, court-by-court analysis, and recommendations for companies and lawmakers, is available on FGV Direito Rio’s website.
Want to understand how this applies to your operation?
Talk to a Certta specialist and find out whether your operation’s verification infrastructure produces and preserves the bundle of evidence Brazilian courts recognize as proof of authorship.
FAQ
Is a selfie valid proof in a digital contract?
It depends on how it’s used. On its own, usually not. FGV Direito Rio’s research analyzed 2,083 collegiate rulings from 21 state courts and found that a selfie or simple photo submitted without supporting elements is one of the main grounds for invalidating digital contracts in Brazil’s judiciary. The problem isn’t the selfie itself: a static photo captured at sign-up only proves that someone with access to the device carried out the action. It doesn’t prove authorship. When combined with geolocation, device IP, and proof of deposit into the contracting party’s own account, the picture changes. What invalidates the contract is isolation, not the method itself.
Why are so many electronic contracts invalidated even when authentication was used?
Because authentication isn’t the same as proof of authorship. Nearly half the contracts analyzed in the FGV research were invalidated: 49.7% of 2,083 decisions. In most of these cases, some authentication method was present. What was missing was the evidentiary convergence the judiciary requires to attribute the act to a specific person. The research also found more than 100 different terms courts use to describe the same methods, which points to terminological and technical fragmentation in both the market and the judiciary itself. The result is widespread legal uncertainty: the same contract, using the same methods, can be valid in one state and invalid in another.
What is multifocal convergence?
It’s the name the FGV research gives to the pattern found in validated contracts. Instead of relying on a single, definitive method, Brazil’s judiciary has been requiring the simultaneous presence of multiple, heterogeneous elements that reinforce one another: authentication methods and evidentiary elements all pointing to the same conclusion about authorship. Multifocal convergence appears as a line of argument for validation in 16 of the 21 courts mapped, making it the most widespread pattern in the entire dataset. The logic is straightforward: the more independent the elements pointing to the same person are, the harder it is to argue that someone else acted.
What elements make up the nuclear convergence bundle?
The research identified a combination that repeats, with minimal variation, across nearly every court that applies multifocal convergence: facial biometrics or a document paired with a selfie, geolocation consistent with the contracting party’s address, the device’s IP address, and, in some cases, proof of deposit into the contracting party’s own account or use of the funds, when financial or banking services are involved. This set is called the nuclear bundle. When present and coherent, it supports validation in most courts. When fragmented, when only one or two elements are presented, it can strengthen the case for invalidation. The strength isn’t in any single element. It’s in the convergence.
How can a company structure its defenses to support the validity of digital contracts?
The FGV research and the event’s discussions point to five practical areas:
- Build the nuclear bundle from onboarding onward. Facial biometrics or a document paired with a selfie, geolocation, and device IP generally need to be present and recorded in an auditable way for every contract. Not as a checklist, but as a coherent chain of evidence.
- Treat authentication as a legal and financial decision, not a technical one. The choice of method directly affects the burden of proof in chargeback disputes and legal proceedings. Weak methods shift the risk onto the provider. Robust, combined methods shift the risk back onto whoever is disputing the transaction.
- Maintain digital evidentiary governance. Organized preservation, auditability, and the intelligibility of records matter as much as the methods themselves. A nuclear bundle that can’t be presented clearly in a dispute doesn’t hold up as a defense.
- Adapt flows for hypervulnerable consumers. In 11 of the 21 courts mapped, hypervulnerability acts as an aggravating factor in the provider’s burden of proof. Elderly and illiterate individuals receive expanded protection. Flows that don’t account for this profile, and the legal requirements that come with it, increase exposure.
- Continuously review biometric mechanisms against generative AI. Deepfakes and synthetic identities evolve faster than lawmakers can legislate. Standalone biometric verification is no longer enough. What actually provides protection is the layer of contextual traceability that no deepfake can coherently replicate.



