Entrust
Entrust sells identity verification to banks, payment companies and other regulated institutions through a named product line built on the Onfido technology it acquired in 2024. Document verification and facial biometrics run under Atlas AI for fully automated end to end checks, with a drag and drop orchestration layer letting an institution combine document checks, biometrics, trusted data sources and passive fraud signals into journeys tuned to its own risk, friction and regulatory requirements.
The position is distinctive because the parent also manufactures the card issuance infrastructure banks use, so verifying a customer and issuing them a physical debit card can happen in one continuous flow.
Capability Axes
Capability grades
15 of 15 axes rated · 6 graded A or B
Models carry the verification itself. Atlas AI is stated to power fully automated end to end identity verification, with document intelligence and facial biometrics doing the judging and passive fraud signals running alongside, and the company describes the artificial intelligence as developed in house.
Against that, the platform is explicitly a combination of models and non model components, mixing document and biometric checks with trusted data sources under a no code orchestration layer that lets an institution assemble a journey. Strip the models and that orchestration layer plus the data source connections would remain and would still be useful, which is the Alloy and Signzy position rather than the pure computer vision position HyperVerge occupies.
The architectural framing is better than most in this lane and it is published as a design principle rather than a feature. Identity verification is positioned explicitly as step up authentication for high risk or high value transactions, so the intended pattern is that friction is applied selectively where risk warrants it rather than uniformly to everyone, and the orchestration layer lets an institution tailor verification methods to individual user and market needs to meet its own risk, friction and regulatory thresholds.
That is real configurable control. What holds it below the top grade is direction. Persona earns an A because a failing applicant is routed into an additional evidence path, whereas step up here escalates into verification on risk signals rather than offering a recovery route out of a failed check, and the underlying engine is described as fully automated end to end with no manual adjudication surface named.
No accuracy figure, false match or false rejection rate, validation evidence, error analysis or model documentation was located. Award winning artificial intelligence and catching the fraud others miss are competitive claims rather than measurements, and no accredited presentation attack detection result or independent benchmark appears.
For a product whose entire function is a binary judgement about whether a person is who they claim to be, the absence of any published error rate in either direction is the central gap, and it is more conspicuous here than for a smaller vendor given the scale of the installed base.
The evidence surface is large and multiply sourced. The identity verification product is stated to serve more than 950 global businesses, and at acquisition the underlying business carried more than 1,200 customers and published annual recurring revenue above 130 million dollars, which is a figure almost nobody in this index discloses. A strategic acquirer paid a reported 650 million dollars for it after diligence, which is scrutiny of a different kind.
Prior named bank deployments are reported in trade coverage, and the banking page carries customer testimony from digital first institutions describing onboarding and sign up work, though those references are anonymised. The parent brings its own scale, with more than 2,500 staff across 150 countries, more than 30 billion payment and identity cards issued and over 100 million identities protected.
No data boundary statement was located. The company states its artificial intelligence is developed in house and that automated security defences take a layered approach to fraud detection, which describes where the models come from without describing what they learn from.
Nothing addresses whether verification attempts submitted by one institution's applicants improve models serving another, which is the standing question in this lane and one that carries weight at a footprint of 950 plus businesses, nor whether biometric captures form part of any training corpus.
No data protection agreement, retention schedule, subprocessor list or deletion commitment specific to the verification product was located. The payload is document images and facial biometrics, which is the category of personal data that cannot be reissued once exposed, and the parent states it protects more than 100 million identities without describing the terms on which any of them are held.
One indirect signal exists, since the acquired technology is described by the acquirer as having proven itself in Europe's high compliance environment, which implies practice shaped by a strict regime, but an implication drawn from an acquisition statement is not a published privacy position.
No attestation, certification, trust centre or enumerated framework specific to the identity verification product was located, and no accredited presentation attack detection certification appears, which is the assurance a buyer compares directly in this lane and which two peers publish.
The situation is unusual because the parent is itself a trust infrastructure company whose certificate business operates under formal external audit and root programme requirements, so the organisational capability plainly exists, and none of it is presented as covering this product. Assurance that exists elsewhere in a group is not assurance a buyer of this line can rely on.
Compliance is asserted repeatedly and no instrument is named. The material refers to complying with global regulations, meeting international regulations and standards, and to the technology having proven itself in a high compliance European environment, none of which identifies a supervisor, statute or admission process for the verification product.
The gap is notable because the parent's certificate business operates under formal external audit regimes and root programme requirements that are genuine passed processes, and none of that assurance transfers to this line or is claimed to. Naming compliance without naming the rule is describing the market.
The company makes an explicit fairness claim and does not evidence it. Document verification is described as powered by award winning artificial intelligence and as fair, accurate and fast globally, and fairness is exactly the property that biometric and document verification cannot be assumed to have, since demographic error differentials in face matching are the best documented in applied machine learning and document recognition degrades on identity formats from less represented jurisdictions.
No demographic performance data, per market accuracy or independent evaluation result was located. The contrast within this lane is direct: Incode and HyperVerge both hold the higher grade specifically because they submitted their face models to government evaluations that measure those differentials by design, and asserting fairness without that submission is a weaker position than saying nothing.
No guarantee, indemnity or falsifiable accuracy commitment was located. The institution holds genuine control through the orchestration layer, since it sets which checks apply to which users and can widen or narrow its own thresholds, which is challenge capability for the buyer. The party with no route is the applicant.
A person whose document is rejected or whose face fails to match is not told which system reached that conclusion, cannot see the result or the signals behind it, and no alternative evidence path or human review is described for them. Step up authentication escalates on risk rather than offering a way back from a failed check, so it does not fill that gap.
The model layer is stated to be built in house, with automated defences described as using artificial intelligence developed internally rather than licensed, which shortens the chain at the point that matters most and is the same disclosure that earns Incode its position on this axis. The commercial chain is also partly visible, with both major card networks and two major enterprise software providers named in the partner network.
What remains undisclosed is the data half: the platform explicitly draws on trusted data sources as one of its verification inputs and not one of those sources is identified, so an institution cannot establish which registries, bureaus or watchlists sit behind a decision. No subprocessor list or hosting arrangement was located.
No other identity vendor in this index occupies this position. Verification connects forward into physical card issuance, so an institution can onboard a customer, authenticate them and issue a debit card within minutes in one continuous flow, and the parent has issued more than 30 billion payment and identity cards and supplies the issuance infrastructure banks run in branches.
Beyond that the verification layer extends across the parent's identity and access management, digital signing and authentication portfolio, so the same verified identity supports account recovery, high risk transaction protection and workforce verification rather than sitting isolated at onboarding. A drag and drop orchestration studio handles the configuration, and the partner network includes both major card networks and major enterprise platforms.
No hosting provider, region selection, residency commitment or private deployment option was located for the verification product. The question is material given a footprint across more than 150 countries and a payload of biometric captures and identity documents, where transfer and localisation rules differ sharply by market, and the European heritage of the acquired technology raises rather than settles the question of where processing now occurs following integration into a United States parent.
No pricing, packaging or basis of charge is published for the identity verification line and every route in is a contact request. The question has real shape here because the product can be bought standalone or as part of a broader identity and access strategy spanning onboarding, account recovery, transaction protection, biometric authentication and digital signing, and nothing indicates how those are priced separately or together, or whether verification is charged per check or per protected customer.
Financial services is a named and separately maintained segment with its own banking page, its own customer references and a stated use case sequence specific to the industry, covering onboarding, authentication and card issuance. Coverage within it spans retail banks, digital first challengers and payments companies.
The limit is that this sits alongside government, travel, gaming, retail, healthcare and enterprise workforce verification as one vertical among several, so the product is a general identity platform with a substantial and deliberately maintained financial services practice rather than a purpose built financial institution product, which is the Persona position.
Alternatives to Entrust
The closest documented capability profiles to Entrust in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Documents Regulatory Status and Licensure where Entrust does not
A lighter documented profile than Entrust
A lighter documented profile than Entrust
Documents Regulatory Status and Licensure where Entrust does not
Stronger documented coverage on Institution and Segment Coverage
Documents AI Safety and Data Stewardship and AI Governance and Bias Disclosure where Entrust does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.