iDenfy
iDenfy is a Lithuanian regulatory technology company providing identity verification, business verification, anti money laundering screening and fraud prevention through a single platform and interface, sold to electronic money institutions, banks, fintechs, cryptocurrency exchanges, gaming operators and marketplaces. Founded in 2017 and led by chief executive Domantas Ciulde, it reports more than one thousand business customers, coverage of over two hundred countries and territories, support for more than sixteen thousand document types, and connections to over one hundred and eighty business registries across one hundred and twenty countries.
The architecture pairs patented three dimensional liveness detection and passive biometric verification with a twenty four hour in house review team that adjudicates flagged registrations, separating genuine submissions degraded by poor lighting or framing from real fraud attempts. Named users include the Bank of Lithuania, Mano Bank, GOAT Finance, PaySet, HollaEx, Coinmerce, Juni, Kevin, Betsafe, VFS Global and Hetzner. Commercial terms are unusually open for the category: rates are published per verification with volume bands, and customers are billed only for approved verifications rather than for every attempt.
Certification is documented to certificate number level, covering information security management certification issued by a named accredited body, a service organisation control type two report over a full twelve month examination period, and a European electronic identification conformity declaration for remote authentication assessed against the relevant regulation and technical standards.
Capability Axes
Capability grades
15 of 15 axes rated · 11 graded A or B
Models carry the throughput and a human layer sits on top of them, which is a real structural difference from the pure automation vendors in this lane. Patented three dimensional liveness detection, passive biometric verification, document authentication across more than sixteen thousand document types and automated risk scoring are all model driven.
But the company markets a twenty four hour in house review team as a differentiator, states that flagged registrations are adjudicated by human specialists who separate genuine submissions degraded by poor lighting or framing from real fraud, and describes the architecture as artificial intelligence plus human review. Strip the models and what remains is a staffed manual verification service, unscalable but real, which is why this sits a grade below Incode, Microblink and AU10TIX rather than alongside them.
The strongest oversight disclosure in this lane by a wide margin, and it is structural rather than asserted. The company names the mechanism, staffs it, and places it in the execution path: a twenty four hour in house team of specialists reviews flagged registrations before a final decision, with the stated purpose of distinguishing a genuine submission affected by capture conditions from a real fraud signal.
A second named surface monitors verification outcomes in real time and flags when approval rates drift below the customer's industry benchmark, which is continuous oversight of the system's behaviour rather than of a single case. Compare the rest of the lane, where full automation without manual review teams is the explicit pitch.
What is still missing is a customer settable confidence threshold, a published sampling rate for the review layer, and any route by which the verified person, rather than the institution, can contest an outcome.
Two of the four qualifying properties are present. External measurement exists through accredited presentation attack detection testing of the liveness layer against the international standard, reinforced by a European conformity assessment that explicitly evaluates against that same standard.
Ongoing monitoring is also shipped as a product surface: the company states its specialists monitor verifications in real time and flag when performance drifts below the customer's industry benchmark, which gives an institution a live behavioural signal across the output stream rather than a point in time claim.
It is held at the middle grade for the reason now established across this whole tier: no model documentation, no validation summary, no published error rates in either direction, no description of how drift is detected in the models themselves rather than in approval rates, and no stated position on supporting a customer's own validation. This is the fourth vendor in the lane to reach this exact ceiling.
Both routes to the top grade are met. Named customers are numerous and several are quoted by named individual and title, including the chief executive of a fintech focused bank, the chief executive of a compliance driven finance business and the co founder of a cryptocurrency exchange toolkit. The most notable reference is the Bank of Lithuania, the country's central bank, described as both a user and a partner in the electronic money institution licensing context.
Independent parties with money at stake assess the product through an accredited certification body, an auditing firm and a European testing institute. Third party review platform standing is reported as top rated in the category for four consecutive years.
Quantified outcomes are published, principally the reduction of onboarding cost by seventy to seventy five percent achieved through the approved only billing model, though that figure is a commercial saving rather than a measure of verification accuracy.
The safety half is well evidenced and independently checked. Patented three dimensional liveness detection and passive verification are covered by accredited presentation attack detection testing against the international standard, and the same standard is assessed again inside the European conformity declaration, so the anti spoofing claim rests on two separate external assessments. The staffed review layer adds a second line of defence against capture failures being misread as fraud.
The stewardship half is unaddressed rather than badly handled: no pooled data or consortium arrangement was located, which distinguishes this vendor favourably from AU10TIX, but equally nothing public states whether verification images, documents or biometric templates are used to train or improve the models, whether a customer can decline that use, or how long submitted identity data is retained.
Presentation is better than most of the lane, with stated alignment to European and Californian data protection law, regular audits of data processing practices, and an elective European data residency option. The substance a bank privacy office would need is still absent. Unlike AU10TIX in the same tier, there is no privacy management system certification, so the privacy claim rests on assertion where the security claim rests on an accredited certificate.
Nothing addresses United States state biometric privacy law, where Illinois, Texas and Washington impose separate consent, retention and destruction duties and Illinois carries a private right of action, which matters for any vendor collecting selfies and liveness video at scale. No retention period is published for identity documents, selfies or biometric templates, and there is no service provider position under United States financial privacy law.
The most granular security disclosure located anywhere in this index, documented to a level that lets a buyer verify it independently rather than take it on trust. The information security management certificate is published with its certificate number, its issuing body, and that body's national accreditation, and the scope is stated as covering development and provision of identity and business verification, fraud prevention and anti money laundering software.
Certification has been continuous since 2020 and the most recent surveillance audit is reported as finding zero non conformities. The service organisation control type two report is named with its auditing firm and a full twelve month examination period, re audited annually.
A European electronic identification conformity declaration is published with its own reference number and issuing testing institute, covering remote authentication by image identification against the relevant European regulation and two technical standards. Accredited presentation attack detection testing covers the biometric layer, and cyber insurance is carried through a named market. Publishing certificate numbers, accreditation chains and audit findings is a materially higher standard than listing badges.
iDenfy holds no financial licence, the expected posture for a technology supplier, but its regulatory footing is better evidenced than most. It holds a European electronic identification conformity declaration issued by a testing institute, assessed against the European electronic identification and trust services regulation and the associated technical standard for identity proofing, which is a formal conformity assessment of the product under law rather than a marketing claim.
Its verification of Baltic mobile identity credentials is stated to meet the high level of assurance tier under that regulation. It is a named provider to and partner of the national central bank in the context of electronic money institution licensing, and product material is written directly against know your customer, know your business and anti money laundering duties. It stops short of the top grade because no financial regulator has supervised or tested the decisioning itself, which is the bar set by CleverChain.
The most interesting C in this tier, because the architecture plausibly mitigates a known bias vector while measuring nothing. The staffed review layer exists specifically to catch submissions degraded by poor lighting or framing, and capture quality failures are a documented source of demographic disparity in facial verification, falling harder on darker skin tones and on cheaper devices. So the human layer may well reduce differential rejection. That is a mechanism, not evidence.
Nothing published measures whether it works, no demographic breakdown of approval or rejection rates is disclosed, no bias testing methodology exists, and no analysis is offered of how performance varies across the two hundred countries and sixteen thousand document types the product covers. Accredited presentation attack detection testing measures spoof resistance, which is a different question entirely from fairness.
Two features point in the right direction and neither reaches the affected person. Billing only for approved verifications places the commercial cost of a failed check on the vendor rather than the customer, which is a genuine allocation of risk and rarer than it sounds. Cyber insurance through a named market provides a financial backstop, though for data incidents rather than for wrong decisions.
What is absent is everything facing the individual: no accuracy guarantee, no remediation commitment, no published appeal route for a person whose verification is refused, no stated retention or deletion right over a rejected submission, and no allocation of responsibility between vendor and institution when an automated decision is wrong. The staffed review layer is the closest thing to recourse and it is operated for the institution's benefit, not at the person's request.
The software is described as proprietary and the liveness detection as patented, and no base model, provider, version or externally sourced component is named for any layer of the product. The pattern established across this index holds again: a proprietary claim substitutes for a disclosure.
There is no subprocessor list, no statement that no component is externally sourced, and no model or version identifier that an institution could record against a verification decision in order to reconstruct later which system produced it. This is the more notable for a vendor that documents its security certifications down to certificate numbers, which shows the disclosure capability exists and has simply not been pointed at the model layer.
Integration breadth is a stated strength and the routes are specific: application programming interface, embedded frame, mobile software development kits, native plugins, a no code shareable verification link, white labelling of the flow, and synchronisation with a large catalogue of general business applications. Customers report going live in hours to a week, and public developer documentation exists with a dedicated compliance section.
What keeps this below the top grade is that the depth runs toward general business software rather than into regulated infrastructure: nothing published describes named integration into core banking platforms, account opening systems or lending origination, and no partner directory, service status page or changelog was located.
Delivery is hosted software as a service reached through application programming interface, embedded frame, mobile software development kits and plugins. The residency position is a concrete option rather than an assurance: European data residency is offered as an elective configuration, and the company operates from and certifies within the European Union, with the information security certificate issued by a European accredited body and the electronic identification conformity assessed by a European testing institute.
Held below the top grade because specific hosting regions are not enumerated, no residency option outside Europe is described despite coverage of more than two hundred countries, data transfer mechanisms for material leaving the European Union are not set out, and there is no subprocessor list.
Exceptional for this index, where the overwhelming majority of vendors publish nothing. Rates are public and per verification, with a stated premium tier price, a volume band price, and an enterprise floor, so a buyer can size a contract before speaking to anyone. Both a pay as you go plan and an enterprise plan are described, plans can be changed by the customer from a subscription page without a sales conversation, and the pricing page explains the unit of billing directly.
Most significantly the billing model itself is disclosed and it shifts risk toward the vendor: customers are charged only for approved verifications and are not billed for failed or fraudulent attempts, with the resulting saving quantified. The company also states the specific circumstances in which it absorbs the cost of a declined attempt. Only the enterprise tier requires a quote.
Breadth of geography and document coverage is genuinely wide, spanning more than two hundred countries and territories, over sixteen thousand document types and more than one hundred and eighty business registries across one hundred and twenty countries, with a customer base above one thousand businesses.
Segment material is specific where it matters, including a dedicated treatment of electronic money institutions and their licensing obligations, and named users across banking, fintech, payments, cryptocurrency, gaming and marketplaces.
It sits below the top grade because the institutional depth is not comparable to peers in this lane: the customer base skews toward smaller and mid sized regulated businesses, the named financial institutions are a central bank and a small national bank rather than a spread across institution tiers, and there is no evidence of deployment at large multinational banks.
Compared With
Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.
Alternatives to iDenfy
The closest documented capability profiles to iDenfy in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Stronger documented coverage on Institution and Segment Coverage and Core Systems and Integration Depth
Documents GLBA and Data Privacy Posture where iDenfy does not
A lighter documented profile than iDenfy
Documents GLBA and Data Privacy Posture where iDenfy does not
Documents GLBA and Data Privacy Posture and Model Supply Chain Disclosure where iDenfy does not
Stronger documented coverage on Institution and Segment Coverage
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.