AML, KYC & Financial Crime
I

Identomat

Identomat is a Georgian American identity verification and compliance platform sold to banks, insurers, electronic money institutions, payment providers, telecom operators, gaming operators and government agencies, covering onboarding know your customer checks, operator led video verification, anti money laundering screening, business verification, age verification and transaction monitoring from a single modular platform.

It was founded in 2019 by chief executive David Lomiashvili, chief operating officer Zurab Kotaria and chief technology officer Rezo Imnadze, is incorporated in the United States with headquarters in Champaign, Illinois and its engineering base in Tbilisi, and raised the largest seed round in the history of Georgian founded startups at three point two million dollars in January 2022, with total funding reported at four point two million across two rounds and a team of roughly thirty.

The verification engine combines document capture and optical character recognition across more than eight thousand eight hundred government issued document types, near field communication chip reading, active, passive and cascading liveness detection tested to level two of the iBeta presentation attack detection programme against the relevant international standard, one to one and one to many face matching, proof of address extraction and risk scoring.

Results route automatically to approval, rejection or a manual review queue according to customer set face similarity thresholds, and a separate operator led video product provides a virtual branch office for cases that require a supervised interview. More than one hundred enterprises and government bodies are reported as customers, named ones including Bank of Georgia, TBC Bank, ProCredit Bank, Credit Agricole, Liberty, the digital bank Space, the insurer Aldagi, the Ukrainian payment institution NovaPay, the Lithuanian electronic money institution Paysera and two Georgian government ministries.

Pricing is published per verification across two priced tiers with stated monthly minimums, included volumes and a full feature comparison grid, and deployment spans public, private and hybrid cloud, hosted and on premises, with data residency selected across multiple cloud regions.

Last VerifiedAugust 20, 2026
Compare Identomat with other vendors
Founded
2019
Headquarters
Champaign, Illinois, United States
Categories
aml-kyc-financial-crime, fraud-and-transaction-risk, compliance-and-surveillance
Assessment

Capability Axes

Capability grades

15 of 15 axes rated · 10 graded A or B

AI Capability
AI Centrality
BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a rules or workflow system.
Vendor Published

Models carry the throughput across the core flow: document classification and optical character recognition over more than eight thousand eight hundred document types, digital forgery detection, active, passive and cascading liveness, one to one and one to many face matching, and a face similarity score that drives the decision.

Held at B rather than A on the same reasoning applied to iDenfy and Ondato, the two nearest indexed peers: a material part of the verification chain is deterministic rather than learned, including near field communication chip reads, machine readable zone parsing and document template validation, so stripping the models leaves a reduced but working checking pipeline rather than nothing.

Autonomy and Oversight Model
BB on Autonomy and Oversight ModelA written commitment that the models work alongside human judgment, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.
Vendor Published

The mechanism is named and positioned: a face similarity score routes each session to automatic approval, automatic rejection or a manual review band against thresholds the customer presets, and a separate operator led video product places a live human interview in the path for cases needing one.

Held at B rather than the iDenfy A because the gate is entirely customer configured with no published default, no stated minimum review band and no vendor staffed adjudication layer, so nothing prevents a buyer from setting the thresholds to approve everything. Worth recording as a favourable disclosure on the other side of the same axis: the vendor states its own staff review cases only when the customer raises a support ticket.

Model Risk Management and Transparency
BB on Model Risk Management and TransparencyReal transparency mechanisms are published, such as per alert explainability, confidence scoring or split testing, without the validation package or supervisory mapping behind them.
Vendor Published

External measurement exists and the subject of the test is identified, which is the discriminator that separated Oz Forensics from au10tix on this axis: the vendor states that its own system defeated three dimensional printed masks, silicone and paper masks, synthesised video avatars and prerecorded video in level two testing.

Caps at B for the same reason as every other proofing vendor in the index, seven of them so far: external testing attests that someone else measured the model and does nothing to help the buying institution validate it. No false accept or false reject rates are published, no model documentation, versioning or drift monitoring is described, and the ceiling is a property of the category rather than a failing of this vendor.

Operational and Outcome Evidence
AA on Operational and Outcome EvidenceNamed customers with hard performance figures and enough method to test them.
Vendor Published

Clears the A bar on a named customer with a quantified outcome attributed to a named executive: the chief marketing officer of Crocobet states that pass rate rose seventy four percent and average onboarding time fell twelvefold after integrating the interfaces.

Four further named executives are quoted, at the insurer Aldagi, the telecom operator Cellfie, an operations director and a World Bank land administration programme manager, alongside a wall of about fourteen named logos and coverage in the Financial Times.

The caveat to carry: the one quantified result belongs to a gaming operator rather than a financial institution, and the platform level figures beside it (ninety eight percent conversion, twelve hundred and sixty percent return on investment, a hundredfold faster activation) are self reported and attach to nobody.

AI Safety and Data Stewardship
CC on AI Safety and Data StewardshipGeneral assurances that do not answer the question this axis asks, which is whether one customer’s data trains models serving its competitors. Unbounded cross client learning stated with no boundary grades here too.
Vendor Published

Silent on the question the index treats as answerable and cheap: nothing states whether customer submitted identity documents, selfies or face images are used to train or improve the vendor's models, and no data separation, opt in or exclusion commitment appears anywhere in the published material. The access limitation and erasure commitments credited under privacy sit alongside this gap rather than filling it.

Against the reference set on this axis, where Mortgage Capital Trading excludes client data from the training corpus outright and AlphaSense binds its providers to zero retention, a biometrics vendor leaving the training question unanswered is a choice rather than an oversight.

Regulatory and Compliance
GLBA and Data Privacy Posture
BB on GLBA and Data Privacy PostureA substantive privacy document that reaches the product itself, short of the subprocessor list or the full data handling detail.
Vendor Published

Above the category norm on the question that matters most for a vendor holding identity documents and face images: it states that no sensitive data leaves its servers or is reached by employees without permission, and that its own staff review verification cases only when the customer raises a support ticket, which is a narrow purpose bound access commitment most of this tier leaves open.

A named data protection officer role is disclosed, retention is configurable and erasure is a product control. Held at B because retention periods are not published and the privacy commitments sit in a policy page and a pricing answer rather than in a structured privacy or trust centre.

Security Certifications and Trust Center
BB on Security Certifications and Trust CenterA recognised certification named in the vendor’s own material without the artefact, or with a scope or renewal question the buyer has to raise.
Vendor Published

Two audited certifications plus laboratory testing: a service organisation control type two report, information security management certification obtained in 2021, and iBeta level two presentation attack detection testing against the relevant international standard, with penetration test reports referenced. Held at B rather than the iDenfy A because nothing is documented to certificate number, examination period, accrediting body or trust portal level.

Two presentation faults recorded once rather than deducted twice: the badge row mixes the real certifications with a privacy statute and an electronic identification regulation, neither of which certifies anything, plus an analyst recognition badge; and the information security certification is absent from that row entirely, appearing only in a pricing page answer and a company timeline.

Regulatory Status and Licensure
CC on Regulatory Status and LicensureThe regulatory position is unstated. Most vendors in this index are technology suppliers and being unlicensed is the correct posture, so this grade records silence about the posture, not a missing licence.
Vendor Published

No licence and no supervised standing. Electronic identification regulation compliance is asserted as a badge rather than evidenced as registration, and procurement by two government ministries and a World Bank land administration programme is a customer relationship rather than a regulatory position. Open and cheap check banked for the next pass: the site footer carries a trust services statement hosted behind a document sharing link.

If that document shows registration as a trust service provider, this becomes the same finding as Authologic, whose regulatory grade moved from C to A on exactly that evidence, so the refusal here is a queued question rather than a closed one.

AI Governance and Bias Disclosure
CC on AI Governance and Bias DisclosureResponsible artificial intelligence committed to in policy language with no evaluation behind it, on a product whose bias surface is modest.
Vendor Published

Nothing published. A face matching and liveness system operating across a hundred and ninety three countries and nine thousand document types offers no demographic performance breakdown, no fairness testing, no false reject rate by cohort and no governance framework. Presentation attack detection testing measures spoof resistance, not differential accuracy across skin tone, age or gender, and the vendor holds no facial recognition vendor test placement that would speak to the latter. Graded C rather than D because the silence is absence rather than a published claim that raises the concern directly.

AI Liability and Recourse
CC on AI Liability and RecourseMechanisms that enable challenge, such as audit trails and source traceability, with nothing standing behind the output and no route for the person affected.
Vendor Published

No recourse route for the person being verified. Nothing describes what happens to a legitimate applicant wrongly rejected by the automatic threshold, no appeal or human rereview right is offered to that person as opposed to the buying institution, and no statement allocates responsibility for a false reject between the vendor and its customer.

This makes the sixth consecutive identity proofing vendor in the index to take C on this axis, which is the strongest single piece of evidence behind the finding that the tier buys its high scores from certification bodies and publishes nothing it would owe to the individual.

Integration and Deployment
Model Supply Chain Disclosure
CC on Model Supply Chain DisclosureThe architecture is described and no provider is named.
Vendor Published

No model providers, base models or third party biometric engines are named anywhere, and the models are presented as the vendor's own. Amazon Web Services is disclosed as infrastructure only. Follows the standing pattern that vendors which build rather than license can stay silent, and the absence is total rather than partial.

Core Systems and Integration Depth
BB on Core Systems and Integration DepthNamed systems or a documented public API, with the depth or the production evidence left open.
Vendor Published

Integration surface is documented and wide: representational state transfer application programming interface, web iframe and redirect, mobile software development kits for iOS, Android, Flutter and React Native, a no code workflow builder, single sign on with security assertion markup language, session transfer by quick response code, link or short message, a form fields interface, media download by interface and a sandbox account, with public documentation. No named core banking or policy administration connectors are published, which is the gap between this and an A in the category.

Deployment Model and Data Residency
BB on Deployment Model and Data ResidencyStated residency commitments or regional hosting options.
Vendor Published

Public, private and hybrid cloud, hosted and on premises are all offered, with on premises and flexible data residency named as features of the top tier, plus multi cloud data backup, configurable data retention and a data erasure control as priced line items. Processing runs on Amazon Web Services across multiple geographic regions chosen to keep data inside the customer's required boundary. Held at B because no specific regions or countries are enumerated and the residency answer routes to a sales conversation.

Commercial
Commercial Transparency
AA on Commercial TransparencyPublished per unit rates a buyer can price against before any conversation.
Vendor Published

Two tiers carry published unit prices with the terms around them: Essentials at forty five cents per verification with a hundred and fifty dollar monthly minimum including three hundred and fifty verifications, Advanced from twenty eight cents with a five hundred and twenty five dollar minimum including twelve hundred, and a third tier quoted. Beneath them a comparison grid of roughly sixty line items across three tiers marks which capabilities are included and which are metered extras.

Volume discounts are stated to exist and to be available to everyone, and the only additional charge is disclosed explicitly as value added tax, with no setup fees and no lock in. Short of the ComplyCube reference bar, which prices about twenty individual services at two tiers, but well above the category norm.

Institution and Segment Coverage
BB on Institution and Segment CoverageNamed segments with dedicated material behind part of the coverage.
Vendor Published

Broad by institution type and narrow by geography. Named financial buyers span retail banks (Bank of Georgia, TBC Bank, ProCredit Bank, Credit Agricole, Liberty), a digital bank (Space), an insurer (Aldagi), a Ukrainian payment institution (NovaPay) and a Lithuanian electronic money institution (Paysera), alongside telecom, gaming, healthcare and two Georgian government ministries.

More than one hundred enterprise and government organisations are claimed, up from over sixty reported in 2022, with document coverage across a hundred and ninety three countries. The concentration is the Caucasus, Ukraine, the Baltics and Central Asia rather than the major financial centres, which is why this is not an A.

Tracked Since Listing

What Changed

Material product, regulatory, evidence and commercial changes at Identomat, each verified against a live source and tagged to the capability axis it bears on. Funding rounds and awards are not product changes and are not logged.

Sep 4, 2026Product / capabilityPartially verified

Identomat shipped a verification update named Mercury, spanning a redesigned interface, an upgraded liveness check, more flexible document capture and review tools, cross-device functionality and support for a wider range of document types.

Bears on: AI CentralitySource
Our read on this change →Tracked since Sep 2026
Head to Head

Compared With

Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.

Alternatives to Identomat

The closest documented capability profiles to Identomat in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.

Documents AI Safety and Data Stewardship and Regulatory Status and Licensure where Identomat does not

Documents AI Safety and Data Stewardship and Regulatory Status and Licensure where Identomat does not

Documents Regulatory Status and Licensure where Identomat does not

A lighter documented profile than Identomat

A lighter documented profile than Identomat

Documents AI Safety and Data Stewardship and Regulatory Status and Licensure, among others where Identomat does not

Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

AI FinTech Index

The AI FinTech Index is an independent index that tracks changes to AI vendors in financial services. It holds 489 vendors across banking, lending, insurance, wealth, capital markets and financial crime compliance, each graded on the same 15 capability axes from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
September 5, 2026
The AI FinTech Index is an editorial reference, not a regulatory body. Vendor data is verified against published sources and public regulatory filings. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 AI FinTech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746