IDMERIT
IDMERIT is a United States identity verification and compliance provider selling know your customer, know your business and anti money laundering checks through a modular set of APIs. Eleven named services make up the platform: IDMkyc for identity matching, IDMkyb for business verification, IDMaml for sanctions, politically exposed person and watchlist screening, IDMscan for identity document scanning, IDMlive for liveness and deepfake detection, IDMdevice, IDMtrust, IDMsocial, IDMautofill, IDMconnect and the IDMkyx umbrella.
Ten industries are addressed by name including banking and finance, fintech, cryptocurrency, insurance, healthcare, online gaming, telecommunications, retail, age restricted commerce and border security. The company positions data coverage rather than modelling as its differentiator, stating on its own product pages that coverage is what makes its service stand out and that its data sets it apart, drawing on relationships with official sources across more than 90 countries and citing wider figures of 190 to 195 nations and 450 data points elsewhere.
Source categories include credit files, government data, electoral rolls, insurance data, mobile records, utilities data, social network files and ecommerce information, and IDMconnect claims direct access to more than 2,300 utility providers across 40 plus countries. The described mechanism is a match rate: identity information submitted to the API triggers a query against licensed sources and the customer receives a match result rather than the underlying records, which the company says protects both the personal data in those records and the integrity of its source relationships. The service is marketed as fully automated with no human interaction in the verification path.
Capability Axes
Capability grades
15 of 15 axes rated · 2 graded A or B
A grade this index awards only nineteen times, meaning the models are genuinely peripheral, and here the vendor argues the case itself. Two headings on its primary product page state the position plainly: coverage is what makes the service stand out, and its data is what sets it apart. The mechanism described is a database match, where submitted identity information triggers a query against licensed sources across more than 90 countries and returns a match rate rather than a judgment.
The source list is a data brokerage list: credit files, government records, electoral rolls, insurance data, mobile records, utilities and social files. The automation the company markets is automation against manual review rather than inference against rules.
Held above a reject because there is a real embedded model line inside the regulated operation rather than around it: IDMscan performs document scanning and biometric authentication and IDMlive performs liveness and deepfake detection, and those carry the verification themselves where they are used. That is the Clearwater and sybrin position, a platform with a genuine embedded AI line, built at C.
This vendor markets the absence of human oversight as a product feature. A section of its product page is headed with the claim that there is no human interaction in a fully automated identity verification service, and the body states that the technology validates and authenticates identities rather than human interaction, presenting that as increasing match rates and security.
That is the weakest position on this axis: it asserts an outcome, describes no control, and explicitly forecloses the human adjudication layer that earned the highest grade awarded to any vendor in this same tier. No confidence threshold, escalation path, review queue, abstention behaviour or appeal step is described anywhere. In a product that decides whether a person is who they say they are, removing the human from the path is a design choice that requires more disclosure, not less, and none accompanies it.
No accuracy rate, no false accept or false reject figure, no benchmark, no independent testing, no evaluation methodology and no validation material for a customer's own model risk function. The comparison within this tier is stark: peers hold independent presentation attack detection testing under ISO/IEC 30107-3 on the named biometric system, and nothing equivalent was located here despite IDMlive being sold for liveness and deepfake detection.
The one quantitative claim located, that the screening tool is 100 percent accurate, is an impossible metric of the kind this index has now catalogued three times in one session, and a figure that cannot be true provides no information about the figures beside it.
No customer is named anywhere in the material located, no case study attaches a result to an institution, and no independent party has published a measured outcome. The figures that do appear are coverage counts rather than results. The one accuracy claim located is that the screening tool is 100 percent accurate, which is not a claim any verification product can substantiate and which weakens rather than supports the evidence position. A blog post about placement in a software directory listing is self published commentary on a third party listing, not evidence of an outcome.
Nothing states whether submitted identity information, scanned documents or biometric captures are retained after a check, reused, or used to train or improve the models behind document scanning, liveness or deepfake detection. The match rate architecture limits what flows outward to the customer and says nothing about what the vendor keeps.
The question is sharp here because the material in question is identity documents and facial captures belonging to people who are not the customer, submitted into a process explicitly designed to involve no human review, and because the company separately describes building a global data universe, which implies accumulation without describing its limits.
A privacy policy, a data protection compliance page and a California do not sell link, which is the ordinary floor. One genuine architectural point is recorded and worth noting: the company states that no data is ever passed from the source back to the customer, who receives only a match result, which limits onward disclosure of third party personal data held in credit files, electoral rolls and government records.
That is real data minimisation, although the stated purpose is partly commercial, protecting the integrity of the vendor's own source relationships. Beyond it nothing: no subprocessor list, no retention schedule, no deletion commitment, no data processing agreement terms and no statement of the lawful basis for querying credit and electoral data about people who did not approach this vendor.
No security certification, attestation or trust portal was located. There is a compliance page addressing data protection regulation, but nothing audited: no ISO certification, no SOC 2, no penetration testing disclosure, no encryption or access control description and no service status page. The footer carries two badges that have the visual weight of assurance and are not: a DMCA protection status marker, which is a copyright notice service, and a membership badge for a business council.
Neither attests to anything about security, and their placement where certification marks normally sit is the badge row problem in a different form. This sits well below the rest of its tier, where certification is the defining strength.
A software supplier outside the regulatory perimeter, with no licence, registration, government trust framework certification or supervised programme located. The contrast within this tier is instructive rather than incidental: identity verification is one of the few categories where genuine government standing is available, through national trust frameworks that permit statutory checks, and peers hold it. Nothing comparable appears here. The compliance material addresses the vendor's adherence to data protection regulation, which is an obligation rather than a standing.
This is a D rather than a C because the vendor does not omit the subject, it publishes a practice that raises the concern directly. A section of its product page headed on demographics states that the company integrates demographics into its identity verification services and that doing so has significantly improved its ability to identify and flag risk factors, then lists the factors it examines: geography, economic status, education, age, income and gender.
Using income, education and economic status as inputs to risk flagging is proxy discrimination by construction, since those attributes correlate strongly with characteristics that may not lawfully be used, and gender is itself a protected characteristic in most jurisdictions where this product is sold. The page does not state that these determine an outcome, and that limit is respected here, but flagging risk on the basis of a person's income and education is what it describes.
Nothing accompanies it: no fairness testing, no demographic performance breakdown, no governance framework, no statement of lawful basis, and no explanation of how the practice is reconciled with equality or automated decision making law. Silence on bias is common in this index; publishing socioeconomic and protected attributes as risk inputs is not.
Nothing states who bears the cost of a wrong determination or how a person contests one, and three published design choices compound the exposure rather than mitigating it. The path is fully automated with no human review by design. Risk flagging draws on demographic attributes including income, education and gender.
And the customer receives a match rate rather than the underlying records, so the institution refusing a person may not itself know which source or attribute produced the result. A person refused on that basis has no relationship with the vendor, no notice that an automated determination occurred, no visibility of the inputs, and no described route to challenge or correct anything.
No model provider, family or version is named for document scanning, biometric matching, liveness or deepfake detection, and no third party provider case study naming this vendor was located. The company describes its interface as proprietary and identifies its data supply chain only by category rather than by supplier, so neither the data sources nor the models behind the products are named. That is a double gap: this vendor's own stated differentiator is the breadth of its source relationships, and not one of those sources is identified.
A genuinely modular architecture, with eleven separately named and separately purchasable services that a buyer can compose, delivered API first. The most specific integration claim is IDMconnect, which states direct access to more than 2,300 utility and telecom providers across 40 plus countries, and connections at that count are a real distribution asset rather than a generic claim.
Held below an A because the depth runs upstream into data suppliers rather than into the buyer's own estate: no core banking, onboarding, case management or customer system is named as an integration target, no public API documentation, software development kit or sandbox was located, and none of the upstream data providers is identified by name.
A hosted API service with no published deployment or residency information: no cloud provider named, no region or jurisdiction stated, no single tenant or private option, and no statement of where identity records, submitted documents or biometric captures rest.
The absence carries more weight than usual because the business is built on querying national data sources under each country's own privacy legislation, so where processing occurs is a live legal question, and the material addresses which datasets may lawfully be accessed without addressing where the resulting processing happens.
No pricing published at any level and no indication of the charging basis, which matters for a modular platform of eleven separately purchasable services where a buyer cannot tell whether cost follows queries, matched records, services enabled or countries covered. Every commercial route terminates in a demo booking or a phone number. No free tier, trial or self service signup is offered.
Ten industries addressed by name with their own pages, spanning banking and finance, fintech, cryptocurrency, insurance, healthcare, online gaming, telecommunications, retail, age restricted commerce and border security, which is genuine segment breadth.
Data reach is real, with relationships across more than 90 countries including sources in markets that are hard to verify such as Brazil, India, China and South Africa, and more than 2,300 utility providers across 40 plus countries through IDMconnect. Held at B rather than A for two reasons. No customer is named at any scale, so the reach is capability rather than demonstrated adoption.
And the coverage figures are internally inconsistent across the vendor's own material, with the product page citing over 90 countries of data sources while other pages claim 190 nations and 195 countries, a factor of two apart with no explanation of what each figure counts. The substantiated number has been used here.
Alternatives to IDMERIT
The closest documented capability profiles to IDMERIT in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Documents AI Centrality and Autonomy and Oversight Model where IDMERIT does not
Documents AI Centrality where IDMERIT does not
Documents AI Centrality and Operational and Outcome Evidence where IDMERIT does not
Documents AI Centrality and Operational and Outcome Evidence, among others where IDMERIT does not
Documents AI Centrality and Model Supply Chain Disclosure where IDMERIT does not
Documents AI Centrality and Regulatory Status and Licensure where IDMERIT does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.